Back to all posts
Guide
9 min read

Best Authentication Providers in 2026: Auth0 vs Clerk vs WorkOS

DevToolLab Team

DevToolLab Team

August 21, 2026

Best Authentication Providers in 2026: Auth0 vs Clerk vs WorkOS

Every app with users eventually hits the same wall: not "who is this person" but "a customer's IT department wants their Okta tenant wired into your login page." The first is a weekend of work. The second is why authentication providers exist.

Here is the number that reframes the comparison. As of August 21, 2026, WorkOS gives away user management for the first 1 million monthly active users, while Auth0's free tier stops at 25,000 MAU and Clerk stops at 50,000 monthly retained users. That looks like a rout until you scroll further down the same WorkOS page, where enterprise SSO costs $125 per connection per month. The free tier is marketing. The per-connection fee for the customer who demanded SAML is the product.

Quick Comparison

ProviderFree tierPaid entryEnterprise SSOSelf-hostBest for
Auth025,000 MAU$35/mo at 500 MAU1 included from FreeNoProtocol breadth, regulated industries
Clerk50,000 MRU per app$25/mo, then $0.02/MRU1 on Pro, $75/mo each afterNoReact and Next.js products
WorkOS1,000,000 MAU$2,500/mo per extra 1M$125/ea, $65/ea at volumeNoB2B SaaS selling to enterprises
Better AuthUnlimited, MITYour database billPlugin, self-managedYesTypeScript teams wanting their own data
KeycloakUnlimited, Apache 2.0Your infra billBuilt in, unlimitedYesFull protocol coverage, no per-seat meter

Federation is the bucket that unblocks contracts, which is exactly why every vendor meters it per connection. Machine identity is the new third product: Clerk lists API keys and M2M tokens as a plan feature, and Auth0 is currently running a banner for "Agent as Principal."

Auth0

Auth0 pricing page showing the Free plan at $0 per month for up to 25,000 monthly active users, Essentials at $35 per month, Professional at $240 per month, and a custom Enterprise tier
Auth0 pricing page showing the Free plan at $0 per month for up to 25,000 monthly active users, Essentials at $35 per month, Professional at $240 per month, and a custom Enterprise tier

Auth0, owned by Okta since 2021, is the incumbent and behaves like one. The free tier is genuinely large at 25,000 MAU, and it now includes things that used to be paywalled: one enterprise connection, self-service SSO, SCIM, and five organizations, each flagged NEW on the pricing page.

Paid pricing is where the incumbent tax shows. The headline $35/mo for B2C Essentials is the price at 500 MAU, and the plan is a step function keyed to your MAU band, so the number moves with you. Professional starts at $240/mo for that same 500-user band. B2B sits on a separate schedule behind the B2C/B2B toggle and costs several times more at the same volume: Essentials is $150/mo and Professional $800/mo at that same 500-MAU band. Price your real use case rather than the headline.

Protocol coverage is the deepest of the three, and Actions let you run server-side logic inside the login pipeline. The tradeoffs: a developer experience that feels dated next to Clerk, and a jump from free tenant to real bill that teams usually discover after launch.

Clerk

Clerk pricing page showing the Hobby plan free with a 50,000 MRU limit per app, Pro at $20 per month billed annually, Business at $250 per month billed annually, and a custom Enterprise plan
Clerk pricing page showing the Hobby plan free with a 50,000 MRU limit per app, Pro at $20 per month billed annually, Business at $250 per month billed annually, and a custom Enterprise plan

Clerk is still the fastest way to get real authentication into a Next.js app, and its billing unit is worth understanding because it is not the industry standard. Clerk meters monthly retained users, which its pricing FAQ defines as a user who visits your app in a given month at least one day after signing up. That free first day is deliberate, so a launch-day signup spike does not bill the way it would on a MAU meter.

Hobby allows 50,000 MRU per app, with the tradeoffs on the same page: 1-day log retention, a fixed 7-day session lifetime, and Clerk branding. Pro is $25/mo ($20/mo annually) with extras at $0.02/mo each, and unlocks MFA, custom session lifetimes, and branding removal. One enterprise connection is included, each additional one is $75/mo, and satellite domains are $10/mo. Business at $300/mo adds a SOC 2 report and 30-day retention; HIPAA with a BAA and a 99.99% SLA sit on Enterprise.

Time to working auth is the shortest here, and organizations, invitations, and roles are first-class. You cannot self-host it, protocol depth is narrower than Auth0's, and the ecosystem leans hard toward React.

One detail before you copy an older tutorial: in @clerk/nextjs 7.x the middleware-plus-createRouteMatcher pattern most posts still show is deprecated, because path matching can diverge from how Next.js routes a request and leave a protected resource reachable. Check inside whatever touches protected data instead:

React TS
// app/dashboard/page.tsx - resource-based check, @clerk/nextjs 7.8.0
import { auth, currentUser } from "@clerk/nextjs/server";

export default async function DashboardPage() {
  await auth.protect();               // redirects unauthenticated visitors
  const user = await currentUser();

  return <h1>Welcome back, {user?.firstName ?? "there"}</h1>;
}

WorkOS

WorkOS pricing calculator showing Single Sign-On and Directory Sync at $125 per connection for 1-15 connections, $100 for 16-30, $80 for 31-50, and $65 for 51-100
WorkOS pricing calculator showing Single Sign-On and Directory Sync at $125 per connection for 1-15 connections, $100 for 16-30, $80 for 31-50, and $65 for 51-100

WorkOS came at this from the opposite end: it started as the enterprise-readiness layer (SSO, SCIM, audit logs) and added its login product, AuthKit, later. That explains the pricing. AuthKit is free to 1 million MAU, then $2,500/mo per additional million, because login is the loss leader. Revenue sits in the connection meter: SSO is $125 per connection for the first 15, then $100 (20% off), $80 (36% off), and $65 at 51-100. Directory Sync uses the identical ladder, and Audit Logs is a separate product.

