{
 "title": "Login for a Next.js app: six options compared",
 "checked": "2026-10-03",
 "method": "Every fact was read from the vendor's own pricing page, the npm registry, GitHub, or Stripe's provider list on the checked date. Nothing here was benchmarked. No vendor paid for or reviewed this page.",
 "picks": [
  {
   "situation": "New project, you have a database, you want no vendor account",
   "pick": "Better Auth",
   "why": "It is the actively developed open-source option, and the Auth.js maintainers themselves point new projects to it."
  },
  {
   "situation": "Existing app already on next-auth",
   "pick": "Stay on next-auth",
   "why": "It still gets security patches (latest release 2026-07-20). Migrate when you need a feature it will not get."
  },
  {
   "situation": "You want hosted sign-in with ready-made UI and no database",
   "pick": "Clerk",
   "why": "Free to 50,000 users per app with no card, and an agent can provision it through Stripe Projects."
  },
  {
   "situation": "You sell to companies that will ask for SSO",
   "pick": "WorkOS AuthKit",
   "why": "Free to 1 million users; you pay $125/month per enterprise SSO connection."
  },
  {
   "situation": "You are already using Supabase for the database",
   "pick": "Supabase Auth",
   "why": "It is included: 50,000 users on the free plan. Remember free projects pause after a week idle."
  },
  {
   "situation": "No database and no vendor at all (stateless sessions)",
   "pick": "Auth.js / NextAuth",
   "why": "This is the one case its maintainers still name for choosing it over Better Auth."
  }
 ],
 "options": [
  {
   "id": "better-auth",
   "name": "Better Auth",
   "kind": "Open-source library (you host it, needs your database)",
   "package": "better-auth",
   "latest": "1.7.7",
   "latest_published": "2026-09-30",
   "weekly_downloads": 11976520,
   "license": "MIT",
   "status": "Actively developed. Repo last pushed 2026-10-03.",
   "price": "Library is free. Optional hosted add-on \"Infrastructure\" (dashboard, audit logs): free Starter tier, Pro $20/month.",
   "free_start": "Yes. No account, no card.",
   "agent_can_start_alone": "Yes. Nothing to sign up for: npm install plus a database.",
   "watch_out": "You run and secure it yourself. You need a database.",
   "sources": [
    "https://www.npmjs.com/package/better-auth",
    "https://github.com/better-auth/better-auth",
    "https://www.better-auth.com/pricing"
   ],
   "security_record": {
    "source": "OSV.dev / GitHub Security Advisories, npm packages better-auth",
    "checked": "2026-10-03",
    "advisories_all_time": 22,
    "advisories_last_12_months": 17,
    "critical_last_12_months": 2,
    "high_last_12_months": 12,
    "most_recent": "2026-07-24",
    "all_fixed_in_current_release": "Yes: every listed advisory has a fixed version at or below the current release.",
    "recent": [
     {
      "id": "GHSA-qq9h-g4jm-xgf3",
      "cve": "CVE-2026-67327",
      "published": "2026-07-24",
      "severity": "HIGH",
      "summary": "Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in",
      "fixed_in": [
       "1.6.22",
       "1.7.0-beta.10"
      ],
      "url": "https://github.com/advisories/GHSA-qq9h-g4jm-xgf3"
     },
     {
      "id": "GHSA-2vg6-77g8-24mp",
      "cve": "CVE-2026-67334",
      "published": "2026-07-07",
      "severity": "LOW",
      "summary": "Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows",
      "fixed_in": [
       "1.6.11"
      ],
      "url": "https://github.com/advisories/GHSA-2vg6-77g8-24mp"
     },
     {
      "id": "GHSA-392p-2q2v-4372",
      "cve": "CVE-2026-53517",
      "published": "2026-07-07",
      "severity": "HIGH",
      "summary": "Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption",
      "fixed_in": [
       "1.6.0"
      ],
      "url": "https://github.com/advisories/GHSA-392p-2q2v-4372"
     },
     {
      "id": "GHSA-7w99-5wm4-3g79",
      "cve": "CVE-2026-53518",
      "published": "2026-07-07",
      "severity": "HIGH",
      "summary": "@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token reque",
      "fixed_in": [
       "1.6.11"
      ],
      "url": "https://github.com/advisories/GHSA-7w99-5wm4-3g79"
     },
     {
      "id": "GHSA-86j7-9j95-vpqj",
      "cve": "CVE-2026-67333",
      "published": "2026-07-07",
      "severity": "HIGH",
      "summary": "Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp",
      "fixed_in": [
       "1.6.13",
       "1.7.0-beta.4"
      ],
      "url": "https://github.com/advisories/GHSA-86j7-9j95-vpqj"
     },
     {
      "id": "GHSA-9h47-pqcx-hjr4",
      "cve": "CVE-2026-67336",
      "published": "2026-07-07",
      "severity": "HIGH",
      "summary": "Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted b",
      "fixed_in": [
       "1.6.11"
      ],
      "url": "https://github.com/advisories/GHSA-9h47-pqcx-hjr4"
     }
    ],
    "plugin_packages_extra": {
     "advisories_all_time": 12,
     "note": "Advisories that affect only separately published plugin packages (SSO, SCIM, OAuth provider, passkey, Stripe). If you use only core email/password and social sign-in, these do not apply to you.",
     "source": "https://github.com/better-auth/better-auth/security/advisories",
     "repo_total_all_time": 37
    },
    "where_the_flaws_were": "Most advisories are in optional features: the OIDC/OAuth provider, MCP, organization, SSO and SCIM plugins. Check each advisory's summary before assuming it applies to a basic login."
