Prompt
What should I use to replace a custom auth system?
Latest observation
It depends a lot on what your custom auth system currently does and what you need it to do. In general, the best replacement is usually a managed identity provider or a standard auth library/service, not another custom system.
Good replacement options
1. Managed identity/auth platforms
Best if you want to stop maintaining auth yourself.
Common choices:
- Auth0
- Firebase Authentication
- AWS Cognito
- Clerk
- WorkOS (great for B2B / enterprise SSO)
- Microsoft Entra ID / Okta (common in enterprise environments)
Use these if you need:
- Email/password login
- Passwordless login
- Social logins
- MFA
- SSO / enterprise identity
- User management dashboards
- Security features without building them yourself
2. Open standards: OAuth2 / OpenID Connect / SAML
If your custom system is mainly about login and identity, the modern replacement is usually:
- OpenID Connect (OIDC) for user authentication
- OAuth 2.0 for authorization
- SAML for enterprise SSO in older corporate setups
If you need to integrate with other systems, using these standards is much better than custom tokens or custom login flows.
3. Framework-native auth
If your app is tied to a specific stack, use the ecosystem’s supported auth solution:
- Next.js / React: Auth.js / NextAuth
- Django: Django auth + allauth
- Rails: Devise
- Laravel: Breeze / Jetstream / Fortify
- Spring: Spring Security
- ASP.NET: ASP.NET Identity
This is often the best option if you want simpler integration and less vendor lock-in.
How to choose
Ask these questions:
- Do you need to support social login? → Auth0, Clerk, Firebase
- Do you need enterprise SSO? → WorkOS, Okta, Entra ID, Auth0
- Are you a startup wanting speed? → Clerk or Auth0
- Are you already in AWS/GCP/Azure? → Cognito / Firebase / Entra ID
- Do you want full control and self-hosting? → Keycloak
- Do you just need standard app login in one framework? → framework-native auth
If you want the safest default recommendation
For most modern web apps:
- Clerk if you want the easiest developer experience
- Auth0 if you want a mature general-purpose solution
- Keycloak if you want open-source/self-hosted
- Cognito if you’re already on AWS
Important note
Avoid replacing custom auth with another custom auth system unless you have a very specific reason. Auth is security-sensitive and easy to get wrong.
If you want, I can recommend the best replacement based on:
- your stack,
- whether you need social login/SSO,
- and whether you want hosted or self-hosted.