The practical 2026 guide to picking an authentication layer for your app, and why the whole question changed this year.
In July 2026, Vercel bought a two-year-old open-source project that a self-taught developer had started from his bedroom in Ethiopia. That project is Better Auth, and its acquisition by the company behind Next.js - announced on July 7 - is the clearest signal yet that the way founders add login to their products is being rewritten. On the other side of the table sits Clerk, the polished, drop-in authentication service that raised a $50M Series C led by Menlo Ventures and Anthropic's Anthology Fund - in October 2025, and now manages 200M+ users across 15,000+ applications.
Here is the problem: authentication is the one part of your app you cannot afford to get wrong, and it is also the part founders understand least. Get it right and nobody notices. Get it wrong and you leak your users' accounts, fail an enterprise security review, or wake up to a five-figure monthly bill you never modeled. For a non-technical founder shipping a product in 2026, the choice between a managed service like Clerk and an own-your-code library like Better Auth is not a detail. It is a decision about cost, data ownership, security liability, and how ready your app is for the AI agents that will soon be logging in on your users' behalf.
This guide breaks down exactly what Clerk and Better Auth do, what they really cost as you grow, where each one wins and where each one quietly fails, and the ten other providers worth knowing before you commit. It goes deep on the pricing traps, the passkey shift that is now impossible to ignore, and the single biggest 2026 story in identity: authentication for AI agents. Start high level, then go into the nitty gritty. By the end you will have a decision framework, not just a list.
Contents
- The 2026 auth landscape at a glance
- What authentication actually is (and what you are really buying)
- Clerk: the managed drop-in
- Better Auth: own your auth
- Clerk vs Better Auth: the head-to-head
- The pricing reality: what you actually pay as you grow
- The rest of the field: ten alternatives worth knowing
- Passwordless and passkeys: the standard you cannot ignore
- How AI agents are changing authentication
- Security and compliance: who is liable when it breaks
- How to choose: a decision framework
- The future outlook
1. The 2026 auth landscape at a glance
Before the deep dives, here is the whole field scored on one page. Authentication buyers in 2026 face a paradox: the free tiers have converged so far upward that at small scale almost everything is free, which means the real differences only show up in cost at scale, who owns your data, how fast you ship, who carries the security liability, and how ready the tool is for AI agents. Those five things are the columns below. This is the master comparison for the guide, and every provider profiled later in the article maps back to a row here.
The scoring is weighted because these criteria do not matter equally. Cost at scale carries the most weight because it is the number one question founders get wrong and the axis where providers diverge most once you pass 50,000 users. Data ownership, time to ship, and security and compliance each carry a fifth of the score. Agent readiness carries the least today, but it is the fastest-rising factor, and by this time next year it may be the column that decides the whole table.
| # | Provider | What It Does | Cost at scale (25%) | Data ownership (20%) | Time to ship (20%) | Security (20%) | Agent-ready (15%) | Final |
|---|---|---|---|---|---|---|---|---|
| 1 | Better Auth | Own-your-DB open-source TS library, now Vercel-backed | 10 - $0 license, pay only your database | 10 - data in your DB, any region, no lock-in | 6 - ~20 min core, but you build the UI | 5 - you own patching; real CVEs; no SOC 2 to inherit | 9 - Agent Auth plugin + open protocol, MCP | 8.1 |
| 2 | WorkOS AuthKit | Hosted auth + enterprise SSO, $2B valuation | 9 - free to 1M MAU, then $2,500/million | 4 - fully hosted, standards-based | 8 - hosted AuthKit UI, quick setup | 9 - SOC 2; powers OpenAI, Anthropic, Cursor | 8 - auth.md agent protocol, fine-grained authz | 7.7 |
| 3 | Supabase Auth | Login bundled with a Postgres backend | 9 - free to 50k MAU, $25/mo to 100k | 8 - open source, self-hostable, your Postgres | 8 - auth, DB, storage in one SDK | 7 - SOC 2 and HIPAA on paid tiers | 5 - JWT/RLS, no agent-first product | 7.6 |
| 4 | Logto | Open-source Auth0 alternative, generous free tier | 9 - free 50k MAU, $16/mo base unlimited | 8 - open source, self-hostable | 7 - prebuilt sign-in, clean docs | 6 - SOC 2 on cloud, smaller vendor | 5 - OIDC provider, machine-to-machine | 7.2 |
| 5 | SuperTokens | Self-hosted auth with unlimited free users | 9 - self-host free, unlimited MAU | 9 - self-host, own your data (Apache 2.0) | 6 - more setup, prebuilt UI available | 6 - you host, or their SOC 2 cloud | 4 - no agent-identity product | 7.1 |
| 6 | Descope | No-code auth flows, agentic-identity leader | 5 - free 7.5k MAU, Growth $799/mo | 4 - managed and hosted | 8 - drag-and-drop flow builder | 8 - FedRAMP High, SOC 2 | 10 - Agentic Identity Hub, 50+ Outbound Apps | 6.8 |
| 7 | Stytch | Passwordless and fraud APIs, agent Connected Apps | 6 - free 10k MAU, paid from ~$249/mo | 4 - managed and hosted | 7 - strong SDKs, headless plus prebuilt | 8 - device fingerprinting, fraud, SOC 2 | 9 - Connected Apps turn your app into an OAuth provider | 6.7 |
| 8 | Clerk | Polished drop-in auth for React and Next.js | 6 - free 50k MRU, but add-ons and SSO stack | 3 - US-only data, proprietary lock-in | 10 - ~10 min to a polished flow, best UI | 8 - SOC 2, HIPAA, 99.99% SLA; no ISO 27001 | 6 - Agent Toolkit and Identity, no client-credentials flow yet | 6.6 |
| 9 | Firebase Auth | Google's auth for mobile-first apps | 8 - free 50k MAU, then $0.0025-0.0055/MAU | 3 - Google-hosted, hard to leave | 8 - fast SDKs, FirebaseUI | 7 - Google infrastructure, SOC and ISO | 3 - no agent-identity product | 6.1 |
| 10 | Auth0 (Okta) | The enterprise incumbent, widest compliance | 3 - the "growth penalty," opaque tiered pricing | 4 - managed, some EU residency | 7 - mature Universal Login, but complex | 9 - SOC 2, ISO, HIPAA, FedRAMP breadth | 8 - Auth for GenAI plus Token Vault | 6.0 |
Each score is 0 to 10, where 5 is adequate and 10 is best in class, and the final column is the weighted average rounded to one decimal. Read the table by column, not just by the final score: Better Auth tops the ranking because the weighting rewards cost and data ownership, exactly where an own-your-code library is unbeatable, but Clerk owns the time-to-ship column with a 10 that nothing else matches. A composite score is a summary, not a verdict. A solo founder who values speed above all and expects to stay under 50,000 users could rationally pick the row ranked eighth. The rest of this guide is the depth behind each number, so you can weight the criteria for your own situation rather than inheriting mine.
