authentication.html

Pick your auth service — 20 options across the five categories that decide most picks

Your auth choice is one of the highest-leverage decisions in any new build — the wrong pick costs you weeks of integration work and quarters of monthly bill. The directory filters by hosted SaaS / bundled / self-hosted / library, plus language, pricing, HIPAA eligibility, SSO/SAML readiness. Every entry gives you a one-line summary, a concrete best-for, an honest skip-this-if, and a paragraph of opinion.

12 SIDE-BY-SIDE COMPARISONS → TOP-5 DECISION HUB →

Filter the list

Category
Language
Pricing
Sort

Showing 20 of 20

Keycloak

Open-source Java-based IDP. Enterprise-grade self-hosted SSO + SAML, heavy to operate.

  • CatSelf-hosted
  • LangJava
  • Stars26.8k
  • PricingOpen source
HIPAA SSO/SAML
Read the take →

Auth.js (NextAuth)

Open-source library for Next.js, SvelteKit, SolidStart. Free, self-managed user database.

  • CatLibrary / OSS
  • LangTypeScript
  • Stars26.4k
  • PricingOpen source
Read the take →

Better Auth

Newer TypeScript-first OSS auth library. Designed as the modern Auth.js alternative.

  • CatLibrary / OSS
  • LangTypeScript
  • Stars18.4k
  • PricingOpen source
SSO/SAML
Read the take →

Authentik

Modern open-source self-hosted IDP. Python-based, lighter than Keycloak.

  • CatSelf-hosted
  • LangPython
  • Stars17.6k
  • PricingOpen source
SSO/SAML
Read the take →

SuperTokens

Open-source self-hosted auth library. SDK-style integration, app-database-aware.

  • CatSelf-hosted
  • LangTypeScript
  • Stars14.6k
  • PricingOpen source
SSO/SAML
Read the take →

Lucia

Lightweight TypeScript auth library. Library-not-framework — minimal opinions, BYO everything.

  • CatLibrary / OSS
  • LangTypeScript
  • Stars9.7k
  • PricingOpen source
Read the take →

Ory

Cloud-native open-source identity stack — Kratos (auth), Hydra (OAuth2), Keto (authorisation).

  • CatSelf-hosted
  • LangGo
  • Stars4.4k
  • PricingOpen source
SSO/SAML
Read the take →

Clerk

TypeScript-first hosted auth with the cleanest developer experience in the category in 2026.

  • CatModern hosted SaaS
  • LangTypeScript
  • Stars1.7k
  • PricingFreemium
HIPAA SSO/SAML
Read the take →

Supabase Auth

Postgres-native auth bundled with Supabase. Free, owned-data, integrates with RLS.

  • CatBundled with platform
  • LangTypeScript
  • Stars1.6k
  • PricingOpen source
HIPAA
Read the take →

FusionAuth

Self-hosted auth from a US team. Lighter than Keycloak, paid for support, free for self-hosting.

  • CatSelf-hosted
  • LangJava
  • Stars1.4k
  • PricingFreemium
SSO/SAML
Read the take →

Descope

Drag-and-drop auth flow builder for teams that want to compose passwordless flows visually.

  • CatModern hosted SaaS
  • LangTypeScript
  • Stars0.4k
  • PricingFreemium
HIPAA SSO/SAML
Read the take →

WorkOS

B2B-only auth focused on enterprise SSO, SAML, SCIM. Not a B2C product.

  • CatEnterprise SaaS
  • LangTypeScript
  • Stars0.3k
  • PricingFreemium
HIPAA SSO/SAML
Read the take →

Kinde

Newer hosted auth from the Australian team behind Canva-grade design polish.

  • CatModern hosted SaaS
  • LangTypeScript
  • Starsclosed
  • PricingFreemium
SSO/SAML
Read the take →

Stytch

Passwordless-first hosted auth — magic links, SMS, biometric, embedded auth.

  • CatModern hosted SaaS
  • LangTypeScript
  • Starsclosed
  • PricingFreemium
HIPAA SSO/SAML
Read the take →

Magic

Passwordless link auth, web3 wallet integration, the original "no passwords" hosted product.

  • CatModern hosted SaaS
  • LangTypeScript
  • Starsclosed
  • PricingFreemium
Read the take →

Auth0

mature

The enterprise hosted auth incumbent. Acquired by Okta in 2021. Mature, expensive, procurement-default.

  • CatEnterprise SaaS
  • LangTypeScript
  • Starsclosed
  • PricingPaid
HIPAA SSO/SAML
Read the take →

Frontegg

B2B-focused hosted auth with self-service admin and entitlements built in.

  • CatEnterprise SaaS
  • LangTypeScript
  • Starsclosed
  • PricingFreemium
HIPAA SSO/SAML
Read the take →

Firebase Auth

Google's bundled auth — email, social, phone, anonymous. Generous free tier, locks you into Google.

  • CatBundled with platform
  • LangJavaScript
  • Starsclosed
  • PricingFreemium
HIPAA
Read the take →

AWS Cognito

Amazon's bundled identity service. Cheap at scale, complex to set up, AWS-locked.

  • CatBundled with platform
  • LangTypeScript
  • Starsclosed
  • PricingFreemium
HIPAA SSO/SAML
Read the take →

Microsoft Entra ID

Microsoft's identity platform (formerly Azure AD). Enterprise default for Microsoft-shop B2B.

  • CatBundled with platform
  • LangC#
  • Starsclosed
  • PricingPaid
HIPAA SSO/SAML
Read the take →

How this directory is curated

This is not a scraped catalogue of every authentication library on GitHub. It is the 20 services worth knowing about in 2026 — picked because each one either belongs in your shortlist for a specific brief or is the answer-of-record for a specific procurement context (Microsoft-shop / AWS-shop / Red Hat-shop).

Star counts are approximate, refreshed each quarter. Closed-source / hosted-only products show closed. The HIPAA flag means a BAA is publicly available; the SSO/SAML flag means enterprise SSO and SAML are out of the box rather than premium-tier add-ons.

The auth choice is the easy half — your migration is the hard one

Picking the auth service is the easy half. The hard half is migrating user accounts off the old stack without breaking sessions, getting your team adopted, and surviving the SOC2 / HIPAA audit conversations. The 30-min call is the right starting place — describe your stack, your scale, your compliance constraints; I tell you what fits.