Offline authentication

What are monthly active users (MAU) in identity pricing?

Monthly active users (MAU) is a billing unit that counts the distinct users who sign in to, or authenticate with, an identity service during a month, rather than every account it stores. Vendors define the details differently, including what counts as activity, which month or window applies, and how anonymous, internal and multi-app users are counted, so compare definitions before comparing prices.

Learning objectives

After reading this article you will be able to:

  • Explain what monthly active users count in identity service pricing
  • Compare how Auth0, Google Identity Platform and Clerk define the users they bill
  • Identify the factors that change an MAU count between vendors

What MAU counts

Identity services that price by monthly active users (MAU) bill for the users who are active in a month, not for every account they store. A product with a large signed-up base and a small group of regular users pays for the regular users.

Google Cloud’s Identity Platform pricing puts it plainly: any account that has signed in within a given month is considered an active user, and inactive users are stored at no cost. Firebase’s pricing page lists monthly active users as the meter for Firebase Authentication with Identity Platform.

How vendors define it

The words “monthly active user” hide real differences. These are the definitions as each vendor’s pricing page stated them on 1 October 2026.

VendorUnitWho counts
Auth0Monthly active users”Users that authenticate in a given month for a given tenant”
Auth0, plan comparisonExternal active users”Any non-internal (non-employee) user that authenticated during a given month for a given tenant”
Google Cloud Identity PlatformMonthly active users”Any account that has signed in within a given month”
ClerkMonthly retained users”A user who visits your app in a given month at least one day after signing up”

Clerk states on the same page that its pricing is based on monthly retained users, not traditional MAU, so a person who signs up and never returns after the first day does not count.

What changes the count

When you compare two identity services, check each of these:

  • What counts as activity. Signing in, authenticating, or returning at least a day after signing up can each be the trigger. A retained-user model and a sign-in model give different numbers for the same traffic.
  • The window. “A given month” can mean a calendar month, and some vendors use a rolling period instead. Bridgefy’s offline SDK, for example, defines a MAU over a 30-day period.
  • Scope. Auth0 counts per tenant. If you run several applications or environments, find out whether one person is counted once or once per application.
  • Anonymous and guest users. Identity Platform excludes anonymous users from the count if automatic clean-up is enabled. Other services count guest sessions as users.
  • Internal users. Auth0’s plan comparison counts external active users, which excludes employees.
  • Other meters. Identity Platform charges phone and multi-factor authentication per message sent, and prices some sign-in methods, such as SAML and OpenID Connect, in a separate tier.

What MAU does not see

Under definitions based on signing in or authenticating, a user counts because they reached the identity service. A check that happens entirely between two devices, such as one phone verifying another’s signature over Bluetooth, is not a sign-in to anyone’s server, so it creates no activity for a sign-in-based meter to count. The user still counts in any month they do sign in.

Not every offline product works that way. Bridgefy counts a unique user that has interacted with your app through its SDK, and its pricing FAQ says users who never touch the offline features do not count. In that model, offline use is what drives the bill. The trade-offs are covered in how much device-to-device authentication costs.

How Offline Protocol counts OfflineID users

Offline Protocol publishes its definition in its licensing documentation: monthly active users “count each end user who signs in to an application at least once in the calendar month (UTC), whichever sign-in method they use. Each guest session counts as one user in the month it starts.” It adds that “a person who signs in to two of your applications counts once in each.”

The Free, Pro and Scale plans cost $0, $99 and $499 a month and include 1,000, 10,000 and 50,000 OfflineID monthly active users. Each user beyond the quota costs $0.02, and Enterprise volumes are set by contract. The pricing page’s own example month is a Pro plan with 2,000 users over the quota: $99 plus $40, or $139.

What happens at the quota depends on how the organization pays. With a card on file, sign-ins continue and the extra users are billed at the overage rate, up to a billing limit if one is set. A Free organization without a card stops at its quota: the first meter to reach it pauses all of its metered hosted services, OfflineID sign-ins included, until it adds a card, picks a paid plan or the next billing period starts. Local peer-to-peer traffic is never metered or paused on any plan.

Frequently asked questions

Do users who never sign in count as MAU?

Not under definitions based on signing in. Google Cloud's Identity Platform pricing says inactive users are stored at no cost, and Auth0 counts users who authenticate in a given month. Check each vendor's definition, because some count other kinds of activity.

Is MAU the only thing an identity service charges for?

Not always. Google Cloud's Identity Platform, for example, charges phone and multi-factor authentication per message sent, and Auth0 lists machine-to-machine authentication separately on its pricing page.

Sources

Build it with Offline Protocol

The licensing and hosted services page defines how OfflineID monthly active users are counted, lists each plan's quotas and overage rates, and explains warnings, billing limits and what pauses when a Free organization without a card reaches its quota.

Read licensing and hosted services