5 ms·
Better Auth is joining Vercel
- mrcwinn 3mo agoI nearly considered using them recently. So glad I dodged the bullet!
- ftchd 3mo agoAin't nobody buying Jose, yet
- electriclove 3mo agoUmm.. so what did you end up using?
- bstsb 3mo agocan Vercel give any assurance that they won’t add a reliance on their closed-source cloud offering for the package? especially given their ownership of next-auth too i really loved better-auth’s DX but the nature of their database adapters means it’s relatively easy to switch over to another provider/library
- Jnr 3mo agoFrom what I remember, next-auth is kind of dead and Better Auth developers have been maintaining security of next-auth for some time now. (or was it Vercel that did the maintaining?) Better Auth is the go-to solution for many people using Nextjs, so it makes sense that Vercel puts some effort in maintaining it. I have never had issues running Nextjs in regular containers, it is just a good open source solution, I don't see why it would be any different with Better Auth.
- deleted 3mo ago[deleted]
- Raed667 3mo agoI was wondering when that would happen, it was meant to be since the beginning
- khurs 3mo agoReminder - KeyCloak was donated to CNCF so a safe choice https://www.keycloak.org https://www.keycloak.org https://www.cncf.io/blog/2023/04/11/keycloak-joins-cncf-as-an-incubating-project/ https://www.cncf.io/blog/2023/04/11/keycloak-joins-cncf-as-a...
- nvegater 3mo agohow is this related to better auth ? In my understanding, keycloak and better auth are fundamentally different. I would compare keycloak more with Ory for example.
- deleted 3mo ago[deleted]
- vaishnavsm 3mo agoKeycloak and Better Auth aren't as fundamentally different as you may think! Better auth supports authn/z, being an identity _source_, being an identity provider, being an OIDC/SSO provider (so others can login using better auth), rbac, SAML/SCIM, and a ton more. It's actually really powerful! Most folks found better auth as an alternative to next-auth/auth.js - but better auth does a lot more than those. (some of those features are enterprise only)
- Natfan 3mo agoso better auth would be more analagous to microsoft entra (formerly azuread)?
- jzebedee 3mo agoIt's a good reminder, because in the auth landscape I wish I had just picked up Keycloak and stuck with it. Commercial auth is a bad value proposition and not the kind of infrastructure where you want to have acquisition churn happening often. The self-hosted space is another headache. I wasted so much time trying to make smaller self-hosted auth solutions work, since Keycloak has a reputation for being heavyweight. I looked into the Ory stack extensively trying to actually use it as advertised for self-hosted / open-source auth. It's aggressively gimped and its SSO features are emphatically _not_ open-source and are gated behind licensing, with no way to find out until you're actually running it. It's also just unfinished. Their "stack" is a lot of cobbled-together Go mixed with incompletely rebranded acquisitions like SAML Jackson (now "Polis"), which they managed to gut so completely it went from a best-in-class OSS library to unusable.
- slig 3mo agoLove better-auth, and congrats to the team!
- mooreds 3mo agoCongrats to Better Auth. I'm in the auth space and see all kinds of things. Anything that makes it easier for developers to build secure applications is a win!
- huflungdung 3mo agoBetter auth is an absolute dumpster fire codebase.
- whalesalad 3mo agoAuth is not hard to roll yourself. Crypto: don't do it. Auth? Easy peasy.
- nicce 3mo agoRolling auth by yourself is very messy. Storing tokens correctly, rotating and using correct tokens, with correct parameters and so on. Endless footguns.
- lackoftactics 3mo agoalso the conseqeunces of implementing it badly from scratch don't make sense if you can use battle-tested solution
- mooreds 3mo agoOh man, it really depends(tm). If you are building a small internal app, sure, but you'd often still be better off leveraging a social provider or employee directory. I work in the auth space (for FusionAuth) and we run into plenty of folks that started out rolling auth themselves. Just username and password right? A bit of hashing, salting and leveraging a built-in crypto library. But then you need to add account recovery. And then MFA. And then registration. And then progressive registration. And then webhook integration. And then passkeys. And then SAML integration. And the delegated SAML setup. And then and then and then. You're distracted from your core application by feature requests for your login system. You have lots of options nowadays. Use a library provided by your framework (Rails, Spring, and Django have them), use a tool like Better Auth, use a third party system like FusionAuth or Auth0. But don't build undifferentiated functionality that impacts your user experience. PS Of course, where I stand depends on where I sit, but I firmly believe that you should not build an auth system the same way you should not build a database.
- whalesalad 3mo agoThis is kinda like the ORM vs no-ORM argument. I think that off-the-shelf auth will accelerate your development for sure (like an ORM) but eventually, you are going to feel constrained by the framework/tool you are using. You will need to work around it. You will find that using it 'correctly' results in poor performance, and so you deviate here and there. Pretty soon you tell yourself, "man I should have just used SQL" or "man, I should have just rolled my own auth". At least ~20 years of software dev has taught me this. For an MVP or a prototype, I think it's okay to use an off-the-shelf tool. For something serious that will have long-term legs, I would do it myself. I hear all of your concerns and arguments and agree there are a lot of footguns. But again, having spent the better part of my adult life using and interfacing with these tools, I have an innate understanding of how to model auth correctly (separate it from the user, separate users from an 'org' or 'team' entity, etc). You said it though, 'it depends' is really the right answer here.
