Skip to content

Arena

Auth & Identity arenaAuth & Identity

Customer identity and auth platforms for sign-up, sign-in, sessions, and multi-tenant access control, judged on OAuth/OIDC depth, session security, MFA and SSO coverage, organizations and RBAC, migration paths, deployment control, and — critically for the agent era — whether AI agents can authenticate safely with scoped machine identities of their own.

56 user stories · 280 judged cells · updated 2026-09-16 · Evidence as of 2026-09-16

Buyer checklist →Procurement report →

Leaderboard — every product ranked by evidenceLeaderboard

Rank by

Best by user type — persona-weighted winnersBest by user type

Per persona, the product with the highest persona-weighted coverage over just that persona's stories — not the same ranking as the overall PA Score leaderboard above.

Best for developer

Keycloak logo

Keycloak

53/100

Runner-up: Better Auth logo Better Auth (47/100)

11 developer stories scored

Best for security-engineer

Keycloak logo

Keycloak

48/100

Runner-up: Auth0 logo Auth0 (46/100)

9 security-engineer stories scored

Best for founder

Auth0 logo

Auth0

70/100

Runner-up: WorkOS logo WorkOS (36/100)

1 founder story scored

Best for ai-native

Auth0 logo

Auth0

42/100

Runner-up: Better Auth logo Better Auth (37/100)

35 ai-native stories scored

Story matrix — every product × every judged storyStory matrix

56/56 stories shown · legend

Agent auth — stories about agent auth in this arenaAgent auth

Delegation

StoryPersona
Auth0 logoAuth0
Clerk logoClerk
WorkOS logoWorkOS
Keycloak logoKeycloak
Better Auth logoBetter Auth
Agent auth — stories about agent auth in this arenaRequire asynchronous human approval (e.g. CIBA-style confirmation) before an autonomous agent completes a sensitive transactionai-native
fullC
8/10
partialC
3/10
none
0/10
none
0/10
none
0/10
Agent auth — stories about agent auth in this arenaHave an agent obtain short-lived, user-consented tokens for third-party APIs (token vault/exchange) so tool calls run under the user's delegated authorityai-native
fullC
8/10
partialC
6/10
partialC
4/10
partialC
4/10
partialC
4/10

Device flow

StoryPersona
Auth0 logoAuth0
Clerk logoClerk
WorkOS logoWorkOS
Keycloak logoKeycloak
Better Auth logoBetter Auth
Agent auth — stories about agent auth in this arenaAuthenticate CLIs and headless agents via the OAuth device authorization flow instead of pasting long-lived secretsai-native
fullT
8/10
partialC
6/10
fullC
9/10
fullC
9/10
fullC
8/10

Machine identity

StoryPersona
Auth0 logoAuth0
Clerk logoClerk
WorkOS logoWorkOS
Keycloak logoKeycloak
Better Auth logoBetter Auth
Agent auth — stories about agent auth in this arenaIssue machine-to-machine credentials (client-credentials flow) so backend services and agents authenticate without a human in the loopai-native
fullC
9/10
fullC
7/10
fullC
8/10
fullC
9/10
partialC
5/10
Agent auth — stories about agent auth in this arenaGive each agent its own least-privilege machine identity with narrowly scoped permissions and instant revocation, instead of sharing a human's credentialsai-native
fullC
7/10
partialC
7/10
partialC
5/10
partialC
6/10
partialC
6/10

Mcp

StoryPersona
Auth0 logoAuth0
Clerk logoClerk
WorkOS logoWorkOS
Keycloak logoKeycloak
Better Auth logoBetter Auth
Agent auth — stories about agent auth in this arenaPut a spec-compliant OAuth authorization flow in front of my MCP server so remote agents connect with scoped, verifiable tokensai-native
partialC
5/10
partialC
6/10
fullT
8/10
partialC
6/10
fullT
8/10

