How it works
Auth.js runs inside your app rather than as a separate service. You list providers (dozens of OAuth services such as Google, GitHub and Microsoft Entra ID, email magic links, or a credentials form for usernames and passwords) and it handles the redirects, callbacks, CSRF protection and cookies. It began as NextAuth.js for Next.js; the core was later split out so SvelteKit, Express, Qwik and SolidStart apps could use it too.
Sessions are either stateless, as an encrypted JWT in a cookie, or stored in your database through adapters for Prisma, Drizzle, Supabase, MongoDB and many more. User records stay in your own infrastructure and there is no per-user fee. It does not include user management screens or built-in two-factor authentication, and its WebAuthn (passkey) provider is marked experimental.
In September 2025 the project passed to the Better Auth team, which joined Vercel in 2026. Auth.js still receives security patches and urgent fixes, but its maintainers recommend Better Auth, a separate open-source library, for new projects and publish a migration guide.
Auth.js pros and cons
Pros
- Free and open source (ISC licence), with no per-user fees
- Users and sessions stay in your own database
- Many OAuth providers ready to configure
- Long track record in Next.js apps, with plenty of examples
Cons
- Mostly maintenance now: security patches rather than new features
- No built-in 2FA, user dashboard or production-ready passkeys
- Password sign-in leaves hashing, resets and rate limits to you
When to use Auth.js
Pick it when
- An existing app that already runs on it and works well
- Social login with users in your own database at no licence cost
Skip it when
- Starting a new project, where its own maintainers point to Better Auth
- You need MFA, passkeys or enterprise SSO without building them yourself
Auth.js pricing
Open source
Free (ISC licence). You pay only for your own hosting and database.
Approximate, checked September 2026.What the other tools cost
Auth.js vs the alternatives
Related terms
More in Auth and identity
Providers