Choose Halo when
- The directory, sessions, and audit log have to stay on your network.
- You want policies, reviews, lifecycle rules, and SSH certificates without a second SKU.
- A cloud identity contract is the thing you are trying to leave.
Compare
Halo and Okta
Okta
| Capability | Halo | Okta |
|---|---|---|
| How you run it | ||
| Licence | Apache-2.0 | Proprietary |
| Self-hosted | You run it | Cloud only |
| Hosted service | None | Okta cloud |
| Published release | Not yet | |
| Sign-in | ||
| Passkeys and security keys | ||
| OpenID Connect | ||
| SAML 2.0 | ||
| Workforce access | ||
| Conditional access | Policies | |
| Requests, reviews, lifecycle | Included | Paid add-on |
| SSH certificates | Built in | Separate product |
| SCIM | In and out | |
| LDAP | Not a directory server | Agents |
Drawn from public documentation. Halo has not published a release yet. Corrections belong in the issue tracker.
The mature Apache-2.0 identity provider. Realms, LDAP, and a Java server you operate.
Flows, forward auth, and an LDAP outpost. The core is MIT. Some features are commercial.
Multi-tenant customer identity, passkeys, and a cloud. The server is AGPL-3.0.
Hosted login for the applications you ship to customers, priced as a developer platform.