The SSO tax - charging extra for single sign-on, named by sso.tax, with SaaS entries back to 2018 - has reached self-hosted software: PLANKA removed OIDC from its free Community edition in v2.2.0 (August 9, 2026), and updating deactivates every SSO-based user. This tracker lists 11 self-hostable apps gating SSO behind a paid tier, six keeping it free - verified August 25, 2026.
On August 9, 2026, PLANKA shipped version 2.2.0 and removed OIDC single sign-on from its free Community edition, which meant anyone who updated a working board found every SSO-based user on it deactivated, admins included. Three days after the announcement, the thread on GitHub was closed and locked, sitting at 86 thumbs-down. That thread is why this page exists.
The practice has a name. sso.tax, whose entries go back to 2018, tracks SaaS vendors that treat single sign-on as a luxury add-on, and its fork ssotax.org carries the same torch. Both lists measure per-user cloud pricing, which is the right lens for SaaS and the wrong one for software you run yourself. Neither covers what hit self-hosters this year: an app that runs on your hardware, under an open license or close to one, where the login method is still the feature behind the paywall.
Nobody was keeping the list for self-hosted software. So I built it. I verified every row on this page against the vendor’s own pricing pages and repositories on August 25, 2026, and each row links its receipt. A row I could not verify that day did not ship.
What is the self-hosted SSO tax?
The SSO tax is the practice of charging extra for single sign-on. In SaaS it shows up as an enterprise tier priced far above the plan you wanted. In self-hosted software it shows up as an open-core split, where the code is free to run while SAML or OIDC login sits in a paid edition, behind a license key, or inside a subscription that can cost more per month than the hardware under it. Same tax, new venue.
Why it stings more at home than in the office is worth spelling out. Once you run five or six services, an identity provider such as Keycloak or Authentik is what turns them into one system. One account per person. One password policy, one place to enforce two-factor, one switch to cut a user off everywhere. An app that paywalls SSO opts out of that system unless you pay, and the price is usually set for companies, not for a family of four. That gap is the tax.
What counts, and what does not
A tracker like this earns links only if its rules are stated before its accusations. Here are mine.
Class A, retroactive removal. A feature that shipped in the free edition moves behind a paywall, and existing free users lose it on update. The community calls this a rug-pull. It is the most serious class because it converts deployed users into hostages of their own upgrade path, people who picked the app in good faith on the feature set it shipped with and now get to choose between paying up and rebuilding somewhere else. PLANKA’s OIDC removal is the 2026 example.
Class B, gated from day one. SSO was never free in the self-hosted edition. This is a defensible business model and most rows below sit in this class. It still belongs on the tracker, because you should price it in before you adopt the app, and because the free alternatives column exists.
Class C, the quote wall. No published price at all. You cannot know the tax without talking to sales. The original sso.tax maintains a separate list for these vendors, and the same pattern appears in self-hosted pricing.
Three things deliberately do not count. Paid support or hosting around a fully free feature is the fair way to fund open source, and the free-side table below names projects doing exactly that. Gating in a vendor’s hosted cloud while the self-hosted build stays free is a SaaS matter, already covered by sso.tax. And a free evaluation edition does not make a feature free. Mattermost’s “Entry” edition includes SAML, and Mattermost’s own pricing page describes it as a limited-use edition of Enterprise Advanced for technical evaluation.
One more fairness rule. Where a vendor grandfathers old versions, the row says so. PLANKA does not disable anything remotely, and older releases keep working. That matters, and a tracker that hides it is a rant.
SAML, OIDC, LDAP: not the same thing
Every row below names the exact protocol, because “SSO” without a protocol name is how wrong accusations happen.
- SAML 2.0. The XML-based enterprise standard. Common in corporate identity systems, heavier to implement, and the single most frequently paywalled protocol on this page.
- OIDC (OpenID Connect). The modern JSON/OAuth2-based standard. What Keycloak, Authelia, and Authentik speak natively, and what most homelab setups want.
- LDAP / Active Directory. Not SSO at all. A directory the app checks credentials against. Users still type a password into each app, and there is no single session. Several vendors sell “LDAP sync” as a separate paid feature.
- Social login. OAuth2 against Google, GitHub, or similar. Convenient, and not the same as bringing your own identity provider.
- Forward-auth. A reverse proxy asks an authenticator before passing traffic. Guards the front door without the app’s cooperation. More on its limits below.