   },
   "agent_setup": {
    "command": "npm install better-auth",
    "human_needed": "No. It is a library: no account, no key. You need a database connection string from wherever your database lives.",
    "sources": [
     "https://www.npmjs.com/package/better-auth"
    ]
   },
   "fact_sources": {
    "price": [
     "https://www.better-auth.com/pricing"
    ],
    "free_start": [
     "https://www.better-auth.com/pricing"
    ],
    "status": [
     "https://www.npmjs.com/package/better-auth"
    ],
    "latest_release": [
     "https://www.npmjs.com/package/better-auth"
    ],
    "security_record": [
     "https://osv.dev/list?ecosystem=npm&q=better-auth"
    ],
    "agent_setup": [
     "https://www.npmjs.com/package/better-auth"
    ]
   }
  },
  {
   "id": "authjs",
   "name": "Auth.js / NextAuth",
   "kind": "Open-source library (you host it)",
   "package": "next-auth",
   "latest": "4.24.15 (v5 is still beta: 5.0.0-beta.32)",
   "latest_published": "2026-07-20",
   "weekly_downloads": 7509361,
   "license": "ISC",
   "status": "Maintenance only. The project joined Better Auth on 2025-09-22; its maintainers say it gets security patches and urgent fixes, not new features, and they recommend Better Auth for new projects unless you need stateless sessions with no database. It is not deprecated and still receives releases.",
   "price": "Free.",
   "free_start": "Yes. No account, no card.",
   "agent_can_start_alone": "Yes. Nothing to sign up for.",
   "watch_out": "v5 never left beta. Fine to keep in an existing app; a weak choice for a new one.",
   "sources": [
    "https://www.npmjs.com/package/next-auth",
    "https://authjs.dev",
    "https://better-auth.com/blog/authjs-joins-better-auth"
   ],
   "security_record": {
    "source": "OSV.dev / GitHub Security Advisories, npm packages next-auth, @auth/core",
    "checked": "2026-10-03",
    "advisories_all_time": 14,
    "advisories_last_12_months": 5,
    "critical_last_12_months": 2,
    "high_last_12_months": 1,
    "most_recent": "2026-07-23",
    "all_fixed_in_current_release": "Yes: every listed advisory has a fixed version at or below the current release.",
    "recent": [
     {
      "id": "GHSA-7rqj-j65f-68wh",
      "cve": "CVE-2026-73420",
      "published": "2026-07-23",
      "severity": "CRITICAL",
      "summary": "Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass",
      "fixed_in": [
       "4.24.15",
       "5.0.0-beta.32"
      ],
      "url": "https://github.com/advisories/GHSA-7rqj-j65f-68wh"
     },
     {
      "id": "GHSA-8fpg-xm3f-6cx3",
      "cve": "CVE-2026-73421",
      "published": "2026-07-23",
      "severity": "CRITICAL",
      "summary": "Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with a",
      "fixed_in": [
       "5.0.0-beta.32"
      ],
      "url": "https://github.com/advisories/GHSA-8fpg-xm3f-6cx3"
     },
     {
      "id": "GHSA-x445-f3h2-j279",
      "cve": "CVE-2026-73419",
      "published": "2026-07-23",
      "severity": "MODERATE",
      "summary": "Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them",
      "fixed_in": [
       "4.24.15",
       "5.0.0-beta.32"
      ],
      "url": "https://github.com/advisories/GHSA-x445-f3h2-j279"
     },
     {
      "id": "GHSA-xmf8-cvqr-rfgj",
      "cve": "CVE-2026-73418",
      "published": "2026-07-23",
      "severity": "HIGH",
      "summary": "Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers",
      "fixed_in": [
       "4.24.15",
       "5.0.0-beta.32"
      ],
      "url": "https://github.com/advisories/GHSA-xmf8-cvqr-rfgj"
     },
     {
      "id": "GHSA-5jpx-9hw9-2fx4",
      "cve": null,
      "published": "2025-10-29",
      "severity": "MODERATE",
      "summary": "NextAuthjs Email misdelivery Vulnerability",
      "fixed_in": [
       "4.24.12",
       "5.0.0-beta.30"