2. What authentication actually is (and what you are really buying)
Strip away the branding and every product in that table does the same three fundamental things. It verifies that a person is who they claim to be (authentication), it decides what that verified person is allowed to do (authorization), and it remembers that decision across page loads so the user does not log in on every click (session management). That is the entire job. Everything else - social login buttons, passkeys, organization roles, magic links - is a feature layered on top of those three primitives. Understanding this matters because it reframes the buying decision: you are not shopping for "login," you are deciding who runs those three primitives and where your users' credentials physically live.
That reframing exposes the real fork in the road, and it is not Clerk versus Better Auth specifically. It is rent versus own. You can rent a managed identity service that stores your users on its infrastructure, runs the verification, patches the security holes, and hands you a polished login box, in exchange for a per-user fee and a dependency you cannot easily leave. Or you can install an open-source library into your own codebase, keep every user record in your own database, and run the three primitives yourself, in exchange for doing the operational work. Clerk is the flagship of the first camp. Better Auth is the flagship of the second. Almost every other provider is a variation on one of these two postures, which is why a two-name comparison can teach you the whole market.
Why does this matter for a non-technical founder specifically? Because the trade-off is not really technical, it is a business decision disguised as a technical one. Renting buys you speed and offloads liability, at the cost of margin and control. Owning buys you margin and control, at the cost of the engineering time and the security responsibility you now carry yourself. The right answer depends entirely on your stage, your team, and your customers, and it changes as you grow. A weekend prototype and a Series B SaaS selling to banks should not make the same choice, and the beauty of 2026 is that the tools have matured enough that both extremes are genuinely viable. The rest of this section, and this guide, is about applying that judgment. For a wider view of how auth fits alongside your database, billing, and email decisions, our breakdown of the AI-native company tech stack maps where each layer sits.
There is a third posture worth naming before we go deeper, because it is genuinely new. You can decline to choose at all and let an AI system assemble the auth layer for you as it builds the app. This is the approach behind company-builder platforms like Founden, which generates the website, the customer app, the billing, and the login as one coherent system from a plain-language description, wiring whichever auth pattern fits rather than making you evaluate a market. That is not better or worse than renting or owning. It is a different altitude of decision, and it only works if you are comfortable letting the builder make the call. We will return to where it fits in the decision framework. For now, hold the three postures in mind: rent, own, or generate.
The market underneath all of this is large and growing quickly, which is why so much venture money is flowing into identity. The broader identity and access management market was valued at roughly $25.34 billion in 2026 and is forecast to reach $77.92 billion by 2034, a 15.1% compound annual growth rate - Fortune Business Insights. Estimates for the consumer-facing slice vary widely by scope, from roughly $3.5 billion to over $14 billion today depending on the analyst, so treat any single market number as a directional signal rather than gospel. The point for a founder is simpler than the exact figure: this is a fast-expanding, well-funded category, which means the tools keep improving and the pricing keeps shifting, so any decision you make deserves a re-check every year.
3. Clerk: the managed drop-in
Clerk is what most founders picture when they think "just add login." It is a fully managed authentication service that ships prebuilt, production-ready UI components for React and Next.js: a <SignIn /> box, a <SignUp /> box, a <UserButton /> avatar menu, and an <OrganizationSwitcher /> for multi-tenant apps. Drop three components into a Next.js project and you have a polished, secure sign-in flow in roughly ten minutes, with password login, social providers, magic links, passkeys, and even Web3 wallets available out of the box - Clerk's React authentication docs. This is Clerk's entire reason for existing and the source of its best-in-class developer experience: it turns weeks of fiddly, security-sensitive work into an afternoon.
The image above is the whole pitch in one screenshot: that form is what a founder gets for importing a single component. Beyond the UI, Clerk ships organizations and B2B multi-tenancy as a first-class feature, with invitations, custom roles, and role-based access control, plus enterprise single sign-on through SAML and OIDC connectors for Okta, Microsoft Entra, and Google Workspace - Clerk's organizations overview. It handles session management with short-lived tokens refreshed automatically, and it lets you run in three modes: fully Clerk-hosted, embedded components, or entirely headless if you want to build your own UI on top of Clerk's backend. For a company that wants to focus on its product and treat identity as a solved problem, this breadth is compelling.
That flexibility matters more than it first appears, because it lets Clerk grow with you rather than forcing an early either-or. A founder can start with the fully hosted Account Portal to launch in an afternoon, then graduate to embedded components for a branded experience, then to Clerk Elements, the composable headless building blocks, when the design team wants pixel control, all without changing providers or migrating users. Clerk also shipped an Agent Toolkit in 2025 that integrates with the Vercel AI SDK and LangChain so agents can authenticate and act, an early move into the agent-identity race we cover later. The best fit for Clerk is a speed-first team: a solo founder, a small startup, or anyone using an AI app builder who wants a production-grade login on day one and is happy to trade some long-run cost and control for that head start.