The tracker: self-hosted apps that charge for SSO
Every row verified against the linked source on 2026-08-25. Prices are the vendor’s published numbers on that date, in the currency they publish. “Moved” means the feature left a free edition on the stated date. “Gated” means it was paid from the start as far as the vendor’s current material shows, with no claim about earlier history.
| App | What is paid | Cheapest tier with it (2026-08-25) | Class | Free route that remains | Receipt |
|---|---|---|---|---|---|
| PLANKA (kanban) | OIDC SSO, removed from Community in v2.2.0 (2026-08-09); updating deactivates SSO-only users | Pro, self-hosted €36/mo (€432/yr) | Moved (Aug 2026) | Password login; TOTP 2FA now free; stay on ≤2.1.1 unsupported; Vikunja has free OIDC | Issue #1754 · pricing |
| Mattermost (team chat) | SAML and OpenID Connect for production use sit on paid plans (the SAML docs list “Entry” too — an evaluation-only edition, see the free-route cell) | Professional and up, quote-based (“prepaid annual subscriptions”) | Gated + quote wall | Free “Entry” edition includes SAML but is “a limited-use edition … for technical evaluation” per the pricing page; Zulip ships SAML/OIDC free | SAML docs · pricing |
| Grafana (dashboards) | SAML — “Available in Grafana Enterprise and Grafana Cloud” | Enterprise, quote-based | Gated + quote wall | Generic OAuth stays in the OSS build — its docs carry no edition banner, unlike SAML’s | SAML docs · OAuth docs |
| Metabase (BI) | SAML — “only available on Pro and Enterprise plans (both self-hosted and on Metabase Cloud)” | Pro, $575/mo | Gated | Open-source edition, without SSO | SAML docs · pricing |
| Teleport (infra access) | SSO via OIDC, SAML, or Active Directory — Enterprise versions only, per vendor FAQ | Enterprise, quote-based | Gated + quote wall | Community edition (the FAQ does not enumerate its auth methods) | FAQ |
| Passbolt (passwords) | SSO (Microsoft, Google, OpenID) and LDAP provisioning at Pro; AD FS at Enterprise | Pro, $4.90/user/mo billed annually, 10-user minimum | Gated | Community edition, without SSO/LDAP; Vaultwarden documents free OIDC | Pricing |
| Bitwarden (passwords) | “Passwordless SSO integration” at Enterprise; Teams lacks it | Enterprise, $6/user/mo billed annually | Gated | Vaultwarden, unofficial, free OIDC | Business pricing |
| n8n (automation) | “SSO, SAML and LDAP” at Business tier | Business, €667/mo billed annually | Gated | Free self-hosted Community build, email login | Pricing |
| Plane (project mgmt) | SAML and OIDC implementations — the pricing table marks both Enterprise Grid only | Enterprise Grid, quote-based | Gated + quote wall | CE self-host auth is passwords and magic links; Vikunja has free OIDC | Pricing · self-host docs |
| OpenProject (project mgmt) | SSO providers (CAS, SAML, OpenID Connect, Kerberos, Okta), reserved for paid Enterprise plans | Enterprise plans, from €10.95/user/mo billed annually with 25-seat minimums | Gated | Community edition (password logins) | Pricing table |
| Seafile (file sync) | SAML 2.0 / ADFS, manual-labeled “(Pro)” | Pro edition (per-user pricing not published on checked pages) | Gated | CE keeps OAuth, Shibboleth, and remote-user; Nextcloud has an official free SSO app | Manual · SSO overview |
Two notes on reading it. The seat minimums matter more than the per-user price, because SSO on Passbolt starts at 10 paid seats — $49 a month at its listed rate even if only three people ever log in — and OpenProject’s plans carry 25-seat minimums on top of the per-user number. And a quote wall is itself data. Five of eleven rows publish no number at all.
The table is honest about what it does not know. Portainer folklore says Business Edition gates OAuth, and Portainer’s current documentation shows OAuth providers with no edition restriction, so there is no Portainer row. The same discipline removed a Rocket.Chat row from a draft of this page: their plan matrix lists basic SAML, LDAP, and custom OAuth in Community, so what they charge for is advanced identity sync, not SSO itself — that story sits in the retreats section below. Absence from this table is not an endorsement. It means I could not verify an SSO paywall from the primary source on build day.
What happened with Planka SSO
The case that made this page worth building deserves the neutral version.
On August 7, 2026, the PLANKA team posted issue #1754, announcing that OIDC/SSO would leave the Community edition with the next release. Their words were direct. “SSO was always meant to be a Pro/enterprise feature on our side.” They also cited support load, over 100 SSO setup requests a month by their count. Version 2.2.0 shipped on August 9. The thread was closed and locked on August 10, at 86 thumbs-down out of 96 reactions.
