10 ms·
From Supabase to Clerk to Better Auth
- zuzululu 5mo agowhat do you get from Better Auth btw? When I used it last year, I still found it lacking and it seemed to be run by one guy.
- volume_tech 5mo ago[flagged]
- azyc 5mo agoLol wut? you get all of your auth data in your own db in 1 cli command. You are not tied to any on db provider. On top of that you get hundreds of auth features like oauth providers (I use it to allow users to log in via google, apple, github) and the best part it's free. Not saying Supabase and Clerk are bad, but they cost money. With better auth you pay exactly $0 for all of this.
- giancarlostoro 5mo agoOr I could use a web framework that offers that out of the box, and its free and lives in my database, wherever I want.
- rozap 5mo agothis is sorta the obvious takeaway here. as a postgres/phoenix/elixir enjoyer i am blissfully unaware of all this sort of SaaS churn.
- Scarbutt 5mo agoWhat framework offers all those auth features OOTB?
- dsagent 5mo agoLaravel https://laravel.com/docs/13.x/authentication https://laravel.com/docs/13.x/authentication https://laravel.com/docs/13.x/socialite https://laravel.com/docs/13.x/socialite https://laravel.com/docs/13.x/sanctum https://laravel.com/docs/13.x/sanctum
- giancarlostoro 5mo agoASP .NET Core, Ruby on Rails, Django, .... the list goes on and on... The ones that don't usually someone built a package that lets it happen.
- skydhash 5mo agoI remember Laravel with Socialite [0]. Laravel is what I usually reach for Web SaaS MVP. You only need a VPS and a managed database for testing out the market and can scale a lot without increasing expenses that much.. [0]: https://laravel.com/docs/13.x/socialite https://laravel.com/docs/13.x/socialite
- mchusma 5mo agoI’ve looked at these auth providers many times over the years and I just don’t get the value. It takes me a couple of minutes to set up auth. Why would I want a dependency? It doesn’t help me with the hardest part which is configuring Google and Apple sign in stuff on Google and Apple. I just don’t get it.
- vevoe 5mo agoI use better auth for a side project i'm working on. It's open source, you can pay them to manage your user/auth tables if you want or you can run it all on your own db.
- giancarlostoro 5mo agoSure, I guess if I'm using a web framework that is not quite batteries included, that makes sense, but Django, ASP .NET Core, Ruby on Rails, and so many others are open source and have authentication / users / roles baked in out of the box.
- lanyard-textile 5mo agoIt must have come a long way then -- I'm integrating it into a new product and it is absolutely fantastic. It just works.
- allthetime 5mo agoI’m setting up a new system (Auth for user facing app, client facing dashboards, internal tool usage, etc.)… it has anonymous app users who can be upgraded to real users upon Auth, organizations, multi-tenant capabilities, all kinda of sign in options… haven’t written a single line of special code this is all handled by included plugins and defaults. It just works and I own all the data.
- cyberax 5mo ago> Some important context is that Clerk is a major success. They just raised 50 million dollars and they have lots of satisfied users. And even more users who are looking to escape. Clerk is just a mess. They are trying to cram EVERYTHING into their libraries: Web3 crap, Stripe, etc. Clerk's JS blob is now triggering the browser inspectors for being slow to load. Every time when we upgraded React, Clerk libraries were the biggest pain with their transitive dependencies. We had issues with Stripe libraries with conflicting versions, etc. And forget about debugging it. The libraries are obfuscated, and the TS code is impenetrable mess of abstractions to support "isomorphic" code that can run transparently on the frontend and backend. And their platform itself is lacking important functionality, like freaking audit logs and versioning. Somebody (probably) accidentally changed a setting in their console, and we couldn't trace back when it happened or who did it. Edit: oh yeah, and don't forget their unreliability. I had to wake up on Sunday to deal with Clerk failing the API calls for token refreshes last week.
- notbekacru 5mo ago> And even more users who are looking to escape. Uhm, companies like Replit and several other large startups are actually adopting Clerk. I guess if your world mainly revolves around X (formerly Twitter), it can seem like everyone is moving away from Clerk. Also, Better Auth’s X presence is pretty much centered around criticizing every auth provider out there, so the discourse there tends to skew heavily negative.
- cco 5mo agoReplit is using Clerk to power their login?