Clerk's pricing is where founders need to read carefully, because in 2026 it changed in two important ways. On February 5, 2026, Clerk raised its free tier from 10,000 to 50,000 monthly retained users - Clerk's pricing explainer. The subtlety is in that phrase "retained users." Clerk bills MRU (Monthly Retained Users), not the industry-standard MAU (Monthly Active Users). An MRU is a user who returns at least 24 hours after signing up, so one-time signups who never come back are never billed. That makes Clerk genuinely cheaper than a naive MAU comparison suggests, but it also makes the metric harder to model, because you cannot know your MRU count until your retention curve settles.
Here is the current structure, verified on Clerk's live pricing page - clerk.com/pricing:
| Plan | Monthly cost | Included users | Notes |
|---|---|---|---|
| Hobby (Free) | $0 | 50,000 MRU | Clerk branding, up to 3 seats |
| Pro | $25/mo ($20 annual) | 50,000 MRU | Then $0.02 per extra MRU |
| Business | $300/mo ($250 annual) | 50,000 MRU | SOC 2 report, 30-day logs, 10 seats |
| Enterprise | Custom | Custom | 99.99% SLA, HIPAA with BAA |
The overage is graduated: $0.02 per MRU from 50,001 to 100,000, then $0.018 up to a million, $0.015 to ten million, and $0.012 beyond - Clerk's pricing explainer. Add-ons stack on top, and this is where B2B bills climb: the Enhanced B2B / Organizations add-on is $100/mo, the Administration add-on for user impersonation is another $100/mo, and each enterprise SSO connection beyond the first costs $75/mo. Clerk also launched Clerk Billing in May 2025, which handles subscriptions and usage-based billing on top of Stripe for 0.7% of billing volume - Clerk's billing announcement. If billing is your bottleneck rather than auth, our guide to the best payment platforms for your business compares that layer directly.
Clerk's momentum is real and well funded. Its $30M Series B in January 2024 came with a strategic Stripe partnership - TechCrunch, and the $50M Series C in October 2025 was led by Menlo Ventures alongside Anthropic's Anthology Fund, a notable vote of confidence from an AI lab in Clerk's agent ambitions. At that raise Clerk reported managing over 200 million users across 15,000+ applications. The customer base skews heavily toward startups and small teams, which is exactly the audience the free tier is built to capture and convert.
So where does Clerk fail? Three places, and they are worth stating plainly. First, cost at scale for B2B, because the add-ons are separate line items and a growing SaaS quickly finds itself paying the base plan plus organizations plus admin plus per-connection SSO fees. Second, data residency: Clerk stores user data in the United States under the EU-US Data Privacy Framework, with no regional residency option, which is a hard blocker for some European enterprise deals - a Clerk comparison from Makerkit. Third, reliability and lock-in, which we will see concretely in the head-to-head. Clerk is a superb choice for shipping fast and staying focused, and a questionable one if you are cost-sensitive, EU-regulated, or allergic to depending on a vendor you cannot easily leave.
4. Better Auth: own your auth
Better Auth is the opposite philosophy expressed as code. It is a framework-agnostic, MIT-licensed TypeScript authentication library that you install directly into your application, and it stores every user record in your own database, in whatever region you choose - Better Auth's introduction docs. There is no separate service to deploy and no hosted dashboard by default. It ships email and password login, session and account management, built-in rate limiting, automatic database migrations, social sign-on, and a deep plugin ecosystem, all running inside your codebase against your Postgres, MySQL, SQLite, or MongoDB instance. Its tagline, "the most comprehensive authentication framework for TypeScript," is not marketing hyperbole so much as an accurate description of scope.
That image is deliberately just the wordmark, and the absence of a UI screenshot is the point: unlike Clerk, Better Auth ships no prebuilt sign-in components. You build the forms; the library handles the logic behind them. The origin story explains why it resonates. Better Auth was created by Bereket Engida, a self-taught developer from Ethiopia who built the first version over roughly six months and pushed it to GitHub in September 2024 - TechCrunch. It solved a pain every developer felt: self-hosted, own-your-data auth with enterprise-grade features and no per-user SaaS bill. Adoption was explosive. The project went from zero to roughly 15,000 GitHub stars in about ten months, raised a $5M seed round in June 2025 led by Peak XV Partners with Y Combinator participating, and entered YC's Spring 2025 batch.
Then came the headline that reframes the entire comparison. On July 7, 2026, Vercel acquired Better Auth - Vercel's announcement. Financial terms were not disclosed. At acquisition, Better Auth had 4.7 million+ weekly npm downloads and 850+ contributors, and the library stays free and open source under MIT, keeps its name, and retains community governance. Founder Bereket Engida and the core team joined Vercel to build "agent identity," giving AI agents their own scoped, revocable credentials. For a buyer, this de-risks the single biggest worry about betting on an open-source project: will it still exist and be maintained in three years? With the company behind Next.js now backing it, the survival question largely disappears, though it does tie Better Auth's roadmap more closely to the Vercel ecosystem.
Because Better Auth is a library, its "pricing" table looks nothing like Clerk's:
| Offering | Cost | What you get |
|---|---|---|
| Better Auth (library) | $0 (MIT) | Full auth, unlimited users, self-hosted |
| Your database | ~$25-50/mo | The Postgres or MySQL it runs on |
| Managed cloud (optional) | Free / $20/mo Pro | Hosted infrastructure add-ons |
The software is free at any scale; your only mandatory cost is the database you were probably already running - a verified 2026 price comparison on DEV. What you get for that zero is remarkable breadth through plugins: two-factor authentication, passkeys, magic links, email OTP, organizations with roles and invitations, generic OAuth, an SSO plugin supporting SAML 2.0 and OIDC, and even an OIDC Provider plugin that lets your app become its own identity provider - Better Auth's SSO plugin docs. The framework support is equally wide: React, Next.js, Nuxt, SvelteKit, SolidStart, Hono, and Express, with adapters for Drizzle, Prisma, and Kysely. This is why Better Auth's raw GitHub star count has now edged past the long-standing incumbent NextAuth, a genuine changing of the guard in the open-source auth world.
