Which Base44 plan includes SSO?
Since October 1, 2026, SSO for apps is on the Enterprise plans, which Base44 calls Business and Enterprise. Neither appears on the pricing page: the public plans go from Free to Elite ($160 a month, billed annually), and Enterprise says to talk to sales for a quote.
Workspaces created before that date keep the earlier rule, Elite or higher. That’s why third-party reviews disagree on which plan you need: some were written before the change. Before talking to sales, check when your workspace was created.
One more thing to know before you ask: a “Sign in with Microsoft” button on a public plan isn’t company SSO. It accepts any Microsoft account and doesn’t remove someone who leaves.
On your own servers, sign-in is part of the app’s server, set up against your tenant. It doesn’t depend on the Base44 plan.
Workspace SSO or app SSO: which one does IT need?
Base44 has two separate features with similar names, and its docs cover them on different pages:
- Workspace SSO is for the people who build in the Base44 editor. They sign in to the workspace with their company account. Adding and removing members automatically (SCIM) is set up separately.
- App SSO is for the employees who use the published app. It supports Microsoft Entra ID, Google Workspace, Okta, GitHub and any OIDC provider. SAML isn’t listed.
For an internal app, the one IT asks about is app SSO: it decides who sees company data. Workspace SSO only controls who can edit the app.
On your own servers, the employees sign in to your server with Entra. The Base44 workspace is left to the few people who build, and they only see test data.
What Base44’s SSO docs leave out
The documentation explains how to connect the provider. It doesn’t answer four questions an IT review will ask:
- Roles. It doesn’t say whether an app role (admin, user) can come from Entra, or whether it’s set by hand inside the app.
- Leavers with an open session. To block someone it says to “remove or suspend them in your identity provider”. That stops the next sign-in. Whether a session that’s already open ends, and when, isn’t stated.
- Audit. The audit logs API is for Enterprise workspaces. It isn’t stated whether it records changes to the app’s own data.
- Sign-in domain. By default the login goes through
app.base44.comeven if the app has its own domain. There’s a setting to use your domain instead.
Context, not a warning: in July 2025, Wiz found a flaw that let anyone into private Base44 apps without signing in, SSO included. It was fixed within 24 hours. It shows that, in the cloud, the sign-in layer is the platform’s and not yours.
Entra ID sign-in on your own servers: what was tested
Keep44 moves the app’s backend to your server and adds its own sign-in layer in front of it. That layer lives outside the code Base44 syncs, so a change made in the editor can’t overwrite it. It uses OpenID Connect with PKCE, checks the token’s signature, and creates or updates the user in your database with no password.
Results of the lab test:
- Work accounts: two test users signed in with their Microsoft account, including the password change and Authenticator on first sign-in.
- Roles from Entra: one user was assigned the admin role and the other the user role. The server read the role at sign-in and enforced it (the user list loaded for the admin and was refused for the user).
- No role, no entry: an account in the directory with no app role got past Microsoft but was turned away by the app, with a message to ask an administrator.
- Offboarding: a user disabled in Entra while signed in was logged out 3.6 minutes later, with nothing touched on the server. A new sign-in was blocked by Microsoft.
- Password sign-in off: the only way in was Entra.
- A change from Base44: the text of the app’s own login screen was changed in the editor and synced to the server. Open sessions stayed valid, new sign-ins worked, and the sign-in page was still the company one.
Tested in the lab on October 7 and 8, 2026: Windows Server 2025, IIS, SQL Server, Node.js and a free Entra ID tenant, with a demo app built in Base44. Not tested yet: HTTPS (the lab ran on localhost), roles assigned by group, Okta or Google, and on-premises Active Directory. This is the setup Keep44 offers; it hasn’t run with a client yet. Base44’s own SSO wasn’t tested: it needs an Enterprise plan, and everything said about it here comes from its documentation.
What the Entra admin should expect
If you manage Entra, none of this is new. These are the details that came up in the lab, in the order they appear:
- One app registration with app roles (for example
adminanduser) and assignment required turned on, so only people you assign can sign in. - A Graph application permission (
User.Read.All, with admin consent) so the server can check every few minutes that an account is still enabled. That’s what closes open sessions. - A client secret with an expiry date. In the lab it was set to 180 days; renewing it is one command on the server. Put the date in IT’s calendar.