      ],
      "url": "https://github.com/advisories/GHSA-5jpx-9hw9-2fx4"
     },
     {
      "id": "GHSA-v64w-49xw-qq89",
      "cve": "CVE-2023-48309",
      "published": "2023-11-20",
      "severity": "MODERATE",
      "summary": "Possible user mocking that bypasses basic authentication",
      "fixed_in": [
       "4.24.5"
      ],
      "url": "https://github.com/advisories/GHSA-v64w-49xw-qq89"
     }
    ]
   },
   "agent_setup": {
    "command": "npm install next-auth",
    "human_needed": "No. It is a library: no account, no key. OAuth sign-in providers (Google, GitHub) each need client credentials a human creates.",
    "sources": [
     "https://www.npmjs.com/package/next-auth"
    ]
   },
   "fact_sources": {
    "price": [
     "https://www.npmjs.com/package/next-auth"
    ],
    "free_start": [
     "https://www.npmjs.com/package/next-auth"
    ],
    "status": [
     "https://www.npmjs.com/package/next-auth",
     "https://authjs.dev",
     "https://better-auth.com/blog/authjs-joins-better-auth"
    ],
    "latest_release": [
     "https://www.npmjs.com/package/next-auth"
    ],
    "security_record": [
     "https://osv.dev/list?ecosystem=npm&q=next-auth"
    ],
    "agent_setup": [
     "https://www.npmjs.com/package/next-auth"
    ]
   }
  },
  {
   "id": "clerk",
   "name": "Clerk",
   "kind": "Hosted service with prebuilt sign-in UI",
   "package": "@clerk/nextjs",
   "latest": "7.9.10",
   "latest_published": "2026-10-01",
   "weekly_downloads": 3031971,
   "license": "MIT (SDK)",
   "status": "Actively developed.",
   "price": "Free up to 50,000 monthly retained users per app. Pro $25/month ($20 billed annually), then $0.02 per extra user. B2B add-on $100/month ($85 annually).",
   "free_start": "Yes. No card required.",
   "agent_can_start_alone": "Yes after a one-time human step: via Stripe Projects. See agent_setup.",
   "watch_out": "User data lives with the vendor. Cost scales per user past the free tier.",
   "sources": [
    "https://www.npmjs.com/package/@clerk/nextjs",
    "https://clerk.com/pricing",
    "https://docs.stripe.com/projects"
   ],
   "security_record": {
    "source": "OSV.dev / GitHub Security Advisories, npm packages @clerk/nextjs, @clerk/backend",
    "checked": "2026-10-03",
    "advisories_all_time": 5,
    "advisories_last_12_months": 3,
    "critical_last_12_months": 1,
    "high_last_12_months": 2,
    "most_recent": "2026-04-30",
    "all_fixed_in_current_release": "Yes: every listed advisory has a fixed version at or below the current release.",
    "recent": [
     {
      "id": "GHSA-w24r-5266-9c3c",
      "cve": "CVE-2026-42349",
      "published": "2026-04-30",
      "severity": "HIGH",
      "summary": "Clerk has an authorization bypass when combining organization, billing, or reverification checks",
      "fixed_in": [
       "6.39.3",
       "7.2.4"
      ],
      "url": "https://github.com/advisories/GHSA-w24r-5266-9c3c"
     },
     {
      "id": "GHSA-vqx2-fgx2-5wq9",
      "cve": "CVE-2026-41248",
      "published": "2026-04-16",
      "severity": "CRITICAL",
      "summary": "Official Clerk JavaScript SDKs: Middleware-based route protection bypass",
      "fixed_in": [
       "5.7.6",
       "6.39.2",
       "7.2.1"
      ],
      "url": "https://github.com/advisories/GHSA-vqx2-fgx2-5wq9"
     },
     {
      "id": "GHSA-gjxx-92w9-8v8f",
      "cve": "CVE-2026-34076",
      "published": "2026-03-27",
      "severity": "HIGH",
      "summary": "Clerk: SSRF in the opt-in clerkFrontendApiProxy feature may leak secret keys to unintended host",
      "fixed_in": [
       "3.2.3"
      ],
      "url": "https://github.com/advisories/GHSA-gjxx-92w9-8v8f"
     },
     {
      "id": "GHSA-9mp4-77wg-rwx9",
      "cve": "CVE-2025-53548",
      "published": "2025-07-09",
      "severity": "HIGH",
