MemetikEdition 2026-09

Lists / Startup stack

Best authentication platforms for SaaS apps (2026): What ChatGPT, Claude & Gemini Recommend

Clerk is named in 49 of 50 AI answers on the best auth for a new SaaS app. 17 platforms ranked by how often ten models name them, and where they split.

Clerk is the authentication platform AI models name for a new SaaS app. Ten models named it in 49 of 50 recorded answers to five buyer questions, and put it first in 29. Auth0, WorkOS and Supabase Auth follow on reach, but none of them opens many answers. The category is developer authentication: hosted login, sessions, user management, organisations and enterprise SSO, plus the open-source libraries that do the same job inside your own stack. The list ranks 17 products by how often the models name them, not by product quality.

TL;DR

1. Clerk

Clerk is the pick for a team building a React or Next.js product that wants sign-in, user management and organisations working without writing auth UI.

Measured: named 49 of 50 (Clerk 98%), first 29 of 50 (Clerk 58%), average position 1.92.

Nine of the ten models named Clerk in every answer, and Sonar Reasoning Pro left it out once. The first-place count is the stronger signal. Being listed shows the models know a product. Being opened with shows it is their default. Asked which auth service a Next.js startup should use, GPT-5.6 Sol, ChatGPT and GPT-5.6 Luna each led with Clerk. The open question for a new SaaS app is how soon enterprise buyers arrive, because that is where the captured guides place Clerk’s gaps.

PropelAuth’s guide says Clerk is known for its developer experience, particularly in the React and Next.js ecosystem.

Kinde’s comparison, a rival’s page, says Clerk is building B2B features but that its consumer-first roots show in its architectural decisions.

Pros

Cons

Pricing: A free tier measured in monthly active users, per PropelAuth’s guide.

Best for: Consumer applications or simple B2B tools where user experience matters more than complex authorisation logic, in Kinde’s assessment.

2. Auth0

Choose Auth0 when the product needs a wide identity feature set, with broad protocol support and deep customisation, and the team can carry the configuration work.

Measured: named 47 of 50 (Auth0 94%), first 4 of 50 (Auth0 8%), average position 3.49.

The models list Auth0 almost everywhere and open with it rarely. Its named-versus-first gap of 86 points is the widest in the panel. Claude described it as “One of the most established players.” That framing explains the gap. An established product is the one an answer compares against, and for a new app the answers lead with something else. The count also includes answers that say Okta, which the panel matches to Auth0.

Descope’s guide, written by a competitor, credits Auth0 with broad protocol support, extensive documentation and a large ecosystem of integrations and developer tooling.

Descope’s guide also says organisations with complex multi-tenant requirements may need to rely on Auth0 Actions, custom logic and additional configuration.

Pros

Cons

Pricing: Per-MAU pricing, with organisation-level features spread across tiers, per PropelAuth’s guide.

Best for: Organisations with dedicated engineering resources to manage configuration, extensibility and customisation, per Descope’s guide.

3. WorkOS

Shortlist WorkOS if the next enterprise deal depends on SAML SSO and SCIM, including when another system already handles login.

Measured: named 40 of 50 (WorkOS 80%), first 9 of 50 (WorkOS 18%), average position 2.93.

WorkOS is the product the models reach for when the question turns to enterprise requirements. ChatGPT’s answer to the B2B question led with WorkOS for enterprise features. GPT-5.6 Luna told teams that already have auth to use WorkOS, and GPT-5.6 Sol noted that it can add SSO or directory sync to an existing login system instead of replacing it. In these answers WorkOS is the enterprise layer a team adds, more than a general login default. Entry 6 covers AuthKit, the WorkOS product some models name directly.

Pros

Cons

Pricing: Enterprise SSO and SCIM connections are billed per connection per month, per PropelAuth’s guide.

Best for: Developer teams selling to enterprises who need a clean API experience and don’t mind building their own UI layer, per Kinde’s comparison.

4. Supabase Auth

Use Supabase Auth if the app already runs on Supabase’s Postgres database, because the auth layer plugs into the row-level security already in place.

