6,598 open-source and SaaS tools, with GitHub stats refreshed every day.

5 alternatives ranked by real activity

Open-source Stytch alternatives

A curated, ranked list of the 5 best open-source alternatives to Stytch.

The best open-source alternative to Stytch is SuperTokens. If that doesn't suit you, other good options are Logto, Hanko, Hexclave and Authorizer.

Stytch alternatives are mainly Auth & Identity tools. 5 of them shipped code in the last 30 days, 5 can be self-hosted, and 2 use a permissive licence.

Last updated October 2, 2026 · ranked by GitHub stars, growth and recent commits

SuperTokens

An open-source authentication provider offering login, session management, MFA and multi-tenancy through frontend and backend SDKs and a Java core service.

GitHub stars
15k
Last commit
today
Latest release
v12.2.0
Self-hosted
Yes
Hosted version
Available
supertokens.comSuperTokens homepage screenshot

SuperTokens is an open-source authentication provider positioned as an alternative to Auth0, Firebase Auth and AWS Cognito. It adds secure login and session management to your apps, with SDKs for popular languages and frameworks such as Node.js, Go, Python, React and React Native.

Its architecture has three building blocks: a frontend SDK that manages session tokens and renders login UI widgets, a backend SDK that provides the APIs for sign-up, sign-in, sign-out and session refreshing, and the SuperTokens Core, an HTTP service in Java that implements the authentication logic and database operations used by the backend SDK. The feature list spans passwordless and social sign-in, email and phone with password, session handling, MFA, multi-tenant organizations with enterprise SSO, user roles, authentication between microservices, and a dashboard for managing users.

You can self-host the core to keep user data in your own database, or use the vendor's managed offering. The repository's license is listed as 'Other' on GitHub, because enterprise features sit under a separate license, so check which features you need. It suits teams that want to own authentication without building it from scratch.

Key features

  • Email-password, passwordless and social login
  • Session management with token refresh
  • Multi-factor authentication support
  • Multi-tenancy and enterprise SSO
  • User roles and microservice authentication
  • User management dashboard

Pricing: Self-hosting is free at any scale. The managed cloud is free below 5K monthly active users, then $0.02 per active user per month, plus optional paid add-ons.

Logto

Open-source identity infrastructure that adds sign-in, enterprise SSO and role-based access control to SaaS and AI products, using OIDC and OAuth 2.1 standards.

GitHub stars
15k
Last commit
yesterday
Latest release
v1.44.0
Licence
MPL-2.0
Self-hosted
Yes
Hosted version
Available
logto.ioLogto homepage screenshot

Logto is an open-source identity platform that handles sign-in, sign-up and access control so product teams do not have to build them from scratch. It is built on OpenID Connect and OAuth 2.1, with SAML also supported, and is aimed at SaaS products and AI or agent-based platforms that need production-ready authentication.

Out of the box it provides multi-tenancy and organizations with member invites and role-based access, enterprise SSO, and prebuilt sign-in flows with a customizable interface. Sign-in options include social login, passwordless methods, MFA and Google One Tap, and it can connect to external identity providers such as Google, Azure AD and Okta. SDKs cover more than 30 frameworks, among them React, Next.js, Angular, Vue, Flutter, Go and Python.

The core is licensed under MPL-2.0 and can be self-hosted by following the OSS installation guide or run locally for development. Logto Cloud offers the same product as a fully managed service. The project also advertises support for the Model Context Protocol and agent-style AI architectures.

Key features

  • OIDC, OAuth 2.1 and SAML support
  • Multi-tenancy with organization RBAC
  • Enterprise single sign-on
  • Prebuilt, customizable sign-in flows
  • Social login, passwordless and MFA
  • SDKs for over 30 frameworks
  • Machine-to-machine access for APIs and CLIs

Pricing: Free cloud plan for up to 50,000 MAU. Pro starts at $24 per month plus token usage and add-ons; Enterprise is quoted, and self-hosting is available.

Hanko

An open-source authentication and user management service built around passkeys, with MFA, social login, SAML SSO and web components, self-hosted or on Hanko Cloud.

GitHub stars
9k
Last commit
today
Latest release
backend/v3.1.0
Self-hosted
Yes
Hosted version
Available
hanko.ioHanko homepage screenshot

Hanko is an authentication and user management solution released as open source, framework-agnostic and designed around privacy-first principles such as data minimalism and phishing resistance. It is presented as an alternative to Auth0, Clerk, WorkOS and Stytch, written in Go, with an API-first and lightweight design.