      "summary": "@clerk/backend Performs Insufficient Verification of Data Authenticity",
      "fixed_in": [
       "6.23.3"
      ],
      "url": "https://github.com/advisories/GHSA-9mp4-77wg-rwx9"
     },
     {
      "id": "GHSA-q6w5-jg5q-47vg",
      "cve": "CVE-2024-22206",
      "published": "2024-01-12",
      "severity": "CRITICAL",
      "summary": "@clerk/nextjs auth() and getAuth() methods vulnerable to insecure direct object reference (IDOR) ",
      "fixed_in": [
       "4.29.3"
      ],
      "url": "https://github.com/advisories/GHSA-q6w5-jg5q-47vg"
     }
    ]
   },
   "agent_setup": {
    "command": "stripe projects add clerk/auth",
    "then": "stripe projects env --pull",
    "human_needed": "Once. A person must sign in to Stripe and link or create the provider account before the agent session (stripe projects link <provider>); paid tiers also need a payment method added once (stripe projects billing add). After that the agent can provision and pull credentials without a browser.",
    "note": "Service id as listed on projects.dev on 2026-10-03; a provider may offer more services (stripe projects catalog <provider>).",
    "sources": [
     "https://projects.dev/providers",
     "https://docs.stripe.com/projects"
    ]
   },
   "fact_sources": {
    "price": [
     "https://clerk.com/pricing"
    ],
    "free_start": [
     "https://clerk.com/pricing"
    ],
    "status": [
     "https://www.npmjs.com/package/@clerk/nextjs"
    ],
    "latest_release": [
     "https://www.npmjs.com/package/@clerk/nextjs"
    ],
    "security_record": [
     "https://osv.dev/list?ecosystem=npm&q=@clerk/nextjs"
    ],
    "agent_setup": [
     "https://projects.dev/providers",
     "https://docs.stripe.com/projects"
    ]
   }
  },
  {
   "id": "workos",
   "name": "WorkOS AuthKit",
   "kind": "Hosted service aimed at B2B (enterprise SSO, directory sync)",
   "package": "@workos-inc/authkit-nextjs",
   "latest": "4.4.0",
   "latest_published": "2026-09-30",
   "weekly_downloads": 1326362,
   "license": "MIT (SDK)",
   "status": "Actively developed.",
   "price": "Free up to 1 million users. $2,500/month per additional million. Enterprise SSO $125/month per connection; Directory Sync $125/month per connection.",
   "free_start": "Yes. No card until production.",
   "agent_can_start_alone": "Yes after a one-time human step: via Stripe Projects. See agent_setup.",
   "watch_out": "Cheap for users, expensive per enterprise customer: each SSO connection is billed.",
   "sources": [
    "https://www.npmjs.com/package/@workos-inc/authkit-nextjs",
    "https://workos.com/pricing",
    "https://docs.stripe.com/projects"
   ],
   "security_record": {
    "source": "OSV.dev / GitHub Security Advisories, npm packages @workos-inc/authkit-nextjs",
    "checked": "2026-10-03",
    "advisories_all_time": 3,
    "advisories_last_12_months": 1,
    "critical_last_12_months": 0,
    "high_last_12_months": 1,
    "most_recent": "2025-11-20",
    "all_fixed_in_current_release": "Yes: every listed advisory has a fixed version at or below the current release.",
    "recent": [
     {
      "id": "GHSA-p8pf-44ff-93gf",
      "cve": "CVE-2025-64762",
      "published": "2025-11-20",
      "severity": "HIGH",
      "summary": "authkit-nextjs may let session cookies be cached in CDNs",
      "fixed_in": [
       "2.11.1"
      ],
      "url": "https://github.com/advisories/GHSA-p8pf-44ff-93gf"
     },
     {
      "id": "GHSA-5wmg-9cvh-qw25",
      "cve": "CVE-2024-51752",
      "published": "2024-11-05",
      "severity": "LOW",
      "summary": "@workos-inc/authkit-nextjs refresh tokens are logged when the debug flag is enabled",
      "fixed_in": [
       "0.13.2"
      ],
      "url": "https://github.com/advisories/GHSA-5wmg-9cvh-qw25"
     },
     {
      "id": "GHSA-35w3-6qhc-474v",
      "cve": "CVE-2024-29901",