Agenticness — how well agents can access and operate the productAgenticness

Agent access

StoryPersona
Auth0 logoAuth0
Clerk logoClerk
WorkOS logoWorkOS
Keycloak logoKeycloak
Better Auth logoBetter Auth
Agenticness — how well agents can access and operate the productPoint an agent at llms.txt or agent-oriented docsai-native
fullT
9/10
fullT
9/10
fullT
9/10
none
0/10
fullT
9/10
Agenticness — how well agents can access and operate the productRun the product headlessly / in CI for automationai-native
partialT
6/10
partialT
5/10
partialT
5/10
disputedD
4/10
partialT
5/10
Agenticness — how well agents can access and operate the productPlug MCP servers into this product so it can use their toolsai-native
partialC
5/10
none
0/10
n/a
n/a
n/a
Agenticness — how well agents can access and operate the productConnect an agent via an official MCP serverai-native
fullT
9/10
fullT
9/10
fullT
8/10
none
0/10
fullT
8/10
Agenticness — how well agents can access and operate the productUse an official CLIai-native
fullT
7/10
fullT
8/10
partialC
3/10
fullC
7/10
fullT
8/10
Agenticness — how well agents can access and operate the productDrive the product through a documented public APIai-native
fullT
8/10
fullT
8/10
fullT
9/10
fullX
8/10
fullT
8/10
Agenticness — how well agents can access and operate the productIssue scoped/least-privilege API credentials for an agentai-native
fullC
8/10
fullC
8/10
partialC
6/10
partialC
7/10
partialT
6/10
Agenticness — how well agents can access and operate the productBuild against official SDKsai-native
partialC
6/10
fullT
8/10
fullC
7/10
none
0/10
partialT
6/10
Agenticness — how well agents can access and operate the productSubscribe to events via webhooksai-native
partialC
5/10
fullC
8/10
partialC
5/10
none
0/10
none
0/10

Agentic features

StoryPersona
Auth0 logoAuth0
Clerk logoClerk
WorkOS logoWorkOS
Keycloak logoKeycloak
Better Auth logoBetter Auth
Agenticness — how well agents can access and operate the productGet AI-generated insights and suggestions from my data inside the productai-native
none
0/10
n/a
none
0/10
n/a
n/a
Agenticness — how well agents can access and operate the productSet up automations that run autonomously in the backgroundai-native
partialC
4/10
none
0/10
none
0/10
n/a
n/a
Agenticness — how well agents can access and operate the productDelegate tasks to a built-in AI assistant inside the productai-native
none
0/10
none
0/10
none
0/10
none
0/10
none
0/10
Agenticness — how well agents can access and operate the productOperate the product with natural-language commandsai-native
fullT
8/10
partialT
5/10
partialT
6/10
n/a
partialT
4/10

Api quality

StoryPersona
Auth0 logoAuth0
Clerk logoClerk
WorkOS logoWorkOS
Keycloak logoKeycloak
Better Auth logoBetter Auth
Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examplesai-native
none
0/10
none
0/10
none
0/10
none
0/10
none
0/10
Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent)ai-native
none
0/10
fullT
9/10
none
0/10
partialT
4/10
none
0/10
Agenticness — how well agents can access and operate the productTest against a sandbox environment without touching production dataai-native
none
0/10
none
0/10
none
0/10
disputedD
4/10
none
0/10
Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policyai-native
none
0/10
none
0/10
none
0/10
none
0/10
none
0/10

Automation depth — how much of the product can run unattendedAutomation depth

StoryPersona
Auth0 logoAuth0
Clerk logoClerk
WorkOS logoWorkOS
Keycloak logoKeycloak
Better Auth logoBetter Auth
Automation depth — how much of the product can run unattendedPerform bulk operations across many items at onceai-native
partialC
4/10
partialC
4/10
partialC
3/10
partialX
5/10
none
0/10
Automation depth — how much of the product can run unattendedDefine rules that trigger actions automatically on eventsai-native
fullC
7/10
partialC
4/10
none
0/10
partialC
3/10
none
0/10
Automation depth — how much of the product can run unattendedSchedule recurring jobs or workflowsai-native
n/a
n/a
n/a
n/a
n/a
Automation depth — how much of the product can run unattendedVersion, review, and roll back my automationsai-native
partialC
4/10
n/a
n/a
n/a
n/a

Deployment control — stories about deployment control in this arenaDeployment control

Deployment

StoryPersona
Auth0 logoAuth0
Clerk logoClerk
WorkOS logoWorkOS
Keycloak logoKeycloak
Better Auth logoBetter Auth
Deployment control — stories about deployment control in this arenaControl where the auth system and its user data run — self-managed deployment, private instance, or my own databasesecurity-engineer
partialC
4/10
none
0/10
none
0/10
fullX
9/10
fullX
9/10

Enterprise sso — stories about enterprise sso in this arenaEnterprise sso

Sso

StoryPersona
Auth0 logoAuth0
Clerk logoClerk
WorkOS logoWorkOS
Keycloak logoKeycloak
Better Auth logoBetter Auth
Enterprise sso — stories about enterprise sso in this arenaConnect enterprise identity providers over SAML and OIDC (Okta, Entra, Google Workspace) for workforce sign-insecurity-engineer
fullC
7/10
fullC
8/10
fullX
9/10
fullX
7/10
fullC
6/10
Enterprise sso — stories about enterprise sso in this arenaSync users and groups from customer directories via SCIM so deprovisioning in the IdP revokes app accesssecurity-engineer
partialC
3/10
none
0/10
fullX
9/10
partialC
6/10
none
0/10

