> As a small fish you may like SSO, want SSO, you may even think you need SSO, but you really can get by without just fine.
SSO is the only way to get 2FA working without the friction becoming prohibitive.
If SSO is a paid feature, only in some plans, you're selling an insecure product. You wouldn't make security patches exclusive to the enterprise plan, you shouldn't make 2FA/SSO exclusive either.