Auth.js (NextAuth.js)

An open-source authentication toolkit that integrates with any JavaScript framework or runtime

Also known as
auth-js-nextauth-js

What is Auth.js (NextAuth.js)?

A suite of open-source authentication packages built on standard web APIs, designed to work with any JavaScript framework and runtime, with support for OAuth, passwordless authentication, and WebAuthn.

Independently observed

Auth.js (NextAuth.js) pricing

We don't have Auth.js (NextAuth.js)'s full plan breakdown yet (its pricing page resisted automated reading). Here's what we could confirm. Always check live pricing for exact numbers.

Pricing as of verify at live pricing ↗Independently observed
Open sourceFree tier

Free and open source

What Auth.js (NextAuth.js) does

The capabilities that matter for auth & identity software, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.

Deployment
Hosting
Self-hosted only
Methods
Social login
Passwordless
Passkeys / WebAuthn
Multi-factor auth
-
Enterprise
SAML SSO
-
SCIM provisioning
-
B2B / multi-tenancy
-
Standards
OpenID Connect provider
-
Delivery
Hosted UI
Headless
Access
RBAC
-
Licensing
Self-hostable OSS core
Independently observed

Platform & deployment

Independently observed
Platforms
  • Web
Deployment
  • Self-hosted

Integrations (1)

Independently observed
  • GitHub

Security & compliance

Known vulnerabilities: 0 (0 in the last 12 months) sourcea count reflects scale & disclosure, not quality

Auth.js (NextAuth.js) FAQ

Common questions about Auth.js (NextAuth.js), answered from independent, dated evidence.

What is Auth.js (NextAuth.js)?

An open-source authentication solution that integrates with web frameworks to provide OAuth-based authentication with customizable sign-in pages. It is indexed under Auth & Identity Software.

Source: https://authjs.dev

Is Auth.js (NextAuth.js) free to use?

Auth.js (NextAuth.js) is open source, so it can be self-hosted and used at no licence cost. It is released under the ISC licence. Pricing changes often, so verify at source before relying on it.

Source: https://authjs.dev

What platforms does Auth.js (NextAuth.js) support?

We have confirmed browser-based access to Auth.js (NextAuth.js). That is the extent of what we could verify from public sources, so it may well offer desktop or mobile clients we have not indexed.

Source: https://authjs.dev

Can Auth.js (NextAuth.js) be self-hosted?

Yes. Auth.js (NextAuth.js) can be deployed self-hosted, so it does not have to run on the vendor's infrastructure.

Source: https://authjs.dev

Is Auth.js (NextAuth.js) open source?

Yes. Auth.js (NextAuth.js) is published under the ISC licence, a permissive licence that generally allows commercial use and modification. Licence terms can change between releases, so verify against the repository for the version you intend to use.

Source: https://github.com/nextauthjs/next-auth

Auth.js (NextAuth.js) alternatives

Other auth & identity software we track, ranked by the same independent score.

All Auth.js (NextAuth.js) alternatives, ranked →

Compare Auth.js (NextAuth.js)

Side by side against other auth & identity software, attribute by attribute, with a source on every value.

Independent · unbought · dated

The vioscaleAI score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for Auth.js (NextAuth.js), not the verdict.

Balanced composite 51 / 100
low · 41%
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Package downloads850.1411.6
Capabilities670.064.2
Dependent projects640.064.0
Security score600.042.5
Stars840.032.2
Integrations90.060.5
Development activity00.090.0
Release cadence00.050.0-
Security posture50.210.0-
Developer Q&A activity00.060.0-

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Activity

AttributeValueEvidence
Commits last 30d0mediumsource · 2026-09-10 · 65%

Adoption

AttributeValueEvidence
Dependent repos6,629highsource · 2026-08-26 · 85%
Github stars28,366highsource · 2026-09-10 · 90%
Package downloads weekly3,493,939highsource · 2026-09-10 · 85%

Content

AttributeValueEvidence
Faq5 itemsmediumsource · 2026-09-10 · 68%

Features

AttributeValueEvidence
CapabilitiesHosting: self · Hosted ui: headless · Open source: Yes · Passwordless: Yes · Social login: Yes · Passkeys webauthn: Yesmediumsource · 2026-09-14 · 60%

Integrations

AttributeValueEvidence
Count1mediumsource · 2026-08-14 · 60%

Language

AttributeValueEvidence
PrimaryTypeScripthighsource · 2026-09-10 · 90%

License

AttributeValueEvidence
SpdxISChighsource · 2026-09-10 · 99%

Pricing

AttributeValueEvidence
Free tierYesmediumsource · 2026-09-14 · 60%
Price levelfreemediumsource · 2026-09-14 · 60%
Modelopen_sourcemediumsource · 2026-09-14 · 60%

Release

AttributeValueEvidence
History20 itemsmediumsource · 2026-09-10 · 70%

Reliability

AttributeValueEvidence
Status pageYesmediumsource · 2026-08-05 · 60%

Security

AttributeValueEvidence
Disclosure policyYesmediumsource · 2026-08-05 · 60%
Scorecard6highsource · 2026-09-10 · 90%
VulnerabilitiesCount: 0 · Source: https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=npm&package_name=%40next-auth%2Fprisma-adapter&per_page=100 · Last 12m: 0highsource · 2026-08-26 · 90%
Still deciding?

Is Auth.js (NextAuth.js) the right choice for you?

Tell us the job, the constraints and what you weigh most, and we will rank Auth.js (NextAuth.js) against the rest of the auth & identity software we index, using the same dated evidence weighted your way.

Free to run, no account needed to start. How the evaluation works

For the makers of Auth.js (NextAuth.js)

Is this your product?

This profile was built from public sources without asking you. You can take the badge below and use it anywhere, and you can claim the profile to correct anything we got wrong. Both are free, and neither moves Auth.js (NextAuth.js) up or down: nobody can buy rank here, including you.

Take the badge

Live, always current, and free to use on your own site. It shows Auth.js (NextAuth.js)'s independent score and links back to this profile.

Auth.js (NextAuth.js), verified on vioscaleAI
HTML
<a href="https://www.vioscale.ai/software/auth-js-nextauth-js" target="_blank" rel="noopener">
  <img src="https://www.vioscale.ai/badge/software/auth-js-nextauth-js.svg" alt="Auth.js (NextAuth.js), verified on vioscaleAI" width="330" height="76" loading="lazy" />
</a>
Markdown, for a README →
Markdown
[![Auth.js (NextAuth.js), verified on vioscaleAI](https://www.vioscale.ai/badge/software/auth-js-nextauth-js.svg)](https://www.vioscale.ai/software/auth-js-nextauth-js)

Claim the profile

Verify you control the domain and you can correct the facts, add the sources we should be reading, and see how AI assistants are describing Auth.js (NextAuth.js). Free, and it does not change the score.

  • Correct anything wrong, with evidence
  • Point our crawler at the pages that matter
  • See which AI systems are reading this profile
Claim Auth.js (NextAuth.js)

Not the owner? How vendor profiles work