You are about to put a third party between your product and your customers’ CRMs. Every vendor will sell you “integrations in days.” The hard part is picking a platform whose pricing you can model, and one you can explain when legal asks who now holds standing access to those systems.
Direct answer: Ampersand is the strongest overall pick for a B2B SaaS team building customer-facing integrations, because it charges on data delivered rather than per connection or per customer, ships custom objects and unlimited integrations on every tier including the free one, and lets you own and export the OAuth credentials rather than locking them inside the vendor. The rest of this list covers where the other platforms fit, since the right choice depends on whether you need normalized reads, deep two-way sync, or a workflow builder your customers configure themselves.
Key takeaways
- Ampersand’s Launch tier is free with up to 5 production customers, unlimited integrations, and a 2GB one-time data credit. Catalyst is $999 a month for up to 25 production customers and 2GB a month. See withampersand.com.
- Ampersand does not bill for connections, customer accounts, integrations, token management, or custom objects. You pay for gigabytes of data delivered, including backfills. That is an unusually clean pricing model in this category.
- Merge is free for your first 3 production linked accounts, then $650 a month for up to 10, and $65 per linked account beyond that.
- Nango is open source and the most transparent on price: free for 10 connections, then $0.29 per connection, $0.72 per compute hour, and $0.50 per GB.
- Paragon and Prismatic do not publish pricing at all. Budget for a sales cycle before you can compare real numbers.
- Self-hosting is an enterprise-tier feature everywhere. Nango, Paragon, and Prismatic all offer it, and all gate it behind a custom contract.
- This is the vendor decision with the widest compliance blast radius you will make this year. The platform holds standing OAuth access to your customers’ CRMs, which makes it a subprocessor for every customer you have.
Comparison table
| Rank | Tool | Best for | Standout capability | Public pricing |
|---|---|---|---|---|
| 1 | Ampersand | SaaS teams building deep two-way integrations without enterprise pricing | Usage-based on data delivered, custom objects on every tier, portable credentials | Free Launch, $999/mo Catalyst |
| 2 | Merge | Shipping standard-field reads across a whole category fast | Unified API with a normalized schema across many providers | Free for 3 accounts, $650/mo for 10, $65/account after |
| 3 | Nango | Engineering teams that want to own the auth layer and the code | Open source, self-hostable, 900+ APIs, fully published unit pricing | Free 10 connections, $50/mo PAYG |
| 4 | Paragon | Teams that want a visual workflow builder alongside managed sync | Managed Sync, ActionKit, and Workflows in one product | Not published, quote required |
| 5 | Prismatic | Vendors whose customers configure their own integrations | Embedded marketplace plus private and GovCloud hosting | Not published, quote required |
| 6 | Building it yourself | Your first one or two integrations | No vendor in the data path, no subprocessor to disclose | Free, plus the engineering time |
How we chose
We looked at four things.
First, whether the platform handles deep two-way sync or only normalized reads, since that determines what you can actually build.
Second, whether pricing is published clearly enough to model before a sales call.
Third, how the platform handles your customers’ credentials and data, which is the part that will come back in every security review you face.
Fourth, whether a small engineering team can ship with it in days rather than quarters.
A note on your own research: this category has an unusually bad literature problem. Nearly every “best alternatives” article ranking these platforms is published by one of the platforms, including several ranking themselves first with confident architecture diagrams. Ampersand publishes a lot of them. We used each vendor’s own pricing page for numbers and have flagged where a claim comes from a vendor rather than a neutral source.
1. Ampersand: priced on what you move, not on how many customers you have
Most platforms in this category charge per connection or per connected customer, which means your integration cost scales with your customer count whether or not those customers use the integration much. Ampersand charges on gigabytes of data delivered instead. Connections, customer accounts, integrations, token management, and custom objects and fields are all explicitly not billed. Backfills count toward the data you move, not as a separate line item.
That distinction matters most at exactly the moment it hurts elsewhere: when you roll an integration out to your whole base and most customers sync a little rather than a lot.