Events webhooks — stories about events webhooks in this arenaEvents webhooks

Audit

StoryPersona
Auth0 logoAuth0
Clerk logoClerk
WorkOS logoWorkOS
Keycloak logoKeycloak
Better Auth logoBetter Auth
Events webhooks — stories about events webhooks in this arenaCapture tamper-evident audit logs of authentication and admin activity and stream or export them to my SIEMsecurity-engineer
partialC
6/10
disputedD
3/10
partialC
6/10
none
0/10
none
0/10

Webhooks

StoryPersona
Auth0 logoAuth0
Clerk logoClerk
WorkOS logoWorkOS
Keycloak logoKeycloak
Better Auth logoBetter Auth
Events webhooks — stories about events webhooks in this arenaSubscribe to webhooks or event streams for auth events (sign-ups, sign-ins, user changes) to keep my systems in syncdeveloper
partialC
5/10
fullC
7/10
partialC
5/10
none
0/10
none
0/10

Framework integration — stories about framework integration in this arenaFramework integration

Frameworks

StoryPersona
Auth0 logoAuth0
Clerk logoClerk
WorkOS logoWorkOS
Keycloak logoKeycloak
Better Auth logoBetter Auth
Framework integration — stories about framework integration in this arenaProtect routes with first-party framework SDKs and middleware (Next.js and peers) that verify sessions at the edgedeveloper
none
0/10
partialX
6/10
none
0/10
none
0/10
partialT
5/10
Framework integration — stories about framework integration in this arenaShip production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pagesdeveloper
fullX
7/10
fullC
8/10
fullX
7/10
fullC
7/10
none
0/10

Mfa passwordless — stories about mfa passwordless in this arenaMfa passwordless

Hardening

StoryPersona
Auth0 logoAuth0
Clerk logoClerk
WorkOS logoWorkOS
Keycloak logoKeycloak
Better Auth logoBetter Auth
Mfa passwordless — stories about mfa passwordless in this arenaRely on built-in protection against bots, credential stuffing, and brute-force attacks on the auth flowssecurity-engineer
fullC
7/10
fullC
8/10
partialC
6/10
fullX
8/10
partialC
6/10

Mfa

StoryPersona
Auth0 logoAuth0
Clerk logoClerk
WorkOS logoWorkOS
Keycloak logoKeycloak
Better Auth logoBetter Auth
Mfa passwordless — stories about mfa passwordless in this arenaRequire multi-factor authentication with TOTP authenticator apps and backup codes, with step-up enforcement where neededsecurity-engineer
fullC
7/10
fullC
8/10
partialC
4/10
partialC
4/10
partialC
7/10

Passwordless

StoryPersona
Auth0 logoAuth0
Clerk logoClerk
WorkOS logoWorkOS
Keycloak logoKeycloak
Better Auth logoBetter Auth
Mfa passwordless — stories about mfa passwordless in this arenaOffer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methodsdeveloper
fullC
8/10
partialC
6/10
fullC
8/10
partialC
6/10
fullX
8/10

Oauth oidc — stories about oauth oidc in this arenaOauth oidc

Flows

StoryPersona
Auth0 logoAuth0
Clerk logoClerk
WorkOS logoWorkOS
Keycloak logoKeycloak
Better Auth logoBetter Auth
Oauth oidc — stories about oauth oidc in this arenaImplement standard OAuth 2.0 / OIDC flows (authorization code with PKCE, refresh tokens) without hand-rolling protocol detailsdeveloper
fullX
7/10
partialC
6/10
partialC
6/10
fullX
9/10
fullC
7/10
Oauth oidc — stories about oauth oidc in this arenaOffer sign-in with a broad set of social and OAuth identity providers through configuration, not custom codedeveloper
fullC
7/10
partialC
6/10
fullX
8/10
fullX
8/10
fullX
8/10

Provider

StoryPersona
Auth0 logoAuth0
Clerk logoClerk
WorkOS logoWorkOS
Keycloak logoKeycloak
Better Auth logoBetter Auth
Oauth oidc — stories about oauth oidc in this arenaTurn my own application into an OAuth provider that issues tokens to third-party clients ("Sign in with my app")developer
partialC
5/10
partialC
5/10
fullC
8/10
fullC
8/10
fullT
7/10

Openness — open source, data portability, and self-hosting storiesOpenness

StoryPersona
Auth0 logoAuth0
Clerk logoClerk
WorkOS logoWorkOS
Keycloak logoKeycloak
Better Auth logoBetter Auth
Openness — open source, data portability, and self-hosting storiesDo everything through the API that I can do in the UIai-native
partialT
7/10
partialT
6/10
fullT
8/10
partialT
7/10
fullT
7/10
Openness — open source, data portability, and self-hosting storiesExport all of my data in open formats and leaveai-native
partialX
5/10
none
0/10
none
0/10
partialC
5/10
partialX
6/10
Openness — open source, data portability, and self-hosting storiesRead the product's source under an open licenseai-native
none
0/10
partialC
4/10
none
0/10
none
0/10
fullX
7/10
Openness — open source, data portability, and self-hosting storiesSelf-host the core productai-native
none
0/10
none
0/10
none
0/10
fullX
9/10
fullX
8/10

