Case Study Deskcasestudydesk.com
Software — Developer ToolsSourced

Case Study: Chromatic replaces in-house SSO with WorkOS

Chromatic Case StudySourced & dated by Case Study Desk
Key facts · TL;DR
Company
Chromatic
Industry
Software — Developer Tools
Challenge
Each enterprise SSO connection took 2-4 hours to provision on an in-house Passport.js setup.
Headline result
Chromatic retired its in-house Passport.js SSO and cut 2-4 hours of manual setup per connection

Key results

2-4 hrs
Manual work per SSO connection removed
vs. in-house Passport.js
<2 wks
Migration to WorkOS
no user disruption

The challenge

Chromatic, maker of the open-source Storybook UI development platform, built its initial single sign-on support on the Passport.js library. Provisioning each enterprise SSO connection took the team 2-4 hours of manual work. Growing requests for user deprovisioning (SCIM) added lifecycle-management overhead the in-house approach did not cover.

The solution

Chromatic migrated its existing SSO connections from Passport.js to WorkOS, adopting WorkOS SSO and Directory Sync (SCIM). Identity-provider configuration and user lifecycle management were consolidated behind a single API and admin portal.

There are a ton of open source libraries that can get you the V1 for SSO, but no one has solved the complexities of SCIM.

JF
Jarel Fryer
Engineering Manager, Chromatic

The results, in context

The engineering team completed the migration in under two weeks without disrupting existing users, and removed the 2-4 hours of manual work previously required to provision each SSO connection. WorkOS additionally handled the SCIM-based deprovisioning that the in-house solution had not addressed.

Products used

WorkOS SSOWorkOS Directory Sync (SCIM)