Clerk

clerk.comcontributed by Samuele Ongaro

KEEP IT

The value is the network, the data or the infrastructure. Keep paying.

Authentication as a service: hosted sign-in flows, sessions, social providers, passkeys and multi-factor, plus organisations and roles for business applications.

Promptfree, for everyone, and the only version there is
Do not build this to save money — but be clear about what you are buying, because it is unusual.

It is **being responsible when it breaks**. Session handling, token rotation and revocation done by people who think about it full time, and sign-in components that already handle every awkward state: an expired link, a half-finished sign-up, an email that has been changed, an account that exists under a social login the user has forgotten about. Those states are where homemade authentication actually fails, and they are dull rather than difficult.

WHEN TO KEEP PAYING
- A small team where nobody wants to own authentication at three in the morning
- You need organisations, roles and invitations, and you want them next week
- The cost of a mistake here is somebody else's account, and you would rather that risk sat elsewhere

WHEN TO BUILD
- Authentication is a known problem with reviewed libraries, and the full shape is covered under Stytch elsewhere in this catalogue
- Do it if you want the users in your own database and no vendor in the login path

WHATEVER YOU CHOOSE, THESE ARE NOT OPTIONAL
- **Passkeys first**, password second. Phishing-resistant, nothing to steal from your database
- argon2id for any password, and check new ones against a breached corpus with k-anonymity so it never leaves your machine
- Session tokens long, random, stored hashed, httpOnly and secure, short-lived with a rotating refresh, revocable centrally
- Identical responses and identical timing for a wrong password and an unknown address, on every route
- Rate limits per address hash and per account, everywhere
- A reset revokes every other session and the user is told
- An append-only auth_events table, because it is the only thing that answers what happened to an account

ASK THE EXIT QUESTION FIRST
If you adopt a provider, find out today whether you could export password hashes and user identifiers. If the answer is no, every user resets their password on the way out, and that is a decision to take knowingly.

THE ONE-LINE VERSION
Pay to move the risk, not to avoid understanding it — and check how you would leave before you arrive.

What you lose

  • Session handling, token rotation and revocation done by people who have thought about it properly
  • Sign-in components that already handle every awkward state: expired links, locked accounts, device changes
  • Social providers, passkeys, magic links and multi-factor, all maintained as they change
  • Organisations, invitations and roles, which is a surprising amount of work
  • Being the party responsible when a session-fixation bug is found

If you would rather not build

  • Lucia — a guide and library for session-based auth you own
  • Auth0 — paid, the enterprise standard, more expensive

What it costs

read from their page 15 Aug 2026

PlanBilled monthlyBilled yearlyLast read
—$25/mo—15 Aug 2026

Their pricing page is where these came from. Seeing a different price? Tell us.

The escape hatch

open source · no votes, no paid placement

Keycloak

$0

Full identity server with SSO, social login and SAML, self-hosted.

keycloak/keycloakfree · open source

Ory Kratos

$0

Identity and user management API you run yourself, without a UI opinion.

ory/kratosfree · open source

Why this verdict

our own opinion · changed only by a person

29/100

Verdict no at 29: sessions and password handling are well-trodden and this prompt does them carefully. It is still a no because the failure mode is total — an authentication bug is every account at once, and the maintained edges keep moving.

History

tracked since 9 Aug 2026 · nothing is ever overwritten

Interest · last 30 dayspeak 1/day
views0130 Aug4 Sept9 Sept14 Sept19 Sept24 Sept28 Sept
— views— prompt copies none yet— votes none yet

Questions about Clerk

answered from the record above

Is Clerk free?

No — the plan we track is $25 a month. Pro at $25/month plus $0.02 per monthly active user beyond the free 10,000; add-ons for SAML and B2B are billed separately.

Can you replace Clerk by building your own?

KEEP IT. The value is the network, the data or the infrastructure. Keep paying. Replacement score 29 out of 100, build time longer than it saves. Read what you lose before you decide.

How much does Clerk cost?

$25 a month on Pro — $300 a year. Recorded 9 Aug 2026.

What do you lose by replacing Clerk?

Session handling, token rotation and revocation done by people who have thought about it properly; Sign-in components that already handle every awkward state: expired links, locked accounts, device changes; Social providers, passkeys, magic links and multi-factor, all maintained as they change; Organisations, invitations and roles, which is a surprising amount of work; Being the party responsible when a session-fixation bug is found. If any of those carry weight for you, keep paying.

Is there an open-source alternative to Clerk?

Yes: Keycloak, Ory Kratos. The prompt on this page is for when you want it your way instead.

Related entries

same category first, most replaced first

All 56 in Dev tools

Not sending yet

Every week, something stops being worth paying for.

New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.

free forever · no tracking pixel · stored here, never passed to anyone

Esc