Why IAM & Billing at Langfuse
Your work will be the foundation everything else is built on.
Every API call, every dashboard load, every team invitation, every usage-based invoice — they all flow through the systems you'll own. Authentication, authorization, and billing aren't features at Langfuse; they're the shared platform that every product team depends on.
This is a role with unusual scope. You'll design the identity and access model that lets Fortune 50 companies manage hundreds of users across projects and environments with fine‑grained permissions. You'll build the billing infrastructure that translates billions of trace events into accurate, real‑time usage metering and invoicing. And you'll do it all in a way that works seamlessly for both Langfuse Cloud and self‑hosted deployments.
The stakes are high — get auth wrong and nothing works; get billing wrong and the business doesn’t work — but that’s exactly what makes this role rewarding. You'll own critical shared components end to end, from design through production.
Langfuse is now part of ClickHouse, and you'll be building platform infrastructure alongside a world‑class team. Few backend roles offer this combination: mission‑critical scope, open source visibility, and direct impact on how thousands of companies adopt and pay for AI tooling.
You will grow at Langfuse by
- Own authentication and identity: you'll build and evolve how users and API keys authenticate with Langfuse — supporting SSO/SAML, OAuth, API key management, and session handling. You'll make sure auth is secure, fast, and frictionless for teams of every size.
- Design fine‑grained authorization: you'll architect the permission model that lets enterprises manage complex organizational structures — projects, roles, and scoped access controls. You'll build the RBAC (and eventually ABAC) layer that product engineers rely on when shipping every new feature.
- Build usage‑based billing infrastructure: Langfuse bills on trace volume. You'll own the metering pipeline that counts events accurately at massive scale, integrates with payment providers, and generates invoices that customers trust. You'll handle plan management, entitlements, and the self‑serve upgrade flows.
- Create shared platform APIs: Auth and billing touch every surface of the product. You'll design clean, well‑documented internal APIs and abstractions that let product engineers move fast without worrying about permission checks or billing edge cases.
- Support self‑hosted flexibility: many teams run Langfuse on their own infrastructure with their own identity providers. You'll make sure our auth layer integrates cleanly with enterprise identity stacks (LDAP, OIDC, SAML).
- Scale for enterprise adoption: as more large organizations adopt Langfuse, the demands on IAM and billing grow fast — audit logging, compliance requirements, multi‑tenant isolation, complex pricing models. You'll be building ahead of that curve.
What we're looking for
- Strong backend engineer who gets excited about designing secure, reliable platform systems that other engineers build on top of.
- Experience building authentication and authorization systems — SSO/SAML, OAuth, RBAC, API key management.
- Familiarity with billing or payments infrastructure — usage‑based metering, payment provider integrations (Stripe or similar), entitlements.
- You think carefully about security, edge cases, and failure modes — especially in multi‑tenant environments.
- You organize yourself. You have strong opinions about API design, system boundaries, and how to ship shared infrastructure safely.
- Comfortable reading and writing TypeScript (our backend) and SQL.
- Interest in open source software and empathy for self‑hosted operators who need to integrate with their own identity stacks.
- Thrives in a small, accountable team where your output is visible and matters.
- CS or quantitative degree preferred.
Bonus points
- Experience building multi‑tenant SaaS platforms with enterprise identity requirements.
- Background in usage‑based billing systems or fintech infrastructure.
- Familiarity with compliance frameworks (SOC 2, GDPR) as they relate to auth and data access.
- Former founder.
#J-18808-Ljbffr