Choosing an auth provider: Clerk, Auth0, WorkOS, or DIY
Clerk vs. Auth0 vs. WorkOS vs. a library like Better Auth: pricing, SSO and SCIM, developer experience, password hash export, and compliance.
By Lance King · · 11 min read
This guide is for founders and engineers picking how users will sign in to a new product, or wondering whether the provider they picked two years ago still fits. The decision usually comes down to four paths: Clerk, Auth0, WorkOS, or running auth inside your own app with an open-source library. The right answer depends less on login screens, which all of them do well, and more on three questions: will you sell to companies that demand single sign-on, how will the bill grow with your user count, and how hard will it be to leave.
The short answer
- Choose Clerk if you’re building a consumer or prosumer app in React or Next.js and want drop-in sign-in components and user management working this afternoon.
- Choose WorkOS if you sell to businesses and expect customers to ask for SAML single sign-on and directory sync, and you want a large free user allowance.
- Choose Auth0 if you need the broadest set of identity features and compliance paperwork, and you have the budget for it.
- Choose a library such as Better Auth if you want users in your own database, no per-user bill, and you have the engineering time to own the security work.
What actually matters
1. How the price scales. Hosted providers charge by users, and each defines “user” differently. Auth0 counts monthly active users (MAUs), which it defines as any non-employee user who authenticated during a given month. Clerk counts monthly retained users (MRUs): “a user who visits your app in a given month at least one day after signing up.” WorkOS AuthKit counts MAUs too, but gives away a very large number of them. Model your bill at 10x your current users before you commit.
2. Enterprise features and what they cost. If you sell to companies, you’ll eventually hear three acronyms. SSO (single sign-on) lets a customer’s employees log in through their company identity provider, usually over SAML or OIDC, the two standard protocols. SCIM (System for Cross-domain Identity Management) lets the customer’s IT team create and remove accounts in your app automatically, often called directory sync. Organizations are the data model that groups users under a customer account. Providers usually price SSO and SCIM per “connection,” meaning per customer that sets one up.
3. Developer experience. How much code you write for sign-in, sessions, and profile screens. Prebuilt UI saves time but ties your front end to the vendor.
4. Data ownership and exit cost. The hardest part of leaving any auth provider is passwords. You can’t decrypt a password hash, so to move users without forcing a reset you need the provider to hand over the hashes and the new system to accept that hash format. Some vendors make this self-serve, some require a support ticket, and some don’t offer it.
5. Compliance. Enterprise buyers will ask for a SOC 2 report, and health-care customers will need a business associate agreement (BAA) under HIPAA. Check which plan tier unlocks each.
6. Who maintains it. For libraries especially, check whether the project is still active. That landscape changed a lot between 2024 and 2026.
The options at a glance
Prices are from each vendor’s official pricing page, as of October 2026.
| Clerk | Auth0 | WorkOS (AuthKit) | Library (e.g. Better Auth) | |
|---|---|---|---|---|
| Free tier | 50,000 MRUs per app (Hobby) | Up to 25,000 MAUs | First 1M MAUs | No license cost; you pay for hosting |
| Paid entry point | Pro $25/mo ($20 billed annually), 50,000 MRUs included | B2C Essentials from $35/mo for 500 MAUs; B2B Essentials from $150/mo for 500 MAUs | $2,500/mo per additional 1M MAUs | Your time |
| Enterprise SSO | 1 connection on Pro, then $75/mo each (2–15) | 1 on Free; 3 on B2B Essentials; extra $100/mo each, max 30 | $125/mo per connection (1–15), discounts at volume | SAML and OIDC via a plugin |
| SCIM / directory sync | 1 connection on Pro | Listed on all plans | $125/mo per connection (1–15) | Build it or add it |
| Password hash export | Self-serve CSV from the dashboard | Support ticket, paid plans only | Not offered, per Better Auth’s migration guide | It’s your database |
| Compliance highlights | SOC 2 report on Business; HIPAA BAA on Enterprise | Okta trust center lists SOC 2, ISO 27001, HIPAA, PCI DSS; HIPAA/BAA an Enterprise add-on | SOC 2 Type 2; BAA on enterprise plans | Whatever your own controls cover |
The hosted options in more detail
Clerk
Clerk’s strength is prebuilt components: sign-in, sign-up, user profile, and organization switcher drop into a React or Next.js app with little code. The free Hobby plan includes 50,000 MRUs per app and 100 monthly retained organizations, but leaves out multifactor authentication (MFA), passkeys, removing Clerk branding, and enterprise SSO.