- cyberax 5mo agoClerk looks _really_ good initially. It's perfect if you want to prototype something and not care about auth. It's only when you start getting into the details that you begin to suffer. For example, there's _still_ no way to do offline auth on mobile. So that your application could be opened if there's no connectivity at the moment. But hey, you can do the Metamask Web3 blockchain thingie! I have never used Twitter/X, and I don't even have an account there. I'm purely talking about my personal experience and the experience of other companies that I know personally. > Also, Better Auth’s X presence is pretty much centered around criticizing every auth provider out there, so the discourse there tends to skew heavily negative. They are actually not wrong. Auth is not such a hard task, it's just a lot of drudgery that detracts you from the actual goal of your company. But it's critical functionality that MUST ALWAYS WORK, before all else. And Clerk just fails this test. I'm switching my company to Logto (it's lightweight and when something breaks, I know how to pick up the pieces), so I don't even have an opinion on Better Auth.
- anishksrini 5mo ago[dead]
- supermdguy 5mo agoBetter auth is great! I love how it's way more hackable than using a something like Clerk. We were able to add a plugin to allow auth via iframe postMessage (embedded in a CRM) and everything worked seamlessly.
- wxw 5mo agoI enjoyed the Supabase migration article from a while ago (https://blog.val.town/blog/migrating-from-supabase https://blog.val.town/blog/migrating-from-supabase) as well. There's a shortage of good, honest writing on long-term engineering decisions, please keep up the blog!
- huflungdung 5mo ago[dead]
- kandros 5mo agoDoes Better Auth still have the weird design to be everything “request header based”? I remember running admin scripts and tests to be very hacky due to it cause if you skipped that plugins wouldn’t run
- moomoo11 5mo agoI've just stuck with Auth0 for years now. Easy to use and high reliability. Some of these other providers are not the best at reliability.
- mikelward 5mo agoAuth0 breaks password managers. Could you upvote https://community.auth0.com/t/request-addition-to-public-suffix-list/122213 https://community.auth0.com/t/request-addition-to-public-suf....
- rbbydotdev 5mo agoTom's articles are always a good read. Anyone remember Auth0 and passportjs? The churn of auth services is never ending, but I suppose so are the standards.
- cpursley 5mo agoIf you're in Elixir-land, I've put together a few packages to help migrating from Supabase (or other stacks): - https://github.com/agoodway/introspex https://github.com/agoodway/introspex (generate Ecto Schemas from postgres tables) - https://github.com/agoodway/pgrest https://github.com/agoodway/pgrest (Supabase/PostgREST compatible query engine) I also found this helpful in the migration: https://github.com/supabase-community/supabase-ex https://github.com/supabase-community/supabase-ex Nothing for auth, I basically did a one-off script for that. Phoenix auth stuff that comes out of the box is great.
- cpursley 5mo agoOh, and http://github.com/agoodway/walex http://github.com/agoodway/walex if you need the realtime database change stuff.
- bekacru 5mo agoHey, Bereket from Better Auth here. I started Better Auth to solve this exact issue for myself, and it later turned into a company. It always give me joy to just see others getting the same value from it :) There is a lot to work on, would love to know what we can improve
- rbbydotdev 5mo agoDo you think the complexity of auth in the browser, is because browsers don't do enough?
- bekacru 5mo agoI think auth is complicated outside of browsers too. But browsers do make some things uniquely confusing, especially cookies and general security primitives are full of footguns
- pc86 5mo agoNot who you're replying to but browsers do way too much. Load the code you're given and don't do anything else.
- mooreds 5mo agoFedCM might be of interest to you. It's one effort to make browsers do more around authentication. Wrote an article about that here: https://fusionauth.io/articles/authentication/fedcm https://fusionauth.io/articles/authentication/fedcm (hosted at my employer's website)
- behailu 5mo agoHey hey! Qq: you guys plan to support Python backends or is there a way for us to do this?
- coreylane 5mo agoWorks fine with my fastapi backend using the JWT plugin. I run better-auth as a standalone service. https://better-auth.com/docs/plugins/jwt https://better-auth.com/docs/plugins/jwt
- deleted 5mo ago[deleted]
- WilcoKruijer 5mo agoYou could almost call the comparison between Clerk and Better Auth unfair. One is a service and one is a library, apples to oranges. Any third-party service integrated into a stack is a liability, libraries as well, but to a lesser degree. It’s about time for more services to be replaced by libraries. Better Auth really shows how to do that imo, it’s a library that integrates on the frontend, backend, and database. This is why it’s so good.