Measured: named 37 of 50 (Supabase Auth 74%), first 0 of 50 (Supabase Auth 0%), average position 4.24.

The models treat Supabase Auth as a conditional pick. Claude Opus 5 put the condition plainly: “If you’re already on Supabase: just use Supabase Auth.” That condition is the likely reason it never opens an answer. It is the right first pick only for a team that has already chosen its database, and none of the five buyer questions assumes that. Both Gemini models named it in every answer. Perplexity named it in 2 of 5. For a new SaaS app still choosing a backend, this is a Supabase decision first and an auth decision second.

Kinde’s comparison says Supabase Auth’s integration with PostgreSQL row-level security enables powerful patterns.

Pros

Cons

Pricing: A generous free tier, per Kinde’s comparison.

Best for: Full-stack applications using Supabase’s database and real-time features, per Kinde’s comparison.

5. Firebase Auth

Firebase Auth suits a mobile-first app, or one already built on Firebase or Google Cloud, where B2B organisation features are not on the near roadmap.

Measured: named 21 of 50 (Firebase Auth 42%), first 1 of 50 (Firebase Auth 2%), average position 4.67.

Firebase Auth splits the panel more than its total suggests. GPT-5.6 Luna and Claude named it in 4 of 5 answers. GPT-5.6 Sol, ChatGPT, Claude Opus 5 and Gemini named it once each. Where it appears, the framing is consistent. The models choose it for where the app is built, not for what the app sells. Perplexity called it a good speed-first choice for apps already built on Firebase or Google Cloud.

Descope’s guide says teams that aren’t already building within a Google or Firebase-heavy ecosystem likely won’t get as much value from the integration.

Pros

Cons

Pricing: No public pricing is recorded.

Best for: Mobile and web teams already building on Firebase or Google Cloud, per Descope’s guide.

6. AuthKit

Consider AuthKit when WorkOS is already on the shortlist and the team wants hosted login and user management from the same vendor that sells the enterprise SSO.

Measured: named 18 of 50 (AuthKit 36%), first 0 of 50 (AuthKit 0%), average position 3.89.

AuthKit is not a second vendor. It is a WorkOS product, and the panel counts it as its own name. An answer that says WorkOS AuthKit counts for both entries, so the two counts overlap and should not be added. What the AuthKit row shows is which models name the specific product. GPT-5.6 Sol named it in every answer and ChatGPT in 4 of 5. Both Gemini models named it in 3 of 5. Claude, Claude Fable 5, Perplexity and Sonar Reasoning Pro never used the name. A buyer asking an OpenAI model hears the product name. A buyer asking Claude hears only the company.

Kinde’s comparison describes AuthKit as WorkOS’s user management product.

Pros

Cons

Pricing: Free up to a high monthly active user threshold, per PropelAuth’s guide.

Best for: Teams building for enterprise customers that want to use WorkOS as a single platform from the start, per Kinde’s comparison.

7. Kinde

Kinde fits a B2B product that needs organisations and SSO early and would like billing and feature flags on the same platform as auth.

Measured: named 17 of 50 (Kinde 34%), first 4 of 50 (Kinde 8%), average position 4.18.

Kinde’s count depends on the model more than most. Claude Opus 5 and Gemini named it in 4 of 5 answers. GPT-5.6 Sol, ChatGPT, GPT-5.6 Luna and Claude never named it. When it does appear, it can lead. Perplexity’s first answer paired Clerk and Kinde as the strongest default picks for most new SaaS startups. Sonar Reasoning Pro put Kinde at the head of its practical shortlist. The section after the model split explains why the models divide where they do.

PropelAuth’s guide, a rival’s page, describes Kinde as combining authentication with feature flags and billing in one place.

Pros

Cons

Pricing: Transparent MAU-based pricing with all B2B features in the base tier, according to Kinde’s own comparison.

Best for: Engineering teams building multi-tenant SaaS applications, in Kinde’s own description.

