Clerk is a hosted auth service with prebuilt UI components. theAuth is an MIT library you run yourself, with AI agents modeled as identities of their own.
Last verified: 2026-10-07. Hosted platform against an MIT library.
You want prebuilt sign-in, profile and organization components and a hosted backend you never operate.
You build on React, Next.js, Vue or Astro and want the fastest path to a working login screen.
You need MCP authorization for user-delegated access through Clerk's OAuth server and helpers, and do not need agents as separate identities.
Choose theAuth if
Agents need their own identity with an owner, delegation depth limits, budgets and a per-agent audit trail.
You must self-host, or you want sessions and user data in your own database.
You want an MIT license and no vendor billing tied to your user counts, plus Go and Python SDKs next to TypeScript.
theAuth is an open source Clerk alternative for teams that want agent identity in the same library as human sign-in. It is not the right pick for every team, and the first column says so.
theAuth vs Clerk feature comparison
Feature comparison of Clerk and theAuth
Feature
Clerk
theAuth
Source license
No, Proprietary (per theAuth README)
Yes, MIT
Self-hostable
No, No, hosted service (per theAuth README)
Yes, Yes, on your own database
Prebuilt UI components
Yes, Component suite across React, Next.js, Vue, Astro and more
Partial or different, Client SDKs for React, Vue, Svelte, Expo and Electron
OAuth 2.1 authorization server for MCP
Yes, Yes, Clerk OAuth server with CIMD and DCR
Yes, Yes, built in
Agent identity with delegation and budgets
Partial or different, Not found in the Clerk docs we checked
Yes, Owner, delegation chains, budgets, audit
Organizations
Partial or different, Offered as a B2B add-on, priced separately
Yes, Organizations with RBAC in the library
Enterprise SSO
Yes, SSO connections; one included on paid plans, more priced per connection
Yes, SAML 2.0 and OIDC SSO, SCIM 2.0
Billing unit
Monthly retained users, so sign-ups who never return are not counted
Library has no per-user fee; Cloud in early access
Check mark: yes. Dash: partial, different, or not found in the docs we checked. Cross: no. Claims about Clerk are from its own public docs (see Sources); theAuth rows are from its repositories.
01
Clerk alternative for AI agents: identity and delegation
Users delegating to agents, or agents as identities.
Clerk
Clerk's MCP and OAuth support is built around users granting access to an MCP server you build, with helpers such as mcp-handler and @clerk/mcp-tools. In the Clerk docs we reviewed we did not find an agent identity model with delegation chains or per-agent budgets. If you need one, check Clerk's docs for your case.
theAuth
theAuth models an agent as an identity with an owner, a cryptographic bearer token (kv_...), wildcard permissions such as mcp:github:*, and delegation chains with configurable depth limits. On top of that sit budget policies per agent, trust scoring, CIBA-style approval for sensitive tool calls, and a full audit trail of every agent action. Read the agents guide and delegation docs.
02
MCP OAuth 2.1 support
Clerk can issue the tokens for an MCP server.
Clerk
Clerk documents building an MCP server in your app with Clerk acting as the OAuth server. It supports Client ID Metadata Documents (recommended for AI agents) and dynamic client registration, each toggled in the dashboard, and it requires PKCE with S256 for the DCR path it shows.
theAuth
theAuth ships an OAuth 2.1 authorization server for MCP: PKCE S256, RFC 9728 protected resource metadata, RFC 8707 resource indicators, RFC 8414 server metadata and RFC 7591 dynamic client registration. The Go module adds RFC 8693 token exchange, DPoP, PAR, JAR, CIBA, CIMD per the MCP spec of 2025-11-25 and refresh token rotation with family revocation. See the MCP guide.
03
Self-hosted Clerk alternative: data ownership
A hosted service against your own database.
Clerk
Clerk is a hosted service. We found no self-hosted option, and the theAuth README lists Clerk as not self-hostable. User records live with the vendor. If your data must stay in your own infrastructure, that rules it out.
theAuth
theAuth is MIT licensed and runs against your own database: SQLite, PostgreSQL, MySQL or Cloudflare D1 in TypeScript, and Postgres, MySQL or in-memory storage in Go. Users, sessions, tokens and audit records stay in storage you control. A hosted theAuth Cloud is in early access for teams that would rather not run it.
04
Licensing and cost model
Hosted billing against an MIT library.
Clerk
Clerk is proprietary and bills on monthly retained users, with separate pricing for the B2B organizations add-on and for SSO connections beyond the included one. Plans and limits change, so check the Clerk pricing page.
theAuth
The library is free under the MIT license. Your costs are the database, the compute and the engineering time to operate it. theAuth Cloud is in early access and has no published prices.
05
Edge runtimes
Where each one runs.
Clerk
Because Clerk is hosted, your app talks to it through a framework SDK or by verifying its tokens. Runtime support depends on the SDK for your framework, so confirm it in Clerk's docs for the platform you deploy on.
theAuth
The TypeScript core runs on Cloudflare Workers, Deno and Bun without code changes, with three runtime dependencies: drizzle-orm, jose and zod. Adapters cover Next.js, SvelteKit, Nuxt, Hono, Express, Fastify, Astro, NestJS, SolidStart and TanStack Start.
Migrating from Clerk to theAuth
theAuth has a Clerk migration guide with a concepts map, a hooks and middleware diff, a Clerk data export plan and a rollout plan. Prebuilt Clerk components do not carry over, so budget time for your sign-in screens.
It can be. theAuth is an open source library with agent identity, scoped permissions, delegation limits, budgets and audit, plus an MCP OAuth 2.1 authorization server. Clerk also documents an OAuth server for MCP, so pick based on whether you want a hosted service or a library, and whether agents need their own identity.
Can I self-host Clerk?
We found no self-hosted option for Clerk, and the theAuth README lists it as not self-hostable. theAuth is MIT licensed and runs on your own database.
Does Clerk support MCP?
Yes. Clerk documents using its OAuth server to protect an MCP server you build, with support for Client ID Metadata Documents and dynamic client registration. theAuth includes its own MCP OAuth 2.1 authorization server.
How is Clerk billed compared with theAuth?
Clerk bills on monthly retained users, with separate pricing for organizations and extra SSO connections, and the numbers change, so see its pricing page. The theAuth library is free under MIT, you pay for your own database and compute, and theAuth Cloud is in early access with no published prices.
How hard is it to migrate from Clerk to theAuth?
There is a step-by-step guide that maps Clerk concepts to theAuth, shows the hooks and middleware changes and covers exporting Clerk data. The main manual work is replacing prebuilt Clerk components with your own sign-in screens.
Sources
Last verified: 2026-10-07. Competitor facts come from the public pages below; plans and prices change, so confirm there.
Install the package, create an agent with scoped permissions, and read its first audit record. The core runs on Postgres, SQLite, MySQL or D1, and the Go module needs a single go get.