- snide 5mo agoThis is why I'm so thankful I went with Lucia early. They sort of sunset their library and replaced it with documentation (and some small utilities) for how to manage and host authentication for yourself. It's always presented as some big, scary thing you can't manage yourself, but I found that taking the week to learn how security and basic salting works, I was able to feel more confident about how everything worked.
- lioeters 5mo agohttps://lucia-auth.com/ https://lucia-auth.com/ I remember when they deprecated the library and instead made it a learning resource on implementing auth from scratch. Brilliant decision, much respect to the author.
- deleted 5mo ago[deleted]
- dakolli 5mo agoThe homepage of val.town says "Zapier for know-code engineers".. Is KNOW-code engineer a term?
- CharlesW 5mo agoIt's just a play on the phrase "no code". Maybe you can help me out: I still have no idea what val.town is. I guess it's an alternative to Cloudflare Workers?
- dakolli 5mo agoThat's a good question, I was having a hard time figuring that out myself. They call themselves the "zapier" for developers. In reality it seems kinda like a FaaS but idk. They have a code intelligence product that seems like a FIM autocomplete. Very confusing product suite.
- petemilly 5mo agoHey, I work at Val Town, and we definitely struggle to describe what it is because the platform is so broad, but I'll try: a javascript code editor in the browser that auto-deploys that code to our servers whenever you edit a file. You can run code by clicking a button, on a cron, via HTTP. And there's other stuff like SQLite and blob storage So yes, like Cloudflare Workers in some ways. Or like CodePen but fullstack. Or Replit. The val town "founding poem" was: > If GitHub Gists could run, > And AWS Lambda were fun
- petemilly 5mo agoThis comment thread was a nudge to push out a quick experimental change to the val.town landing page, so thank you. Very open to feedback on that messaging if anyone has any. Most customers these days ask about using val town with claude code, so you could also think of us as a deployment platform for vibe coded apps
- dakolli 5mo agoI wasn't trying to be negative. I think the changes you made to your landing page are more communicative than before, good luck with val.town.
- melonpan7 5mo agoIf anything I feel like Clerk adoption is becoming the norm in recent years. I started using it about a year ago and found it to have troublesome reliability.
- allthetime 5mo agoClaude, etc. enthusiastically recommend it
- elAhmo 5mo agoUsing Clerk, quite unhappy with it. No proper RBAC (roles are tied to organizations, not stored on user itself, so you cannot have a concept of global admin or something like that, unless you use metadata for storing arbitrary key value paris), and more than once in the past weeks/months it had a downtime causing the whole app to fail. Would think twice before using it in the future.
- mooreds 5mo agoDisclaimer: I work for a Clerk competitor, FusionAuth. Can you share your evaluation process? I'm always curious how folks evaluate auth providers. Did you do a spike? Full POC across a couple of solutions? Rely on a recommendation from a friend? Run through a quickstart and decide it worked and you had bigger problems to solve? Something else?
- nateb2022 5mo agoNice website! I like your docs too. Small tip though, the couple obviously AI-written articles (ostensibly for SEO purposes) in your footer are a little of a code smell. Also design wise, the main logo item (vortex looking thingy) is a tad bit complex, maybe think about a redesign focused on making it more simple/recognizable. The rotating dashes on the landing page hero are a good motif though, so I'd lean into that. Also noticed that on this page: https://fusionauth.io/tech-papers/winter-2026-g2-fusionauth-momentum-leader-customer-identity-and-access-management-ciam https://fusionauth.io/tech-papers/winter-2026-g2-fusionauth-... the form under "To get this tech paper complete the form below." doesn't load on Firefox with Enhanced Tracking Protection enabled. Disabling it causes the form to load though.
- mooreds 5mo agoThanks for the feedback, I'll pass it on!