8. PropelAuth

PropelAuth is worth a look for a product that is multi-tenant B2B from day one and wants organisations, per-organisation roles and self-serve enterprise SSO modelled natively.

Measured: named 15 of 50 (PropelAuth 30%), first 0 of 50 (PropelAuth 0%), average position 4.33.

Three models supply most of PropelAuth’s presence. Gemini named it in every answer, and Claude Opus 5 and Claude Fable 5 named it in 3 of 5 each. GPT-5.6 Sol, ChatGPT, GPT-5.6 Luna and Claude never named it. Gemini 3.5 Flash’s first answer offered WorkOS or PropelAuth for B2B SaaS that needs enterprise readiness. PropelAuth also wrote one of the comparison pages that ranks for this question, and the models that name PropelAuth most include models that cite that page.

PropelAuth’s guide makes organisations the core of the data model, with one user able to belong to several organisations with different roles in each.

Pros

Cons

Pricing: Free to start, with custom roles and permissions on paid plans rather than gated behind an enterprise tier, per PropelAuth’s guide.

Best for: Teams building B2B SaaS, in PropelAuth’s own guide.

9. NextAuth / Auth.js

NextAuth / Auth.js is for a Next.js team that wants to own the auth code and user data and would sooner not pay a hosted vendor.

Measured: named 14 of 50 (NextAuth / Auth.js 28%), first 2 of 50 (NextAuth / Auth.js 4%), average position 4.5.

Auth.js is an open-source library in a list of hosted services, so it appears where ownership comes up. Claude’s Next.js answer led its list with it, describing it as free, open-source and built specifically with Next.js in mind. GPT-5.6 Luna’s B2B answer named it among the existing auth systems WorkOS can sit on top of. Sonar Reasoning Pro grouped it with the developer-first, self-hosted options. None of the captured comparison pages covers it. The practical reading is that Auth.js is the do-it-yourself baseline the hosted products are measured against. Better Auth, at entry 11, draws the same kind of buyer.

Pros

Cons

Pricing: No vendor pricing is recorded. Claude’s answer describes it as free and open-source.

10. Stytch

Stytch fits a product whose sign-in is built around passwordless login: magic links, one-time codes and passkeys.

Measured: named 14 of 50 (Stytch 28%), first 0 of 50 (Stytch 0%), average position 5.21.

ChatGPT gives Stytch its strongest showing, naming it in 3 of 5 answers. ChatGPT’s first answer put Stytch in the row for B2B SaaS where enterprise SSO and SCIM are a near-term sales requirement. Sonar Reasoning Pro offered it for startups that are B2C and passwordless-first. Claude Opus 5, Claude Fable 5 and Gemini 3.5 Flash never named it. The models disagree on which buyer Stytch serves, and its captured record describes a product that sits across both.

Kinde’s comparison says Stytch focuses on passwordless authentication and that its B2B feature set has matured considerably, now including SCIM, RBAC and an Admin Portal.

Pros

Cons

Pricing: No public pricing is recorded.

Best for: Consumer applications and modern B2B tools where passwordless authentication and passkeys align with user expectations, per Kinde’s comparison.

11. Better Auth

Better Auth suits a team that wants a code-first, self-hosted library with all user data in its own database.

Measured: named 13 of 50 (Better Auth 26%), first 1 of 50 (Better Auth 2%), average position 4.08.

Better Auth’s spread is even. Every model named it at least once, and none more than twice. That is a steady low presence, not one model’s enthusiasm. Perplexity’s Next.js answer paired it with Clerk as the two defaults, with Better Auth for teams that want more ownership and a code-first, self-hosted setup. Sonar Reasoning Pro made the same pairing. Claude Opus 5 listed Better Auth plus a host on its shortlist. None of the captured comparison pages covers it, though a video on Better Auth plugins appears in the same Google results.

Pros

Cons

Pricing: No public pricing is recorded.

12. Keycloak

Keycloak belongs on the list for a team with DevOps capacity that wants open-source, self-hosted identity with full control over federation.

Measured: named 13 of 50 (Keycloak 26%), first 0 of 50 (Keycloak 0%), average position 7.54.