The mechanics are the sharp edge. Updating to 2.2.0 deactivates every SSO-based user, because those accounts have no password. An admin has to set passwords and reactivate them one by one. If the admin account itself was SSO-based, that person is locked out unless they create a new admin through the documented script first. The team’s own warning says to plan the migration before updating.
The fair-side ledger, stated plainly. Nothing is disabled remotely, and 2.1.1 keeps working for as long as you accept running without updates. The same release moved TOTP two-factor along with auto-logout and trusted devices from Pro into Community, so account security in the free tier went up while identity federation went out. Pro costs €36 a month self-hosted, which is priced for teams, and their stated line is that account security stays free while enterprise identity is paid.
If you run PLANKA with SSO today, the realistic options are four. Pay for Pro. Convert users to password logins plus the newly free TOTP. Freeze on 2.1.1 and accept the security trade of no updates. Or migrate boards to Vikunja, which speaks OIDC free. I have not tested a PLANKA-to-Vikunja migration, so check Vikunja’s importers against your data before committing to that path.
Self-hosted apps where SSO stays free
The counterexamples are the strongest argument that free SSO is viable. Same verification date, same receipt discipline.
| App | Free identity support (verified 2026-08-25) | Receipt |
|---|---|---|
| Zulip (team chat) | Email, LDAP/AD, SAML, OIDC, social (Google, GitHub, GitLab, Discord, Apple), JWT — no plan restrictions in the auth docs | Auth methods |
| BookStack (wiki) | OIDC “as a primary method of authentication,” SAML 2.0 and LDAP alongside | OIDC docs |
| Paperless-ngx (documents) | OIDC and social auth via django-allauth since v2.5.0, plus remote-user | Advanced usage |
| Vikunja (kanban/tasks) | OIDC against “Authentik, Keycloak or similar” | OpenID docs |
| Vaultwarden (passwords) | OIDC SSO with per-provider guides; a master password is still required | Wiki |
| Nextcloud (files+) | Official “SSO & SAML” app maintained by Nextcloud GmbH, installable from the app store | App store |
Zulip is the row I would show a vendor. A team chat server competing in the same category as Mattermost above ships SAML and OIDC free in every self-hosted deployment, LDAP too. It can be done.
We run several of these ourselves. Our Paperless-ngx setup guide and Nextcloud AIO walkthrough cover two of the six, and the self-hosted starter list puts them in context.
Your escape hatches
Run your own identity provider. Keycloak speaks OIDC free, and so do Authelia and Authentik. Our Authelia vs Authentik comparison picks between the two for a homelab, with the Authentik setup tutorial as the follow-through. Every app in the free-side table plugs into any of them.
Forward-auth for the rest, with honesty about its limits. Authelia or Authentik in front of your reverse proxy will challenge visitors before any backend sees traffic. For a single-user homelab that is often all the SSO you need. What it cannot do is put per-user identity inside an app whose native SSO is paywalled. The app still sees its own local accounts. One login at the door, separate accounts behind it. That is the honest limit, and any guide promising otherwise is selling something.
Pick apps by the auth column before you deploy. The cheapest time to avoid the SSO tax is before your data lives in the app. That is the real use of this tracker, and it pairs with our break-even calculator when the alternative is paying for the hosted product instead.
Related retreats: not SSO, same pattern
Three events, 2021 through 2026, belong in the same memory even though none is an SSO paywall. Different classes, labeled as such.
| Project | What happened | Class | Receipt |
|---|---|---|---|
| Rocket.Chat (team chat) | Advanced identity sync (role mapping, extended attribute sync, background sync) moved to paid plans in a late-September 2021 release; the announcement kept “all the basic functionalities of LDAP, SAML, Social Logins and Custom OAuth” in Community, and the current plan matrix still lists them there | Advanced-tier migration | 2021 announcement · plan matrix |
| MinIO (object storage) | Admin features stripped from the community web console between the 2025-04-22 and 2025-05-24 releases; management moved to the mc CLI or the paid AIStor product | Feature removal | Discussion #21316 · Blocks & Files |
| Cal.com (scheduling) | Announced on April 14, 2026 that the production codebase was going closed source, citing AI-assisted vulnerability discovery; a version of the codebase released to the community as Cal.diy under MIT | License retreat | Cal.com blog |
Four dated incidents on this page span 2021 through 2026. The common thread is that the sharp edge sits in the migration path, wherever the announcement lands. Watch changelogs, and treat identity features as the canary.