Pro costs $25 a month, or $20 billed annually, as of October 2026. It includes 50,000 MRUs, then charges $0.02 per MRU from 50,001 to 100,000, stepping down to $0.018, $0.015, and $0.012 at higher volumes. Pro includes one enterprise SSO connection (SAML, OIDC, or EASIE). Additional connections cost $75 a month each for 2 to 15, then $60 each for 16 to 100. Pro also includes one directory sync connection; Clerk’s pricing page says additional ones will cost $75 a month each from January 1, 2027. An Enhanced B2B Authentication add-on is $100 a month ($85 billed annually).
Business is $300 a month ($250 billed annually) and adds a SOC 2 report, priority support, and 30 days of application and admin logs. HIPAA compliance with a BAA is listed under Enterprise.
On exit, Clerk is the most open of the three hosted options: admins can export a CSV of users that includes hashed passwords straight from the dashboard. Clerk can also import users with existing hashes and upgrades them to bcrypt.
Auth0
Auth0 is part of Okta and has a broad identity feature set and a long compliance list. Okta’s trust center lists SOC 2, ISO 27001, HIPAA, and PCI DSS among its certifications; ask sales which apply to the Auth0 product and tier you’re buying.
The free plan covers up to 25,000 MAUs, one enterprise connection, five organizations, and one custom domain. Paid plans split into B2C and B2B tracks, and the B2B track costs more. As of October 2026, B2C Essentials starts at $35 a month for 500 MAUs and is listed at $700 a month for 10,000 MAUs. B2B Essentials starts at $150 a month for 500 MAUs, includes three enterprise SSO connections and unlimited organizations, and is listed at $2,100 a month for 10,000 MAUs. Extra enterprise connections are $100 a month each, up to 30. B2B Professional starts at $800 a month and includes five connections.
The catch is the curve. Auth0 gets expensive quickly as active users grow, especially on the B2B track, so run your projected numbers through its calculator, not just today’s.
Leaving is possible but slower. Auth0’s bulk export tools don’t include password hashes. Its data export policy says you can request them through a support ticket, that this isn’t available on the Free tier, and that Auth0 can’t guarantee an export on a specific date. Plan migrations with that delay in mind.
WorkOS
WorkOS started as an enterprise-features API (SSO and directory sync you add to any auth system) and now also sells AuthKit, a full user management product with a hosted login page, MFA, role-based access control, and bot detection.
The pricing model is unusual. AuthKit’s first one million MAUs are free; each additional million costs $2,500 a month, as of October 2026. Instead of charging for users, WorkOS charges for enterprise connections: $125 a month per SSO connection for the first 15, dropping to $100, $80, and $65 at higher volumes. Directory sync uses the same tiers. Audit log streaming, a custom domain ($99 a month), and Radar bot protection are add-ons.
For a B2B company, this ties cost to revenue: you pay more when a paying enterprise customer turns on SSO.
WorkOS lists SOC 2 Type 2, GDPR and CCPA compliance, and BAAs on enterprise plans.
On exit: WorkOS imports password hashes in several formats, including bcrypt, scrypt, PBKDF2, and argon2. Going the other way is harder. Better Auth’s WorkOS migration guide says “WorkOS does not provide an export of password hashes at this time,” which means users would need to reset passwords if you leave. Confirm the current policy with WorkOS before you sign, and get the answer in writing.
Building your own with a library
Rolling your own no longer means writing password hashing from scratch. It means running an open-source library inside your app, with users in your own database. You skip the per-user bill and the export problem. You take on security updates, abuse protection, email deliverability for login links, and every enterprise feature request. The build vs. buy tradeoff applies in full here.
The library landscape has shifted, so here is where things stand in October 2026:
- Better Auth is a framework-agnostic TypeScript auth framework with plugins for two-factor authentication, passkeys, multi-tenancy, and SSO over OIDC, OAuth2, and SAML 2.0. Vercel announced on July 7, 2026 that it had acquired the company behind it. Vercel says the library stays free and MIT-licensed under the same name, with the same open contribution model. That’s reassuring, but the roadmap now sits inside a platform company, so watch where it goes.