- MFA from the first sign-in. New tenants come with security defaults on, so users register Microsoft Authenticator the first time. Nothing to change on the app side.
- Roles by group need Entra ID P1 or P2. On the free tier, roles are assigned user by user.
- A long redirect. A guest account’s sign-in response was over 2,048 characters, the default query string limit in IIS, and the request never reached the app. Raising
maxQueryStringfixed it.
Registering the app and its roles took 20 to 30 minutes in the portal, plus one minute to configure the server. That was measured once, so take it as a rough guide.
One known gap: taking someone’s role away without disabling the account doesn’t end an open session until it expires (12 hours in the lab). Disabling the account does. If your process removes roles rather than accounts, say so in the Diagnosis.
What about on-premises Active Directory?
Most companies with an on-premises Active Directory already sync it to Entra ID (Entra Connect or the newer Cloud Sync). In that case the same sign-in works: people use the account they already have.
If the directory never touches the cloud, the option is Windows Authentication in IIS on the internal network. Keep44 hasn’t tested it in the lab yet, so it’s checked case by case in the Diagnosis, never promised.
Base44 Enterprise or your own servers?
| Option | When it fits | What stays the same |
|---|---|---|
| Enterprise plan | Sign-in is IT’s only objection, and a new vendor review isn’t a problem | The app and its data run in Base44’s cloud; production spends credits; the contract and price are set by sales |
| Your own servers | IT wants sign-in, data and backups inside its own systems, or the app has to reach internal systems | The team keeps building in Base44 (Builder plan or higher, for GitHub sync) |
On every plan except Enterprise, Base44’s license also allows company data to be used to train AI models. On your own servers that question goes away, because Base44 only sees test data. The full list of IT questions is in the Base44 security review checklist for IT, and how the move works is in the guide to running a Base44 app on-premise.
When Keep44 isn’t the answer: if your company already has a Base44 Enterprise plan, or a quote it’s happy with, and IT accepts the app in the cloud, set up Entra in Base44 following its documentation. Before signing, ask sales the four questions in what the docs leave out.
What IT needs to know
To paste into the review ticket. Each point needs a written answer before approval.
- Plan: which Base44 plan the workspace is on, and when it was created (before or after October 1, 2026).
- Which SSO: app SSO for the employees, not only workspace SSO for the builders.
- Directory: sign-in limited to your tenant, with Entra’s MFA.
- Roles: where each app role is assigned, in Entra or by hand in the app.
- Leavers: what happens to an open session when an account is disabled, and how long it lasts.
- Passwords: whether password sign-in is off, and who holds the emergency access.
- Audit: where sign-ins and changes to the app’s data are recorded.
- Secret: who renews the client secret, and when it expires.
- Owner: who maintains the app and its sign-in, and what happens if the Base44 plan changes.
If you built the app
You don’t have to rebuild it. You keep changing it in Base44 with test data, and the changes reach the company server. The login screen you designed in Base44 is replaced in production by the company sign-in. You need a Base44 plan with GitHub sync (Builder, $40 a month billed annually, or higher). Bring IT this guide and the checklist above: it answers the sign-in part of their review before they ask.
Sources
- Base44: Setting up SSO (app SSO, plans, rule for workspaces created before October 1, 2026, providers, removing users, callback domain). Accessed 10/9/2026.
- Base44: Microsoft Entra SSO (workspace SSO, SCIM set up separately). Accessed 10/9/2026.
- Base44: New plans and workspaces (Business and Enterprise as the Enterprise plans). Accessed 10/9/2026.
- Base44: Pricing (public plans and prices, Enterprise through sales, GitHub from Builder). Accessed 10/9/2026.
- Base44: Audit Logs API (Enterprise workspaces). Accessed 10/9/2026.
- Base44: Terms of Service update, June 2026 (license for training AI models). Accessed 10/8/2026.
- Wiz: critical vulnerability in Base44 (July 2025, fixed within 24 hours). Accessed 10/8/2026.
- Microsoft: Security defaults (MFA with Authenticator on new tenants). Accessed 10/9/2026.
- Microsoft: Assign users and groups to an application (group-based assignment needs P1 or P2). Accessed 10/9/2026.
- Microsoft: Entra Connect Sync (syncing on-premises Active Directory; Cloud Sync replacing it). Accessed 10/9/2026.