Prompt
Can you help me choose an auth provider for a web app that needs passwordless login, MFA, and account recovery?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
Yes — I can help.
For a web app needing passwordless login, MFA, and account recovery, the main options usually fall into two buckets:
Good managed providers
-
Auth0
- Strong feature set: passwordless, MFA, recovery, social login, enterprise SSO.
- Very flexible, but can get expensive as usage grows.
- Good if you want maximum capability and don’t mind vendor lock-in / cost.
-
Clerk
- Very developer-friendly and fast to integrate.
- Supports passwordless, MFA, user management, and account recovery workflows.
- Great for modern web apps; less enterprise-heavy than Auth0.
-
Firebase Authentication
- Solid for passwordless and basic auth needs.
- MFA support exists, but recovery and advanced auth workflows are less polished than Auth0/Clerk.
- Best if you’re already in the Google/Firebase ecosystem.
-
Stytch
- Strong passwordless-first auth, MFA, and recovery.
- Good modern API-first choice.
- Worth considering if you want auth as a service without the Auth0 complexity.
-
WorkOS
- Excellent for enterprise auth/SSO, but not usually the first choice for consumer passwordless auth.
- Better if you expect enterprise customers later.
If you want open-source / more control
-
Keycloak
- Powerful and self-hostable.
- Supports MFA, recovery flows, and more, but more operational overhead.
- Better for teams that want control and can handle maintenance.
-
Supabase Auth
- Good if you already use Supabase.
- Passwordless support is decent; MFA and recovery are improving but may be less mature than Auth0/Clerk.
My short recommendation
- Best overall for most web apps: Clerk or Auth0
- Best if you want passwordless-first and a modern API: Stytch
- Best if you want self-hosted control: Keycloak
- Best if you’re already on Firebase: Firebase Auth
What matters most in choosing
- Passwordless method
- Magic links vs OTP vs passkeys
- MFA support
- TOTP, SMS, WebAuthn/passkeys, backup codes
- Account recovery
- Recovery codes, verified email/phone fallback, support flows
- User experience
- Hosted vs embedded UI, customization, passkeys support
- Cost and scale
- Compliance / enterprise needs
- SSO, SCIM, audit logs, organization support
If you want, I can make this more concrete by giving you a comparison table of Auth0 vs Clerk vs Stytch vs Firebase vs Keycloak, or I can recommend one based on your stack (e.g. React/Next.js, Django, Rails, etc.).