5 ms·
Auth.js is now part of Better Auth
- awaseem 1y agoWow this is such a natural fit! Used both products, better auth is a clear successor. What a great path forward
- Everhusk 1y agoGreat news for dev simplicity, Better Auth is just... better.
- kevinkatzke 1y agoUsed and loved both products. Great to see they are joining forces.
- bottlepalm 1y agoThey're not. Better Auth is only 'maintaining' Auth.js to push people towards Better Auth.
- BoorishBears 1y agoRauch got a heck of a deal: hire NextAuth/Auth.js lead developer, use zombified Auth.js as a funnel to Clerk (a portco) with prominent CTAs on every page. Then a replacement to zombified Auth.js pops up, but this time he's early so I would take bets on him having a slice. Use your closeness (via having hired the lead dev) to facilitate "absorbing" (read: erasing) the last dregs of Auth.js, successfully replacing it with a duopoly you've invested in both sides of! Bonus: Having raised (which you helped with) they can't undercut Clerk on some shoestring budget.. they'll fail! The prophecy continues :) https://news.ycombinator.com/item?id=40321997 https://news.ycombinator.com/item?id=40321997
- dzonga 1y agoonly in javascript where auth is such a big issue. in rails you can use the rails 8 auth or a better alternative authentication-zero. before it was devise. java - spring security, shiro etc. but just complex things. alternatively - use services like fusionAuth
- evv 1y agoWhy is auth "such a big issue" in JS? I've used a number of solutions but haven't had big issues with them.
- readline_prompt 1y agoSame. I've personally never had issues with any auth packages, granted I've never used auth0. Personally, they all seem quite similar, especially in the react world. Anything that can help me utilize oauth standards is fine to me.
- jamesjulich 1y agoIt’s not that auth is unsolved in other languages/frameworks, but it’s often way too complex or configuration-heavy. If adding passkey support to my app is going to take 2 hours, that’s two hours I’m spending away from building my core product. For smaller projects, that’s not time that I could afford. For example, if I want to add passkeys to my .NET CORE app, this is the guide Microsoft provides: https://learn.microsoft.com/en-us/aspnet/core/security/authentication/passkeys/?view=aspnetcore-10.0 https://learn.microsoft.com/en-us/aspnet/core/security/authe... Contrast that to better-auth (which is 7 lines of code total in server changes, and virtually no change to client API usage): https://www.better-auth.com/docs/plugins/passkey https://www.better-auth.com/docs/plugins/passkey For some projects, the flexibility of other solutions might be needed. But for ease-of-use and development speed, better-auth has been a clear winner for me.
- 9dev 1y agoIt’s Microsoft. Did you expect less than 30 pages of useless techno-babble?
- LordN00b 1y agoExcuse me, incoming contrarian! learn.microsoft, is for learning about the concepts as well as the practical applications. Also for user facing security, wouldn't you want all the knowledge available to you? Much easier to find the foot guns in these kinds of situations.
- jamesjulich 1y agoThis framework has made auth such a non-issue for me. The setup is easy and the usage is consistent framework to framework. So glad to see that they’re continuing to do well.
- daveidol 1y agoPlease add support for Swift!
- mooreds 1y agoNow, this response was "not on my bingo card" as the youths say. I find it surprising that Swift would come up on a discussion about JavaScript auth libraries. Can you tell us more about what you are looking for?
- daveidol 1y agoSorry it was a bit off-topic (not related to Auth.js). I'm specifically asking about Better-Auth, as I'd love to use it in an iOS app but the client library is all JS. I'd even consider writing my own client library, but there is virtually no documentation on how to do so.
- mooreds 1y agoThanks for explaining. I saw the same sentiment for golang in other comments. No real suggestions for ya, sorry!
- lordofgibbons 1y agoI really wish there was such an easy off-the shelf auth solution for Go
- rickette 1y agohttps://github.com/authelia/authelia https://github.com/authelia/authelia?
- lordofgibbons 1y agoI've seen this, and the fact that it's written in Go is kind of irrelevant if I have to manage an external service. I just want it to be simple like what other languages have.
- portaouflop 1y agohttps://github.com/ory/kratos https://github.com/ory/kratos ?
- lordofgibbons 1y agoExtremely complex and requires running another multiple services. I just want auth, I don't want to set up kubernetes to orchestrate all the components of Ory.
- portaouflop 1y agoYou don’t need k8s, that is overkill. It’s a simple lightweight service that runs in docker or you install bare metal. Ory Kratos will satisfy 90% of use cases that you might have
- mooreds 1y agoAgreed. There are solutions out there for golang (FusionAuth, my employer, is one) but I think you are looking for one that integrates directly into an application the way that better-auth does (just like devise for rails, or Django's user model). I'm not aware of any such library for golang. This reddit thread might be helpful: https://www.reddit.com/r/golang/comments/1le9q65/is_there_a_golang_version_of_betterauth/ https://www.reddit.com/r/golang/comments/1le9q65/is_there_a_... with some options to evaluate.
- nikcub 1y ago> Chances are, if you’ve used ChatGPT, Google Labs, Cal.com or a million other websites, you’ve already interacted with Auth.js. I missed OpenAI migrating away from auth0. They must have been one of their largest customers - anybody know the story?
- Aeolun 1y agoOry also claims they are used by openai, so I guess they built their solution on Ory services + better-auth?