Answers treat Keycloak as the fallback. Its average position of 7.54 is the latest in the panel, so answers reach it after most other products. The Perplexity family names it most (Keycloak 50% of Perplexity-family answers). Sonar Reasoning Pro’s B2B answer offered Ory or Keycloak for teams that specifically want an open-source, self-hosted stack. For a new SaaS app, it belongs on a shortlist only if running identity infrastructure is a deliberate choice.

Descope’s guide says Keycloak provides support for SAML, OIDC, OAuth 2.0, LDAP and Active Directory integration through a self-hosted architecture.

Pros

Cons

Pricing: No public pricing is recorded.

Best for: Teams with DevOps resources that want open-source IAM, per Descope’s guide.

13. AWS Cognito

AWS Cognito makes sense when the app already runs on AWS and auth needs to plug into API Gateway, Lambda and IAM.

Measured: named 10 of 50 (AWS Cognito 20%), first 0 of 50 (AWS Cognito 0%), average position 6.1.

Cognito’s reach depends on the model family. GPT-5.6 Sol named it in 3 of 5 answers. Claude Opus 5, Gemini and Gemini 3.5 Flash never did. Perplexity listed Amazon Cognito among the top platforms for startups, and Sonar Reasoning Pro did the same. The captured guides call it Amazon Cognito. The models treat it as an answer to where the app is hosted, not to what the product needs.

Kinde’s comparison, written by a competitor, says the Cognito developer experience frustrates with poor documentation and confusing concepts like user pools versus identity pools.

Pros

Cons

Pricing: Pay-as-you-go, in line with AWS, per Kinde’s comparison.

Best for: AWS-first teams building SaaS, APIs or mobile apps, per Descope’s guide.

14. Descope

Descope is for a team where non-engineers need to change sign-up and login journeys, or where one product serves both consumers and business customers.

Measured: named 7 of 50 (Descope 14%), first 0 of 50 (Descope 0%), average position 6.57.

Descope is thinly named. Claude Opus 5 named it twice. GPT-5.6 Sol, ChatGPT, Gemini and Gemini 3.5 Flash never did. Sonar Reasoning Pro’s B2B answer offered Auth0 or Descope for teams that want a full identity layer. Seven mentions are too few to read a model preference beyond the split. Descope also publishes one of the comparison pages that rank for this question.

Descope’s own guide calls Descope the strongest fit for B2B SaaS teams that need workflow-driven, tenant-aware identity.

PropelAuth’s guide says Descope centres its product on a visual, drag-and-drop flow builder for composing authentication journeys.

Pros

Cons

Pricing: No public pricing is recorded.

Best for: Descope’s flow-first approach suits teams that span B2C and B2B, per PropelAuth’s guide.

15. Frontegg

Frontegg fits a team that wants a packaged, customer-facing admin portal with SSO, SCIM and roles already built.

Measured: named 7 of 50 (Frontegg 14%), first 0 of 50 (Frontegg 0%), average position 6.71.

Frontegg’s mentions sit mostly with two Anthropic models. Claude named it in 3 of 5 answers and Claude Fable 5 in 2. The three OpenAI models and both Gemini models never named it. A buyer asking a model outside the Anthropic family is unlikely to hear the name at all. For a team that wants an admin portal its customers can use from the first enterprise deal, the packaging described below is the reason to look.

Descope’s guide, a competitor’s page, says Frontegg packages many common enterprise identity requirements into a single platform.

Pros

Cons

Pricing: No public pricing is recorded.

Best for: Frontegg is ideal for SaaS companies that want packaged authentication, user management, enterprise SSO, SCIM, and admin portal capabilities for multi-tenant B2B applications, per Descope’s guide.

16. FusionAuth

FusionAuth is an option when data residency rules or per-user pricing rule out a hosted service and the team can run its own auth infrastructure.

Measured: named 5 of 50 (FusionAuth 10%), first 0 of 50 (FusionAuth 0%), average position 6.8.