The arithmetic inverts on customer type. A consumer app with 400,000 users and no SAML customers pays WorkOS nothing, and would pay Clerk roughly $7,000/mo past the included 50,000 MRU. A B2B product with 8,000 users and 30 enterprise customers on SSO plus SCIM pays about $6,750/mo while its user meter stays free, because the bands are graduated: WorkOS's own calculator returns $3,375 for 30 SSO connections (15 at $125 plus 15 at $100), and Directory Sync is billed on the identical ladder.

The SSO implementation is the least painful in the category, which is the whole pitch: every identity provider interprets SAML differently and WorkOS absorbs that variance. Admin Portal hands connection setup to the customer's IT admin. If you are not selling to enterprises, most of what you pay for is irrelevant.

The Open-Source Side

If a vendor holding your user table is the blocker, these are in better shape than two years ago. All figures read from each repository on August 21, 2026.

Better Auth changed the conversation for TypeScript teams: MIT, 29,627 stars, v1.7.1 shipped August 18, 2026. It is a library rather than a server: you point it at your own database and it owns the schema, endpoints, and plugins for organizations, passkeys, and two-factor. Vercel acquired it on July 7, 2026, saying the library "remains free and open source under MIT, retains its name," with the team now on agent identity. Worth knowing before you adopt it, though the license did not change.

Better Auth homepage describing itself as the most comprehensive authentication framework for TypeScript
Better Auth homepage describing itself as the most comprehensive authentication framework for TypeScript

Keycloak is the heavyweight: Apache 2.0, 36,325 stars, 26.7.2 released August 19, 2026, with unlimited realms and SAML connections and no per-connection meter anywhere. The price is operational. Zitadel (AGPL 3.0, 14,816 stars) is the closest analog to a hosted platform, Ory Kratos ships no UI, and Logto targets smaller teams. authentik and SuperTokens use split licensing, so read the license before assuming a feature is free.

Running Better Auth Locally

We ran Better Auth 1.7.1 with better-sqlite3 on Node 25. Mounting auth.handler on any server gives you the endpoints:

ts
// auth.ts
import { betterAuth } from "better-auth";
import Database from "better-sqlite3";

export const auth = betterAuth({
  database: new Database("./auth.db"),
  emailAndPassword: { enabled: true },
  session: { expiresIn: 60 * 60 * 24 * 7 },
});

One gotcha cost us twenty minutes. The documented npx @better-auth/cli migrate resolves to @better-auth/cli@1.4.21, which npm flags as no longer supported and which writes a 1.4-era schema, so against 1.7.1 the first signup dies with table account has no column named issuer. Skip the CLI and call getMigrations(auth.options) from better-auth/db/migration, which diffs your live schema and reported exactly the gap (account: issuer) before applying it. After that signup and signin work, the cookie comes back as better-auth.session_token, and get-session returns the 7-day expiry set above. Set BETTER_AUTH_URL or callbacks break, and generate BETTER_AUTH_SECRET with openssl rand -base64 32.

How to Pick

Start from your customers, not your framework, because that is the variable that moves the bill.

Consumers or small teams on Next.js: Clerk, because the free tier covers the pre-revenue phase and the retained-user meter survives a launch spike. Enterprise contracts: WorkOS, where auth cost tracks deals closed. Regulated industry or unusual protocols: Auth0, once you have modeled your real MAU band. Data residency: self-host with Better Auth or Keycloak.

Avoid picking on free-tier size alone. Free tiers are marketing; the per-connection fee and the MAU step function are where two years of bills come from.

Migrating Without a Flag Day

The fear is "every user gets logged out at once." It is avoidable.

  1. Inventory login methods and hashes. bcrypt and argon2id usually import directly; anything homegrown means a forced reset for that cohort.
  2. Stand the new provider up beside the old one behind a flag: import profiles first and hashes second so IDs stay stable, then send new signups to it while existing sessions keep validating against the old one.
  3. Migrate returning users lazily: on a successful login against the old provider, write the credential into the new one in the same request, so the active population moves itself in weeks. Move enterprise connections one customer at a time, and verify the boring flows (password reset, MFA recovery codes, SCIM deprovisioning) before deleting anything.

Conclusion

Clerk if your customers are people and your framework is React. WorkOS if your customers are companies and a SAML connection stands between you and a contract. Auth0 if you need protocol depth or compliance breadth. Better Auth or Keycloak if the user table has to stay on your side of the network.

Free tiers are now large enough that early-stage cost is no longer a differentiator, and all three vendors now sell machine identity alongside human login. If agents will act on your users' behalf, evaluate that part now: it is the least mature and the most likely to reshape your pricing.

Related Posts

Best SQL Clients in 2026: 8 Tools Compared

DBeaver, DataGrip, Beekeeper Studio, TablePlus, DbGate, DbVisualizer, Chat2DB and VS Code's MSSQL extension, priced for a five-developer team.

By DevToolLab Team•

What Is an Agent Harness? Pi 1.0 Explained

An agent harness is the loop, tools, permissions and context around a model. Watch Pi 1.0 run one, then compare Claude Code, Codex, OpenCode and DeepSeek.

By DevToolLab Team•

Best AI Penetration Testing Tools in 2026

Aikido, XBOW, NodeZero, RunSybil, Strix, Shannon and PentAGI compared on published prices, licenses and the one third-party head-to-head test of 2026.

By DevToolLab Team•