One capability deserves special attention because it flips a common assumption about open-source tools being less capable than paid ones. Better Auth's OIDC Provider plugin lets your own application become a full identity provider, so instead of only consuming "Sign in with Google," your product can offer "Sign in with [your app]" to third parties, the same primitive that powers enterprise SSO and, increasingly, agent authorization. It also ships magic links and email one-time codes as first-class plugins, which means the passwordless flows that used to require a specialized vendor are now a few lines of configuration against your own database. Those email-based flows do assume you have a reliable sending setup, which is its own decision covered in our guide to the best email sending tools for your platform. The breadth is the reason teams increasingly reach for Better Auth over the older, thinner libraries: it covers the enterprise checklist without an enterprise price.
Now the honest downsides, because owning your auth means owning its risks. You host and operate it, which means the database, sessions, scaling, and uptime are your responsibility, not a vendor's. There is no prebuilt UI, so a solo founder spends one to three days building login forms that Clerk hands over for free. And critically, security is yours to maintain. Better Auth has shipped multiple real vulnerabilities, including CVE-2025-61928, a critical account-takeover flaw in its API-keys plugin rated 9.3, which was disclosed by an external scanner and patched within about 48 hours in version 1.3.26 - the ZeroPath disclosure, and a later cryptographic-defaults flaw in its OIDC and MCP plugins fixed in August 2026. The fast patch turnaround is a genuinely positive signal about the team's discipline, but the lesson stands: when you self-host auth, you must track releases and update quickly, because a critical bug in your login is now your incident to manage, not someone else's.
5. Clerk vs Better Auth: the head-to-head
Put the two side by side and the trade-off snaps into focus. This is not a case of one product being better than the other; it is a case of two products optimizing for opposite priorities, and the right pick depends on which priorities are yours. The grouped chart below scores both across the five criteria from the master table, and it visualizes the trade-off more clearly than any paragraph can: the two lines are almost mirror images of each other. Clerk towers on time-to-ship and edges ahead on security-you-can-inherit. Better Auth dominates on cost, data ownership, and agent-readiness. There is no overlap where one is simply superior.
The developer experience gap is the clearest single difference. Clerk gets you to a polished, working login in roughly ten minutes because the UI is done for you; independent comparisons rate its developer experience around 9 out of 10 - the DEV price-verification writeup. Better Auth's core setup takes about twenty minutes, but then you spend one to three days building the interface, landing it around 7 out of 10 on the same scale. For a non-technical founder or a solo builder racing to a demo, that difference is not academic. It can be the difference between launching this weekend and launching next month. This is Clerk's home turf, and no amount of cost advantage changes the fact that speed-to-first-login is where it wins.
The cost and data-ownership gap runs the other way, and it widens as you grow. Better Auth's software cost is zero at any user count; you pay only for the database. Clerk's cost is modest until you cross the free tier, then climbs with your user base and your add-ons. Just as important is where your users live: with Better Auth every record sits in your own database in your chosen region, giving you complete GDPR and residency control, while Clerk keeps everything in the US with no regional option. And lock-in is asymmetric: leaving Clerk for another provider is cited at roughly two engineer-weeks of migration work - Makerkit's comparison, whereas Better Auth, being your own code against your own database, imposes no exit tax at all. If you are building for European customers or expect to negotiate enterprise data-residency clauses, this axis alone can decide the choice.
One concrete feature captures the philosophy gap better than any score: B2B organizations. If your product is multi-tenant SaaS where customers invite their teammates, you need organizations, roles, and invitations, and here the pricing postures diverge sharply. Better Auth ships a first-class organization plugin with member, invitation, and role tables built in and free, part of the library. Clerk offers the same capability as a paid B2B add-on at $100 a month on top of your base plan - Makerkit's comparison. For a bootstrapped SaaS, that single line item can be the deciding factor, because multi-tenancy is not a nice-to-have for B2B, it is the product, and paying a recurring premium for a table structure feels different from paying for a hosted service. This is the rent-versus-own trade-off made specific: with Clerk you rent the org model and it appears on the invoice; with Better Auth you own it and it appears in your codebase.
The most instructive evidence is a real migration, not a benchmark. Val Town, a developer platform, publicly documented moving from Clerk to Better Auth in April 2026, and the reasons are specific and sobering - Val Town's engineering blog. They hit a 5-requests-per-second account-wide rate limit on Clerk's user API in production, a webhook-syncing model that created "two authorities" for the same user data, and reliability they described as "teetering between two and three nines" since May 2025, where outages did not just break login but made the whole site unusable for already-logged-in users. Their migration used a two-week dual-authentication window that accepted either cookie type during the transition. One company's experience is not a universal verdict, and plenty of teams run Clerk happily at scale, but Val Town's writeup is a primary-source reminder that a managed dependency is exactly that: a dependency, with someone else's rate limits and uptime baked into your product.
To see the head-to-head framed as a straightforward 2026 comparison, this independent walkthrough weighs the two directly and reaches similar conclusions about where each fits.
So how should you read the two? Choose Clerk when time-to-ship and a polished, zero-effort UI matter more than long-run cost, when you are US-based or US-serving, and when you would rather pay a vendor to own the security and operational burden. Choose Better Auth when you want zero per-user cost, full control of your data and its residency, no vendor lock-in, and an auth layer that lives in your own repository where you (or your AI coding agent) can shape it freely. The decision is genuinely stage-dependent, which is why the same team might legitimately start on Clerk to launch fast and migrate to Better Auth once the per-user bill and the lock-in start to bite, or start on Better Auth precisely to avoid ever making that migration.