FusionAuth sits at the edge of the answer set. Five models named it once each. Sonar Reasoning Pro’s answer to the first question put it on a practical shortlist next to Kinde, Clerk and Auth0. Its presence is too thin to read a model preference from, and no model opened with it. Of the captured guides, only Kinde’s covers it.

Kinde’s comparison describes FusionAuth as a self-hosted authentication platform with no user limits.

Kinde’s page also warns that running production authentication infrastructure requires significant operational expertise.

Pros

Cons

Pricing: Self-hosted with no user limits, per Kinde’s comparison.

Best for: Organisations with strict data residency requirements or those wanting to avoid per-user pricing, per Kinde’s comparison.

17. Ory

Ory is for a platform engineering team that wants modular, open-source identity services it can compose itself.

Measured: named 1 of 50 (Ory 2%), first 0 of 50 (Ory 0%), average position 4.

Ory appeared once, in Sonar Reasoning Pro’s answer to the B2B question, as an open-source, self-hosted alternative alongside Keycloak. Its average position comes from that single answer and says little. One mention cannot show a model preference. For a new SaaS app without a platform team, the models’ near-silence is consistent with how the captured guides describe the ownership it asks for.

Descope’s guide says Ory typically requires more engineering ownership and operational management than more packaged SaaS identity platforms.

Pros

Cons

Pricing: No public pricing is recorded.

Best for: Platform engineering teams comfortable with Kubernetes and microservices architectures, per Kinde’s comparison.

How the tools compare

Clerk leads on every measure the panel records. Answer share is the share of the 50 recorded answers that named a product. Named first is the share where it appeared before any other tracked product. Average position is where it sits, on average, in the order of tracked products an answer names. The pricing column repeats the pricing line from each entry, where a captured page states one.

Rank Vendor Named Share First First share Avg position Pricing model
1 Clerk 49/50 98% 29/50 58% 1.92 Free tier by monthly active users
2 Auth0 47/50 94% 4/50 8% 3.49 Per-MAU
3 WorkOS 40/50 80% 9/50 18% 2.93 Per SSO or SCIM connection
4 Supabase Auth 37/50 74% 0/50 0% 4.24 Generous free tier
5 Firebase Auth 21/50 42% 1/50 2% 4.67 Not recorded
6 AuthKit 18/50 36% 0/50 0% 3.89 Free to a high MAU threshold
7 Kinde 17/50 34% 4/50 8% 4.18 MAU-based
8 PropelAuth 15/50 30% 0/50 0% 4.33 Free start, paid plans
9 NextAuth / Auth.js 14/50 28% 2/50 4% 4.5 Not recorded
10 Stytch 14/50 28% 0/50 0% 5.21 Not recorded
11 Better Auth 13/50 26% 1/50 2% 4.08 Not recorded
12 Keycloak 13/50 26% 0/50 0% 7.54 Not recorded
13 AWS Cognito 10/50 20% 0/50 0% 6.1 Pay-as-you-go
14 Descope 7/50 14% 0/50 0% 6.57 Not recorded
15 Frontegg 7/50 14% 0/50 0% 6.71 Not recorded
16 FusionAuth 5/50 10% 0/50 0% 6.8 Self-hosted, no user limits
17 Ory 1/50 2% 0/50 0% 4 Not recorded

The pattern below the leader is a four-product tier and then a drop. Clerk, Auth0, WorkOS and Supabase Auth each appear in 37 or more answers. Below Supabase Auth the count falls to 21 and keeps sliding. First place is far more concentrated than reach. Supabase Auth, AuthKit, PropelAuth, Stytch and every product below Better Auth were never named first. Reach tells you who is on the shortlist. First place tells you who the models open with.

Where the models disagree

The models agree on the top of the list and split on the tail. Clerk leads the per-model count for every model, and every model family has it as its leader. Auth0 appears in 4 or 5 of 5 answers from every model. Below that, the model you ask changes what you hear.