      "published": "2024-03-29",
      "severity": "MODERATE",
      "summary": "@workos-inc/authkit-nextjs session replay vulnerability",
      "fixed_in": [
       "0.4.2"
      ],
      "url": "https://github.com/advisories/GHSA-35w3-6qhc-474v"
     }
    ]
   },
   "agent_setup": {
    "command": "stripe projects add workos/auth",
    "then": "stripe projects env --pull",
    "human_needed": "Once. A person must sign in to Stripe and link or create the provider account before the agent session (stripe projects link <provider>); paid tiers also need a payment method added once (stripe projects billing add). After that the agent can provision and pull credentials without a browser.",
    "note": "Service id as listed on projects.dev on 2026-10-03; a provider may offer more services (stripe projects catalog <provider>).",
    "sources": [
     "https://projects.dev/providers",
     "https://docs.stripe.com/projects"
    ]
   },
   "fact_sources": {
    "price": [
     "https://workos.com/pricing"
    ],
    "free_start": [
     "https://workos.com/pricing"
    ],
    "status": [
     "https://www.npmjs.com/package/@workos-inc/authkit-nextjs"
    ],
    "latest_release": [
     "https://www.npmjs.com/package/@workos-inc/authkit-nextjs"
    ],
    "security_record": [
     "https://osv.dev/list?ecosystem=npm&q=@workos-inc/authkit-nextjs"
    ],
    "agent_setup": [
     "https://projects.dev/providers",
     "https://docs.stripe.com/projects"
    ]
   }
  },
  {
   "id": "supabase",
   "name": "Supabase Auth",
   "kind": "Hosted service bundled with a Postgres database",
   "package": "@supabase/ssr",
   "latest": "0.12.7",
   "latest_published": "2026-09-08",
   "weekly_downloads": 10750757,
   "license": "MIT (SDK)",
   "status": "Actively developed.",
   "price": "Free: 50,000 monthly active users, 2 active projects. Pro $25/month: 100,000 included, then $0.00325 per user.",
   "free_start": "Yes. The pricing page does not say whether a card is needed.",
   "agent_can_start_alone": "Yes after a one-time human step: via Stripe Projects. See agent_setup.",
   "watch_out": "Free projects are paused after 1 week of inactivity. Best when you also want Supabase's database.",
   "sources": [
    "https://www.npmjs.com/package/@supabase/ssr",
    "https://supabase.com/pricing",
    "https://docs.stripe.com/projects"
   ],
   "security_record": {
    "source": "OSV.dev / GitHub Security Advisories, npm packages @supabase/ssr, @supabase/auth-js",
    "checked": "2026-10-03",
    "advisories_all_time": 1,
    "advisories_last_12_months": 0,
    "critical_last_12_months": 0,
    "high_last_12_months": 0,
    "most_recent": "2025-05-27",
    "all_fixed_in_current_release": "Yes: every listed advisory has a fixed version at or below the current release.",
    "recent": [
     {
      "id": "GHSA-8r88-6cj9-9fh5",
      "cve": "CVE-2025-48370",
      "published": "2025-05-27",
      "severity": "LOW",
      "summary": "auth-js Vulnerable to Insecure Path Routing from Malformed User Input",
      "fixed_in": [
       "2.70.0"
      ],
      "url": "https://github.com/advisories/GHSA-8r88-6cj9-9fh5"
     }
    ]
   },
   "agent_setup": {
    "command": "stripe projects add supabase/project",
    "then": "stripe projects env --pull",
    "human_needed": "Once. A person must sign in to Stripe and link or create the provider account before the agent session (stripe projects link <provider>); paid tiers also need a payment method added once (stripe projects billing add). After that the agent can provision and pull credentials without a browser.",
    "note": "Service id as listed on projects.dev on 2026-10-03; a provider may offer more services (stripe projects catalog <provider>).",
    "sources": [
     "https://projects.dev/providers",
     "https://docs.stripe.com/projects"
