Prompt
What should I use for authentication in a SaaS app?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
For most SaaS apps, the best choice is usually:
Use a proven identity provider (IdP) with OAuth 2.0 / OpenID Connect (OIDC)
Examples: Auth0, Clerk, Firebase Auth, Supabase Auth, AWS Cognito, Azure AD B2C.
Recommended default
- Authentication protocol: OpenID Connect (built on OAuth 2.0)
- Session handling: Secure, server-side sessions for web apps, or short-lived tokens if you’re building an API/mobile app
- Passwordless / MFA support: strongly recommended
- Social login / SSO: add as needed
Why this is usually the right choice
- Secure and widely supported
- Faster to build than rolling your own auth
- Supports:
- email/password
- magic links
- social login
- enterprise SSO (SAML/OIDC)
- MFA
- user management
If you’re building:
1) A traditional web app
Use:
- OIDC login
- HttpOnly, Secure cookies
- Server-side session store This is often simpler and safer than storing JWTs in the browser.
2) A SPA + API
Use:
- OIDC with Authorization Code + PKCE
- Keep tokens short-lived
- Prefer backend-for-frontend (BFF) or secure cookie sessions if possible
3) Mobile app
Use:
- OIDC Authorization Code + PKCE
- System browser login flow
- Short-lived access tokens
Avoid
- Rolling your own password storage or login flow unless you have a very specific reason
- Storing sensitive tokens in localStorage
- Using raw JWTs as a full replacement for session management without a clear reason
Practical recommendation
If you want the safest default:
- Auth0 or Clerk for speed and completeness
- Supabase Auth or Firebase Auth if you want a simpler, more integrated stack
- OIDC + secure cookies if you have your own backend and want tighter control
If you tell me your stack (e.g. Next.js, Django, Rails, Laravel, SPA, mobile) and whether you need SSO or multi-tenant orgs, I can recommend a specific setup.