Stackfacts

Login for a Next.js app: six options compared

Published by Stackfacts, an independent publisher. No paid placement.

Facts checked 2026-10-03. Every fact was read from the vendor's own pricing page, the npm registry, GitHub, or Stripe's provider list on the checked date. Nothing here was benchmarked. No vendor paid for or reviewed this page. Machine-readable copy: /nextjs-auth.json. Agents can also call this as a tool: how.

Picks by situation (our reading of the facts below, not a ranking)

Your situationPickWhy
New project, you have a database, you want no vendor accountBetter AuthIt is the actively developed open-source option, and the Auth.js maintainers themselves point new projects to it.
Existing app already on next-authStay on next-authIt still gets security patches (latest release 2026-07-20). Migrate when you need a feature it will not get.
You want hosted sign-in with ready-made UI and no databaseClerkFree to 50,000 users per app with no card, and an agent can provision it through Stripe Projects.
You sell to companies that will ask for SSOWorkOS AuthKitFree to 1 million users; you pay $125/month per enterprise SSO connection.
You are already using Supabase for the databaseSupabase AuthIt is included: 50,000 users on the free plan. Remember free projects pause after a week idle.
No database and no vendor at all (stateless sessions)Auth.js / NextAuthThis is the one case its maintainers still name for choosing it over Better Auth.

At a glance

OptionPriceFree startIdle / status
Better AuthLibrary is freeYesActively developed
Auth.js / NextAuthFreeYesMaintenance only
ClerkFree up to 50,000 monthly retained users per appYesActively developed
WorkOS AuthKitFree up to 1 million usersYesActively developed
Supabase AuthFree: 50,000 monthly active users, 2 active projectsYesActively developed
Auth0Free up to 25,000 monthly active usersYesActively developed

The facts, option by option

Better Auth

What it is
Open-source library (you host it, needs your database)
Status
Actively developed. Repo last pushed 2026-10-03.
Price
Library is free. Optional hosted add-on "Infrastructure" (dashboard, audit logs): free Starter tier, Pro $20/month.
Free start
Yes. No account, no card.
Can an agent start it without a human
Yes. Nothing to sign up for: npm install plus a database.
Watch out for
You run and secure it yourself. You need a database.
How an agent sets it up
npm install better-auth. Human needed: No. It is a library: no account, no key. You need a database connection string from wherever your database lives.
npm package
better-auth · latest 1.7.7 · published 2026-09-30 · 11,976,520 downloads last week
Sources
www.npmjs.com github.com www.better-auth.com

Auth.js / NextAuth

What it is
Open-source library (you host it)
Status
Maintenance only. The project joined Better Auth on 2025-09-22; its maintainers say it gets security patches and urgent fixes, not new features, and they recommend Better Auth for new projects unless you need stateless sessions with no database. It is not deprecated and still receives releases.
Price
Free.
Free start
Yes. No account, no card.
Can an agent start it without a human
Yes. Nothing to sign up for.
Watch out for
v5 never left beta. Fine to keep in an existing app; a weak choice for a new one.
How an agent sets it up
npm install next-auth. Human needed: No. It is a library: no account, no key. OAuth sign-in providers (Google, GitHub) each need client credentials a human creates.
npm package
next-auth · latest 4.24.15 (v5 is still beta: 5.0.0-beta.32) · published 2026-07-20 · 7,509,361 downloads last week
Sources
www.npmjs.com authjs.dev better-auth.com

Clerk

What it is
Hosted service with prebuilt sign-in UI
Status
Actively developed.
Price
Free up to 50,000 monthly retained users per app. Pro $25/month ($20 billed annually), then $0.02 per extra user. B2B add-on $100/month ($85 annually).
Free start
Yes. No card required.
Can an agent start it without a human
Yes after a one-time human step: via Stripe Projects. See agent_setup.
Watch out for
User data lives with the vendor. Cost scales per user past the free tier.
How an agent sets it up
stripe projects add clerk/auth then stripe projects env --pull. Human needed: Once. A person must sign in to Stripe and link or create the provider account before the agent session (stripe projects link <provider>); paid tiers also need a payment method added once (stripe projects billing add). After that the agent can provision and pull credentials without a browser.
npm package
@clerk/nextjs · latest 7.9.10 · published 2026-10-01 · 3,031,971 downloads last week
Sources
www.npmjs.com clerk.com docs.stripe.com