The free Launch tier is genuinely usable for shipping, not just evaluating. It covers up to 5 production customers with unlimited integrations, the full connector catalog, bi-directional syncs, unlimited custom objects and fields, managed auth, the UI mapping library, and an AI SDK, with 3-day log retention and community support. Catalyst at $999 a month raises that to 25 production customers with 2GB a month, adds real-time syncs and custom record associations, and moves log retention to 7 days. Accelerate is custom annual pricing for up to 200 production customers with configurable sync frequencies, enterprise CRM syncs, and a 90-day sandbox. Enterprise removes the customer cap and adds permission sync, transformation functions, a hosted data store, and on-prem, VPC, or BYOC deployment.
The feature that deserves more attention than it gets: Ampersand says you can import existing OAuth credentials and export them if you leave. That is a vendor claim rather than an audited fact, but it addresses something real. In most of this category, the refresh tokens your customers granted live inside the vendor, and migrating off means asking every customer to re-authorize. Portable credentials turn a painful re-consent campaign into a data export. If you are worried about lock-in, that is the specific thing to ask about, and it applies to every vendor on this list.
There is also a startup program, which is worth an email if the $999 step feels steep for where you are.
The honest tradeoffs: the tiers are gated on production customer counts, so the jump from 5 to 25 to 200 can force an upgrade before your data volume does. Real-time sync is a Catalyst feature, not a Launch one, so free-tier syncs are scheduled. And the hosted data store, which is what you want if you need to hold the synced records yourself rather than proxy them, sits at Enterprise.
One thing to check before you sign: Ampersand’s pricing page lists access to SOC 2 and other compliance reports as a Catalyst-tier feature, not something on Launch. Ampersand claims SOC 2 Type II, GDPR, and ISO 27001 on its own site and runs a trust center at trust.withampersand.com. Pull the actual report rather than trusting the claim, and confirm whether you can read it on the free tier. Your first enterprise customer will ask for it.
- Best for: B2B SaaS teams building real two-way integrations with CRMs and ERPs, especially where customers have custom objects and fields.
- Who should pick something else: teams that need normalized read access across an entire category quickly and do not care about custom objects. Merge ships that faster.
- Pricing: Launch free, Catalyst $999/month, Accelerate and Enterprise custom, all usage-based on data delivered (withampersand.com/pricing).
2. Merge: one schema across a whole category
Merge’s approach is different in kind. Instead of giving you access to each provider’s API, it normalizes many providers behind one schema, so you write against a single “HRIS” or “CRM” or “ticketing” interface and get dozens of integrations. When your customers use standard fields, this is by far the fastest way to ship breadth.
Pricing is the most transparent of the fully managed options at the entry point: your first 3 production linked accounts are free, then $650 a month covers up to 10, with $65 per linked account after that. Launch caps you at 100 requests a minute with 3-day log retention. Professional and Enterprise are contract-based and add custom fields, field-level scopes, configurable sync frequencies, higher rate limits, longer retention, and an audit trail at the top.
The tradeoff is inherent to the model. A normalized schema is an abstraction, and abstractions leak. The moment a customer wants their custom Salesforce object synced, or a field the common schema does not represent, you are outside what the unified API gives you cleanly. Merge has custom field support on Professional, but the architecture is optimized for standard fields.
- Best for: covering an entire category, particularly HRIS or accounting, where standard fields carry most of the value.
- Who should pick something else: teams whose customers live in customized CRM instances, which in enterprise sales is most of them.
- Pricing: free for 3 production linked accounts, $650/month up to 10, $65 per additional account, Professional and Enterprise contract-based (merge.dev).
3. Nango: open source, and you can run it yourself
Nango is the option for teams that would rather own this layer than rent it. It is open source, covers 900 or more APIs and MCP servers with 6,000 or more pre-built tools, triggers, and syncs, and publishes its unit economics openly: free for 10 connections with 10 compute hours and 10GB a month, then $50 a month pay-as-you-go at $0.29 per connection, $0.72 per compute hour, and $0.50 per GB.
For a compliance-minded reader, the interesting part is the Enterprise tier: self-hosting and bring-your-own-cloud in AWS, GCP, or Azure, plus HIPAA with a BAA, SAML SSO, and SCIM. If your customers’ data cannot leave your infrastructure, this is the shortest path to that outcome without building from scratch.
The tradeoff: you build more. Nango gives you a strong auth and sync layer and leaves the orchestration to you. Vendors who compete with it describe this as “you build your own sync infrastructure,” which is roughly fair.
- Best for: engineering teams with the appetite to own integration infrastructure, or anyone with a hard requirement that credentials stay in their own cloud.
