Prompt
What should I use to replace a custom authentication system?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
If you’re replacing a custom authentication system, the best choice is usually a standard identity provider / auth platform rather than building auth yourself.
Good options
- Auth0 – very common, flexible, easy to integrate
- AWS Cognito – good if you’re already on AWS
- Firebase Authentication – simple and fast for mobile/web apps
- Clerk – developer-friendly, modern UI/components
- Supabase Auth – good if you use Supabase/Postgres
- Keycloak – strong open-source choice for self-hosting
- Okta – enterprise-focused
What to pick
- Need enterprise SSO/SAML/OIDC? → Okta, Auth0, Keycloak
- Want easiest developer experience? → Clerk, Auth0, Firebase
- Already on AWS? → Cognito
- Want self-hosted/open source? → Keycloak
- Using Supabase? → Supabase Auth
Recommendation
For most apps, the safest replacement is:
- Use an external IdP/auth service
- Adopt OAuth 2.0 / OpenID Connect
- Use MFA, password reset, email verification, and session handling from the provider
- Avoid storing passwords yourself if possible
If you want a quick default
- Startup / web app: Clerk or Auth0
- Enterprise / self-hosted: Keycloak
- AWS-heavy stack: Cognito
If you want, I can help you choose the best one based on your stack, user count, and whether you need SSO, MFA, or self-hosting.