- pdantix 5mo agoi'm currently in the process of evaluating switching our b2b app off clerk too. a customer asked for custom roles (diverging from our default set), which is technically possible on clerk now with role sets, but it's a bit of a workaround rather than first class. thankfully i'm familiar with better auth from a side project, but migrating SSO/SCIM sounds like it might be a bit of a pain
- tornikeo 5mo agoCan someone more intelligent then me tell me why should I offload my postgres users table to some 3rd party provider? Like what is so hard about keeping that table in my VM on hetzner that I have to give it off to someone else? It's not payments, it's just a few fields of data
- mvkel 5mo agoStart any greenfield project, hand-coded auth takes up 50% of the development time of the entire MVP
- awestroke 5mo agoIt takes like an hour. So that's a quick mvp then
- transitorykris 5mo agoSocial logins, email logins, password resets, multi-tenant, organizations, many to many users to organizations, etc etc. Not necessary for MVP, but can definitely be painful hacking in later if the MVP hits.
- koliber 5mo agoWhat you are talking about is in a large part authentication. You can do authentication using an external service and still have your user table locally. You can also do authorization locally with a local session table while leaving authentication to a SaaS.
- RedShift1 5mo agoBy the time you're so big you need all of that, there will be other people at the table to "hack that in".
- SkyPuncher 5mo agoI strongly disagree. If you’re selling to other businesses, much of that is an expectation.
- BoppreH 5mo ago> A hard lesson you learn building a complex system is that its reliability is the minimum of the combined reliability of its critical parts. It's worse than that, the combined availability is the product of all components in the critical path. If your software, the authentication layer, and the cloud provider each have 99% availability, and any one of them can bring your service down, then your final availability is just 97%. With eleven components like that you have zero nines of availability. That's why reducing components and going for reliable solutions is so important. I'm happy that the team took this path.
- gordonhart 5mo agoLearned this one the hard way during the last major CloudFlare outage. I don't use them, but their outage bricked my app for hours anyway because the Auth0 public keys used to verify JWTs were served behind CloudFlare, breaking the entire auth chain. Fun!
- dzonga 5mo agoin rails I just authentication-zero. no need for 3rd party provider.
- nop_slide 5mo agoThis is what I use, great little library and haven’t touched nor thought about my auth since I set it up.
- mooreds 5mo agoIs that the new library that came out in rails 8? Saw someone present on that at RailsConf 2025 and it seemed like a great solution for all rails apps. Hope it leads that ecosystem to get rid of devise (which I always found confusing).
- manishsharan 5mo agoHas anyone used Keycloak for actual production? I have often thought about it but I stick to Auth0 just because I don't know if Keycloak has a good track record?
- dizhn 5mo agoFor what it's worth Authentik has been listing Cloudflare as a customer for a while. Worth a look. There might be something in their blog.
- deleted 5mo ago[deleted]
- sudb 5mo agoYes! I used keycloak for multitenant auth and it worked fine - a little dated but functional. Nowadays I'd probably stick to something like Clerk/BetterAuth/Supertokens.
- mooreds 5mo agoYou might be interested in some of the presentations at KeyConf[0]. You can also get some real world stories from the Reddit[1]. I was at KubeCon EU this year (representing my employer, FusionAuth) and there were lots of folks who were running Keycloak who came and chatted with us. It's a different set of tradeoffs than Auth0 or other SaaS services. More control, but more responsibility too. 0: https://events.linuxfoundation.org/kubecon-cloudnativecon-europe/co-located-events/keycloakcon/#thank-you-for-attending https://events.linuxfoundation.org/kubecon-cloudnativecon-eu... 1: https://www.reddit.com/r/KeyCloak/ https://www.reddit.com/r/KeyCloak/
- sally_glance 5mo agoI've seen it used in production by larger orgs. The scale where you plan for around 6 months of migration, customization and integration of your legacy zoo with 7 different user account DBs. On one hand, all of these projects were successful and now run it in production. On the other, they all really needed the 6 months to whip it into shape. Edit: Meaning I would use it if you need to get up and running quickly, but it's a solid foundation to build on long-term.
- oncensher 5mo agoHad a similar journey recently. Started with Stack Auth, found it unusable in production due to extremely hard rate limits and bad performance even when not rate limited. Switched to WorkOS AuthKit, which works much better and supports useful enterprise features. But inclined to BetterAuth for new projects. - Syncing external auth provider state with your user state is a bug center. It helps to keep as little state as possible in the auth provider, but there is still some. - Refreshing JWT access tokens every few minutes is another bug center and honestly there is no need to do this if you control your own auth. - WorkOS does not have a complete API. It is built on the assumption that you have one product per billing account and a fixed number of environments (staging, production, and they can give you another one if you ask support). You have to whitelist redirect and other URLs in the dashboard, and there doesn't seem to be an easy way for agents to do it. Outsourcing auth does not make much sense IMO. The less you can split your state over multiple services the fewer problems you will have. Sometimes it is inevitable, like for payments, or if you need specialized databases for performance reasons. But for auth there is really no good reason if good libraries are available. To people who say that using a service will help you get started faster, none of the problems I hit with auth services had to do with having high scale -- most of them hit before I even launched.