6. The pricing reality: what you actually pay as you grow
Pricing is where founders make the most expensive mistakes, and the mistakes come from comparing the wrong numbers. The first trap is the free-tier illusion. In early 2026 nearly every major provider raised its free tier into the tens of thousands of users, so at 10,000 or even 50,000 users, Clerk, Supabase, Firebase, and WorkOS are all effectively free or nearly so. This convergence means the free tier is no longer a differentiator; it is table stakes. Choosing an auth provider because it is "free up to 50,000" is choosing on a feature that almost everyone now offers. The real cost question is not "what does it cost at launch," it is "what does the curve look like at 100,000 and beyond," because that is where the providers diverge by orders of magnitude.
The chart below plots the monthly cost of three representative choices as an app grows from 10,000 to 100,000 users. Note what happens at the right edge. Clerk on the Pro plan stays at its $25 base through 50,000 retained users, then climbs to roughly $1,025 per month at 100,000 as the per-user overage kicks in. Better Auth stays essentially flat, because you are only paying for a database that scales cheaply. And WorkOS AuthKit stays at zero, because its free tier extends all the way to one million users. The lines tell the whole story: below 50,000 users the choice barely matters on cost, and above it, the choice matters enormously.
Two honesty notes on that chart, because the numbers deserve caveats. The Better Auth line is an infrastructure estimate, not a published price: the library is free, and $15 to $50 a month is a reasonable range for a small server plus a managed Postgres, which will vary with your host and region. The WorkOS line covers core authentication only; its enterprise SSO connections are billed separately at $125 per connection. And a critical correction on Clerk: many 2026 comparison posts still quote $1,825 to $2,025 per month at 100,000 users, but those figures use Clerk's old 10,000-user free tier and MAU framing from before the February 2026 change. Under the current 50,000-MRU tier, the honest number is closer to $1,025 per month - Clerk's pricing explainer. If you read a comparison quoting the higher figure, it is out of date, and that matters because a $12,000-a-year error is exactly the kind of thing that pushes a founder to the wrong decision.
The second trap is the metric mismatch. Providers bill on different units, and the units are not comparable. Clerk bills MRU (retained users only). Most competitors bill MAU (any active user). Ory bills average daily active users. Auth0 uses tiered MAU bands that are notoriously opaque, to the point that third-party trackers cannot cleanly compute the price at 50,000 users - a 2026 Auth0 pricing analysis. This is not an accident; the unit is a pricing lever. A retained-user metric flatters Clerk relative to an active-user metric, and a daily-active metric can flatter or punish depending on your usage pattern. When you model cost, convert everything to your own real numbers, because a headline "per user" price means nothing until you know which users the vendor counts. For a fuller picture of how these infrastructure costs add up across the whole app, our guide to what it costs to build an app with AI puts auth in context with the rest of the bill.
The practical takeaway is a two-part rule. First, at launch and through your first tens of thousands of users, pick on developer experience and fit, not price, because they are all roughly free and the time you save shipping is worth more than any pricing edge. Second, before you scale, model the curve at ten times your current size using your real metric, and re-check it annually, because pricing in this category changes constantly. The founders who get burned are the ones who chose a provider at 5,000 users for its free tier and never re-modeled, then discovered at 200,000 users that they had architected themselves into a five-figure monthly bill and a two-week migration. Auth is cheap to choose well and expensive to choose carelessly, and the difference is entirely in whether you did the arithmetic.
7. The rest of the field: ten alternatives worth knowing
Clerk and Better Auth are the two poles, but the space between them is crowded with strong, well-funded options, and for many founders one of these fits better than either headliner. The field sorts naturally into a few buckets: enterprise and B2B specialists that exist to help you close big deals, backend-bundled options where auth comes free with your database, open-source self-hostable libraries in Better Auth's spirit, and passkey-first newcomers. Knowing which bucket you are shopping in narrows the field faster than comparing every product feature by feature. The diagram below lays out the map.
Start with the enterprise and B2B specialists, because this is where the biggest 2026 money moved. WorkOS raised a $100M Series C at a $2 billion valuation in March 2026 and counts OpenAI, Anthropic, xAI, Cursor, and Perplexity as customers - WorkOS's Series C announcement. Its AuthKit is free to a staggering one million MAU, with enterprise SSO priced per connection, making it the default for a startup that needs to sell to large companies. Auth0, now owned by Okta, is the mature incumbent with the widest compliance breadth, but it is widely criticized as a "growth penalty" because its opaque tiered pricing punishes scale. Stytch specializes in passwordless flows and fraud detection with device fingerprinting, and Descope offers no-code visual auth flows and has pivoted hard into agent identity, raising $35M in late 2025 - Upstarts Media. If your buyers are enterprises, one of these four probably belongs on your shortlist ahead of Clerk.
The backend-bundled options are the pragmatic default for founders who want fewer moving parts. Supabase bundles authentication with a full Postgres database, storage, and real-time subscriptions, free to 50,000 MAU and then $25 a month to 100,000, all open source and self-hostable if you ever want to leave. Firebase Authentication, Google's offering, is free to 50,000 MAU and remains the fastest path for mobile-first apps deep in the Google ecosystem, at the cost of meaningful lock-in. The appeal here is architectural simplicity: your auth, your data, and your storage come from one vendor with one SDK, which for a small team is one fewer integration to reason about. The trade-off is that you are betting your data layer and your identity layer on the same company at once, so if you outgrow one you may be forced to migrate both. Our comparison of the best databases for your product covers that bundling trade-off in depth.
The open-source self-hostable camp shares Better Auth's own-your-data philosophy with different trade-offs. SuperTokens is self-hostable with genuinely unlimited free users, a strong choice for teams that want to own everything without running Keycloak's operational weight. Logto is a generous open-source Auth0 alternative, free to 50,000 MAU on its cloud with a $16-a-month base for unlimited users beyond that. Ory offers standards-pure, composable identity infrastructure for teams that want maximum flexibility. And Zitadel targets compliance-heavy self-hosted deployments with full audit logging. These tools reward teams with engineering capacity and a strong preference for control, and they punish teams without it, because the operational burden is the price of the ownership.
