# Auth.js (NextAuth.js) vs Auth0

**Leader by Vioscale score:** Auth0

| Attribute | Auth.js (NextAuth.js) | Auth0 |
|---|---|---|
| **Vioscale score** | 54.8 (47% (low)) | 88.5 (72% (medium)) |
| activity.commits_last_30d | 7 | - |
| adoption.dependent_repos | 6,629 | - |
| adoption.github_stars | 28,345 | - |
| adoption.package_downloads_weekly | 5,865,070 | - |
| deployment.options | `{"self_hosted":true}` | `{"cloud":true,"self_hosted":true}` |
| description.long | An open-source authentication solution that integrates with web frameworks to provide OAuth-based authentication with customizable sign-in pages. | A managed authentication service that handles user identity verification, single sign-on, and API security. Supports passwordless login, multi-factor authentication, role-based access control, and machine-to-machine authentication with enterprise-grade features for compliance and security. |
| features.capabilities | `{"hosting":"self","hosted_ui":"headless","open_source":true,"social_login":true}` | `{"mfa":true,"oidc":true,"rbac":true,"hosting":"cloud","saml_sso":true,"hosted_ui":"both","open_source":false,"passwordless":true,"social_login":true,"b2b_multi_tenant":true,"passkeys_webauthn":true,"scim_provisioning":true}` |
| integrations.count | 1 | 14 |
| integrations.list | `[{"name":"GitHub"}]` | `[{"name":"Datadog"},{"name":"Splunk"},{"name":"AWS"},{"name":"Azure"},{"name":"Slack"},{"name":"Segment"},{"name":"Salesforce"},{"name":"Tealium"},{"name":"Web3Auth"},{"name":"Spruce ID"},{"name":"Unstoppable Domains"},{"name":"Dock.io"},{"name":"Ethereum Name Service"},{"name":"NFT services"}]` |
| language.primary | TypeScript | - |
| license.spdx | ISC | - |
| market.availability | - | `{"hqCountry":"US","primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"web":true}` | `{"cli":true,"ios":true,"web":true,"android":true}` |
| pricing | `{"type":"open_source","summary":"Free and open source","freeTier":true,"sourceUrl":"https://authjs.dev","retrievedAt":"2026-08-14T11:04:51.520Z"}` | `{"type":"subscription","plans":[{"free":true,"name":"Free","summary":"Free, up to 25,000 monthly active users","features":["1 Custom Domain","Passwordless Authentication","Unlimited Social Connections","5 Organizations","Brand Customization","Basic Attack Protection","Community Support","1 Enterprise Connection","Self-Service SSO","SCIM"],"commitment":"monthly","components":[{"kind":"fixed","amount":0,"period":"month","currency":"USD"}],"description":"For getting started with authentication","contactSales":false,"includedLimits":{"monthly_active_users":"25000"}},{"free":false,"name":"Essentials","summary":"$35/month, up to 500 monthly active users","features":["Everything in Free","Higher Auth and API limits","Pro Multi-Factor Authentication","Role-based Access Control per Organization","10 Organizations","Stream Audit Logs to Datadog, Splunk, AWS, Azure","Separate Production & Development Environments","Standard Support"],"commitment":"monthly","components":[{"kind":"fixed","amount":35,"period":"month","currency":"USD"}],"description":"For projects with higher production demands","contactSales":false,"includedLimits":{"monthly_active_users":"500"}},{"free":false,"name":"Professional","summary":"$240/month, up to 500 monthly active users","features":["Everything in Essentials","Use existing User Database for Logins","Enterprise Multi-Factor Authentication","Enhanced Attack Protection","Machine-to-Machine Tokens"],"commitment":"monthly","components":[{"kind":"fixed","amount":240,"period":"month","currency":"USD"}],"description":"For teams and projects that need added security","contactSales":false,"includedLimits":{"monthly_active_users":"500"}},{"free":false,"name":"Enterprise","summary":"Custom pricing with 99.99% SLA and enterprise support","features":["Everything in Professional","Custom User & SSO Tiers","99.99% SLA","Enterprise Rate Limits","Enterprise Administration & Support","Advanced Security Features"],"description":"For enterprises needing to scale with top-tier support","contactSales":true}],"addOns":[{"name":"Private Deployment"},{"name":"Machine-to-Machine (M2M) Add-on"}],"summary":"Free tier up to 25k MAU, then $35–$240/month. Pricing based on monthly active users.","currency":"USD","freeTier":true,"sourceUrl":"https://auth0.com/pricing","retrievedAt":"2026-08-14T12:15:50.906Z","startingPrice":{"amount":35,"period":"month","currency":"USD"},"billingPeriods":["month"]}` |
| pricing.free_tier | yes | yes |
| pricing.model | commercial | freemium |
| pricing.price_level | free | mid |
| pricing.transparent | - | yes |