- mooreds 5mo ago> Outsourcing auth does not make much sense IMO. The less you can split your state over multiple services the fewer problems you will have. I agree with the general principle. Fewer moving pieces make for more stable applications ("choose boring technology"[0]). However, I was wondering what you do when you have more than one application that the same userbase wants to access. I can see 3 options: 1. make them register/have credentials for each application (not a great user experience) 2. use a standalone auth server and deal with the increased complexity 3. pick one of your applications to 'own auth' and have the other applications delegate to it. congrats, you've just invented a standalone auth server that is coupled to one of your apps What am I missing? 0: https://boringtechnology.club/ https://boringtechnology.club/
- oncensher 5mo ago
- notbekacru 5mo agoWhen is the Better Auth to WorkOS to Vanilla Auth post coming
- smnscu 5mo agoI've been through the exact same migration path and I'm so incredibly happy with Better Auth. Good reminder that I should contribute: https://better-auth.com/docs/reference/contributing https://better-auth.com/docs/reference/contributing
- ryanhiebert 5mo agoMy biggest question, that I didn’t see answered, is how the transition comes to an end. If creds aren’t in your system, how well do they transfer? Does it require user involvement? What if they don’t fast enough? What about complex integrations like SSO, SCIM, and passkeys (which are domain scoped)?
- wg0 5mo agoNever outsource your auth no matter what unless you're vibe coding and it doesn't matter. If that's the case, don't put auth in at all because it's just you anyway or just use vibe coded password lookups from database at that point. Lastly - here's the law of mother nature: Software funded by VCs will milk you and will milk you dry. Not now, not tomorrow maybe decade or two later when the hot potato being passed around reaches to the last party holding the bag that now needs its money back with all that others had their 10x returns already taken from them by soldng them at an inflated price to the last party holding the bag. Clerk's pricing should be evidence enough.
- skrtskrt 5mo agoYou can literally plug the Better Auth libraries into a little Node server and run it as a separate auth server for free, forever, same as if you used a Django or Rails deployment for that purpose. That’s all it takes to not use their cloud at all.
- wg0 5mo agoI'm not talking about open source libraries.
- _heimdall 5mo agoI'm surprised to see so many top comments here promoting building your own auth. For years I've only heard "never roll your own auth."
- small_scombrus 5mo agoThere are few hard and fast rules, but "never use something that could change as a primary key" and "never roll your own Auth" will always be true
- DimmieMan 5mo agoI think it's a correction, There's multiple levels of interpretation: 1. Don't roll your own crypto 2. Don't roll your own auth strategy 3. Don't Roll your own auth code 4. Don't host your own auth infrastructure. For the last few years level 4 has been aggressively pushed with a lot of advertising spend to push people towards prohibitively expensive hosted providers. Donning a tinfoil hat for a moment, auth as a service companies have made everything seem substantially more difficult than it is too for simple needs. Now we're seeing a correction back to 2 and 3 as people way up the risks of SaaS vs just using a easier to manage local library and discovering it's not as scary as it's been made out to be if you follow now fairly well established patterns. the providers aren't going anywhere, people still need them for a variety of reasons but their time as the default is ending and whether this is good is to be determined.
- jpalomaki 5mo agoIt’s likely because the quick thought is that auth is just user table with hashed password. Then when you really start thinking about it, the list of requirements grows. Of course it’s still totally doable for an average developer, but takes time and mistakes can be catastrophic. And maybe the time is better spent developing stuff that differentiates you from others.
- pururvaagarwal 5mo ago[flagged]
- JSR_FDED 5mo agoSo let me be the one to invite ridicule and scorn by admitting I wrote my own auth code. It was fiddly and boring at the same time. It also wasn’t rocket science, and it works well. I’ll be the first to admit that there are cases where this is a bad idea, I’m just responding to the chants of never roll your own auth. Knowing every single line of code involved allowed me to add some location-based functionality for one client, provide tailored logging to meet the needs of another client, and my favorite was winning a deal against much bigger competitors by being able to integrate with an absolutely ancient legacy system. Just like “Goto considered harmful”, DRY, YAGNI, etc - they’re great at making you slow down and think. But they’re not inviolable.
