Prompt
What should I use instead of rolling my own auth?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
If you can avoid rolling your own auth, the usual “best” alternative is:
Use a proven identity provider / auth platform
Common options:
- Auth0 — very common for app auth, social logins, enterprise features
- Firebase Authentication — good for mobile/web apps, quick to integrate
- AWS Cognito — works well if you’re already on AWS
- Okta — strong enterprise/SSO support
- Clerk — developer-friendly auth for modern web apps
- Supabase Auth — nice if you’re already using Supabase/Postgres
If you need self-hosted / open source
- Keycloak — one of the most popular self-hosted identity platforms
- Ory — more modular, modern, and API-first
- Zitadel — also a solid modern IAM option
What to use in practice
- Small app / fastest setup: Clerk, Firebase Auth, or Supabase Auth
- Enterprise / SSO / B2B: Auth0, Okta, Keycloak, Zitadel
- AWS-heavy stack: Cognito
- Need full control / self-host: Keycloak or Ory
Important principle
Even when using a provider, try to keep authorization decisions in your app:
- Auth = who the user is
- Authorization = what they can do
Good baseline architecture
- Use OIDC/OAuth2 for login
- Store sessions with secure cookies or use short-lived tokens
- Delegate password handling, MFA, email verification, and account recovery to the provider
If you want, I can recommend the best option for your specific stack (React, Next.js, mobile, backend language, cloud, etc.).