Head to head
Stop guessing which one. Put them side by side.
Up to 4 tools, same rows for each: what it is, what it really costs, the trap, and how to wire it up. The URL carries your picks — send it to anyone.
Hexclave (Stack Auth)Better AuthLucia
Quick read
- Free with no card: Better Auth, Lucia.
| Field | Hexclave (Stack Auth)hexclave.com | Better Authbetter-auth.com | Lucialucia-auth.com |
|---|---|---|---|
| What it is | Open-source Clerk alternative, formerly Stack Auth, now a Y Combinator-backed company called Hexclave. Ships prebuilt React components, organizations, RBAC and user impersonation. Client SDKs are MIT-licensed and the server is AGPLv3 with commercial licensing available; the whole stack self-hosts for free. | Framework-agnostic TypeScript authentication library that runs inside your own app and writes to your own database. Covers email/password, social OAuth, two-factor, organizations, passkeys and API keys through a plugin system. Vercel acquired the project in July 2026; it stays MIT-licensed, self-hosted and community-governed. | No longer a library. Lucia was deprecated in March 2025 and now exists as a learning resource: a copy-paste auth_session.ts reference implementation plus The Auth Book, a free guide covering sessions, tokens and password handling. The site was last refreshed in July 2026. |
| Category | Auth & user management | Auth & user management | Auth & user management |
| Cost tier | mixed | free | free |
| Pricing | Free to 10k MAU · $49/mo Team (50k) · $299/mo Growth · self-host free | Free and open source (MIT) · self-hosted, no MAU fees | Free · deprecated library, now MIT reference code and a written guide |
| Why builders pick it | The closest thing to Clerk's component-level developer experience that you can also run on your own infrastructure, which makes the escape hatch real rather than theoretical. | No per-MAU bill ever and no vendor holding your user table — auth becomes just another dependency. The plugin system covers most of what you would otherwise pay Clerk or Auth0 for. | Read it before choosing any vendor — it is the fastest way to genuinely understand what session auth does, and the single-file implementation is enough for small projects. |
| Watch out for | Rebranded from Stack Auth during 2026, so docs, packages (@stackframe/stack) and URLs still mix both names. AGPLv3 on the server means self-hosting inside a closed-source product requires a commercial license. | You own the hard parts: session security, email deliverability, rate limiting and breach response are all yours. Vercel's July 2026 acquisition preserves MIT licensing, but roadmap direction now sits with a hosting vendor. | Do not install the npm package for new work; it is unmaintained and will not receive security fixes. This is documentation and example code, not a supported dependency. |
| How to wire it up | npx @stackframe/init-stack@latest | npm i better-auth | not logged |
| Editor's pick | No | No | No |
Which one did you ship?
The grid says what these tools are. This says what builders did about it — one decision per person, changeable whenever you change your mind.
0/280Sign in to add yours.
Or try
Hand this to your Lovable agent
# Tool comparison — Hexclave (Stack Auth) vs Better Auth vs Lucia Source: Kbaise, a directory of tools that work with Lovable projects. Pick one and tell me why before writing any integration code. ## Hexclave (Stack Auth) (hexclave) - URL: https://www.hexclave.com - Category: Auth & user management - Cost: mixed — Free to 10k MAU · $49/mo Team (50k) · $299/mo Growth · self-host free - What it is: Open-source Clerk alternative, formerly Stack Auth, now a Y Combinator-backed company called Hexclave. Ships prebuilt React components, organizations, RBAC and user impersonation. Client SDKs are MIT-licensed and the server is AGPLv3 with commercial licensing available; the whole stack self-hosts for free. - Why builders pick it: The closest thing to Clerk's component-level developer experience that you can also run on your own infrastructure, which makes the escape hatch real rather than theoretical. - Trap: Rebranded from Stack Auth during 2026, so docs, packages (@stackframe/stack) and URLs still mix both names. AGPLv3 on the server means self-hosting inside a closed-source product requires a commercial license. - Wiring: npx @stackframe/init-stack@latest - Full dossier: /api/public/tools/hexclave ## Better Auth (better-auth) - URL: https://better-auth.com - Category: Auth & user management - Cost: free — Free and open source (MIT) · self-hosted, no MAU fees - What it is: Framework-agnostic TypeScript authentication library that runs inside your own app and writes to your own database. Covers email/password, social OAuth, two-factor, organizations, passkeys and API keys through a plugin system. Vercel acquired the project in July 2026; it stays MIT-licensed, self-hosted and community-governed. - Why builders pick it: No per-MAU bill ever and no vendor holding your user table — auth becomes just another dependency. The plugin system covers most of what you would otherwise pay Clerk or Auth0 for. - Trap: You own the hard parts: session security, email deliverability, rate limiting and breach response are all yours. Vercel's July 2026 acquisition preserves MIT licensing, but roadmap direction now sits with a hosting vendor. - Wiring: npm i better-auth - Full dossier: /api/public/tools/better-auth ## Lucia (lucia) - URL: https://lucia-auth.com - Category: Auth & user management - Cost: free — Free · deprecated library, now MIT reference code and a written guide - What it is: No longer a library. Lucia was deprecated in March 2025 and now exists as a learning resource: a copy-paste auth_session.ts reference implementation plus The Auth Book, a free guide covering sessions, tokens and password handling. The site was last refreshed in July 2026. - Why builders pick it: Read it before choosing any vendor — it is the fastest way to genuinely understand what session auth does, and the single-file implementation is enough for small projects. - Trap: Do not install the npm package for new work; it is unmaintained and will not receive security fixes. This is documentation and example code, not a supported dependency. - Full dossier: /api/public/tools/lucia ## Quick read - Free with no card: Better Auth, Lucia. ## Rules 1. Prefer the free tier when no budget was stated, and say what the ceiling is. 2. Read the full dossier before integrating. 3. Fetch /api/public/models before writing any AI model ID.
Agents can fetch the same thing: GET /api/public/compare?slugs=hexclave,better-auth,lucia