A self-hosted Firebase Auth alternative for AI agents

theAuthvsFirebase Auth

Firebase Authentication is Google's managed sign-in service for app backends. theAuth is an MIT library you run on your own database, with agent identity built in.

Last verified: 2026-10-07. Managed service against an MIT library.

Short answer

Choose Firebase Auth if

  • You build mobile apps on iOS, Android, Flutter or Unity and want SDKs for those platforms.
  • You already use Firebase and want drop-in sign-in screens with FirebaseUI Auth.
  • You want Google to operate it, with an upgrade to Identity Platform for SAML and OIDC providers, multi-factor auth and multi-tenancy.

Choose theAuth if

  • You need to self-host or keep user data in your own database.
  • Your agents need identity, delegation limits, budgets and audit, and you want an MCP OAuth 2.1 authorization server.
  • You want MIT-licensed code in your repository with SSO and SCIM included.

theAuth is an open source Firebase Auth alternative for teams that want agent identity in the same library as human sign-in. It is not the right pick for every team, and the first column says so.

theAuth vs Firebase Auth feature comparison

Feature comparison of Firebase Auth and theAuth
FeatureFirebase AuththeAuth
Self-hostableNo, No self-hosted option documented; Google-managed serviceYes, Yes, on your own database
Native mobile SDKsYes, iOS, Android, Web, Flutter, C++ and Unity, plus Admin SDKsPartial or different, Expo and Electron clients; web and server SDKs for TypeScript, Go and Python
Drop-in sign-in UIYes, FirebaseUI AuthPartial or different, Client SDKs for React, Vue, Svelte, Expo and Electron
SAML and OIDC providersPartial or different, Through the Identity Platform upgradeYes, SAML 2.0 and OIDC SSO, SCIM 2.0
Multi-factor authPartial or different, SMS-based, through the Identity Platform upgradeYes, TOTP 2FA and passkeys
Multi-tenancyPartial or different, Through the Identity Platform upgradeYes, Organizations with RBAC and tenant tagging
OAuth 2.1 authorization server for MCPPartial or different, Not covered in the Firebase Authentication docs we checkedYes, Yes, built in
Agent identityPartial or different, Not covered in the Firebase Authentication docs we checkedYes, Owner, delegation, budgets, audit
Billing unitNo cost up to a monthly active user threshold, then Google Cloud pricing; phone auth billed per SMSLibrary has no per-user fee; Cloud in early access

Check mark: yes. Dash: partial, different, or not found in the docs we checked. Cross: no. Claims about Firebase Auth are from its own public docs (see Sources); theAuth rows are from its repositories.

01

Firebase Auth alternative for AI agents: identity and delegation

Sign-in for users, or identity for agents.

Firebase Auth

Firebase Authentication is described as a backend service for verifying user identity across platforms and sign-in methods. The overview we checked does not describe an agent identity model, delegation chains or per-agent budgets. If you have an agent requirement, confirm it with Google's documentation.

theAuth

theAuth models an agent as an identity with an owner, a cryptographic bearer token (kv_...), wildcard permissions such as mcp:github:*, and delegation chains with configurable depth limits. On top of that sit budget policies per agent, trust scoring, CIBA-style approval for sensitive tool calls, and a full audit trail of every agent action. Read the agents guide and delegation docs.

02

MCP OAuth 2.1 support

Not part of the Firebase Authentication overview.

Firebase Auth

We did not find MCP authorization server support in the Firebase Authentication documentation we reviewed, so we make no claim about it. Firebase can still issue identities for your own apps, and you could place an MCP authorization server in front. Verify against Google's docs for your design.

theAuth

theAuth ships an OAuth 2.1 authorization server for MCP: PKCE S256, RFC 9728 protected resource metadata, RFC 8707 resource indicators, RFC 8414 server metadata and RFC 7591 dynamic client registration. The Go module adds RFC 8693 token exchange, DPoP, PAR, JAR, CIBA, CIMD per the MCP spec of 2025-11-25 and refresh token rotation with family revocation. See the MCP guide.

03

Self-hosted Firebase Auth alternative: data ownership

Google-managed, or your database.

Firebase Auth

Firebase Authentication is a managed backend service and we found no self-hosted option. The optional upgrade to Identity Platform adds SAML and OIDC providers, multi-factor auth, blocking functions, audit logging, multi-tenancy and an enterprise SLA, still as a managed service.

theAuth

theAuth is MIT licensed and runs against your own database: SQLite, PostgreSQL, MySQL or Cloudflare D1 in TypeScript, and Postgres, MySQL or in-memory storage in Go. Users, sessions, tokens and audit records stay in storage you control. A hosted theAuth Cloud is in early access for teams that would rather not run it.

04

Licensing and cost model

Metered usage against an MIT library.

Firebase Auth

Firebase's pricing page lists no-cost authentication up to a monthly active user threshold, a much smaller free allowance for SAML and OIDC, and phone authentication billed per SMS sent. Thresholds and rates change, so see the Firebase pricing page.

theAuth

The library is free under the MIT license. Your costs are the database, the compute and the engineering time to operate it. theAuth Cloud is in early access and has no published prices.

05

Edge runtimes

Where each one runs.

Firebase Auth

Firebase Authentication offers Web, Node.js Admin and mobile SDKs. We did not verify its behavior on edge runtimes such as Workers or Deno, so check the SDK for your platform.

theAuth

The TypeScript core runs on Cloudflare Workers, Deno and Bun without code changes, with three runtime dependencies: drizzle-orm, jose and zod. Adapters cover Next.js, SvelteKit, Nuxt, Hono, Express, Fastify, Astro, NestJS, SolidStart and TanStack Start.

Migrating from Firebase Auth to theAuth

There is no Firebase-specific theAuth migration guide yet. Start from the migration hub. Plan the cutover so existing sessions keep working while you move users over.

Firebase Auth alternative: common questions

Is theAuth a Firebase Auth alternative for AI agents?

It can be, especially if you want to self-host. theAuth is an MIT library that gives each AI agent its own identity, permissions, delegation limits and audit trail, and includes an MCP OAuth 2.1 authorization server. Firebase Authentication is a managed Google service with strong mobile SDK coverage.

Can I self-host Firebase Authentication?

We found no self-hosted option for Firebase Authentication. It is a managed backend service. theAuth is MIT licensed and runs on your own database.

What does Firebase Authentication do better than theAuth?

Native mobile coverage and drop-in UI. Firebase provides SDKs for iOS, Android, Web, Flutter, C++ and Unity, and FirebaseUI Auth handles sign-in screens.

Does Firebase Authentication cost anything?

Firebase lists no-cost authentication up to a monthly active user threshold, with phone authentication billed per SMS. Thresholds change, so check its pricing page. The theAuth library is free under MIT, and theAuth Cloud is in early access with no published prices.

Sources

Last verified: 2026-10-07. Competitor facts come from the public pages below; plans and prices change, so confirm there.

Keep reading

Get started

Give your first agent an identity.

Install the package, create an agent with scoped permissions, and read its first audit record. The core runs on Postgres, SQLite, MySQL or D1, and the Go module needs a single go get.

  • npm install @glinr/theauth
  • go get github.com/glincker/theauth-go
Or skip hosting with theAuth Cloud