- Who should pick something else: a small team that wants to ship three CRM integrations this month and move on.
- Pricing: free for 10 connections, $50/month pay-as-you-go with published unit rates, Enterprise custom with self-hosting and BYOC (nango.dev).
4. Paragon: managed sync plus a workflow builder
Paragon bundles three things: Managed Sync for keeping data in step, ActionKit for exposing provider actions to your product or your AI agents, and Workflows for visual trigger-and-action automation. Auth is fully managed, and you can embed the SDK or run it headless.
Billing is per Connected User, meaning the number of customer organizations using your integrations, which is the model Ampersand deliberately avoids. Whether that is better or worse depends entirely on your usage shape: heavy sync across few customers favors Connected Users, light sync across many favors data volume.
Enterprise adds self-host and forward-deploy options, dynamic field mapping, SAML SSO, SLAs, and professional services.
The catch: no published pricing at any tier. There is a free trial, but you cannot model cost before talking to sales.
- Best for: teams that want a visual workflow layer their solutions engineers can use, alongside managed sync.
- Who should pick something else: anyone who needs to forecast integration COGS before committing.
- Pricing: not published, quote required (useparagon.com).
5. Prismatic: for when your customers do the configuring
Prismatic’s distinguishing feature is the embedded integration marketplace: your customers browse, enable, and configure integrations themselves inside your product. It supports both code-first and low-code building, has MCP server support, and explicitly never bills on API calls or executions, which removes a whole class of budget surprise.
Enterprise adds high execution concurrency, private and GovCloud hosting, an embedded workflow builder, on-prem connectivity, SSO, and custom log retention. GovCloud and on-prem connectivity are the differentiators here, and they matter if you sell into public sector or into customers running things in their own data centers.
The catch: same as Paragon, no published pricing. The model is volume per-instance, and you will need a demo to learn what that costs.
- Best for: vendors whose customers expect self-serve integration setup, and anyone with public sector or on-prem requirements.
- Who should pick something else: small teams that want to ship a Salesforce sync this sprint without a procurement process.
- Pricing: not published, quote required (prismatic.io).
6. Building it yourself: correct for longer than vendors admit
Your first integration does not need a platform. One OAuth flow, a token refresh job, a webhook handler, and a mapping table is a week of work for a competent engineer, and you will understand your own integration better for having built it.
The point where this stops being the right answer is specific and worth naming, because most teams pass it without noticing. You need a platform when you are maintaining more than two or three providers, when token refresh failures start generating support tickets, when customers ask for field mapping you have to configure by hand, or when the second engineer has to learn the integration code and cannot.
There is also a compliance argument for building, and it is real: no vendor in the data path means no new subprocessor to disclose, no additional DPA, and no third party holding standing access to your customers’ systems. That is a genuine advantage, and it is one you trade away knowingly rather than by default.
- Best for: one or two integrations, or a team whose customers have hard no-subprocessor requirements.
- Who should pick something else: anyone at three or more providers. The maintenance cost is not the build, it is the API changes you did not see coming.
- Pricing: free, plus roughly a week per integration and ongoing maintenance forever.
What actually changes when you embed one of these
This is the part the comparison posts skip, and it is why this article is on a compliance blog.
The platform becomes a subprocessor for every one of your customers. Not just a vendor you use. When your customer connects their Salesforce through your product, the integration platform reads their CRM data on your behalf. Under most DPAs you have signed, that puts it on your subprocessor list, and adding it usually requires advance notice to customers who have a right to object. Teams routinely ship an integration and update the subprocessor list months later, or never.
An OAuth refresh token is a standing key to your customer’s CRM. It does not expire on its own, it survives your customer’s employee turnover, and whoever holds it can read what its scopes allow at any time. Concentrating thousands of those tokens in one vendor is a real risk concentration, and it deserves a line in your risk register with an actual treatment decision rather than a “high” rating nobody revisits.
Scope minimization is the control you can act on today. Most integration setups request far broader OAuth scopes than the feature needs, because broad scopes are easier and nobody pushes back during the build. Requesting read and write on all objects when you need two objects is the integration equivalent of giving every employee admin. Your customers’ security teams increasingly do read the consent screen, and a narrow scope request is a sales asset. Under SOC 2 this is CC6.1 and CC6.3, least privilege, applied to machine access.