| release.history | `[{"url":"https://github.com/nextauthjs/next-auth/releases/tag/next-auth%404.24.15","date":"2026-07-20T23:22:47Z","type":"stable","version":"next-auth@4.24.15"},{"url":"https://github.com/nextauthjs/next-auth/releases/tag/%40auth/xata-adapter%401.11.3","date":"2026-07-20T21:54:07Z","type":"stable","version":"@auth/xata-adapter@1.11.3"},{"url":"https://github.com/nextauthjs/next-auth/releases/tag/%40auth/upstash-redis-adapter%402.11.3","date":"2026-07-20T21:54:09Z","type":"stable","version":"@auth/upstash-redis-adapter@2.11.3"},{"url":"https://github.com/nextauthjs/next-auth/releases/tag/%40auth/unstorage-adapter%402.11.3","date":"2026-07-20T21:54:11Z","type":"stable","version":"@auth/unstorage-adapter@2.11.3"},{"url":"https://github.com/nextauthjs/next-auth/releases/tag/%40auth/typeorm-adapter%402.11.3","date":"2026-07-20T21:54:13Z","type":"stable","version":"@auth/typeorm-adapter@2.11.3"},{"url":"https://github.com/nextauthjs/next-auth/releases/tag/%40auth/sveltekit%401.11.3","date":"2026-07-20T21:54:00Z","type":"stable","version":"@auth/sveltekit@1.11.3"},{"url":"https://github.com/nextauthjs/next-auth/releases/tag/%40auth/surrealdb-adapter%402.2.3","date":"2026-07-20T21:54:14Z","type":"stable","version":"@auth/surrealdb-adapter@2.2.3"},{"url":"https://github.com/nextauthjs/next-auth/releases/tag/%40auth/supabase-adapter%401.11.3","date":"2026-07-20T21:54:16Z","type":"stable","version":"@auth/supabase-adapter@1.11.3"},{"url":"https://github.com/nextauthjs/next-auth/releases/tag/%40auth/solid-start%400.19.3","date":"2026-07-20T21:54:02Z","type":"stable","version":"@auth/solid-start@0.19.3"},{"url":"https://github.com/nextauthjs/next-auth/releases/tag/%40auth/sequelize-adapter%402.11.3","date":"2026-07-20T21:54:18Z","type":"stable","version":"@auth/sequelize-adapter@2.11.3"},{"url":"https://github.com/nextauthjs/next-auth/releases/tag/%40auth/qwik%400.9.3","date":"2026-07-20T21:54:03Z","type":"stable","version":"@auth/qwik@0.9.3"},{"url":"https://github.com/nextauthjs/next-auth/releases/tag/%40auth/prisma-adapter%402.11.3","date":"2026-07-20T21:54:19Z","type":"stable","version":"@auth/prisma-adapter@2.11.3"},{"url":"https://github.com/nextauthjs/next-auth/releases/tag/%40auth/pouchdb-adapter%402.11.3","date":"2026-07-20T21:54:21Z","type":"stable","version":"@auth/pouchdb-adapter@2.11.3"},{"url":"https://github.com/nextauthjs/next-auth/releases/tag/%40auth/pg-adapter%401.11.3","date":"2026-07-20T21:54:23Z","type":"stable","version":"@auth/pg-adapter@1.11.3"},{"url":"https://github.com/nextauthjs/next-auth/releases/tag/%40auth/neon-adapter%401.11.3","date":"2026-07-20T21:54:24Z","type":"stable","version":"@auth/neon-adapter@1.11.3"},{"url":"https://github.com/nextauthjs/next-auth/releases/tag/%40auth/neo4j-adapter%402.11.3","date":"2026-07-20T21:54:26Z","type":"stable","version":"@auth/neo4j-adapter@2.11.3"},{"url":"https://github.com/nextauthjs/next-auth/releases/tag/%40auth/mongodb-adapter%403.11.3","date":"2026-07-20T21:54:28Z","type":"stable","version":"@auth/mongodb-adapter@3.11.3"},{"url":"https://github.com/nextauthjs/next-auth/releases/tag/%40auth/mikro-orm-adapter%402.11.3","date":"2026-07-20T21:54:30Z","type":"stable","version":"@auth/mikro-orm-adapter@2.11.3"},{"url":"https://github.com/nextauthjs/next-auth/releases/tag/%40auth/kysely-adapter%401.11.3","date":"2026-07-20T21:54:31Z","type":"stable","version":"@auth/kysely-adapter@1.11.3"},{"url":"https://github.com/nextauthjs/next-auth/releases/tag/%40auth/hasura-adapter%401.11.3","date":"2026-07-20T21:54:33Z","type":"stable","version":"@auth/hasura-adapter@1.11.3"}]` | - |
| reliability.sla_pct | - | 99.99 |
| reliability.status_page | yes | yes |
| security.disclosure_policy | yes | yes |
| security.fedramp | - | yes |
| security.gdpr | - | yes |
| security.hipaa | - | yes |
| security.iso27001 | - | yes |
| security.pci | - | yes |
| security.scorecard | 6 | - |
| security.soc2 | - | yes |
| security.vulnerabilities | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=npm&package_name=%40next-auth%2Fprisma-adapter&per_page=100","last_12m":0,"max_severity":null}` | - |

## Capabilities (Auth & Identity Software)

| Capability | Auth.js (NextAuth.js) | Auth0 |
|---|:--:|:--:|
| **Deployment** |  |  |
| Hosting | Self-hosted only | Cloud only |
| **Methods** |  |  |
| Social login | ✓ | ✓ |
| Passwordless | - | ✓ |
| Passkeys / WebAuthn | - | ✓ |
| Multi-factor auth | - | ✓ |
| **Enterprise** |  |  |
| SAML SSO | - | ✓ |
| SCIM provisioning | - | ✓ |
| B2B / multi-tenancy | - | ✓ |
| **Standards** |  |  |
| OpenID Connect provider | - | ✓ |
| **Delivery** |  |  |
| Hosted UI | Headless | Both |
| **Access** |  |  |
| RBAC | - | ✓ |
| **Licensing** |  |  |
| Self-hostable OSS core | ✓ | ✗ |

*Source: Vioscale. Generated 2026-09-01T17:15:55.752Z. "-" = undocumented, not absent.*