- agrippanux 3mo agoUggggg I just implemented Better Auth for our new product - time to start looking for backup plans. I used to be a huge Vercel fanboy but everything they have done in the last few years turns into a complicated mess.
- __s 3mo agoSilent execution of tremor was a pain in the ass trying to upgrade to nextjs 15 / react 19: https://github.com/tremorlabs/tremor/issues/148 https://github.com/tremorlabs/tremor/issues/148
- ebeirne 3mo agoThis is amazing although I would really like for them to explore filling the backend gaps. An acquisition of Trigger.dev or Inngest would be the obvious move and nobody would be surprised. Thoughts?
- magnio 3mo agoI used Better Auth for my mobile app backend. It works okayish. My biggest complaints are the OpenAPI specification gets little care, as it mainly caters for JS frontend, and breaking changes in patch version are more common than most packages.
- fnoef 3mo agoAh, here we go again. Glad I decided to roll my own auth rather then using some library. I had a feeling that eventually they will join Vercel.
- notatoad 3mo agoYeah, we rolled our own auth as well. Everybody says you shouldn’t, it’s a risk, etc etc. but to me that’s less risk than our auth getting bought by somebody whose business goals don’t necessarily align with mine.
- pzo 3mo agowhy not instead fork repo just in case but still use better auth until proven wrong? In case they go evil you just build from you forked one. At that point you would still have to either maintain your own auth or better auth fork. With current AI your agents probably still will be better with maintaining a fork. Auth libs have pretty limited API surfaces comparing to e.g. ui frameworks.
- fnoef 3mo agoI prefer to maintain my code, tailored for my need, than maintaining a massive library that has support for every authentication method there is, while trying to be as generic as possible and fit every business.
- slig 3mo agoThe data lives in your server, everything is yours, if that happens, you just fork or write your own. Not sure what writing yourself first buys here.
- notatoad 3mo agoUsing something third party isn’t free - even for zero monetary cost there’s integration cost, documentation, support, and maintenance uncertainty. The choice between rolling your own and third party is already a trade-off. The future uncertainty around third party services without a clear business just tips the scales, it’s not the whole justification.
- bekacru 3mo agoBereket Here the team at Vercel has been my biggest inspiration and always reflected many of the reasons we started working on Better Auth. This would allow us to focus more on what made better-auth great in the first place It hasn't even been 2 years since we started but thank you everyone from the open-source community for helping us make an impact in short amount of time. There is a lot to do to improve on open source auth and im really excited to be back focusing full time on building
- orliesaurus 3mo agowhat will be your role at Vercel? Aren't you afraid that you might lose control over the project's future - becoming a cog in a much more complex system?
- oooyay 3mo agoYou're saying that BetterAuth will remain 100% free and open source, will continue to be maintained, and unlocked from Vercels ecosystem?
- mavelikara 3mo agoYou are asking the wrong person.
- bekacru 3mo agoYeah, Vercel has already done this before like with Nuxt, Svelte and other. But I also do want to have a better story for auth with all those frameworks and Nextjs as well.
- Aroni 3mo agoHi Bereket, Congratulations on the acquisition! We are building auth for developing markets (secure MFA for users without smartphones). Would love to get your thoughts on the auth landscape. I'm +254-seven-zero-seven-144992 on WhatsApp. Cheers!
- bhouston 3mo agoCongrats BetterAuth! It was the system I was considering before I rolled my own auth system around the passwordless concepts of: OTP + Passkeys + Google login. It is quite nice and simple and I've ported it to 3 separate projects now just via LLM: Talk: https://ben3d.ca/blog/passwordless-login-system https://ben3d.ca/blog/passwordless-login-system Live Demo: https://passwordless.ben3d.ca https://passwordless.ben3d.ca Demo Code: https://github.com/bhouston/passwordless https://github.com/bhouston/passwordless If you are building a user system with a database already, adding passwordless auth is easy.
- quibono 3mo agoOn one hand I love how much easier the email + OTP / passkey flow is on the dev side, I find it _very_ frustrating as a user of services. User+password combos are straightforward at least.
- giancarlostoro 3mo agoI would rather have keypass and "email me a temp auth link" which then requires 2-factor confirmation. I tire of passwords.
- bhouston 3mo agoPasswords are definitely not better than passkeys for login flow as a user, at least not on MacOS / iPhone, etc. I just tap my finger onto the fingerprint reader on my MacBook or I just look at the camera on my iPhone - biometrics for the win. But you need something as a backup to passkeys so I choose emailed OTP, but it isn't meant to be the primary way to log in.
