Your login page.

A hosted sign-in on your domain — email, Google, Apple — for every app you ship, wired by the AI that built the app. Users are counted and never billed. The bill doesn't move when your app starts working.

$15 a month, and it isn't just this app — every Parsons product is on the same subscription. Cancel any time. Monthly active users are metered and never billed, at every size — because auth isn't what we sell.

Works with ClaudeChatGPTCursorthe built-in chat
Real projects, real users. The console, on a phone.
auth.parsons.ai
The Auth console: nine projects, 23 users, two active this month, fourteen API keys, each project's providers and status.
The console, for when you want to look. Projects, users, keys, activity — with chat built in. Every button on it is also a tool your AI can call.
How it works

A login on your domain, from one sentence.

01

Make a project.

One per app or client. It gets a hosted login page, a key, and the providers you turn on.

Set up login for the bakery site — email and Google.
Projects 9
BKbakery-site · email · Googlelive
ILinvoice-lens · email · Google · Applelive
DMDemo videos · emaillive
9 projects · 23 users · never billed per user
02

Paste one link into your AI.

Your account comes with one private address. Paste it into Claude, ChatGPT or Cursor once, and Auth's tools are there. No AI of your own? The console has chat built in.

Your connection MCP Hub
https://mcp-hub.parsons.ai/p/prof_••••••••/mcp
ClaudeChatGPTCursorany MCP client
Paste it once. Tools you haven't granted aren't there.
03

Put it on your domain.

login.sunrisebakery.com, styled with your name and mark. Email magic links, Google, Apple. Your app gets a session it can trust.

Put the login on login.sunrisebakery.com with the bakery logo.
Tool calls your AI · just now
set_domainlogin.sunrisebakery.comDNS ready
enable_providergoogleon
set_brandingname, mark, colourdone
Live on your domain. Sessions verified in one line.
04

Watch who signs in.

Users, sign-ins, failed attempts, new devices. Rotate a key with a 24-hour overlap — but only with a person present.

Rotate the production key for invoice-lens.
rotate_project_key refused, on purpose
Here's a session-gated link. I can't rotate it for you — a human has to be present when a production key is replaced. The 24-hour overlap starts when you click.
Some things stay a person's.
What you get

One login, every app, no per-user bill.

EMEmail · magic linkon
GOGoogleon
APAppleon
01

The providers people expect

Email magic links, Google and Apple sign-in, on by a switch. Enterprise SSO when you need it, not as a tier.

BKlogin.sunrisebakery.comlive
ILauth.invoicelens.applive
02

On your domain, in your name

Hosted, but yours: your subdomain, your mark, your colour. Users never see ours.

Monthly active users
23
metered · never billed · 2 this month
03

Users counted, not charged

MAU is a number on the console, at every size. Every other auth vendor's bill goes up when your app works. Ours can't.

K1invoice-lens · productionactive
K2invoice-lens · stagingactive
K3bakery-site · rotated Sep 3expired
04

Keys with a rotation you can trust

Per project, per environment. Rotation with a 24-hour overlap — and a person in the loop for production.

Who signed in from a new device today?
Two — dana@ from an iPhone in San Diego at 9:14, and a failed attempt for ben@ from a browser in Lagos at 3:02. Want me to flag Ben's?
05

Activity you can ask about

Sign-ins, failures, new devices — answered from the log, not a chart you have to read.

RL/v2 · per key300 / 60 min
RL/v2 · per origin IP600 / 60 min
RLSign-in · per account10 / 2 min
06

Rate limits, published

"Rate-limited" is a phrase. These are the numbers — unrounded, on the details page in full — so you can check them against your traffic before you integrate.

What it can't do

It signs your users in. It cannot bill you for them.

  • ×Charge per monthly active userMAU is metered for visibility and never billed, at any size.
  • ×Rotate a production key without a personrotate_project_key hands you a session-gated link. A human clicks it.
  • ×See another project's usersUsers belong to the project. Two apps' user tables never meet.
  • Create projects, enable providers, brand the login, set the domain
  • Read users, sessions, sign-ins and failures
  • Issue and rotate keys, with an overlap
Your usersigns in on your domain
Authverifies · issues a session
Your apptrusts the session
× a bill per user · no path from here
What we holdYour users' emails and sign-in history, per project. Passwords never — magic links and OAuth only.
What it costsNothing per user. The $15 covers Auth and every other product.
What leaving doesExport users. Point your domain elsewhere.

There is no security slogan on this page and no badge we haven't earned. Everything in that list is a thing you can check; the full mechanism and every tool are on the details page.

Pricing

Fifteen dollars a month — and it isn't just this app.

Parsons Cloudmonthly
Every product, one login15.00
Auth · hosted login, providers, keys0.00
Monthly active users uncapped, never billed0.00
Projects and domains0.00
Projects unlimited0.00
Seats nobody is billed as one0.00
Total$15.00/mo
or $150 a year — two months free
Start your 14-day trial
Card at checkout · cancel any time · no free tier

Is it worth it? Start where we look worst.

Every auth vendor has a generous free tier, and for a side project you should use one. Here's what the first paid tiers publish.

Auth0 Essentials · 500 MAU$35 / mo
Clerk Pro · 10k MAU$25 / mo
Supabase Pro · 100k MAU$25 / mo
Parsons — every product$15 / mo

Ours is $15 with no MAU line at all — and it's also the host, the database and the domain the app needs. The lines above are fine until your app works; then they move. And there is no free tier because the free tier is where the per-user bill is hiding.

Set up one login, sign in on your own domain, and watch the user count that never becomes a bill.