Two other managed options round out the picture for specific situations. Kinde is a developer-friendly managed platform that raised its free tier to 25,000 MAU in early 2026 and pairs auth with built-in billing and feature-flag tooling, positioning itself as a lighter, cheaper Clerk for indie founders. AWS Cognito is the pragmatic choice if your infrastructure already lives in Amazon Web Services, with a reworked pricing model that gives new accounts 10,000 free MAU, though its developer experience is widely considered rougher than the newer entrants. Neither is likely to top a greenfield shortlist in 2026, but both are rational when your surrounding stack pulls you toward them, which is exactly the point: auth is rarely chosen in isolation, it is chosen to fit the integrations and stack you already run.
Two more categories deserve a mention before we move on. The passkey-first newcomers, led by Hanko and Corbado, are built around WebAuthn and passwordless login from the ground up rather than bolting it on, which matters more every quarter as passkeys go mainstream. And the venerable Auth.js (NextAuth) remains the free, no-vendor default for Next.js projects, though it requires more manual assembly and lacks some of Better Auth's built-in polish, which is precisely why Better Auth has been eating its share. The lesson across all ten is that "best auth" is not a single answer. It is the intersection of your stage, your buyers, your team's capacity, and your appetite for control, and the reason to know the field is so that you recognize your own situation in one of these buckets rather than defaulting to whichever name you heard first.
8. Passwordless and passkeys: the standard you cannot ignore
Whatever provider you pick, it must handle passkeys well, because in 2026 passkeys crossed the line from experiment to expectation. The FIDO Alliance's World Passkey Day 2026 report estimates roughly 5 billion passkeys now in use worldwide, with consumer awareness at 90%, up from 75% a year earlier, and 75% of people having enabled a passkey on at least one account - the 2026 FIDO report. This is not a niche security feature for the paranoid anymore. It is becoming the default way ordinary people log in, and an app whose login flow does not offer it will increasingly feel dated to the very users you are trying to convert. Understanding what a passkey is matters for the buying decision, so here is the plain version: a passkey replaces a password with a cryptographic key stored on your device and unlocked by your face or fingerprint, which means there is no password to phish, reuse, or leak.
The big-tech numbers turn the trend into hard reality. Google reports around 800 million accounts using passkeys and over 2.5 billion passkey sign-ins, Amazon has crossed 175 million customers with passkeys enabled, and Microsoft made passkeys the default for all new consumer accounts in 2025, covering 1.5 billion users and driving a 120% jump in passwordless sign-ins - SC Media's coverage. More persuasive than adoption is performance: the FIDO Passkey Index, drawn from nine large deployments including Amazon, Google, and Microsoft, found passkey sign-ins succeed 93% of the time versus 63% for other methods, cut sign-in time by 73%, and reduced login-related help-desk tickets by 81% - the FIDO Passkey Index. For a founder, those are not security abstractions. They are conversion and support-cost numbers, and they argue that passkeys are a growth feature, not just a safety feature.
The security case underneath the convenience is what makes this urgent rather than optional. The 2025 threat data is ugly: MFA-bypass attempts rose roughly 218% in a single year, and credential stuffing accounted for about 22% of breaches, the single most common vector, ahead of phishing - DeepStrike's 2026 password statistics. Attackers are now using AI-powered real-time phishing proxies that can defeat one-time-code MFA by relaying the code as the victim types it. Passkeys are the structural answer because they are phishing-resistant by design: there is no shared secret to steal and no code to relay, since the cryptographic challenge is bound to the specific website. This is why both Clerk and Better Auth ship passkey support, and why any provider you evaluate that treats passkeys as an afterthought should be treated with suspicion.
The practical guidance for a non-technical founder is to make passkey quality a first-class evaluation criterion, not a checkbox. All the serious providers now offer WebAuthn passkeys, but the implementations differ in how gracefully they handle device loss, cross-device sign-in, account recovery, and the fallback path when a passkey is not available. Those edge cases are where a mediocre implementation frustrates users and a good one delights them, and they are exactly the parts that keep changing as browsers and operating systems evolve their passkey behavior. This is a genuine point in favor of managed providers for less technical teams: keeping a passkey implementation correct as the standard evolves is ongoing work, and it is work a managed vendor does for you, whereas with a self-hosted library it is work you inherit. Weigh that honestly against the ownership benefits when you choose.
9. How AI agents are changing authentication
The most important shift in authentication is not about human users at all. It is about AI agents logging in on your users' behalf, and it is the reason identity is suddenly one of the hottest categories in software. When an AI agent books a flight, files an expense, or queries your API for a customer, something has to answer a new question that classic auth never handled: who is this agent, what is it allowed to do, and on whose authority is it acting? A human logging in is a solved problem. An autonomous agent acting for a human, with its own scoped and revocable permissions, is not, and every serious identity vendor is now racing to solve it. This is the column in the master table that carries the least weight today and will carry the most tomorrow.
The center of gravity is the Model Context Protocol authorization spec, which is how AI assistants securely connect to external tools and data. It matured fast through three revisions in 2025. The March 2025 revision made OAuth 2.1 the baseline, the June 2025 revision reclassified MCP servers as OAuth resource servers that validate tokens rather than issue them, and the November 2025 revision hardened the rules further by requiring every access token to be bound to a specific audience via resource indicators and forbidding token pass-through to downstream APIs - Descope's MCP auth spec explainer. In plain terms, the industry agreed on how an agent proves it is allowed to use a tool, and it built that agreement on the same OAuth foundations that already secure "Sign in with Google." If you plan to expose your product to AI agents, this is the standard your auth layer needs to speak. Our guide to shipping an MCP server for your product walks through the practical side of that.
