# Multi-Tenant authentication

**URL:** <https://community.weweb.io/t/multi-tenant-authentication/8313>\
**Category:** How do I?\
**Tags:** authentication\
**Created:** [April 25, 2024, 5:25pm UTC](https://community.weweb.io/t/multi-tenant-authentication/8313 "2024-04-25T17:25:57Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![JulianW](https://avatars.discourse-cdn.com/v4/letter/j/85e7bf/32.png) [@JulianW](https://community.weweb.io/u/JulianW)\
**Post date:** [April 25, 2024, 5:25pm UTC](https://community.weweb.io/t/multi-tenant-authentication/8313/1 "2024-04-25T17:25:57Z")

</div>

We’re trying to build a multi-tenant SaaS in weweb.  
So multiple tenants would be on the SaaS. Each tenant has their own OAuth/SAML connection to their identity provider and each tenant would have their own users.  
How would I set this up in weweb?

---

<div class="post-metadata">

**Author:** ![Doc](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/doc/32/8594_2.png) [@Doc](https://community.weweb.io/u/Doc)\
**Post date:** [April 29, 2024, 3:31am UTC](https://community.weweb.io/t/multi-tenant-authentication/8313/2 "2024-04-29T03:31:36Z")

</div>

Great question, let me check with the team and get back to you ASAP with a possible solution or resource that can help you.

---

<div class="post-metadata">

**Author:** ![raydeck](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/raydeck/32/384_2.png) [@raydeck](https://community.weweb.io/u/raydeck)\
**Post date:** [April 29, 2024, 11:29am UTC](https://community.weweb.io/t/multi-tenant-authentication/8313/3 "2024-04-29T11:29:34Z")

</div>

Most of the time you would want to use a third-party auth provider to handle this higher level of complexity. [Auth0](https://auth0.com) does it out of the box, but there are others too. That reduces the surface area of how auth affects weweb to a link or embed on the login page. Subsequent pages have the token from the auth provider (or that you redeemed with the backend - like redeeming an Auth0 identity token for a Xano access token) in context to decide what actions to take/allow.

We’ve had others working multitenant deployments (including using wildcard domains) using weweb at [State Change](https://statechange.ai).

---

<div class="post-metadata">

**Author:** ![JulianW](https://avatars.discourse-cdn.com/v4/letter/j/85e7bf/32.png) [@JulianW](https://community.weweb.io/u/JulianW)\
**Post date:** [May 1, 2024, 2:11am UTC](https://community.weweb.io/t/multi-tenant-authentication/8313/4 "2024-05-01T02:11:45Z")

</div>

Thank you AWS Cogito did the trick!
