An open source Supabase Auth alternative for AI agents
theAuthvsSupabase Auth
Supabase Auth is the identity piece of a Postgres backend platform. theAuth is a standalone auth library whose agents are identities of their own, not stand-ins for existing users.
Last verified: 2026-10-07. Backend platform against an MIT library.
You already run on Supabase Postgres and want authorization through Row Level Security policies.
You want one platform for database, auth and APIs, hosted or self-hosted with Docker Compose.
Letting an AI agent act as one of your existing users, with RLS applied, is exactly the model you want.
Choose theAuth if
Auth should be separate from your database choice: SQLite, PostgreSQL, MySQL or Cloudflare D1.
Agents need their own identity, delegation limits, budgets and audit rather than acting as a user.
You deploy to Workers, Deno or Bun, or need Go and Python SDKs.
theAuth is an open source Supabase Auth alternative for teams that want agent identity in the same library as human sign-in. It is not the right pick for every team, and the first column says so.
theAuth vs Supabase Auth feature comparison
Feature comparison of Supabase Auth and theAuth
Feature
Supabase Auth
theAuth
Source license
Yes, MIT (the supabase/auth server)
Yes, MIT
Self-hostable
Yes, Yes, self-host Supabase with Docker Compose
Yes, Yes, on your own database
Scope
Auth is one part of a platform with database and APIs
Auth only; you bring the database
Database-level authorization
Yes, Row Level Security integration
Partial or different, Own policy engine (RBAC, ReBAC), not tied to Postgres RLS
OAuth 2.1 authorization server for MCP
Yes, Yes, OAuth 2.1 with PKCE; MCP clients can register
Yes, Yes, built in
Agent identity
Partial or different, Agents authenticate as your existing users
Yes, Own identity: owner, delegation, budgets, audit
Enterprise SSO
Yes, SAML 2.0, on paid plans
Yes, SAML 2.0 and OIDC SSO, SCIM 2.0
Multi-factor auth
Yes, TOTP and phone
Yes, TOTP 2FA and passkeys
Billing unit
Monthly active users, with separate SSO and third-party MAU and an advanced MFA add-on
Library has no per-user fee; Cloud in early access
Check mark: yes. Dash: partial, different, or not found in the docs we checked. Cross: no. Claims about Supabase Auth are from its own public docs (see Sources); theAuth rows are from its repositories.
01
Supabase Auth alternative for AI agents: identity and delegation
Agents as existing users, or as identities.
Supabase Auth
In Supabase's MCP guide, "AI agents authenticate as your existing users": the user approves access, Supabase issues access and refresh tokens, and the MCP server calls your API with Row Level Security applied. That is a clean fit if you want agents to inherit exactly a user's database rights, and it means an agent has no identity of its own.
theAuth
theAuth models an agent as an identity with an owner, a cryptographic bearer token (kv_...), wildcard permissions such as mcp:github:*, and delegation chains with configurable depth limits. On top of that sit budget policies per agent, trust scoring, CIBA-style approval for sensitive tool calls, and a full audit trail of every agent action. Read the agents guide and delegation docs.
02
MCP OAuth 2.1 support
Supabase includes an OAuth 2.1 server.
Supabase Auth
Supabase documents OAuth 2.1 with PKCE for MCP clients: clients discover configuration from discovery endpoints and can register themselves, the user approves, and tokens rotate automatically.
theAuth
theAuth ships an OAuth 2.1 authorization server for MCP: PKCE S256, RFC 9728 protected resource metadata, RFC 8707 resource indicators, RFC 8414 server metadata and RFC 7591 dynamic client registration. The Go module adds RFC 8693 token exchange, DPoP, PAR, JAR, CIBA, CIMD per the MCP spec of 2025-11-25 and refresh token rotation with family revocation. See the MCP guide.
03
Self-hosting and data ownership
Both can run on your own infrastructure.
Supabase Auth
Supabase can be self-hosted: its docs describe running your own Supabase on your computer, server or cloud, with Docker Compose recommended. The auth server is MIT licensed Go code. Self-hosting brings the whole platform with it, not only auth.
theAuth
theAuth is MIT licensed and runs against your own database: SQLite, PostgreSQL, MySQL or Cloudflare D1 in TypeScript, and Postgres, MySQL or in-memory storage in Go. Users, sessions, tokens and audit records stay in storage you control. A hosted theAuth Cloud is in early access for teams that would rather not run it.
04
Licensing and cost model
MAU billing against an MIT library.
Supabase Auth
The Supabase Auth server is MIT, and hosted Supabase bills Auth by monthly active users with separate lines for third-party MAU, SSO MAU and advanced MFA. Included amounts and rates change, so check the Supabase pricing page.
theAuth
The library is free under the MIT license. Your costs are the database, the compute and the engineering time to operate it. theAuth Cloud is in early access and has no published prices.
05
Edge runtimes
Where each one runs.
Supabase Auth
Supabase Auth is a server your app calls over HTTP, with client libraries for the browser and server rendering frameworks. Runtime support depends on the client library you use, so check it for your platform.
theAuth
The TypeScript core runs on Cloudflare Workers, Deno and Bun without code changes, with three runtime dependencies: drizzle-orm, jose and zod. Adapters cover Next.js, SvelteKit, Nuxt, Hono, Express, Fastify, Astro, NestJS, SolidStart and TanStack Start.
Migrating from Supabase Auth to theAuth
There is no Supabase-specific theAuth migration guide yet. The migration hub covers the general approach, and the guides for Auth0, Clerk and Better Auth show how users, sessions and OAuth accounts map across. Plan on rebuilding any authorization you do through Row Level Security in another policy layer.
Is theAuth a Supabase Auth alternative for AI agents?
It can be. theAuth is an open source auth library, independent of any database platform, where each AI agent has its own identity, permissions, delegation limits and audit trail. Supabase Auth is the better fit when you already use Supabase Postgres and Row Level Security.
Can I self-host Supabase Auth?
Yes. Supabase documents self-hosting the platform with Docker Compose, and the auth server is MIT licensed. theAuth is also MIT and self-hostable, on SQLite, PostgreSQL, MySQL or Cloudflare D1.
Does Supabase Auth support MCP OAuth 2.1?
Yes. Supabase documents an OAuth 2.1 implementation with PKCE for MCP clients, where agents authenticate as your existing users. theAuth ships its own MCP OAuth 2.1 authorization server.
When should I stay on Supabase Auth?
Stay if your app is built around Supabase Postgres and you rely on Row Level Security policies for authorization. Moving auth out means rebuilding those rules in another policy layer.
Sources
Last verified: 2026-10-07. Competitor facts come from the public pages below; plans and prices change, so confirm there.
Install the package, create an agent with scoped permissions, and read its first audit record. The core runs on Postgres, SQLite, MySQL or D1, and the Go module needs a single go get.