It supports modern sign-in methods including passwords, email passcodes, passkeys, MFA with TOTP and security keys, social logins such as Apple, Google and GitHub, custom OIDC and OAuth connections and SAML enterprise SSO. Configuration is flexible, for example passkey-only or OAuth-only setups, and passwords can be deletable by users. Hanko Elements web components make integration quick, a JS SDK is available, webhooks and server-side sessions with remote revocation are included, and a full API supports custom front ends. Organizations, roles and permissions plus mobile SDKs are on the roadmap.

You can self-host Hanko or use it as a fully managed service on Hanko Cloud. The repository lists the licence as Other, so review the licence file for the terms. It suits developers who want to own their authentication stack without building it from scratch.

Key features

  • Passkeys, passwords and email passcodes
  • MFA with TOTP and security keys
  • Social login and custom OIDC connections
  • SAML enterprise SSO
  • Hanko Elements web components
  • Webhooks and server-side sessions
  • JS SDK and API-first design

Pricing: Free Starter plan covers 10,000 monthly active users. Pro is $29 per month plus $0.01 per user above 10,000; Enterprise is custom. The code is open source for self-hosting.

Hexclave

A user infrastructure platform that handles authentication, teams, RBAC, API keys, payments, emails and analytics for apps, with a dashboard and optional deployment hosting.

GitHub stars
6.9k
Last commit
today
Latest release
dashboard-v1.0.123
Self-hosted
Yes
Hosted version
Available
hexclave.comHexclave homepage screenshot

Hexclave positions itself as infrastructure for the user side of an app: you pick the frontend, backend and database, and it manages everything around your users. That covers authentication, teams, permissions, API keys, payments, emails and analytics, packaged as a catalog of modules that you enable when your product needs them, all sharing one user model.

Authentication supports passkeys, OAuth and CLI auth, with methods toggled from the dashboard without code changes. Teams add workspaces, email invites and roles, while RBAC provides nested roles and a single permission check usable on server or client. API keys are auto-revoked if leaked and show their secret only once. Payments cover subscriptions, single charges and credit-based usage metering for individuals or teams, and emails cover transactional and marketing sends with an AI template editor.

Setup is designed around pasting one prompt into a coding agent, and a Hexclave Deploy offering can deploy the frontend, backend and database together. The code is TypeScript with Next.js, topics mention self-hosting and alternatives such as Auth0, Clerk, Supabase and PostHog, and the repository lists the licence as Other, so review the licence terms.

Key features

  • Passkey, OAuth and CLI authentication
  • Teams, workspaces and email invites
  • Nested roles with RBAC checks
  • API keys with auto-revocation of leaks
  • Subscriptions, one-time payments and usage credits
  • Transactional and marketing emails
  • Product analytics for user activity

Pricing: Free forever plan for up to 10,000 auth users, and free self-hosting. Team is $49 per month and Growth $299 per month, with extra dashboard admins at $29 each.

Authorizer

Self-hosted authentication and authorization server with OAuth2/OIDC, social login, MFA, magic links, and RBAC that works with more than a dozen database backends.

GitHub stars
2.1k
Last commit
3 days ago
Latest release
2.4.1
Licence
Apache-2.0
Self-hosted
Yes
authorizer.devAuthorizer homepage screenshot

Authorizer is an open-source authentication and authorization server written in Go that you can host yourself. Its pitch is that you bring your own database and stay in control of user data. It supports more than 13 backends, including Postgres, MySQL, SQLite, SQL Server, MariaDB, Cassandra, ScyllaDB, MongoDB, ArangoDB, DynamoDB, and Couchbase. It is released under the Apache-2.0 license.

From one place it offers OAuth 2.0 and OpenID Connect, social login, multi-factor authentication, magic links, role-based access control, webhooks, and email templates, and it ships with a built-in login page and an admin panel. Version 2 is configured entirely through command-line arguments and does not read .env files or operating system environment variables.

You can run it as a Docker image or micro-service in your own infrastructure, or deploy it quickly on Railway. It suits developers who want a hosted-auth style experience without lock-in and with a choice of database.

Key features

  • OAuth 2.0 and OpenID Connect provider
  • Social login and magic links
  • Multi-factor authentication
  • Role-based access control
  • Built-in login page and admin panel
  • 13+ database backends
  • Webhooks and email templates

Pricing: Free and open source under the Apache-2.0 license.

Stytch alternatives: questions

What is the best open-source alternative to Stytch?
SuperTokens is the top-ranked open-source alternative to Stytch on Enlisted: An open-source authentication provider offering login, session management, MFA and multi-tenancy through frontend and backend SDKs and a Java core service. Other strong options are Logto, Hanko, Hexclave and Authorizer.
Are these Stytch alternatives free?
All 5 are open source, so the code is free to use under its licence, and 5 of them can be self-hosted on your own server. 4 also offer a paid or managed cloud version if you'd rather not host it yourself.
How is this list of Stytch alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 5 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all