- noveltyaccount 3mo agoThat demo code looks great -- please add a license :)
- zuzululu 3mo agoim amused that people are still relying on third party for handling auth when you can roll your own now with LLMs
- lackoftactics 3mo agoIt's one of those things you shouldn't trust LLMs to such an extent; that part should be very solid because the consequences of bad practices are getting to front page of hacker news :)
- zuzululu 3mo agodepends what LLM you are using but most frontier models have seen almost every github/doc/best practices its very hard to get something like supabase/lovable type of mess unless you purposely prompt it to be bad without much inner knowledge but even then it is rectifiable with the right prompts
- RideOnTime22 3mo agoEverything is "rectifiable with the right prompts" if you handwave the hallucinations it makes (which yes, even frontier models do. Or I guess all companies that had major outages within the past months were using fossil models). And it's funny this same argument can be said since Sonnet 3.7. But the issues still pop up.
- zuzululu 3mo agowe've advanced significantly since 3.7
- slig 3mo agoIt's not third party, it's a library you use and you store the data. Got tired of it? Write your own, the data is there.
- RichardChu 3mo agoBetter Auth is great, I use it for all my projects. Congrats to the team!
- mariopt 3mo agoSo, it's just a matter of time until they destroy this project in favour of their cloud interests. Such a shame, it is (was) a nice open source project.
- jgeurts 3mo agoBummed. Vercel is not a great steward of open source. Happy that Bereket got an exit, though.
- Jnr 3mo agoHow so? I am using their open source software, what have I missed?
- BoorishBears 3mo agoWe came full circle! https://news.ycombinator.com/item?id=45393382 https://news.ycombinator.com/item?id=45393382 https://news.ycombinator.com/item?id=45398577 https://news.ycombinator.com/item?id=45398577 I've said before: > Vercel is not a problem. Pumping millions of dollars into the JS ecosystem through sponsorships and events to define the development landscape in terms of what helps your bottom line... that's bad. > What Rauch is doing is the developer equivalent of private equity squeezing, and what's insane is how well it's working.
- mrcwinn 3mo agoKeycloak is excellent.
- ndom91 3mo agoCongrats! Better auth still provides a grade A dev experience, even with all the plugins, integrations, and tons of things they support. Best of luck over there!
- nightski 3mo agoOpen source isn't really open any more. It's just pre-acquisition. I'm happy to the creators for their payday but honestly just happy I opted out of BetterAuth building my latest product.
- deleted 3mo ago[deleted]
- andix 3mo agoIs it about the license? I see less and less new projects using GPL, and a lot of MIT(ish) licenses. Most complex open source projects like Linux for example have a lot of contributions by corporations. The GPL kind of forces them to participate in open source, instead of just creating internal forks. GPL and even LGPL are tricky for libraries though.
- tough 3mo agoI think it's more about the bait and switch marketing optics of offering a "core" part of your codebase as "FOSS" to get the extra brownie points by doing so, while it's at the same time littered with caveat emptors, and imports from "enterprise licensed" code for the features that business care about. Also all the "commercial open source" or COSS seems to lean into that, its a valid strategy to monetize open source, but should be done transparently and being very upfront about its bait-y nature to businesses or enterprises imho
- Jnr 3mo ago> "features that business care about" I don't see companies using open source lining up to support the developers. Good for developers to come up with some monetization strategies to keep their software alive.
- deleted 3mo ago[deleted]
- hankyone 3mo agoHmmm so Convex support is going to take even more of a backseat I guess
- tough 3mo agoso does anything change or will change for better-auth FOSS consumers? Or not really and that mostly depends on what Vercel imposes as new direction going forward? I guess vercel is a good home for foss projects, at worst they'll make first class adoption on their ecosystem without actively hampering others etc
- byyll 3mo agoSucks. Now I have to look for alternatives.
- yesidoagree 3mo agoWorse Auth
- Suzie121 3mo agoIt's not that easy to get back a scammed funds because these scammers are very smart and they will cover their traces but if you manage to find a trustworthy and reliable Recovery company because many scammers are out there disguising as Recovery agents and will only take your money without recovering your funds, I was a victim of such myself after loosing all my funds to cryptocurrency scam. I sort for a help and I met few recovery agents, I was scammed by a particular one again Luckily for me I was referred to these legitimate company and they where able to recover my money back to me. You can as well contact them on RECOVERYDAREK AT gmail DOT com for a help.
- customentity 3mo agoCongrats to Better Auth !! I can't wait to see what happens next
- aitchnyu 3mo agoHow is BetterAuth in terms of vendor lockin? For a hobby project, I once tried a provider which stored all data within itself and required API calls for every user request. Then I tried Hanko which just authenticates and can be replaced relatively easily (very easily if no passwords IIRC).
- Tomy9 2mo agoIs rauch planning to control Open source, why are we seeing more acquisitions. Also Is this the time they officially announce the death of Auth.js?