browserid.me issues certificates as your domain — your users sign in as you@yourdomain.com everywhere, you govern every identity and agent from one console, and you can leave anytime.
A managed identity answers to its domain: you set the roster, the sites, and what agents may be granted. When someone leaves, one revocation stops their sign-ins and kills every agent grant they ever signed — everywhere, without you having to know where "everywhere" is.
Add a signed _browserid record to your DNSSEC-secured zone and browserid.me operates the full identity surface as your domain — the issuer is you, not us. Relying parties resolve your key straight from DNS; no one calls our servers to trust your users.
And it's never a one-way door. It's your domain and your DNS: issue through us today, and flip that one record to a self-hosted key whenever you want. Nothing you depend on is un-leaveable — no migration, no permission, no lock-in.
Point at your Google Workspace and your directory is the roster — users auto-provision on first sign-in and deprovision when you remove them. No roster to maintain by hand.
Run the whole primary surface yourself, on your own key, from day one — the same protocol, no custodial step at all.