- ipnon 5mo agoIt’s not that crazy! Or hard. If you can store a hashed password in your users table, and keep the salt secret, you have working auth.
- SahAssar 5mo agoI'm not discouraging anyone from writing your own auth, but if you have even a little bit higher requirements it becomes more complex. For example I have audited codebases where the TOTP code was enough to get a valid token (without a password, due to a bug), where there was no rate limits on password attempts and one where the password lockout system meant that you could DDoS all admin access trivially, etc, etc. That's even before you need to integrate with a third party via something like OIDC or SAML or SCIM which are probably needed for a product used by businesses these days. It is hard for serious use-cases. That does not mean you should not do it, but know what tradeoff you are doing in the build-vs-buy equation. Know that this part of your system probably requires more testing, review and expertise than your core product.
- Capricorn2481 5mo ago> and one where the password lockout system meant that you could DDoS all admin access trivially What happened there?
- MrDarcy 5mo agoRecently went with a vendor of an agentic observability and evaluation product built on Supabase and Clerk. The number of vulnerabilities and CVE’s and outright… I don’t even know the words, coming from this stack is staggering. Be very very wary of any vendor selling something built on this Supabase + Clerk stack. That alone is a very strong indicator they do not understand basic security or data protection.
- swyx 5mo ago> There is no val associated with this domain
- stevekrouse 5mo agoback online!
- veltas 5mo ago> A hard lesson you learn building a complex system is that its reliability is the minimum of the combined reliability of its critical parts. More like "its failures are the total of its critical components' failures" when you've got two nines on your least reliable component so most likely any critical component failure will be exclusive.
- jakubriedl 5mo agoI've recently switched from Clerk to BetterAuth as well and it's really good and definitely would recommend to anyone. It supports more things I need, it's more reliable, and much cheaper. The reason why it work for me is that it's finally a open-source solution that is on par or better with commercial. When I've selected Clerk originally the reason was that there wasn't open-source alternative, and I won't roll my own auth, I'm not suicidal. But now? I really don't see a single reason why I would pick Clerk, Auth0, Kinde, ...
- sreekanth850 5mo agoI can never imagine putting my user table on a vendor locked cloud provider. And we use Open Iddict.
- olegoode 5mo agoSuper validating, as someone who was recently tempted to use Supabase for a project and decided to give Better Auth a shot instead. It's really made things super simple so far to the point I was semi-worried I'd missed a crucial step. But nope, they just thought of everything.
- jillesvangurp 5mo agoThis sounds like moving the problem, not solving it. I've been doing server based systems since forever and sso is this big complicated topic where people seem to bias to using either really complicated and convoluted enterprise solutions or some walled garden with lots of limitations. In both cases you are buying into somebody else's solution. That complex framework is complex because the company behind it threw everything and the kitchen sink at it. You don't actually need most of what it needs. And that company makes money by adding more crap to it, via certification, training and consulting. It's complex by design. You can't just sit down and use it. You have to study it first. Become an expert in using it. If you've ever used Keycloak, Spring Security, or similarly convoluted solutions, you know what I'm talking about. And then that walled garden thing (auth0 or whatever is in fashion these days) is super simple to use. Just do magic steps 1 2 and 3 and you are good to go. But don't deviate from the happy path! There is a happy path. Either you are a perfect match for it or you aren't. The middle ground is realizing that a users table with a bcrypt encrypted password column and a few other bits and bobs isn't all that hard. Building some sane flows around resetting passwords, 2FA, emailing login links, etc. Easy. You can actually vibe code most of this stuff these days. And I've done all this manually in the past as well. I've implemented SSO, Oauth (1 & 2), OpenID Connect, etc. I've implemented API call counting, rate limiting, 2FA, etc. I use some frameworks for most of the heavy lifting and dealing with hashing, JWTs, and all the rest. Most of the rest is just simple API plumbing. Most of these flows aren't all that complex. You need good tests and a good understanding of what the system is supposed to do. But that's a constant in this space. Trying to use somebody else's really complicated solution without that is not going to be easier, better, or faster.
