Prompt
What should I use instead of building OAuth from scratch?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
Instead of building OAuth from scratch, use an established identity/auth provider or OAuth/OIDC library depending on what you need.
Best options
1) Managed identity providers
Good if you want the fastest, safest path.
- Auth0
- Okta
- Firebase Authentication
- AWS Cognito
- Clerk
- WorkOS (great for enterprise SSO)
- Supabase Auth (nice if you’re already using Supabase)
These handle:
- OAuth/OIDC login flows
- token issuance and refresh
- user management
- social logins
- SSO / enterprise connections
- security updates and edge cases
2) Open-source auth platforms
Good if you want more control or self-hosting.
- Keycloak
- ORY (Hydra/Kratos)
- Zitadel
- Dex (more for identity federation)
3) Libraries for implementing OAuth/OIDC clients or servers
Good if you only need protocol support in your app.
- AppAuth (mobile)
- passport.js (Node.js)
- oauthlib (Python)
- Spring Security OAuth2 / built-in Spring Security support
- openid-client (Node.js)
- Authlib (Python)
Important note
If by “OAuth” you mean “login with Google/GitHub/etc.”, you usually want OpenID Connect (OIDC) on top of OAuth 2.0, not raw OAuth alone.
Simple recommendation
- Startup / web app: Auth0, Clerk, Supabase Auth, Firebase Auth
- Enterprise SSO: WorkOS, Okta, Azure AD, Auth0
- Self-hosted: Keycloak or ORY
- Custom app integration: use an OAuth/OIDC library, not a hand-rolled implementation
If you tell me your stack (frontend/backend/cloud) and whether you need social login, SSO, or API access, I can recommend the best specific choice.