The maintainer’s side
This page is not an argument that maintainers owe anyone free SSO, because building and then supporting SAML against every corporate identity provider that ever shipped a quirky metadata file is genuinely expensive work that someone has to fund. PLANKA’s hundred-requests-a-month figure is their own number, and I believe the shape of it. Enterprise identity is the classic open-core line because the buyers are enterprises, and a project that funds development by charging them is behaving better than one that quietly abandons its free edition.
Paying is sometimes the right call. If a team of 30 depends on OpenProject with Okta, €10.95 per user per month is a rounding error against migration cost. What this tracker exists to catch is narrower — removals from deployed free editions and upgrade paths that deactivate users, plus security features priced behind quote walls. Those are choices, and the first table records who made them.
How this page is maintained
Each row carries the date it was verified and a link to the source that backs it. When an app changes its tiers, the row gets re-verified against that same source and the update log at the bottom of this page records the change. New incidents get a dated row when a primary source exists, and the lastmod stamp above reflects the latest pass.
Corrections are welcome, including from maintainers. If a row misstates your pricing or your history, use the contact route on our about page and it will be checked against your source and fixed. The table data is available under CC BY 4.0, the same license as our measured datasets. Cite the page, take the table.
Frequently asked questions
What is the SSO tax?
Why do open-source apps charge for SSO?
Is Planka still free?
What happened with Planka SSO?
What are free alternatives to apps that charge for SSO?
Can a reverse proxy like Authelia replace paid SSO?
Evidence ledger
- Last updated
- Methodology
- This guide was written and edited by Lowell K. Wood IV in St. Louis County, MO. It draws on 32 cited sources, listed below, each checked against the original page on the date above. Full editorial standard: methodology. Tracker rows state only what the linked primary source said on the verification date. Rows that could not be verified against a primary source that day were dropped rather than published.
- Sources
- PLANKA issue #1754 — OIDC/SSO moves to PLANKA Pro accessed 2026-08-25
- PLANKA pricing accessed 2026-08-25
- PLANKA v2.2.0 release accessed 2026-08-25
- Rocket.Chat 2021 announcement — identity management changes accessed 2026-08-25
- Rocket.Chat authentication across plans (plan matrix) accessed 2026-08-25
- Portainer OAuth authentication docs accessed 2026-08-25
- Mattermost SAML SSO documentation accessed 2026-08-25
- Mattermost pricing accessed 2026-08-25
- Grafana SAML authentication docs accessed 2026-08-25
- Grafana generic OAuth docs accessed 2026-08-25
- Metabase SAML docs accessed 2026-08-25
- Metabase pricing accessed 2026-08-25
- Teleport FAQ accessed 2026-08-25
- Passbolt pricing accessed 2026-08-25
- Bitwarden business pricing accessed 2026-08-25
- n8n pricing accessed 2026-08-25
- Plane pricing accessed 2026-08-25
- Plane self-hosting authentication docs accessed 2026-08-25
- OpenProject pricing and feature comparison accessed 2026-08-25
- Seafile admin manual — SAML 2.0 (Pro) accessed 2026-08-25
- Seafile admin manual — single sign-on overview accessed 2026-08-25
- Zulip authentication methods accessed 2026-08-25
- BookStack OIDC docs accessed 2026-08-25
- Paperless-ngx advanced usage docs (OIDC via django-allauth) accessed 2026-08-25
- Vikunja OpenID docs accessed 2026-08-25
- Vaultwarden wiki — SSO using OpenID Connect accessed 2026-08-25
- Nextcloud SSO & SAML app (official) accessed 2026-08-25
- MinIO discussion #21316 — admin features gone accessed 2026-08-25
- Blocks & Files on the MinIO community console change accessed 2026-08-25
- Cal.com — why we went closed source accessed 2026-08-25
- The SSO Wall of Shame (sso.tax) accessed 2026-08-25
- SSOtax.org Wall of Shame accessed 2026-08-25
- Update log
- 2026-08-25 — First publication. All 11 paid-tier rows, 6 free-side rows, and 3 retreat entries verified against vendor pricing pages, docs, or repositories on 2026-08-25, then re-checked by an independent cold fact-check pass before publish; two draft rows (Portainer, Rocket.Chat) were removed when vendor docs contradicted the accusation. Full receipt log kept in the site’s ops tree; corrections route below.
- Corrections
- Spotted an error or a stale number? Email hello@techfuelhq.com. Confirmed corrections are added to the update log above.