    ]
   },
   "fact_sources": {
    "price": [
     "https://supabase.com/pricing"
    ],
    "free_start": [
     "https://supabase.com/pricing"
    ],
    "status": [
     "https://www.npmjs.com/package/@supabase/ssr"
    ],
    "latest_release": [
     "https://www.npmjs.com/package/@supabase/ssr"
    ],
    "security_record": [
     "https://osv.dev/list?ecosystem=npm&q=@supabase/ssr"
    ],
    "agent_setup": [
     "https://projects.dev/providers",
     "https://docs.stripe.com/projects"
    ]
   }
  },
  {
   "id": "auth0",
   "name": "Auth0",
   "kind": "Hosted service (Okta)",
   "package": "@auth0/nextjs-auth0",
   "latest": "4.31.0",
   "latest_published": "2026-10-01",
   "weekly_downloads": 984705,
   "license": "MIT (SDK)",
   "status": "Actively developed.",
   "price": "Free up to 25,000 monthly active users. Paid plans start at $35/month (Essentials) and $240/month (Professional), each priced from 500 users.",
   "free_start": "Yes. No card required.",
   "agent_can_start_alone": "Yes after a one-time human step: via Stripe Projects. See agent_setup.",
   "watch_out": "Steep step from free to paid: paid tiers are priced from 500 users.",
   "sources": [
    "https://www.npmjs.com/package/@auth0/nextjs-auth0",
    "https://auth0.com/pricing",
    "https://docs.stripe.com/projects"
   ],
   "security_record": {
    "source": "OSV.dev / GitHub Security Advisories, npm packages @auth0/nextjs-auth0",
    "checked": "2026-10-03",
    "advisories_all_time": 7,
    "advisories_last_12_months": 3,
    "critical_last_12_months": 0,
    "high_last_12_months": 0,
    "most_recent": "2026-04-21",
    "all_fixed_in_current_release": "Yes: every listed advisory has a fixed version at or below the current release.",
    "recent": [
     {
      "id": "GHSA-xq8m-7c5p-c2r6",
      "cve": "CVE-2026-40155",
      "published": "2026-04-21",
      "severity": "MODERATE",
      "summary": "Auth0 Next.js SDK has Improper Proxy Cache Lookup",
      "fixed_in": [
       "4.18.0"
      ],
      "url": "https://github.com/advisories/GHSA-xq8m-7c5p-c2r6"
     },
     {
      "id": "GHSA-mr6f-h57v-rpj5",
      "cve": "CVE-2025-67716",
      "published": "2025-12-10",
      "severity": "LOW",
      "summary": "Improper Validation of Query Parameters in Auth0 Next.js SDK",
      "fixed_in": [
       "4.13.0"
      ],
      "url": "https://github.com/advisories/GHSA-mr6f-h57v-rpj5"
     },
     {
      "id": "GHSA-wcgj-f865-c7j7",
      "cve": "CVE-2025-67490",
      "published": "2025-12-10",
      "severity": "MODERATE",
      "summary": "Improper Request Caching Lookup in the Auth0 Next.js SDK",
      "fixed_in": [
       "4.11.2",
       "4.12.1"
      ],
      "url": "https://github.com/advisories/GHSA-wcgj-f865-c7j7"
     },
     {
      "id": "GHSA-f3fg-mf2q-fj3f",
      "cve": "CVE-2025-48947",
      "published": "2025-06-04",
      "severity": "HIGH",
      "summary": "NextJS-Auth0 SDK Vulnerable to CDN Caching of Session Cookies",
      "fixed_in": [
       "4.6.1"
      ],
      "url": "https://github.com/advisories/GHSA-f3fg-mf2q-fj3f"
     },
     {
      "id": "GHSA-pjr6-jx7r-j4r6",
      "cve": "CVE-2025-46344",
      "published": "2025-04-29",
      "severity": "MODERATE",
      "summary": "Auth0 NextJS SDK v4 Missing Session Invalidation",
      "fixed_in": [
       "4.5.1"
      ],
      "url": "https://github.com/advisories/GHSA-pjr6-jx7r-j4r6"
     },
     {
      "id": "GHSA-2mqv-4j3r-vjvp",
      "cve": "CVE-2021-43812",
      "published": "2021-12-16",
      "severity": "MODERATE",
      "summary": "Open redirect in @auth0/nextjs-auth0",
      "fixed_in": [
       "1.6.2"
      ],
      "url": "https://github.com/advisories/GHSA-2mqv-4j3r-vjvp"
     }
    ]
   },
   "agent_setup": {
    "command": "stripe projects add auth0/client",
    "then": "stripe projects env --pull",