- arian_ 5mo agoThe auth migration cycle is the startup version of moving apartments. You swear each time will be the last, you lose stuff in the transition, and somehow the new place has the exact same problems as the old one but in different rooms.
- raphinou 5mo agoI've had good experience with authelia. Simple and light to self host.
- swyx 5mo ago> And reluctantly I have to hand it to the LLMs here: with the augmentation of the robots, we were able to take the more complex route of supporting both Better Auth and Clerk for a transitional period of two weeks. Every endpoint that handled authentication would accept either kind of cookie, and users slowly moved over to Better Auth because that was the kind of session that the sign-in page provided. Like anything related to security, close reading, rewriting, and testing of all of the code was necessary to make sure we didn't self-own, and the eventual pure-Better Auth auth was handwritten entirely. just beautiful. nothing to add, clap clap
- Eli_EB 5mo ago[dead]
- luodaint 5mo agoNotable that in each step, there’s an added abstraction; specifically, an authentication abstraction is the hardest one to reverse. Using a passwordless login from scratch (magic link + Google OAuth2, sessions stored in Postgres without an external auth vendor) gets us around that altogether. The fears about why one would avoid it are generally not justified. Deliverability is the only true problem. Address that, with a proper provider for transactions, and we’re in boring territory – which is the most delightful kind. To move from Clerk to Better Auth is logical if the choice is between sovereignty and convenience. It’s the core problem that any group doesn’t want to confront right away: “How much of this am I truly willing to own?”
- danborn26 5mo agoBetter Auth has been a huge time saver for me. Clerk's pricing got a bit out of hand for side projects.
- koala-news 5mo agoFeels like auth is either “this took 2 hours” or “this consumed half the company for 3 years”, with basically no middle ground.
- riffic 5mo ago"Better Auth" apparently has nothing to do with "Better Stack" which runs a product called "Better Uptime" and focuses on monitoring or incident response I guess, right?
- tancky777 5mo ago[dead]
- lacymorrow 5mo ago[flagged]
- nkmnz 5mo agoFor me, the real issue of switching auth providers hasn’t been touched: do thy all use the same hashing functions or how did they move the password hash column across providers? Running them in parallel and rehashing on first login?
- anotherevan 5mo agoIf the provider is worth its salt¹ it will prefix the stored password with the hash that was used. That way it can update the hash when the user next logs in if it is out of date. E.g.: {argon2}… ¹ See what I did there?
- nkmnz 5mo agoI see what you did there, but I assume you mean "prefix the stored hash with the algorithm that was used", right? I still don't know how this would help with a migration, though. They would still need to run both auth systems in parallel until every single user has logged in again - or force everyone to create a new password. Right?
- anotherevan 5mo agoAssuming you get get access to the hashed passwords the other party used as part of the migration data, and you know what hash was used for them, then there's nothing to stop you using them yourself. But in reality, I doubt they would release either of those things.
- kreidema 5mo agoBeen using BetterAuth for half a year/one year now. It's exactly what I always wanted when using Clerk (and its free as a side effect). I was never a fan of the "we'll manage your user Table", always set up the Web hooks to sync everything to my own user table, but still loved the development experience clerk provided (most of it). I will never go back. Lets see if in 3 years I have a different opinion, but I can't imagine so.
- jcmartinezdev 5mo agoWhat's the next stop? it's gotta be auth0
- joekrill 5mo ago> Better Auth checked a lot of boxes right out of the gate: high code quality, Maybe I have high standards, but I absolutely would not describe Better Auth as having "high code quality". It has certainly been improving, but when I first looked at this project it felt really rushed and thrown together, with little automated tests. There's was virtually no logging last I looked, so there's little options to monitor what's happening. I think they've added hooks now so you can "bring your own logging", I guess. And they finally added audit logs but that's only if you use their managed services. Having said that, I actually use Better Auth, and I'm a huge fan despite those criticisms. I love that it's open source and extendable (there's a free 3rd-party audit logging addon, actually). It's super straight-forward to implement compared with similar products (Ory Kratos, Keycloak, etc). You don't even need a separate DB if you don't want - you can have it create tables in your existing database. And it _is_ improving quickly.
- theuniverseson 5mo ago[flagged]
- renzom13 5mo ago[flagged]