Stackfacts
Login for a Next.js app: six options compared
Published by Stackfacts, an independent publisher. No paid placement.
Facts checked 2026-10-03. Every fact was read from the vendor's own pricing page, the npm registry, GitHub, or Stripe's provider list on the checked date. Nothing here was benchmarked. No vendor paid for or reviewed this page. Machine-readable copy: /nextjs-auth.json. Agents can also call this as a tool: how.
Picks by situation (our reading of the facts below, not a ranking)
| Your situation | Pick | Why |
|---|
| New project, you have a database, you want no vendor account | Better Auth | It is the actively developed open-source option, and the Auth.js maintainers themselves point new projects to it. |
| Existing app already on next-auth | Stay on next-auth | It still gets security patches (latest release 2026-07-20). Migrate when you need a feature it will not get. |
| You want hosted sign-in with ready-made UI and no database | Clerk | Free to 50,000 users per app with no card, and an agent can provision it through Stripe Projects. |
| You sell to companies that will ask for SSO | WorkOS AuthKit | Free to 1 million users; you pay $125/month per enterprise SSO connection. |
| You are already using Supabase for the database | Supabase Auth | It is included: 50,000 users on the free plan. Remember free projects pause after a week idle. |
| No database and no vendor at all (stateless sessions) | Auth.js / NextAuth | This is the one case its maintainers still name for choosing it over Better Auth. |
At a glance
| Option | Price | Free start | Idle / status |
|---|
| Better Auth | Library is free | Yes | Actively developed |
| Auth.js / NextAuth | Free | Yes | Maintenance only |
| Clerk | Free up to 50,000 monthly retained users per app | Yes | Actively developed |
| WorkOS AuthKit | Free up to 1 million users | Yes | Actively developed |
| Supabase Auth | Free: 50,000 monthly active users, 2 active projects | Yes | Actively developed |
| Auth0 | Free up to 25,000 monthly active users | Yes | Actively developed |
The facts, option by option
Better Auth
- What it is
- Open-source library (you host it, needs your database)
- Status
- Actively developed. Repo last pushed 2026-10-03.
- Price
- Library is free. Optional hosted add-on "Infrastructure" (dashboard, audit logs): free Starter tier, Pro $20/month.
- Free start
- Yes. No account, no card.
- Can an agent start it without a human
- Yes. Nothing to sign up for: npm install plus a database.
- Watch out for
- You run and secure it yourself. You need a database.
- How an agent sets it up
npm install better-auth. Human needed: No. It is a library: no account, no key. You need a database connection string from wherever your database lives.- npm package
- better-auth · latest 1.7.7 · published 2026-09-30 · 11,976,520 downloads last week
- Sources
- www.npmjs.com github.com www.better-auth.com
Auth.js / NextAuth
- What it is
- Open-source library (you host it)
- Status
- Maintenance only. The project joined Better Auth on 2025-09-22; its maintainers say it gets security patches and urgent fixes, not new features, and they recommend Better Auth for new projects unless you need stateless sessions with no database. It is not deprecated and still receives releases.
- Price
- Free.
- Free start
- Yes. No account, no card.
- Can an agent start it without a human
- Yes. Nothing to sign up for.
- Watch out for
- v5 never left beta. Fine to keep in an existing app; a weak choice for a new one.
- How an agent sets it up
npm install next-auth. Human needed: No. It is a library: no account, no key. OAuth sign-in providers (Google, GitHub) each need client credentials a human creates.- npm package
- next-auth · latest 4.24.15 (v5 is still beta: 5.0.0-beta.32) · published 2026-07-20 · 7,509,361 downloads last week
- Sources
- www.npmjs.com authjs.dev better-auth.com
Clerk
- What it is
- Hosted service with prebuilt sign-in UI
- Status
- Actively developed.
- Price
- Free up to 50,000 monthly retained users per app. Pro $25/month ($20 billed annually), then $0.02 per extra user. B2B add-on $100/month ($85 annually).
- Free start
- Yes. No card required.
- Can an agent start it without a human
- Yes after a one-time human step: via Stripe Projects. See agent_setup.
- Watch out for
- User data lives with the vendor. Cost scales per user past the free tier.
- How an agent sets it up
stripe projects add clerk/auth then stripe projects env --pull. Human needed: Once. A person must sign in to Stripe and link or create the provider account before the agent session (stripe projects link <provider>); paid tiers also need a payment method added once (stripe projects billing add). After that the agent can provision and pull credentials without a browser.- npm package
- @clerk/nextjs · latest 7.9.10 · published 2026-10-01 · 3,031,971 downloads last week
- Sources
- www.npmjs.com clerk.com docs.stripe.com
WorkOS AuthKit
- What it is
- Hosted service aimed at B2B (enterprise SSO, directory sync)
- Status
- Actively developed.