Orgs multitenant — stories about orgs multitenant in this arenaOrgs multitenant

Orgs

StoryPersona
Auth0 logoAuth0
Clerk logoClerk
WorkOS logoWorkOS
Keycloak logoKeycloak
Better Auth logoBetter Auth
Orgs multitenant — stories about orgs multitenant in this arenaGive each customer organization its own SSO connection with verified domains and just-in-time provisioningsecurity-engineer
partialC
6/10
partialC
5/10
partialC
5/10
partialC
4/10
partialC
5/10
Orgs multitenant — stories about orgs multitenant in this arenaModel multi-tenant B2B apps with organizations, memberships, and invitation flows out of the boxdeveloper
partialC
6/10
fullX
8/10
partialC
6/10
partialC
6/10
partialX
6/10

Privacy posture — data-handling and privacy storiesPrivacy posture

StoryPersona
Auth0 logoAuth0
Clerk logoClerk
WorkOS logoWorkOS
Keycloak logoKeycloak
Better Auth logoBetter Auth
Privacy posture — data-handling and privacy storiesChoose where my data is stored (region/residency)ai-native
partialC
4/10
none
0/10
none
0/10
partialC
4/10
partialX
5/10
Privacy posture — data-handling and privacy storiesPrevent my data from being used to train AI modelsai-native
n/a
none
0/10
n/a
n/a
n/a
Privacy posture — data-handling and privacy storiesControl data retention and deletionai-native
none
0/10
none
0/10
none
0/10
partialC
3/10
partialX
4/10
Privacy posture — data-handling and privacy storiesOpt out of telemetry and usage trackingai-native
none
0/10
none
0/10
n/a
none
0/10
none
0/10

Rbac permissions — stories about rbac permissions in this arenaRbac permissions

Rbac

StoryPersona
Auth0 logoAuth0
Clerk logoClerk
WorkOS logoWorkOS
Keycloak logoKeycloak
Better Auth logoBetter Auth
Rbac permissions — stories about rbac permissions in this arenaExpress fine-grained, resource-level authorization (relationship- or policy-based) beyond simple rolessecurity-engineer
fullC
7/10
partialX
3/10
partialC
5/10
fullC
9/10
partialC
4/10
Rbac permissions — stories about rbac permissions in this arenaDefine roles and permissions and have them enforced and surfaced in session tokens for authorization checksdeveloper
fullC
8/10
partialX
7/10
fullC
8/10
fullC
8/10
partialC
6/10

Session management — stories about session management in this arenaSession management

Sessions

StoryPersona
Auth0 logoAuth0
Clerk logoClerk
WorkOS logoWorkOS
Keycloak logoKeycloak
Better Auth logoBetter Auth
Session management — stories about session management in this arenaLet users and admins see active sessions and devices and revoke them individually or all at oncesecurity-engineer
none
0/10
partialC
6/10
none
0/10
fullC
7/10
partialC
5/10
Session management — stories about session management in this arenaManage session lifecycle — expiry, refresh, and immediate server-side revocation of a compromised sessiondeveloper
none
0/10
disputedD
5/10
none
0/10
fullC
7/10
fullC
8/10

User migration — stories about user migration in this arenaUser migration

Migration

StoryPersona
Auth0 logoAuth0
Clerk logoClerk
WorkOS logoWorkOS
Keycloak logoKeycloak
Better Auth logoBetter Auth
User migration — stories about user migration in this arenaBulk-import existing users — including password hashes — and export them again, so I am never locked indeveloper
partialX
6/10
partialC
4/10
partialX
5/10
partialC
5/10
partialX
5/10
User migration — stories about user migration in this arenaFollow vendor-maintained migration guides or tooling for moving off a competing auth provider without forcing password resetsfounder
fullC
7/10
partialC
5/10
partialC
6/10
partialC
4/10
partialC
6/10
Verdict✓ fullclear evidence~ partialwith caveats! disputedevidence conflicts— noneno evidence foundn/aquestion doesn't apply to this kind of product
ProofT probedtested by usX communityusers back itC claimedvendor claim onlyD contradictedevidence disagrees⚿ auth-gatedprobe hit a live sign-in wall — verified reachable, untestable keylessly
quality 0–10 · PA Score /100 · A–D = evidence confidence · full guide

Adjacent arenas — categories often shopped togetherAdjacent arenas

Shopping this category often means shopping these too.