- tonyhart7 1y ago"anybody know the story?" what story??? chance are if you are planet scale enterprise, you are big enough to maintain or create or fork popular custom OSS auth themselves I mean can you imagine the cost ??? also the effect of third party that hold your entire user data
- grinich 1y agoThey migrated SSO/SAML to WorkOS, and consumer auth to forked open source.
- gbear605 1y agoI don’t know the story, but I’m not surprised. I led an effort to switch my company to Auth0 recently and they’re… bad. They have very poor support for anything even barely outside of normal, and when things are working correctly they not very good. But when you have a requirement to move to a third party SaaS service, I suppose Auth0 is maybe the best of a bad bunch.
- demarq 1y agoSame, I felt like I was writing my own auth. They don’t seem to understand that we’re trying to get away from the complexity of auth. I’ve talked with their sales people but may as well be talking to a wall.
- ascendantlogic 1y agoI interviewed for an SRE position at Auth0 years ago. My interviewer told me it was all held together by duct tape and prayers. I'm glad I didn't end up taking that position.
- reilly3000 1y agoBetter Auth has raised $5M. I don’t think it’s great to see a truly free project get absorbed into a commercial venture.
- nfinished 1y agoNot only is Auth.js truly free, it's truly abandoned.
- alongub 1y agoExactly
- bstsb 1y agowhile i agree, in this case at least it looks like the money raised is for a future SaaS auth solution built on top of the open-source project
- 9dev 1y agoWhich will invariably lead to that open source project to become less and less useful if implemented separately from the SaaS platform. I’ve seen this game plan often enough. Good for them, bad for the rest of us.
- joshdavham 1y ago> I’ve seen this game plan often enough. I probably haven't been around as long as you. Could you provide an example of one that comes to mind?
- lukasb 1y agoThis is funny to me because when someone asked re: Better Auth "better than what?" my off-the-cuff response was "better than Auth.js" and here we are.
- robertdaniels 1y ago[dead]
- presentation 1y agoI am bummed by this, basically sounds like they’re sunsetting future development into Auth.js. I tried Better Auth and it was not usable for what I wanted to do - I manage my own database schema and expose it through a permissioned GraphQL API. With Auth.js I just needed to implement a documented set of functions with specified input and output types, like creating users, storing tokens, etc. - however I wanted to - and then it all just worked with my own custom GraphQL API as the backend. But with Better Auth it’s all insanely general, where the data types are “whatever a particular plugin wants” meaning the any type in TypeScript; and the only thing you can do is delegate responsibility for design of database schemas and execution of data migrations to whatever plugin developers decide you need for the particular authentication methods you support. Way beyond the pale for an auth library in my opinion, I thought I was dumb and just didn’t understand the library but when I asked the community about it, they told me that’s by design - plugins determine their own data model. This isn’t a matter of me having a weird use case with the whole GraphQL thing, I can’t imagine anyone who takes their data modeling/security seriously would be fine with delegating that kind of control to plugin developers. (Yes I know you can make your own adapters, but the interface for that is literally “implement a general purpose SQL-like query executor” where the models that you’re querying/mutating are arbitrary strings - so basically no control over your schema. It literally just takes in a code: string value for eval’ing your migrations! Insane! [1]) When I saw the announcements before about Better Auth, emphasizing not that it was innovative nor technically good in any way, but instead focusing on the fact that its developer was self-taught and has only been coding for a few years [2], I tried to restrain myself from assuming anything about how it might be designed, especially since it seems everyone was hyping it up… but I’m not so confident my prejudices were totally wrong. I guess this is marginally better than the status quo where Auth.js was basically unmaintained and not being developed further at all. Which is to say, the state of open source auth libraries in JS is surprisingly poor. [1] https://github.com/better-auth/better-auth/blob/f6cbdcc84ee5d2971fdcc8b23ff7c174f88cf45b/packages/better-auth/src/types/adapter.ts#L28 https://github.com/better-auth/better-auth/blob/f6cbdcc84ee5... [2] https://techcrunch.com/2025/06/25/this-self-taught-ethiopian-dev-built-an-authentication-tool-and-got-into-yc/ https://techcrunch.com/2025/06/25/this-self-taught-ethiopian...
- bekacru 1y ago
- dandanisaur 1y agoremoved the notice about vercel like 3 hours after the announcement https://github.com/nextauthjs/next-auth/commit/9215909ffd7aefca5a172cbce2298cc2b0e90624 https://github.com/nextauthjs/next-auth/commit/9215909ffd7ae...
- mooreds 1y agoWonder when they are going to remove the sponsors list? https://next-auth.js.org/sponsors https://next-auth.js.org/sponsors
- xenator 1y agoLabuba driven development
- masto 1y agoI've been using Clerk and it seems fine. I'm sure there's some drama, because everything comes with drama, but I just want to get on with building stuff.
- ramon156 1y agoI haven't tried Clerk, but if the money spent actually makes things easier, then it seems like a good fit for certain projects. Better Auth didn't take more than an hr to setup in my repo, which is already pretty bare-bones to begin with.
- domlebo70 1y agoWith Auth.js, I assume they control the database layer? I.e. can i supply my own functions for reading and writing to the DB, or I have to use their Kysely stuff?
- n10l 1y ago[dead]
- deleted 1y ago[deleted]
- n10l 1y ago[dead]