- Price
- Free up to 1 million users. $2,500/month per additional million. Enterprise SSO $125/month per connection; Directory Sync $125/month per connection.
- Free start
- Yes. No card until production.
- Can an agent start it without a human
- Yes after a one-time human step: via Stripe Projects. See agent_setup.
- Watch out for
- Cheap for users, expensive per enterprise customer: each SSO connection is billed.
- How an agent sets it up
stripe projects add workos/auth then stripe projects env --pull. Human needed: Once. A person must sign in to Stripe and link or create the provider account before the agent session (stripe projects link <provider>); paid tiers also need a payment method added once (stripe projects billing add). After that the agent can provision and pull credentials without a browser.- npm package
- @workos-inc/authkit-nextjs · latest 4.4.0 · published 2026-09-30 · 1,326,362 downloads last week
- Sources
- www.npmjs.com workos.com docs.stripe.com
Supabase Auth
- What it is
- Hosted service bundled with a Postgres database
- Status
- Actively developed.
- Price
- Free: 50,000 monthly active users, 2 active projects. Pro $25/month: 100,000 included, then $0.00325 per user.
- Free start
- Yes. The pricing page does not say whether a card is needed.
- Can an agent start it without a human
- Yes after a one-time human step: via Stripe Projects. See agent_setup.
- Watch out for
- Free projects are paused after 1 week of inactivity. Best when you also want Supabase's database.
- How an agent sets it up
stripe projects add supabase/project then stripe projects env --pull. Human needed: Once. A person must sign in to Stripe and link or create the provider account before the agent session (stripe projects link <provider>); paid tiers also need a payment method added once (stripe projects billing add). After that the agent can provision and pull credentials without a browser.- npm package
- @supabase/ssr · latest 0.12.7 · published 2026-09-08 · 10,750,757 downloads last week
- Sources
- www.npmjs.com supabase.com docs.stripe.com
Auth0
- What it is
- Hosted service (Okta)
- Status
- Actively developed.
- Price
- Free up to 25,000 monthly active users. Paid plans start at $35/month (Essentials) and $240/month (Professional), each priced from 500 users.
- Free start
- Yes. No card required.
- Can an agent start it without a human
- Yes after a one-time human step: via Stripe Projects. See agent_setup.
- Watch out for
- Steep step from free to paid: paid tiers are priced from 500 users.
- How an agent sets it up
stripe projects add auth0/client then stripe projects env --pull. Human needed: Once. A person must sign in to Stripe and link or create the provider account before the agent session (stripe projects link <provider>); paid tiers also need a payment method added once (stripe projects billing add). After that the agent can provision and pull credentials without a browser.- npm package
- @auth0/nextjs-auth0 · latest 4.31.0 · published 2026-10-01 · 984,705 downloads last week
- Sources
- www.npmjs.com auth0.com docs.stripe.com
Lucia
Deprecated on npm (last release 2024-10-20). Do not start new projects on it.
Security record (published advisories)
Counts are published advisories for the open-source packages only. A higher count can mean more code, more plugins, or more people looking, and does not by itself mean less safe. For hosted services (Clerk, WorkOS, Supabase, Auth0) the server side is closed: flaws there are fixed by the vendor and never appear in these databases, so their counts cover only the client SDK. What matters for a new project: are you on a version at or above every 'fixed in', and how fast were fixes shipped.
How we count: we query OSV.dev for each npm package named in the 'source' field and count every advisory whose affected package is that package, published on or after 2025-10-03 for the 12-month figure. Plugin packages published separately (for Better Auth: @better-auth/sso, @better-auth/scim, @better-auth/oauth-provider, @better-auth/passkey, @better-auth/stripe) are NOT in the main count and are reported separately. A project's GitHub advisories page is paginated and shows about 10 per page, so a count read from its first page will be lower than ours.
| Option | Advisories, last 12 months | Critical | High | All time | Most recent |
|---|
| Better Auth | 17 | 2 | 12 | 22 | 2026-07-24 |
| Auth.js / NextAuth | 5 | 2 | 1 | 14 | 2026-07-23 |
| Clerk | 3 | 1 | 2 | 5 | 2026-04-30 |
| WorkOS AuthKit | 1 | 0 | 1 | 3 | 2025-11-20 |
| Supabase Auth | 0 | 0 | 0 | 1 | 2025-05-27 |
| Auth0 | 3 | 0 | 0 | 7 | 2026-04-21 |
Most recent advisories per option
Better Auth
Most advisories are in optional features: the OIDC/OAuth provider, MCP, organization, SSO and SCIM plugins. Check each advisory's summary before assuming it applies to a basic login. Plus 12 advisories affecting only separately published plugin packages (37 across the repository). GitHub advisories.
