The open source Clerk alternative for AI agents

theAuthvsClerk

Clerk is a hosted auth service with prebuilt UI components. theAuth is an MIT library you run yourself, with AI agents modeled as identities of their own.

Last verified: 2026-10-07. Hosted platform against an MIT library.

Short answer

Choose Clerk if

  • You want prebuilt sign-in, profile and organization components and a hosted backend you never operate.
  • You build on React, Next.js, Vue or Astro and want the fastest path to a working login screen.
  • You need MCP authorization for user-delegated access through Clerk's OAuth server and helpers, and do not need agents as separate identities.

Choose theAuth if

  • Agents need their own identity with an owner, delegation depth limits, budgets and a per-agent audit trail.
  • You must self-host, or you want sessions and user data in your own database.
  • You want an MIT license and no vendor billing tied to your user counts, plus Go and Python SDKs next to TypeScript.

theAuth is an open source Clerk alternative for teams that want agent identity in the same library as human sign-in. It is not the right pick for every team, and the first column says so.

theAuth vs Clerk feature comparison

Feature comparison of Clerk and theAuth
FeatureClerktheAuth
Source licenseNo, Proprietary (per theAuth README)Yes, MIT
Self-hostableNo, No, hosted service (per theAuth README)Yes, Yes, on your own database
Prebuilt UI componentsYes, Component suite across React, Next.js, Vue, Astro and morePartial or different, Client SDKs for React, Vue, Svelte, Expo and Electron
OAuth 2.1 authorization server for MCPYes, Yes, Clerk OAuth server with CIMD and DCRYes, Yes, built in
Agent identity with delegation and budgetsPartial or different, Not found in the Clerk docs we checkedYes, Owner, delegation chains, budgets, audit
OrganizationsPartial or different, Offered as a B2B add-on, priced separatelyYes, Organizations with RBAC in the library
Enterprise SSOYes, SSO connections; one included on paid plans, more priced per connectionYes, SAML 2.0 and OIDC SSO, SCIM 2.0
Billing unitMonthly retained users, so sign-ups who never return are not countedLibrary has no per-user fee; Cloud in early access

Check mark: yes. Dash: partial, different, or not found in the docs we checked. Cross: no. Claims about Clerk are from its own public docs (see Sources); theAuth rows are from its repositories.

01

Clerk alternative for AI agents: identity and delegation

Users delegating to agents, or agents as identities.

Clerk

Clerk's MCP and OAuth support is built around users granting access to an MCP server you build, with helpers such as mcp-handler and @clerk/mcp-tools. In the Clerk docs we reviewed we did not find an agent identity model with delegation chains or per-agent budgets. If you need one, check Clerk's docs for your case.

theAuth

theAuth models an agent as an identity with an owner, a cryptographic bearer token (kv_...), wildcard permissions such as mcp:github:*, and delegation chains with configurable depth limits. On top of that sit budget policies per agent, trust scoring, CIBA-style approval for sensitive tool calls, and a full audit trail of every agent action. Read the agents guide and delegation docs.

02

MCP OAuth 2.1 support

Clerk can issue the tokens for an MCP server.

Clerk

Clerk documents building an MCP server in your app with Clerk acting as the OAuth server. It supports Client ID Metadata Documents (recommended for AI agents) and dynamic client registration, each toggled in the dashboard, and it requires PKCE with S256 for the DCR path it shows.

theAuth

theAuth ships an OAuth 2.1 authorization server for MCP: PKCE S256, RFC 9728 protected resource metadata, RFC 8707 resource indicators, RFC 8414 server metadata and RFC 7591 dynamic client registration. The Go module adds RFC 8693 token exchange, DPoP, PAR, JAR, CIBA, CIMD per the MCP spec of 2025-11-25 and refresh token rotation with family revocation. See the MCP guide.

03

Self-hosted Clerk alternative: data ownership

A hosted service against your own database.

Clerk

Clerk is a hosted service. We found no self-hosted option, and the theAuth README lists Clerk as not self-hostable. User records live with the vendor. If your data must stay in your own infrastructure, that rules it out.

theAuth

theAuth is MIT licensed and runs against your own database: SQLite, PostgreSQL, MySQL or Cloudflare D1 in TypeScript, and Postgres, MySQL or in-memory storage in Go. Users, sessions, tokens and audit records stay in storage you control. A hosted theAuth Cloud is in early access for teams that would rather not run it.

04

Licensing and cost model

Hosted billing against an MIT library.

Clerk

Clerk is proprietary and bills on monthly retained users, with separate pricing for the B2B organizations add-on and for SSO connections beyond the included one. Plans and limits change, so check the Clerk pricing page.

theAuth

The library is free under the MIT license. Your costs are the database, the compute and the engineering time to operate it. theAuth Cloud is in early access and has no published prices.

05

Edge runtimes

Where each one runs.

Clerk

Because Clerk is hosted, your app talks to it through a framework SDK or by verifying its tokens. Runtime support depends on the SDK for your framework, so confirm it in Clerk's docs for the platform you deploy on.

theAuth

The TypeScript core runs on Cloudflare Workers, Deno and Bun without code changes, with three runtime dependencies: drizzle-orm, jose and zod. Adapters cover Next.js, SvelteKit, Nuxt, Hono, Express, Fastify, Astro, NestJS, SolidStart and TanStack Start.

Migrating from Clerk to theAuth

theAuth has a Clerk migration guide with a concepts map, a hooks and middleware diff, a Clerk data export plan and a rollout plan. Prebuilt Clerk components do not carry over, so budget time for your sign-in screens.

Clerk alternative: common questions

Is theAuth a Clerk alternative for AI agents?

It can be. theAuth is an open source library with agent identity, scoped permissions, delegation limits, budgets and audit, plus an MCP OAuth 2.1 authorization server. Clerk also documents an OAuth server for MCP, so pick based on whether you want a hosted service or a library, and whether agents need their own identity.

Can I self-host Clerk?

We found no self-hosted option for Clerk, and the theAuth README lists it as not self-hostable. theAuth is MIT licensed and runs on your own database.

Does Clerk support MCP?

Yes. Clerk documents using its OAuth server to protect an MCP server you build, with support for Client ID Metadata Documents and dynamic client registration. theAuth includes its own MCP OAuth 2.1 authorization server.

How is Clerk billed compared with theAuth?

Clerk bills on monthly retained users, with separate pricing for organizations and extra SSO connections, and the numbers change, so see its pricing page. The theAuth library is free under MIT, you pay for your own database and compute, and theAuth Cloud is in early access with no published prices.

How hard is it to migrate from Clerk to theAuth?

There is a step-by-step guide that maps Clerk concepts to theAuth, shows the hooks and middleware changes and covers exporting Clerk data. The main manual work is replacing prebuilt Clerk components with your own sign-in screens.

Sources

Last verified: 2026-10-07. Competitor facts come from the public pages below; plans and prices change, so confirm there.

Keep reading

Get started

Give your first agent an identity.

Install the package, create an agent with scoped permissions, and read its first audit record. The core runs on Postgres, SQLite, MySQL or D1, and the Go module needs a single go get.

  • npm install @glinr/theauth
  • go get github.com/glincker/theauth-go
Or skip hosting with theAuth Cloud