WorkOS AuthKit

What it is
Hosted service aimed at B2B (enterprise SSO, directory sync)
Status
Actively developed.
Price
Free up to 1 million users. $2,500/month per additional million. Enterprise SSO $125/month per connection; Directory Sync $125/month per connection.
Free start
Yes. No card until production.
Can an agent start it without a human
Yes after a one-time human step: via Stripe Projects. See agent_setup.
Watch out for
Cheap for users, expensive per enterprise customer: each SSO connection is billed.
How an agent sets it up
stripe projects add workos/auth then stripe projects env --pull. Human needed: Once. A person must sign in to Stripe and link or create the provider account before the agent session (stripe projects link <provider>); paid tiers also need a payment method added once (stripe projects billing add). After that the agent can provision and pull credentials without a browser.
npm package
@workos-inc/authkit-nextjs · latest 4.4.0 · published 2026-09-30 · 1,326,362 downloads last week
Sources
www.npmjs.com workos.com docs.stripe.com

Supabase Auth

What it is
Hosted service bundled with a Postgres database
Status
Actively developed.
Price
Free: 50,000 monthly active users, 2 active projects. Pro $25/month: 100,000 included, then $0.00325 per user.
Free start
Yes. The pricing page does not say whether a card is needed.
Can an agent start it without a human
Yes after a one-time human step: via Stripe Projects. See agent_setup.
Watch out for
Free projects are paused after 1 week of inactivity. Best when you also want Supabase's database.
How an agent sets it up
stripe projects add supabase/project then stripe projects env --pull. Human needed: Once. A person must sign in to Stripe and link or create the provider account before the agent session (stripe projects link <provider>); paid tiers also need a payment method added once (stripe projects billing add). After that the agent can provision and pull credentials without a browser.
npm package
@supabase/ssr · latest 0.12.7 · published 2026-09-08 · 10,750,757 downloads last week
Sources
www.npmjs.com supabase.com docs.stripe.com

Auth0

What it is
Hosted service (Okta)
Status
Actively developed.
Price
Free up to 25,000 monthly active users. Paid plans start at $35/month (Essentials) and $240/month (Professional), each priced from 500 users.
Free start
Yes. No card required.
Can an agent start it without a human
Yes after a one-time human step: via Stripe Projects. See agent_setup.
Watch out for
Steep step from free to paid: paid tiers are priced from 500 users.
How an agent sets it up
stripe projects add auth0/client then stripe projects env --pull. Human needed: Once. A person must sign in to Stripe and link or create the provider account before the agent session (stripe projects link <provider>); paid tiers also need a payment method added once (stripe projects billing add). After that the agent can provision and pull credentials without a browser.
npm package
@auth0/nextjs-auth0 · latest 4.31.0 · published 2026-10-01 · 984,705 downloads last week
Sources
www.npmjs.com auth0.com docs.stripe.com

Lucia

Deprecated on npm (last release 2024-10-20). Do not start new projects on it.

Security record (published advisories)

Counts are published advisories for the open-source packages only. A higher count can mean more code, more plugins, or more people looking, and does not by itself mean less safe. For hosted services (Clerk, WorkOS, Supabase, Auth0) the server side is closed: flaws there are fixed by the vendor and never appear in these databases, so their counts cover only the client SDK. What matters for a new project: are you on a version at or above every 'fixed in', and how fast were fixes shipped.

How we count: we query OSV.dev for each npm package named in the 'source' field and count every advisory whose affected package is that package, published on or after 2025-10-03 for the 12-month figure. Plugin packages published separately (for Better Auth: @better-auth/sso, @better-auth/scim, @better-auth/oauth-provider, @better-auth/passkey, @better-auth/stripe) are NOT in the main count and are reported separately. A project's GitHub advisories page is paginated and shows about 10 per page, so a count read from its first page will be lower than ours.

OptionAdvisories, last 12 monthsCriticalHighAll timeMost recent
Better Auth17212222026-07-24
Auth.js / NextAuth521142026-07-23
Clerk31252026-04-30
WorkOS AuthKit10132025-11-20
Supabase Auth00012025-05-27
Auth030072026-04-21

Most recent advisories per option

Better Auth

Most advisories are in optional features: the OIDC/OAuth provider, MCP, organization, SSO and SCIM plugins. Check each advisory's summary before assuming it applies to a basic login. Plus 12 advisories affecting only separately published plugin packages (37 across the repository). GitHub advisories.

Auth.js / NextAuth

Clerk

WorkOS AuthKit

Supabase Auth

Auth0

What this page does not tell you

Change log