Guides10 min read

Open Source Clerk Alternatives: The Three Shapes They Come In

The lists name the same nine projects. They are three different kinds of software, and picking the wrong shape costs more than the invoice you left.

Every list of open source Clerk alternatives hands you the same nine names in a different order. The names are not the hard part. The hard part is that those nine projects are three different kinds of software, they cost you in three different ways, and the lists rank them as though the choice were between brands rather than between architectures.

Here is the sorting that actually decides your next two years, and what each shape charges you instead of money.

Can you self-host Clerk?

No. Clerk is a hosted service and does not ship a self-hostable edition. That is the reason this subject produces lists of other projects instead of a deployment guide, and it is worth stating plainly first, because a fair number of people arrive here looking for a Docker image that does not exist.

One more thing before the list, in fairness to what you are leaving. Clerk is free to 50,000 monthly retained users and 25 dollars a month on Pro, read on their pricing page on 24 August 2026. If that is your bill, nothing below will save you money, and we have written the full arithmetic on both sides rather than repeat it here. What a move can buy you is not on the invoice: it is the address your users live at, and the right to leave again later.

"Open source" is three different promises

The label answers three separate questions, and every comparison treats them as one. They come apart quickly in practice.

Can I read the code? True of everything below, and the least useful of the three. Reading an identity server does not mean you will operate one.

Can I run it myself? Usually yes, and the license decides what that costs you. Apache 2.0 and MIT ask nothing back. Zitadel is AGPL-3.0, which is a deliberate choice on their part and a real question for yours: if you are shipping a product on top of it, read the terms before you build rather than after.

Can I leave with my data? This is the one that matters, and it is answered by the export format rather than by the license. A project can be perfectly open and still make your password hashes hard to move.

The three shapes

Where the login runs is the whole difference between them, so it is worth seeing it before reading about it. Among the open source Clerk alternatives below, one shape puts authentication inside your application, one puts it in a service of its own next door, and one leaves it running on somebody else's infrastructure.

ShapeWhat you deployWhat it costs youWhen it is right
A library in your appnothing newthe features you build yourselfone application, one database, your own screens
An identity servera second service and its databaseoperating it, and upgrading itseveral apps behind one login, or federation
Open source, hosted by themnothingan invoice again, usually smalleryou want the exit written down, not exercised

Shape 1: a library inside your application

No new service, no second database, no network hop at login. The user table lands next to the rest of your data and sessions are issued by your own code.

Auth.js (ISC) is the default in the Next.js world: providers, database adapters, and a session strategy you pick on purpose. It is deliberately unopinionated, which means it hands you a foundation rather than a product.

Better Auth (MIT) is the TypeScript-first framework that grew fastest over the last two years, and its plugin catalogue is the reason. The organization plugin ships organizations, members, invitations, roles and teams inside the open source package, which is precisely the feature Clerk sells as an add-on.

Worth a line, because old lists still recommend it: Lucia was deprecated in March 2025 and now exists as a learning resource with a single-file replacement rather than a maintained package. If a comparison you are reading still lists it as a live option, that comparison has not been updated in over a year.

Shape 2: an identity server you deploy

A separate service that owns identity for everything you run. This is the shape people underestimate, because the install is an afternoon and the operation is forever.

Keycloak (Apache 2.0) is the incumbent, written in Java and part of the CNCF ecosystem. It does everything, enterprise protocols included, and it expects an operator.

Ory Kratos (Apache 2.0) is headless and API-first, with no bundled UI at all. That is a feature if you were going to build your own screens anyway, and a surprise if you were not.

Zitadel (AGPL-3.0) is the most complete on paper for B2B: multi-tenancy, SAML, SCIM and passkeys in the core, on Postgres. Read the license against your plans.

Logto (MPL-2.0) is the friendliest of the servers for a small team, with prebuilt sign-in flows and multi-tenancy, and a managed cloud for when you would rather not run it.

SuperTokens (Apache 2.0, with enterprise features under a separate license) splits into a core service plus frontend and backend SDKs, so it sits between the two shapes.

Authentik (MIT, with an enterprise edition license covering some components) is the one to look at when your problem is single sign-on across internal tools, LDAP and RADIUS included, rather than the login of one SaaS.

Hexclave, formerly Stack Auth, is the closest thing here to Clerk's own product shape, bundling auth with teams, payments and emails. It is dual licensed MIT and AGPLv3, which is again a question to answer before you build.

Shape 3: the same code, hosted by someone else

Logto, Zitadel, Ory and SuperTokens all sell a managed version of the thing you could run yourself. On a list of alternatives that looks like a contradiction, and it is not: you are back to an invoice, but the exit is written down and the export format is documented. For a team that wants the option to leave without wanting to operate a server this week, it is an honest middle, and it is what a good share of the people who say they moved to open source auth actually did.