Vendor GPT-5.6 Sol ChatGPT GPT-5.6 Luna Claude Opus 5 Claude Claude Fable 5 Gemini Gemini 3.5 Flash Perplexity Sonar Reasoning Pro
Clerk 5/5 5/5 5/5 5/5 5/5 5/5 5/5 5/5 5/5 4/5
Auth0 4/5 5/5 5/5 5/5 5/5 5/5 5/5 5/5 4/5 4/5
WorkOS 5/5 4/5 3/5 4/5 3/5 3/5 5/5 5/5 4/5 4/5
Supabase Auth 4/5 3/5 4/5 4/5 4/5 3/5 5/5 5/5 2/5 3/5
Firebase Auth 1/5 1/5 4/5 1/5 4/5 3/5 1/5 2/5 2/5 2/5
AuthKit 5/5 4/5 2/5 1/5 0/5 0/5 3/5 3/5 0/5 0/5
Kinde 0/5 0/5 0/5 4/5 0/5 3/5 4/5 3/5 1/5 2/5
PropelAuth 0/5 0/5 0/5 3/5 0/5 3/5 5/5 2/5 1/5 1/5
NextAuth / Auth.js 1/5 0/5 2/5 1/5 3/5 1/5 2/5 1/5 1/5 2/5
Stytch 2/5 3/5 2/5 0/5 1/5 0/5 2/5 0/5 2/5 2/5
Better Auth 1/5 1/5 1/5 2/5 1/5 1/5 2/5 2/5 1/5 1/5
Keycloak 1/5 1/5 1/5 1/5 0/5 3/5 1/5 0/5 2/5 3/5
AWS Cognito 3/5 2/5 1/5 0/5 1/5 1/5 0/5 0/5 1/5 1/5
Descope 0/5 0/5 1/5 2/5 1/5 1/5 0/5 0/5 1/5 1/5
Frontegg 0/5 0/5 0/5 1/5 3/5 2/5 0/5 0/5 0/5 1/5
FusionAuth 0/5 0/5 0/5 0/5 1/5 1/5 1/5 0/5 1/5 1/5
Ory 0/5 0/5 0/5 0/5 0/5 0/5 0/5 0/5 0/5 1/5

Model by model, the sharpest splits are these.

GPT-5.6 Sol and ChatGPT use the AuthKit name most. GPT-5.6 Sol named AuthKit in every answer. Claude, Claude Fable 5, Perplexity and Sonar Reasoning Pro never did. All three OpenAI models also skipped Kinde and PropelAuth entirely.

GPT-5.6 Luna and Claude are the two models that reach for Firebase Auth, at 4 of 5 each. Claude is also the model most likely to name NextAuth / Auth.js and Frontegg.

Claude Opus 5 and Claude Fable 5 carry most of the B2B-specialist names. Both named PropelAuth in 3 of 5 answers, and Claude Opus 5 named Kinde in 4 of 5.

Gemini named PropelAuth and Supabase Auth in all 5 answers. Gemini 3.5 Flash matched it on Supabase Auth.

Perplexity and Sonar Reasoning Pro are the models that name Keycloak most often, and Sonar Reasoning Pro is the only model that named Ory.

Why do Kinde and PropelAuth appear for some models and not others?

Kinde and PropelAuth show up in answers from models that cite vendor-written comparison pages. Where a model’s readable citations skip those pages, both names drop out. The table cannot show this. The recorded citations can.

Kinde’s own site is the most-cited host in the recorded answers, at kinde.com (99). PropelAuth’s is second, at propelauth.com (88), and workos.com (83) is third. Clerk’s site, clerk.com (31), sits well below all three, yet Clerk is named in 49 of 50 answers and Kinde in 17. Being cited and being named are different things.

Kinde’s comparison names Kinde its top pick for B2B SaaS authentication.

PropelAuth’s guide calls PropelAuth the most complete B2B-native option of the six platforms it compares.

