A self-hosted Firebase Auth alternative for AI agents
theAuthvsFirebase Auth
Firebase Authentication is Google's managed sign-in service for app backends. theAuth is an MIT library you run on your own database, with agent identity built in.
Last verified: 2026-10-07. Managed service against an MIT library.
You build mobile apps on iOS, Android, Flutter or Unity and want SDKs for those platforms.
You already use Firebase and want drop-in sign-in screens with FirebaseUI Auth.
You want Google to operate it, with an upgrade to Identity Platform for SAML and OIDC providers, multi-factor auth and multi-tenancy.
Choose theAuth if
You need to self-host or keep user data in your own database.
Your agents need identity, delegation limits, budgets and audit, and you want an MCP OAuth 2.1 authorization server.
You want MIT-licensed code in your repository with SSO and SCIM included.
theAuth is an open source Firebase Auth alternative for teams that want agent identity in the same library as human sign-in. It is not the right pick for every team, and the first column says so.
theAuth vs Firebase Auth feature comparison
Feature comparison of Firebase Auth and theAuth
Feature
Firebase Auth
theAuth
Self-hostable
No, No self-hosted option documented; Google-managed service
Yes, Yes, on your own database
Native mobile SDKs
Yes, iOS, Android, Web, Flutter, C++ and Unity, plus Admin SDKs
Partial or different, Expo and Electron clients; web and server SDKs for TypeScript, Go and Python
Drop-in sign-in UI
Yes, FirebaseUI Auth
Partial or different, Client SDKs for React, Vue, Svelte, Expo and Electron
SAML and OIDC providers
Partial or different, Through the Identity Platform upgrade
Yes, SAML 2.0 and OIDC SSO, SCIM 2.0
Multi-factor auth
Partial or different, SMS-based, through the Identity Platform upgrade
Yes, TOTP 2FA and passkeys
Multi-tenancy
Partial or different, Through the Identity Platform upgrade
Yes, Organizations with RBAC and tenant tagging
OAuth 2.1 authorization server for MCP
Partial or different, Not covered in the Firebase Authentication docs we checked
Yes, Yes, built in
Agent identity
Partial or different, Not covered in the Firebase Authentication docs we checked
Yes, Owner, delegation, budgets, audit
Billing unit
No cost up to a monthly active user threshold, then Google Cloud pricing; phone auth billed per SMS
Library has no per-user fee; Cloud in early access
Check mark: yes. Dash: partial, different, or not found in the docs we checked. Cross: no. Claims about Firebase Auth are from its own public docs (see Sources); theAuth rows are from its repositories.
01
Firebase Auth alternative for AI agents: identity and delegation
Sign-in for users, or identity for agents.
Firebase Auth
Firebase Authentication is described as a backend service for verifying user identity across platforms and sign-in methods. The overview we checked does not describe an agent identity model, delegation chains or per-agent budgets. If you have an agent requirement, confirm it with Google's documentation.
theAuth
theAuth models an agent as an identity with an owner, a cryptographic bearer token (kv_...), wildcard permissions such as mcp:github:*, and delegation chains with configurable depth limits. On top of that sit budget policies per agent, trust scoring, CIBA-style approval for sensitive tool calls, and a full audit trail of every agent action. Read the agents guide and delegation docs.
02
MCP OAuth 2.1 support
Not part of the Firebase Authentication overview.
Firebase Auth
We did not find MCP authorization server support in the Firebase Authentication documentation we reviewed, so we make no claim about it. Firebase can still issue identities for your own apps, and you could place an MCP authorization server in front. Verify against Google's docs for your design.
theAuth
theAuth ships an OAuth 2.1 authorization server for MCP: PKCE S256, RFC 9728 protected resource metadata, RFC 8707 resource indicators, RFC 8414 server metadata and RFC 7591 dynamic client registration. The Go module adds RFC 8693 token exchange, DPoP, PAR, JAR, CIBA, CIMD per the MCP spec of 2025-11-25 and refresh token rotation with family revocation. See the MCP guide.
03
Self-hosted Firebase Auth alternative: data ownership
Google-managed, or your database.
Firebase Auth
Firebase Authentication is a managed backend service and we found no self-hosted option. The optional upgrade to Identity Platform adds SAML and OIDC providers, multi-factor auth, blocking functions, audit logging, multi-tenancy and an enterprise SLA, still as a managed service.
theAuth
theAuth is MIT licensed and runs against your own database: SQLite, PostgreSQL, MySQL or Cloudflare D1 in TypeScript, and Postgres, MySQL or in-memory storage in Go. Users, sessions, tokens and audit records stay in storage you control. A hosted theAuth Cloud is in early access for teams that would rather not run it.
04
Licensing and cost model
Metered usage against an MIT library.
Firebase Auth
Firebase's pricing page lists no-cost authentication up to a monthly active user threshold, a much smaller free allowance for SAML and OIDC, and phone authentication billed per SMS sent. Thresholds and rates change, so see the Firebase pricing page.
theAuth
The library is free under the MIT license. Your costs are the database, the compute and the engineering time to operate it. theAuth Cloud is in early access and has no published prices.
05
Edge runtimes
Where each one runs.
Firebase Auth
Firebase Authentication offers Web, Node.js Admin and mobile SDKs. We did not verify its behavior on edge runtimes such as Workers or Deno, so check the SDK for your platform.
theAuth
The TypeScript core runs on Cloudflare Workers, Deno and Bun without code changes, with three runtime dependencies: drizzle-orm, jose and zod. Adapters cover Next.js, SvelteKit, Nuxt, Hono, Express, Fastify, Astro, NestJS, SolidStart and TanStack Start.
Migrating from Firebase Auth to theAuth
There is no Firebase-specific theAuth migration guide yet. Start from the migration hub. Plan the cutover so existing sessions keep working while you move users over.
Is theAuth a Firebase Auth alternative for AI agents?
It can be, especially if you want to self-host. theAuth is an MIT library that gives each AI agent its own identity, permissions, delegation limits and audit trail, and includes an MCP OAuth 2.1 authorization server. Firebase Authentication is a managed Google service with strong mobile SDK coverage.
Can I self-host Firebase Authentication?
We found no self-hosted option for Firebase Authentication. It is a managed backend service. theAuth is MIT licensed and runs on your own database.
What does Firebase Authentication do better than theAuth?
Native mobile coverage and drop-in UI. Firebase provides SDKs for iOS, Android, Web, Flutter, C++ and Unity, and FirebaseUI Auth handles sign-in screens.
Does Firebase Authentication cost anything?
Firebase lists no-cost authentication up to a monthly active user threshold, with phone authentication billed per SMS. Thresholds change, so check its pricing page. The theAuth library is free under MIT, and theAuth Cloud is in early access with no published prices.
Sources
Last verified: 2026-10-07. Competitor facts come from the public pages below; plans and prices change, so confirm there.
Install the package, create an agent with scoped permissions, and read its first audit record. The core runs on Postgres, SQLite, MySQL or D1, and the Go module needs a single go get.