Where open source Clerk alternatives actually save money

For a consumer app under the free tier, every argument in this piece is about ownership rather than money. The bill that actually moves is B2B, and it moves early.

Clerk prices B2B authentication as a 100 dollar a month add-on with 100 organizations included, administration at another 100, and enterprise connections beyond the first at 75 dollars a month each, all read on their pricing page on 24 August 2026. A modest B2B product with two enterprise customers pays for the plan, organizations and a connection before its user count matters at all.

That is the number an open source alternative can genuinely remove, and only some of them do. Better Auth's organization plugin covers it in the library shape. Zitadel and Logto cover it in the server shape. Plain Auth.js does not, and you would be building invitations and role checks yourself.

The honest other half: SAML and SCIM stay a project wherever you go. Keycloak, Zitadel and Authentik ship them, which is exactly why those three are heavier to operate than the rest. If an enterprise customer is asking for directory provisioning this quarter, that requirement should pick your shape before any preference about licenses does.

What leaving actually costs

The code is the easy half of any migration. The part that decides your timeline is whether your password hashes come with you, and on this point Clerk is better than several of its competitors: an admin can download a CSV that includes hashed passwords from the dashboard. If they are bcrypt in the standard format they verify against your own code untouched, and the move is one import rather than a dual run that lasts months. We wrote the whole procedure, including what to do when the hashes are out of reach.

Two costs nobody itemises. Everyone is signed out at the cutover, because sessions belong to whoever issued them, so plan for every user to sign in once. And the screens are yours now: sign-in, sign-up, verification and password reset, plus the emails behind them.

Where we fit, and where we do not

We build a free starter kit, so this is the paragraph where you should expect the pitch. Here it is, and then here is the part that costs us.

OpenStarterKit is shape 1, already wired: Auth.js v5 with Prisma and Postgres on Next.js 16, MIT licensed, with OAuth, magic links, email and password, password reset with session revocation, and roles, next to a complete Stripe integration. It is not an alternative to Clerk the company. It is the case where the choice above has been made for you and the code is yours from the first commit. The complete guide to self-hosted authentication in Next.js is the argument, and the authentication setup guide is the implementation.

Where we lose, stated plainly. We do not ship SAML or SCIM, so the enterprise row above is not us. Two-factor authentication is on the roadmap, not in your hands today. And organizations, members and invitations are not in the free kit: they are the paid tier we are building, which means that on the B2B line, the most expensive line on Clerk's invoice, Better Auth's organization plugin is ahead of our free kit right now. That is an uncomfortable sentence to publish and it is true today, which is the only test a comparison page has to pass.

If you would rather run your own numbers than read ours, the break-even calculator asks what you are building instead of how many users you have.

Frequently asked questions

Can you self-host Clerk?

No. Clerk is a hosted service and does not ship a self-hostable edition, which is why every list on this subject is a list of other projects rather than a deployment guide. If you want your login to run on your own infrastructure, the decision is which replacement shape you are willing to operate: a library inside your app, an identity server you deploy, or the same open source code hosted by its maker.

What is the best open source alternative to Clerk?

There is no single answer, because the projects are not interchangeable. For one Next.js application, a library such as Auth.js or Better Auth keeps the user table in the database you already run and adds no service to operate. For several applications sharing one login, or for enterprise federation, an identity server such as Keycloak, Ory, Zitadel or Logto is the right shape and a library is not. Choose the shape first and the project second.

Is there a free alternative to Clerk?

Several, and all of them are free in the same narrow sense: no invoice, and a maintenance bill instead. It is also worth checking what you would actually save. Clerk is free to 50,000 monthly retained users and 25 dollars a month on Pro, read on their pricing page on 24 August 2026, so for most projects the saving is close to zero and the real reason to move is ownership rather than price.

Do open source alternatives handle organizations and B2B?

Some do, and this is where the money actually is. Clerk prices B2B authentication as a 100 dollar a month add-on and enterprise connections from 75 dollars a month each. Better Auth ships organizations, members, invitations, roles and teams in its open source organization plugin, and Zitadel and Logto have multi-tenancy in the server itself. Plain Auth.js does not: you would build it. SAML and SCIM remain a real project wherever you land.

What does it cost to leave Clerk?

Less than most providers, because Clerk lets an admin download a CSV that includes hashed passwords, which is the single fact that decides whether a migration is one import or a months-long dual run. Everyone is signed out at the cutover, since sessions belong to whoever issued them, so plan for every user to sign in once and make sure they land on the sign-in page rather than an error.

Pick the shape, then the project

If you take one thing from this: the open source Clerk alternatives on every list are not nine options, they are three decisions and you only get to make one of them. A library if you have one app and want the user table in your own database. A server if identity has to serve more than one thing. A managed version of either if the exit matters more to you than the hosting.

Whichever you pick, the questions worth asking in advance are the ones no comparison table has a column for: what does the export contain, who gets paged when an advisory lands, and what happens to your login the day the invoice arrives.