The vendor race to serve this is well underway, and it reorders the whole comparison. Auth0 shipped "Auth for GenAI" with a Token Vault that securely stores and refreshes the OAuth tokens an agent needs to act on a user's behalf across Gmail, Slack, and other services - Auth0's announcement. Stytch launched Connected Apps, which turns your own app into an OAuth identity provider for agents and MCP clients, and made it work on top of existing auth stacks so you do not have to rip and replace - Stytch's Connected Apps. Descope's Agentic Identity Hub treats agents as first-class identities with tool-level scopes and 50+ integration templates for token management - Descope's Agentic Identity Hub 2.0. And WorkOS released auth.md, an open agent-registration protocol built on OAuth standards - MarkTechPost. On this axis, the enterprise specialists are visibly ahead.
Where do our two headliners land? Better Auth ships an Agent Auth plugin alongside an open Agent Auth Protocol, drafted in February 2026, that gives agents capability-based authorization, revocation, and short-lived signed tokens, with adapters for OpenAPI and MCP - Better Auth's Agent Auth docs, and Vercel's entire acquisition thesis is building "agent identity" on top of it. Clerk has machine-to-machine tokens and an Agent Toolkit, but as of mid-2026 it does not yet support the OAuth client-credentials flow, and agent identity is not yet a first-class actor in its model - a 2026 analysis by Scalekit. This is a meaningful gap: if AI agents acting on behalf of your users are central to your product, Better Auth, Auth0, Stytch, Descope, and WorkOS are further along than Clerk today.
There is a subtler reason AI agents favor the own-your-code approach, and it is structural rather than feature-driven. Because Better Auth lives in your own repository as plain TypeScript, an AI coding agent like Claude Code or Cursor can read, extend, and refactor your auth logic directly, the same way it edits any other file in your project. Clerk's hosted service is a black box the agent can only call, not modify. As more founders build their apps with AI coding assistants, this "the agent can see the code" property becomes a quiet but real advantage, because the auth layer stops being a special vendor integration and becomes just another part of the codebase the AI can maintain. This is not a marketing claim; it follows directly from the code-first, MIT-licensed nature of the library, and it is a large part of why Better Auth caught fire in the AI-coding era. For a sense of how these coding agents differ, our comparison of Claude Code vs Codex vs Devin covers the tools doing this work.
This is the thread that connects auth to the broader shift toward autonomous software, and it is the arena where builders like Yuma Heymans (@yumahey) have been operating. As founder of the AI workforce platform O-mega and co-founder of the autonomous recruiting product HeroHunt.ai, Heymans has spent years building systems where software agents act on a user's behalf, which is precisely the problem agent authentication now formalizes. When your product's users are increasingly AI agents rather than humans clicking buttons, the identity layer stops being plumbing and becomes strategy, and that is the direction the whole category is heading.
10. Security and compliance: who is liable when it breaks
For a non-technical founder, the security question reduces to one blunt phrase: when your login gets breached, whose problem is it? This is the hidden variable in the rent-versus-own decision, and it deserves to be stated as plainly as the pricing. With a managed provider like Clerk, a vulnerability in the authentication layer is the vendor's to find, patch, and disclose, and their compliance attestations cover the auth data they hold. With a self-hosted library like Better Auth, a misconfiguration or an unpatched dependency in your deployment is yours, which means the attack surface, the patch cadence, and the breach liability all sit with your team. Neither choice removes your legal obligations as the data controller, but they distribute the day-to-day security work very differently.
The compliance split is concrete and worth understanding before an enterprise buyer asks you about it. Clerk is SOC 2 Type 2 and HIPAA compliant, has been since 2022, is GDPR and EU-US Data Privacy Framework aligned, and offers a 99.99% uptime SLA on Enterprise, though it lacks ISO 27001 and, as noted, regional data residency - Clerk's security overview. Those attestations are not abstractions; they are documents you can hand to an enterprise security team to pass a vendor review, and inheriting them from your provider can save weeks in a sales cycle. Better Auth, by contrast, stores all data in your own database, giving you full residency and GDPR control, but it hands you no vendor attestations to inherit, because there is no vendor. For a company selling into regulated industries, that difference can decide whether you pick a managed provider purely to borrow its compliance paperwork.
It helps to separate two things founders routinely conflate: compliance and security. Compliance is the paperwork that proves you meet a standard, and it is genuinely easier to inherit from a managed vendor. Security is whether your users' accounts actually stay safe, and no attestation guarantees it. A SOC 2 report tells an enterprise buyer that Clerk follows documented controls; it does not mean your specific integration is configured correctly, and misconfiguration is the more common failure mode than a vendor breach. The corollary matters for the own-your-auth camp: choosing Better Auth does not automatically make you less secure, and choosing Clerk does not automatically make you compliant, because you still have to configure sessions, token scopes, and access rules correctly on either side. The honest framing is that a managed provider gives you a higher floor (hardened defaults you cannot easily undo) while a self-hosted library gives you a higher ceiling (total control if you have the discipline to use it well). Know which one your team actually needs before the sales cycle forces the question.
The 2025 and 2026 threat landscape sharpens why this matters. Beyond the credential-stuffing and MFA-bypass surge covered earlier, the year's most instructive incident was the Salesloft-Drift breach, where compromised OAuth integration tokens exposed data from over 700 companies, and MFA never triggered because the authorization had already happened - MojoAuth's threat analysis. The lesson is that in an era of connected apps and agent tokens, the token is the new password, and how your auth layer scopes, stores, and revokes tokens matters as much as how it verifies humans. OWASP's 2025 Top 10 keeps broken access control at number one and authentication failures near the top, and its core guidance, to enforce access control once in trusted server-side code and deny by default, applies whether you rent or own - OWASP Top 10:2025.
