An open source Supabase Auth alternative for AI agents

theAuthvsSupabase Auth

Supabase Auth is the identity piece of a Postgres backend platform. theAuth is a standalone auth library whose agents are identities of their own, not stand-ins for existing users.

Last verified: 2026-10-07. Backend platform against an MIT library.

Short answer

Choose Supabase Auth if

  • You already run on Supabase Postgres and want authorization through Row Level Security policies.
  • You want one platform for database, auth and APIs, hosted or self-hosted with Docker Compose.
  • Letting an AI agent act as one of your existing users, with RLS applied, is exactly the model you want.

Choose theAuth if

  • Auth should be separate from your database choice: SQLite, PostgreSQL, MySQL or Cloudflare D1.
  • Agents need their own identity, delegation limits, budgets and audit rather than acting as a user.
  • You deploy to Workers, Deno or Bun, or need Go and Python SDKs.

theAuth is an open source Supabase Auth alternative for teams that want agent identity in the same library as human sign-in. It is not the right pick for every team, and the first column says so.

theAuth vs Supabase Auth feature comparison

Feature comparison of Supabase Auth and theAuth
FeatureSupabase AuththeAuth
Source licenseYes, MIT (the supabase/auth server)Yes, MIT
Self-hostableYes, Yes, self-host Supabase with Docker ComposeYes, Yes, on your own database
ScopeAuth is one part of a platform with database and APIsAuth only; you bring the database
Database-level authorizationYes, Row Level Security integrationPartial or different, Own policy engine (RBAC, ReBAC), not tied to Postgres RLS
OAuth 2.1 authorization server for MCPYes, Yes, OAuth 2.1 with PKCE; MCP clients can registerYes, Yes, built in
Agent identityPartial or different, Agents authenticate as your existing usersYes, Own identity: owner, delegation, budgets, audit
Enterprise SSOYes, SAML 2.0, on paid plansYes, SAML 2.0 and OIDC SSO, SCIM 2.0
Multi-factor authYes, TOTP and phoneYes, TOTP 2FA and passkeys
Billing unitMonthly active users, with separate SSO and third-party MAU and an advanced MFA add-onLibrary has no per-user fee; Cloud in early access

Check mark: yes. Dash: partial, different, or not found in the docs we checked. Cross: no. Claims about Supabase Auth are from its own public docs (see Sources); theAuth rows are from its repositories.

01

Supabase Auth alternative for AI agents: identity and delegation

Agents as existing users, or as identities.

Supabase Auth

In Supabase's MCP guide, "AI agents authenticate as your existing users": the user approves access, Supabase issues access and refresh tokens, and the MCP server calls your API with Row Level Security applied. That is a clean fit if you want agents to inherit exactly a user's database rights, and it means an agent has no identity of its own.

theAuth

theAuth models an agent as an identity with an owner, a cryptographic bearer token (kv_...), wildcard permissions such as mcp:github:*, and delegation chains with configurable depth limits. On top of that sit budget policies per agent, trust scoring, CIBA-style approval for sensitive tool calls, and a full audit trail of every agent action. Read the agents guide and delegation docs.

02

MCP OAuth 2.1 support

Supabase includes an OAuth 2.1 server.

Supabase Auth

Supabase documents OAuth 2.1 with PKCE for MCP clients: clients discover configuration from discovery endpoints and can register themselves, the user approves, and tokens rotate automatically.

theAuth

theAuth ships an OAuth 2.1 authorization server for MCP: PKCE S256, RFC 9728 protected resource metadata, RFC 8707 resource indicators, RFC 8414 server metadata and RFC 7591 dynamic client registration. The Go module adds RFC 8693 token exchange, DPoP, PAR, JAR, CIBA, CIMD per the MCP spec of 2025-11-25 and refresh token rotation with family revocation. See the MCP guide.

03

Self-hosting and data ownership

Both can run on your own infrastructure.

Supabase Auth

Supabase can be self-hosted: its docs describe running your own Supabase on your computer, server or cloud, with Docker Compose recommended. The auth server is MIT licensed Go code. Self-hosting brings the whole platform with it, not only auth.

theAuth

theAuth is MIT licensed and runs against your own database: SQLite, PostgreSQL, MySQL or Cloudflare D1 in TypeScript, and Postgres, MySQL or in-memory storage in Go. Users, sessions, tokens and audit records stay in storage you control. A hosted theAuth Cloud is in early access for teams that would rather not run it.

04

Licensing and cost model

MAU billing against an MIT library.

Supabase Auth

The Supabase Auth server is MIT, and hosted Supabase bills Auth by monthly active users with separate lines for third-party MAU, SSO MAU and advanced MFA. Included amounts and rates change, so check the Supabase pricing page.

theAuth

The library is free under the MIT license. Your costs are the database, the compute and the engineering time to operate it. theAuth Cloud is in early access and has no published prices.

05

Edge runtimes

Where each one runs.

Supabase Auth

Supabase Auth is a server your app calls over HTTP, with client libraries for the browser and server rendering frameworks. Runtime support depends on the client library you use, so check it for your platform.

theAuth

The TypeScript core runs on Cloudflare Workers, Deno and Bun without code changes, with three runtime dependencies: drizzle-orm, jose and zod. Adapters cover Next.js, SvelteKit, Nuxt, Hono, Express, Fastify, Astro, NestJS, SolidStart and TanStack Start.

Migrating from Supabase Auth to theAuth

There is no Supabase-specific theAuth migration guide yet. The migration hub covers the general approach, and the guides for Auth0, Clerk and Better Auth show how users, sessions and OAuth accounts map across. Plan on rebuilding any authorization you do through Row Level Security in another policy layer.

Supabase Auth alternative: common questions

Is theAuth a Supabase Auth alternative for AI agents?

It can be. theAuth is an open source auth library, independent of any database platform, where each AI agent has its own identity, permissions, delegation limits and audit trail. Supabase Auth is the better fit when you already use Supabase Postgres and Row Level Security.

Can I self-host Supabase Auth?

Yes. Supabase documents self-hosting the platform with Docker Compose, and the auth server is MIT licensed. theAuth is also MIT and self-hostable, on SQLite, PostgreSQL, MySQL or Cloudflare D1.

Does Supabase Auth support MCP OAuth 2.1?

Yes. Supabase documents an OAuth 2.1 implementation with PKCE for MCP clients, where agents authenticate as your existing users. theAuth ships its own MCP OAuth 2.1 authorization server.

When should I stay on Supabase Auth?

Stay if your app is built around Supabase Postgres and you rely on Row Level Security policies for authorization. Moving auth out means rebuilding those rules in another policy layer.

Sources

Last verified: 2026-10-07. Competitor facts come from the public pages below; plans and prices change, so confirm there.

Keep reading

Get started

Give your first agent an identity.

Install the package, create an agent with scoped permissions, and read its first audit record. The core runs on Postgres, SQLite, MySQL or D1, and the Go module needs a single go get.

  • npm install @glinr/theauth
  • go get github.com/glincker/theauth-go
Or skip hosting with theAuth Cloud