Authentication as a service: hosted sign-in flows, sessions, social providers, passkeys and multi-factor, plus organisations and roles for business applications.
Do not build this to save money — but be clear about what you are buying, because it is unusual. It is **being responsible when it breaks**. Session handling, token rotation and revocation done by people who think about it full time, and sign-in components that already handle every awkward state: an expired link, a half-finished sign-up, an email that has been changed, an account that exists under a social login the user has forgotten about. Those states are where homemade authentication actually fails, and they are dull rather than difficult. WHEN TO KEEP PAYING - A small team where nobody wants to own authentication at three in the morning - You need organisations, roles and invitations, and you want them next week - The cost of a mistake here is somebody else's account, and you would rather that risk sat elsewhere WHEN TO BUILD - Authentication is a known problem with reviewed libraries, and the full shape is covered under Stytch elsewhere in this catalogue - Do it if you want the users in your own database and no vendor in the login path WHATEVER YOU CHOOSE, THESE ARE NOT OPTIONAL - **Passkeys first**, password second. Phishing-resistant, nothing to steal from your database - argon2id for any password, and check new ones against a breached corpus with k-anonymity so it never leaves your machine - Session tokens long, random, stored hashed, httpOnly and secure, short-lived with a rotating refresh, revocable centrally - Identical responses and identical timing for a wrong password and an unknown address, on every route - Rate limits per address hash and per account, everywhere - A reset revokes every other session and the user is told - An append-only auth_events table, because it is the only thing that answers what happened to an account ASK THE EXIT QUESTION FIRST If you adopt a provider, find out today whether you could export password hashes and user identifiers. If the answer is no, every user resets their password on the way out, and that is a decision to take knowingly. THE ONE-LINE VERSION Pay to move the risk, not to avoid understanding it — and check how you would leave before you arrive.
What you lose
- Session handling, token rotation and revocation done by people who have thought about it properly
- Sign-in components that already handle every awkward state: expired links, locked accounts, device changes
- Social providers, passkeys, magic links and multi-factor, all maintained as they change
- Organisations, invitations and roles, which is a surprising amount of work
- Being the party responsible when a session-fixation bug is found
If you would rather not build
- Lucia — a guide and library for session-based auth you own
- Auth0 — paid, the enterprise standard, more expensive
What it costs
read from their page 15 Aug 2026
| Plan | Billed monthly | Billed yearly | Last read |
|---|---|---|---|
| — | $25/mo | — | 15 Aug 2026 |
Their pricing page is where these came from. Seeing a different price? Tell us.
The escape hatch
open source · no votes, no paid placement
Keycloak
$0Full identity server with SSO, social login and SAML, self-hosted.
keycloak/keycloakfree · open source
Ory Kratos
$0Identity and user management API you run yourself, without a UI opinion.
ory/kratosfree · open source
Why this verdict
our own opinion · changed only by a person
29/100
Verdict no at 29: sessions and password handling are well-trodden and this prompt does them carefully. It is still a no because the failure mode is total — an authentication bug is every account at once, and the maintained edges keep moving.
History
tracked since 9 Aug 2026 · nothing is ever overwritten
Questions about Clerk
answered from the record above
Is Clerk free?
No — the plan we track is $25 a month. Pro at $25/month plus $0.02 per monthly active user beyond the free 10,000; add-ons for SAML and B2B are billed separately.
Can you replace Clerk by building your own?
KEEP IT. The value is the network, the data or the infrastructure. Keep paying. Replacement score 29 out of 100, build time longer than it saves. Read what you lose before you decide.
How much does Clerk cost?
$25 a month on Pro — $300 a year. Recorded 9 Aug 2026.
What do you lose by replacing Clerk?
Session handling, token rotation and revocation done by people who have thought about it properly; Sign-in components that already handle every awkward state: expired links, locked accounts, device changes; Social providers, passkeys, magic links and multi-factor, all maintained as they change; Organisations, invitations and roles, which is a surprising amount of work; Being the party responsible when a session-fixation bug is found. If any of those carry weight for you, keep paying.
Is there an open-source alternative to Clerk?
Yes: Keycloak, Ory Kratos. The prompt on this page is for when you want it your way instead.
Related entries
same category first, most replaced first
Every week, something stops being worth paying for.
New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.
free forever · no tracking pixel · stored here, never passed to anyone