The honest synthesis is that neither posture is inherently more secure; they fail in different ways. A managed provider gives you hardened defaults, professional patching, and inheritable compliance, but concentrates risk in a vendor whose outage or breach becomes yours by proxy, as Val Town's reliability experience showed. A self-hosted library gives you complete control and no third-party dependency, but every credential store you host is itself a liability, and Better Auth's real critical CVE this year is a reminder that self-hosted auth demands genuine security discipline, fast patching, and someone whose job is to watch for advisories. For most non-technical founders shipping quickly, the managed posture is the safer default precisely because it moves the hardest security work to a team that does it full time. For teams with real engineering capacity and a strong data-control requirement, owning it is defensible, provided you commit to the operational maturity it demands.
11. How to choose: a decision framework
By now the pattern should be clear: there is no universally best auth provider, only the best fit for your stage, your buyers, your team, and your appetite for control. The decision tree below encodes the reasoning from first principles rather than by brand loyalty. Start at the top with the question that filters hardest, and let each branch narrow the field. The goal is not to arrive at a single name but to arrive at the right posture, after which two or three names will be obviously appropriate and the rest obviously not.
Translate the branches into concrete profiles. If you are a non-technical solo founder shipping a consumer app and speed is everything, Clerk's drop-in UI is hard to beat, and its free tier will carry you a long way before cost matters. If you are a B2B SaaS founder whose deals hinge on enterprise SSO and SCIM, start with WorkOS or Auth0, because closing a six-figure contract that requires SAML is worth more than saving on the auth line item. If you are building for European customers or you philosophically want to own your users' data and never pay per user, Better Auth or SuperTokens is the natural home, especially now that Vercel's backing removes the survival risk. And if you want the fewest moving parts, a backend-bundled option like Supabase gives you auth and database together. The wrong move is to pick the name you heard on a podcast without matching it to your own branch of this tree.
There is a fourth path that sidesteps the tree entirely, and it is increasingly viable for founders who would rather not become auth experts at all. Instead of evaluating providers, you can let an AI system build the whole app, auth included, and make the choice for you. This is the model behind autonomous company builders like Founden, which takes a plain description of your business and generates the product, the customer app, the billing, and the login as one integrated whole, wiring an appropriate auth layer without asking you to weigh MRU against MAU or SOC 2 against self-hosting. For a non-technical founder, the appeal is obvious: the best auth decision is sometimes the one you never have to make yourself. The honest caveat is equally clear: you are trusting the builder's judgment and its choices, so this path fits founders who value shipping the whole company over hand-picking each component. It sits alongside rent and own as a legitimate third option, not above them.
Whatever path you choose, apply three durable rules that outlast any specific provider. First, do not over-optimize at launch: below fifty thousand users almost everything is free and fast, so choose on developer experience and fit, then revisit. Second, model the cost curve at ten times your size using your real user metric before you commit, because the divergence lives at scale and the metric mismatch hides it. Third, treat data ownership and exit cost as features, not afterthoughts, because the day you want to leave a provider is the day you discover how much lock-in you accepted. A founder who follows those three rules will rarely make an expensive auth mistake, regardless of which row in the master table they land on. For the wider context of assembling a startup from these decisions, our 2026 founder's guide to starting a company places auth alongside the other early calls.
12. The future outlook
Where is all of this heading? The clearest signal is the flow of capital and talent, and it points in one direction: agent identity is the next battleground. WorkOS reached a $2 billion valuation partly on the strength of powering the AI labs, Clerk's Series C drew investment from an AI lab's own fund, and Vercel bought Better Auth explicitly to build agent identity into the fabric of the web's most popular framework. When the money moves this decisively toward one theme, it is telling you where the product roadmaps will go. The auth layer of 2028 will not just verify humans; it will manage a population of AI agents, each with its own scoped, revocable, auditable identity, acting on behalf of the humans who authorized them. The providers that own that transition will own the category.
The second trend is consolidation of the open-source middle. Better Auth overtaking NextAuth in raw popularity and then being absorbed by Vercel is a preview of what happens next: the strongest open-source projects get acquired by platform companies that fold identity into their broader developer offerings. This is mostly good for founders, because it stabilizes projects that were previously one maintainer's passion, but it also concentrates power. A Better Auth backed by Vercel is safer to depend on and more tied to the Vercel ecosystem at the same time. Expect more of these acquisitions, and factor the platform alignment into your choice: an open-source tool's corporate parent is now part of what you are betting on, not a footnote.
The third trend is the quiet disappearance of the auth decision itself for a growing slice of builders. As AI coding agents become the default way apps get made, the auth layer increasingly gets generated rather than chosen, wired up correctly by an agent that reads the docs and follows the current best practice without the founder ever comparing providers. Company-builder platforms take this furthest by generating auth as one part of an entire working business. This does not eliminate the need to understand the trade-offs in this guide, because someone or something still makes the choice, and knowing what a good choice looks like is how you evaluate whether the generated one is right. But it does mean the center of gravity is shifting from "which provider do I integrate" toward "which builder do I trust to integrate it well." Our look at the autonomous business traces where that shift leads.
The reasoning from first principles closes the loop. Authentication was always three primitives - verify identity, grant permissions, remember the session - and the technology shift underneath 2026 is that intelligence became cheap enough to generate and operate those primitives on demand. When the intelligence to wire up auth correctly is nearly free, the scarce resource stops being the auth code and becomes the judgment about which posture fits your business. That is the durable skill this guide is really about. The providers will keep changing, the pricing will keep shifting, and the model names in the AI tooling around them will be different in six months. What will not change is the underlying decision: rent, own, or generate, weighed against your stage, your buyers, and how much control you need. Get that judgment right and the specific provider almost takes care of itself.
This guide reflects the authentication landscape as of August 2026. Pricing, funding, security disclosures, and AI model versions in this space change frequently (Better Auth's Vercel acquisition and Clerk's February 2026 pricing shift both landed within the last year), so verify current details on each provider's official pages before you commit.