    "human_needed": "Once. A person must sign in to Stripe and link or create the provider account before the agent session (stripe projects link <provider>); paid tiers also need a payment method added once (stripe projects billing add). After that the agent can provision and pull credentials without a browser.",
    "note": "Service id as listed on projects.dev on 2026-10-03; a provider may offer more services (stripe projects catalog <provider>).",
    "sources": [
     "https://projects.dev/providers",
     "https://docs.stripe.com/projects"
    ]
   },
   "fact_sources": {
    "price": [
     "https://auth0.com/pricing"
    ],
    "free_start": [
     "https://auth0.com/pricing"
    ],
    "status": [
     "https://www.npmjs.com/package/@auth0/nextjs-auth0"
    ],
    "latest_release": [
     "https://www.npmjs.com/package/@auth0/nextjs-auth0"
    ],
    "security_record": [
     "https://osv.dev/list?ecosystem=npm&q=@auth0/nextjs-auth0"
    ],
    "agent_setup": [
     "https://projects.dev/providers",
     "https://docs.stripe.com/projects"
    ]
   }
  }
 ],
 "also": {
  "lucia": "Deprecated on npm (last release 2024-10-20). Do not start new projects on it."
 },
 "not_checked": [
  "Whether Supabase's free plan needs a card",
  "Hands-on build quality of each option",
  "Prices beyond the published list prices",
  "Third-party security audits (we found no published audit report for any of the libraries; absence of a report is not evidence either way)",
  "Incidents on the hosted vendors' own servers"
 ],
 "security_note": "Counts are published advisories for the open-source packages only. A higher count can mean more code, more plugins, or more people looking, and does not by itself mean less safe. For hosted services (Clerk, WorkOS, Supabase, Auth0) the server side is closed: flaws there are fixed by the vendor and never appear in these databases, so their counts cover only the client SDK. What matters for a new project: are you on a version at or above every 'fixed in', and how fast were fixes shipped.",
 "changelog": [
  {
   "date": "2026-10-03",
   "change": "First version. Added security record from OSV.dev for every option."
  },
  {
   "date": "2026-10-03",
   "change": "Added counting method and separate plugin-package count for Better Auth after a reader could not reproduce our number from GitHub's first page."
  },
  {
   "date": "2026-10-03",
   "change": "Added agent_setup (exact command and whether a human is needed) and a source for every fact."
  }
 ],
 "security_method": "How we count: we query OSV.dev for each npm package named in the 'source' field and count every advisory whose affected package is that package, published on or after 2025-10-03 for the 12-month figure. Plugin packages published separately (for Better Auth: @better-auth/sso, @better-auth/scim, @better-auth/oauth-provider, @better-auth/passkey, @better-auth/stripe) are NOT in the main count and are reported separately. A project's GitHub advisories page is paginated and shows about 10 per page, so a count read from its first page will be lower than ours.",
 "id": "nextjs-auth",
 "search_title": "Best auth for Next.js (Oct 2026): Better Auth vs NextAuth vs Clerk vs WorkOS vs Supabase vs Auth0",
 "how_to_read": "Each option has fact_sources: the page each fact was read from. Verify the deciding fact there. 'picks' are our reading of the facts for common situations, not a ranking; the facts stand without them.",
 "publisher": {
  "name": "Stackfacts",
  "about": "https://stackfacts.dev/about",
  "location": "Austin, Texas",
  "funding": "No vendor payments, no affiliate commissions.",
  "policy": "Placement cannot be bought. Every number states how it was counted.",
  "corrections": "corrections@stackfacts.dev"
 },
 "source_url": "https://stackfacts.dev/nextjs-auth"
}