- Auth.js (formerly NextAuth.js) is now maintained by the Better Auth team, as announced on September 22, 2025. Existing apps keep working and get security patches and urgent fixes, but the maintainers “strongly recommend new projects to start with Better Auth.” Don’t start a new project on it.
- Lucia is no longer a library. Its README says it “was deprecated on March 2025” and points to a single-file replacement you copy into your codebase, plus a guide to implementing sessions yourself. That’s useful learning material, not a dependency to install.
A library is reasonable when your users are consumers or individual developers, your team is comfortable owning auth code, and you don’t expect enterprise SSO requests soon.
Open-source servers you host yourself
There’s a middle path: run a full identity server in your own infrastructure.
- Keycloak is an open-source identity and access management server and a Cloud Native Computing Foundation incubation project. It supports OIDC, OAuth 2.0, and SAML 2.0, and connects to existing LDAP or Active Directory servers. It’s powerful and heavy to operate.
- Ory Kratos is an Apache-2.0 identity server you can self-host, with Postgres, MySQL, or CockroachDB. Ory also sells a managed, API-compatible version called Ory Network, which gives you a way to move between hosted and self-hosted.
- Supabase Auth stores users in a schema inside your project’s Postgres database and ties into row-level security. If you already use Supabase, it’s the obvious default, and your user data stays in a database you can query.
Which one for you
Prices in this section are as of October 2026.
Solo founder, consumer app. Clerk’s free tier or WorkOS AuthKit’s free tier will carry you a long way. Pick Clerk if you want the prebuilt React components; pick AuthKit if you want a hosted login page and a very high free ceiling. If you’re already on Supabase, use Supabase Auth.
Growing B2B startup. WorkOS fits best if SSO requests are already in your pipeline, because its cost rises with enterprise customers rather than with all users. Clerk is a reasonable alternative if you value its components and expect only a handful of SSO customers; compare its $75 per extra connection against WorkOS’s $125.
Regulated company or large enterprise buyer. Auth0 has the most compliance coverage and enterprise features, and its sales team will expect to negotiate. WorkOS and Clerk both offer BAAs, but only on their enterprise tiers. Ask every vendor for its SOC 2 report early.
Team that wants full control. Better Auth in your own database, or Keycloak or Ory if you need a standalone identity server for several apps. Budget engineering time for it every quarter, not just at launch.
Mistakes to avoid
- Pricing only today’s user count. Model 10x. Auth0’s B2B track and Clerk’s per-MRU overage both look very different at scale.
- Ignoring how “user” is defined. MAU and MRU count different things. A product with many one-time sign-ups behaves differently under each.
- Assuming you can leave easily. Ask for the password hash export process before you sign. Self-serve, support ticket, and “not available” are very different answers.
- Starting new code on a library in maintenance mode. Auth.js and Lucia are not where new projects should begin.
- Building SSO and SCIM yourself to save a few hundred dollars a month. Enterprise identity has endless edge cases across identity providers. That’s often the part worth buying even if you run the rest yourself.
- Letting the choice go undocumented. Write a short technical decision record noting the pricing you were quoted and the exit plan. You’ll want it when the renewal arrives.
A quick checklist
- Do you sell to businesses that will ask for SAML SSO or SCIM in the next year?
- What will the provider cost at your expected user count in 12 and 36 months?
- How does the provider define a billable user?
- Can you export password hashes, and how long does it take?
- Which plan tier gives you a SOC 2 report or a BAA, if you need one?
- Are you comfortable with the prebuilt UI tying your front end to one vendor?
- If you’re using a library, is it actively maintained, and who will patch it?
- Have you written down the decision and the exit plan?
Sources
- Clerk pricing
- Clerk docs: Migrating your data
- Auth0 home page
- Auth0 pricing
- Auth0 docs: Data export and transfer policy
- Auth0 docs: Export data
- Okta Security Trust Center
- WorkOS pricing
- WorkOS security
- AuthKit
- WorkOS docs: Migrate from Clerk
- WorkOS docs: Migrate from other services
- Better Auth: Migrating from WorkOS
- Better Auth introduction
- Better Auth SSO plugin
- Vercel: Vercel acquires Better Auth
- Better Auth: Auth.js is now part of Better Auth
- Lucia on GitHub
- Keycloak
- Ory Kratos on GitHub
- Supabase Auth docs