Ask HN: How Are You Handling Auth in 2026?

12 pointsposted a month ago
by joshcsimmons

Item id: 46455469

20 Comments

grinich

a month ago

WorkOS powers auth for OpenAI, Anthropic, Cursor, Vercel, Perplexity, Clay, Webflow, Granola, and a bunch of others. Free up to 1m users, you pay for enterprise features.

I'm the founder and happy to help. We've differentiated by focusing on "b2b auth" via SAML/SCIM, but today we do everything else. We also have products for feature flags, encryption, bot blocking, MCP auth, etc.

Fun fact, we actually launched on HN in 2020 :) https://news.ycombinator.com/item?id=22607402

dasubhajit

a month ago

Recently I moved to WorkOS for modulus.so. love your product.

MCP auth and feature flags are two feature that got me in. I also like that it's flexible enough for me to write custom logic in auth flow - which a lot of providers tries to abstract.

ok1984

a month ago

The obvious answer would be use oauth and base it on one of the main providers such as Google, Microsoft or Meta.

However starting from last year, due to the fact that these companies are becoming too dominant and I don’t trust them anymore I started applying a philosophy of avoiding to depend on them as much as possible unless customers explicitly require to use their services, for this reason we opted to always have our own solution and if needed integrate it with 3rd party solutions, this way we are not slave to FAMGE companies and we have full control over our product, it’s a small drop in an ocean but at least I sleep with more inner peace knowing that I am still contributing to the distributed architecture of internet.

Sounds crazy, potentially less secure, and time consuming but still, I prefer this approach.

Microsoft already F** Us by buying GitHub, others by stealing accumulated knowledge of stackoverflow, and forcing everybody to be AI dependent because they poured billions in it… I am not letting it happen again.

joshcsimmons

a month ago

This is phenomenal, more power to you

aeneas_ory

a month ago

Don‘t get locked in by those SaaS-only vendors. Modern stacks self-host because SaaS has a tendency to extort you once they need to show growth and are unable to acquire new customers fast enough.

Your best bet then is Ory https://github.com/ory / https://www.ory.com because it has an OSS version, enterprise version for self hosters, and a SaaS! And the source code is visible to everyone unlike other vendors :) Plus all the big names like OpenAI or Mistral use Ory as well.

willjohnsonio

a month ago

Auth0 is an option not just for the enterprise. I'm developer advocate there, you get 25,000 users in our free tier with a custom domain, unlimited social connections, basic attack protection, and more.(https://auth0.com/pricing). We also have the Auth0 for Startups program you can apply to and get one year free. (https://auth0.com/startups)

Reach out with any questions. Would love to help you with your project

code-developer

a month ago

SSOJet handles auth for a number of SaaS teams. There’s a free tier without any limitation of users, with pricing mainly for enterprise features.

It started with a focus on B2B auth (SAML/SCIM) and has expanded to cover most common auth needs. Also includes a few adjacent security and access features.

rasulkireev

a month ago

I use django-allauth and it hasn't failed me once.

leros

a month ago

Firebase Auth if I don't need enterprise stuff. Auth0 if I do.

I'm curious to explore some alternatives for enterprise auth like Clerk, but haven't yet.

joshcsimmons

a month ago

Clerk seems pricey once you scale.

leros

a month ago

That's ok for enterprise stuff where revenue per user is high. I'd hate to lose a 5/6 figure deal because I have to spend time rolling out some sort of enterprise auth solution for a client.

speedgoose

a month ago

Keycloak and OpenID Connect and/or OAuth2. I can plug external identity providers to it. It’s not SaaS.

Vishal19111999

a month ago

I've used Clerk, it's good. Supabase auth has some minor issues, needs to be more polished.

journal

a month ago

I add claims to cookies and handle my own authentication.

sama004

a month ago

better-auth has been genuinely amazing for ts ecosystem, don't be overdependent on the plugins tho some are not flexible for every use case