Prompt
What should I use for auth in a React app?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
It depends on your app, but for most React apps the best default is:
Recommended approach
- Use an external identity provider: Auth0, Clerk, Firebase Auth, Supabase Auth, Cognito, or your own OIDC provider.
- Use OAuth 2.0 / OpenID Connect (OIDC) for login.
- Keep tokens out of localStorage if possible.
- Prefer HttpOnly, Secure cookies for session handling when you control the backend.
Good choices by app type
1) SaaS / production app with a backend
- Best overall: OIDC with Authorization Code + PKCE
- Store session in HttpOnly cookies
- Backend verifies session/JWT
- Good options: Auth0, Clerk, Cognito, Azure AD B2C, Keycloak
2) Fastest to build
- Clerk or Firebase Auth
- Less auth plumbing
- Good UX and social login support
3) You already have a backend and want full control
- Implement session-based auth
- Use server-side sessions + HttpOnly cookies
- Avoid rolling your own JWT auth unless you have a specific reason
4) Internal enterprise app
- OIDC/SAML via your IdP
- Examples: Azure AD, Okta, Google Workspace, Auth0
What to avoid
- Storing JWTs in localStorage — vulnerable to XSS theft
- Building custom password auth from scratch unless necessary
- Using long-lived access tokens in the browser
Practical recommendation
If you want the simplest solid setup:
- React + backend + HttpOnly cookie session
- Or React + Clerk/Auth0 with OIDC PKCE
If you want, I can recommend a specific auth setup based on:
- whether you have a backend,
- whether you need social login,
- your stack (Node, Django, Rails, etc.).