Know whether data is stored or passed through. Some platforms proxy calls and hold nothing. Others cache or store synced records. That single fact determines whether a breach at your integration vendor exposes your customers’ CRM records or just their tokens, and it belongs in your data map either way. Ampersand offers both cached and pass-through options, with a hosted data store at the Enterprise tier, so this is a configuration decision you should make deliberately rather than inherit.
Revocation is offboarding. When a customer churns, their tokens should be revoked, not left to expire. Same discipline as removing a departed employee’s access, same failure mode when nobody owns it. Write the revocation step into your churn runbook before you need it.
What should you ask an integration platform before you sign?
- Do you store my customers’ records, or only proxy requests? If you store, for how long?
- Where are OAuth tokens stored, how are they encrypted, and who on your side can access them?
- Can I export the credentials and migrate off without asking every customer to re-authorize?
- Which OAuth scopes do your connectors request by default, and can I narrow them?
- Do you have a current SOC 2 Type II report I can read, or only a badge, and is access to it gated behind a paid tier?
- Who are your subprocessors, and how much notice do I get when they change?
- Is self-hosting or BYOC available, and at what tier?
- What happens to my customers’ tokens when I cancel?
Frequently Asked Questions
What is the difference between a unified API and an embedded iPaaS?
A unified API like Merge normalizes many providers behind one schema, so you write once and get breadth, at the cost of anything non-standard. An embedded iPaaS like Prismatic or Paragon gives you a workflow builder and a customer-facing configuration surface. Ampersand and Nango sit closer to infrastructure: direct access to each provider’s objects with the auth, sync, and retry work handled for you.
How much should I budget?
Model it against your own usage shape, because the pricing models are not comparable. Merge at $650 a month for 10 linked accounts is $65 per customer. Ampersand at $999 for up to 25 customers is $40 per customer at the cap, and less if you are volume-light. Nango at $0.29 per connection is far cheaper on paper and costs you engineering time instead. The number that decides it is whether your integration usage is concentrated in a few heavy customers or spread thin across many.
Should I self-host?
Only if you have a requirement that says so, usually a customer contract or a regulated data type. Self-hosting is an enterprise-tier feature at Nango, Paragon, and Prismatic, so it comes with a custom contract anyway. It removes a subprocessor from your disclosure and adds an operational burden you now own.
Do I need to tell my customers I am using one?
Almost certainly yes. If the platform processes your customers’ personal data, it is a subprocessor, and most DPAs require it on your published list with notice before you add it. Check the notice period in your own customer DPA, because retroactively adding a subprocessor that has been live for six months is an awkward conversation.
What OAuth scopes should I request?
The narrowest set that makes the feature work, and re-check them when the feature changes. Broad scopes are the default in most connector catalogs because they are easier to build against, not because they are necessary. Narrow scopes are also worth real money in enterprise sales, since a security reviewer who reads your consent screen and sees three permissions instead of thirty will move faster.
What happens to my customers’ connections if I switch platforms?
This is the lock-in question, and the answer varies more than any other item on this list. If credentials are portable, you export and migrate. If they are not, every customer has to re-authorize, which in practice means a percentage of them never do and you lose the integration for them. Ask before you build, not when you are leaving.
Does this matter for SOC 2 or ISO 27001?
In three places. Vendor management, because the platform is a subprocessor handling your customers’ data. Access control, because OAuth scopes and token custody are logical access decisions under CC6. And change management, because adding a subprocessor triggers notice obligations you need a process for.
Is a free tier safe to use in production?
Ampersand’s Launch tier and Merge’s first three linked accounts are both genuinely production-capable, which is unusual and welcome. Check two things before relying on one: log retention, which is 3 days on both entry tiers and is not enough to debug an incident reported a week late, and whether access to the vendor’s SOC 2 report is gated behind a paid plan, because your first enterprise customer will ask for it.
Pick on architecture first. Deep two-way sync with custom objects is Ampersand. Broad normalized reads across a category is Merge. Owning the layer yourself is Nango. Customer-configured marketplaces is Prismatic. Workflow builders are Paragon.
Then do the twenty minutes nobody does: add the platform to your subprocessor list, check the OAuth scopes your connectors actually request, and write down whether your customers’ records are stored or passed through. Your integration platform is not just your vendor. It is a vendor your customers inherit without choosing it.