- 2026-07-24 · HIGH · CVE-2026-67327 · Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in · fixed in 1.6.22, 1.7.0-beta.10
- 2026-07-07 · LOW · CVE-2026-67334 · Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows · fixed in 1.6.11
- 2026-07-07 · HIGH · CVE-2026-53517 · Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption · fixed in 1.6.0
- 2026-07-07 · HIGH · CVE-2026-53518 · @better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token reque · fixed in 1.6.11
- 2026-07-07 · HIGH · CVE-2026-67333 · Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp · fixed in 1.6.13, 1.7.0-beta.4
- 2026-07-07 · HIGH · CVE-2026-67336 · Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted b · fixed in 1.6.11
Auth.js / NextAuth
- 2026-07-23 · CRITICAL · CVE-2026-73420 · Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass · fixed in 4.24.15, 5.0.0-beta.32
- 2026-07-23 · CRITICAL · CVE-2026-73421 · Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with a · fixed in 5.0.0-beta.32
- 2026-07-23 · MODERATE · CVE-2026-73419 · Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them · fixed in 4.24.15, 5.0.0-beta.32
- 2026-07-23 · HIGH · CVE-2026-73418 · Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers · fixed in 4.24.15, 5.0.0-beta.32
- 2025-10-29 · MODERATE · GHSA-5jpx-9hw9-2fx4 · NextAuthjs Email misdelivery Vulnerability · fixed in 4.24.12, 5.0.0-beta.30
- 2023-11-20 · MODERATE · CVE-2023-48309 · Possible user mocking that bypasses basic authentication · fixed in 4.24.5
Clerk
- 2026-04-30 · HIGH · CVE-2026-42349 · Clerk has an authorization bypass when combining organization, billing, or reverification checks · fixed in 6.39.3, 7.2.4
- 2026-04-16 · CRITICAL · CVE-2026-41248 · Official Clerk JavaScript SDKs: Middleware-based route protection bypass · fixed in 5.7.6, 6.39.2, 7.2.1
- 2026-03-27 · HIGH · CVE-2026-34076 · Clerk: SSRF in the opt-in clerkFrontendApiProxy feature may leak secret keys to unintended host · fixed in 3.2.3
- 2025-07-09 · HIGH · CVE-2025-53548 · @clerk/backend Performs Insufficient Verification of Data Authenticity · fixed in 6.23.3
- 2024-01-12 · CRITICAL · CVE-2024-22206 · @clerk/nextjs auth() and getAuth() methods vulnerable to insecure direct object reference (IDOR) · fixed in 4.29.3
WorkOS AuthKit
- 2025-11-20 · HIGH · CVE-2025-64762 · authkit-nextjs may let session cookies be cached in CDNs · fixed in 2.11.1
- 2024-11-05 · LOW · CVE-2024-51752 · @workos-inc/authkit-nextjs refresh tokens are logged when the debug flag is enabled · fixed in 0.13.2
- 2024-03-29 · MODERATE · CVE-2024-29901 · @workos-inc/authkit-nextjs session replay vulnerability · fixed in 0.4.2
Supabase Auth
- 2025-05-27 · LOW · CVE-2025-48370 · auth-js Vulnerable to Insecure Path Routing from Malformed User Input · fixed in 2.70.0
Auth0
- 2026-04-21 · MODERATE · CVE-2026-40155 · Auth0 Next.js SDK has Improper Proxy Cache Lookup · fixed in 4.18.0
- 2025-12-10 · LOW · CVE-2025-67716 · Improper Validation of Query Parameters in Auth0 Next.js SDK · fixed in 4.13.0
- 2025-12-10 · MODERATE · CVE-2025-67490 · Improper Request Caching Lookup in the Auth0 Next.js SDK · fixed in 4.11.2, 4.12.1
- 2025-06-04 · HIGH · CVE-2025-48947 · NextJS-Auth0 SDK Vulnerable to CDN Caching of Session Cookies · fixed in 4.6.1
- 2025-04-29 · MODERATE · CVE-2025-46344 · Auth0 NextJS SDK v4 Missing Session Invalidation · fixed in 4.5.1
- 2021-12-16 · MODERATE · CVE-2021-43812 · Open redirect in @auth0/nextjs-auth0 · fixed in 1.6.2
What this page does not tell you
- Whether Supabase's free plan needs a card
- Hands-on build quality of each option
- Prices beyond the published list prices
- Third-party security audits (we found no published audit report for any of the libraries; absence of a report is not evidence either way)
- Incidents on the hosted vendors' own servers
Change log
- 2026-10-03: First version. Added security record from OSV.dev for every option.
- 2026-10-03: Added counting method and separate plugin-package count for Better Auth after a reader could not reproduce our number from GitHub's first page.
- 2026-10-03: Added agent_setup (exact command and whether a human is needed) and a source for every fact.