Both pages appear in the captured Google results for this exact question. In the recorded answers, pages on kinde.com and propelauth.com are cited by Claude Opus 5, Claude Fable 5, Perplexity and Sonar Reasoning Pro. All four name both Kinde and PropelAuth at least once. No answer from GPT-5.6 Sol, ChatGPT, GPT-5.6 Luna or Claude cites either site, and none of those four models names either product. The two Gemini models name both as well, but their citations are recorded as redirect links or not at all, so their trail is not visible here.

Some models notice the source problem. Claude Opus 5 warned that most comparison articles are “published by vendors ranking themselves first”.

PropelAuth’s guide says WorkOS is focused on the enterprise SSO and directory sync side and gives you building blocks rather than a full end-to-end B2B platform.

Claude Fable 5’s B2B answer repeats that sentence almost word for word: “WorkOS is focused on the enterprise SSO and directory sync side, and gives you building blocks rather than a full end-to-end B2B platform”.

The reading, which is an inference and not a measurement: a model that searches the web takes the list of names from a vendor’s guide, and often its wording, but not the guide’s ranking. The top-pick label did not travel. The models named Kinde first in 4 of 50 answers. Citing a page is also not the same as naming its author. Perplexity cited Kinde’s pages and named Kinde in 1 of 5 answers. For the tail of this list, a product’s presence says as much about which pages a model retrieves as about the product.

What should a buyer do with this?

Use the top four as a starting shortlist and the rest as situational picks. Then test against your own requirements, because the models and the guides both inherit vendor framing.

  1. Building a React or Next.js app for smaller customers first: start with Clerk. Check SCIM and per-connection SSO costs before your first enterprise deal.
  2. Selling to enterprises from day one: compare WorkOS, including AuthKit, against Auth0. Price SSO per connection against the number of enterprise customers you expect.
  3. Already committed to Supabase or Firebase: use the auth layer that ships with the platform, and budget custom work for SAML SSO and organisations.
  4. Want to own the code: NextAuth / Auth.js or Better Auth for Next.js, Keycloak or Ory if a platform team will run it.
  5. Considering Kinde, PropelAuth or Descope: read their own comparison pages as sales documents, then ask a model that does not cite them. If the product still comes up, that is a stronger signal.

Every recorded answer and cited source for this category is in the developer auth category record.

How the sample was built

10 models x 5 fixed prompts = 50 recorded answers, edition 2026-09. Each model answered each prompt once. The five questions, verbatim:

  1. “What is the best authentication provider for a new SaaS app? Name specific products.”
  2. “Which auth service should I use for a Next.js startup?”
  3. “Compare the top user authentication platforms for startups.”
  4. “I’m building a B2B app and need SSO and user management. What do you recommend?”
  5. “Best managed auth for a startup that wants to avoid building login itself?”

The ten models come from four families. OpenAI supplied 15 answers from GPT-5.6 Sol, ChatGPT and GPT-5.6 Luna. Anthropic supplied 15 from Claude Opus 5, Claude and Claude Fable 5. Google supplied 10 from Gemini and Gemini 3.5 Flash. Perplexity supplied 10 from Perplexity and Sonar Reasoning Pro. The panel tracked 17 vendors in this category and every one was named at least once. The method page explains how answers are recorded and how names are counted.

How this sits against the authentication guides

The comparison pages that rank for this question are written by vendors, and each ranks its own author first. The list above counts names across ten models and ranks nobody by preference.

PropelAuth’s guide compares six B2B authentication platforms: PropelAuth, WorkOS, Auth0, Clerk, Kinde and Descope.

PropelAuth’s guide evaluates each platform against the same B2B rubric, including organisations, roles and permissions, self-serve organisation management, migration path and pricing transparency.

PropelAuth’s guide closes with a link to get started with PropelAuth for free.

Kinde’s comparison names Kinde its top pick, then covers Auth0, Clerk, Supabase Auth, Firebase Auth, WorkOS, FusionAuth, Amazon Cognito, Ory and Stytch.

Kinde’s methodology says testing included building a multi-tenant application with each provider.

Descope’s guide is written by Descope’s Sr. Product Marketing Manager.

Descope’s guide compares eight solutions: Descope, Auth0, WorkOS, Frontegg, Ory, Keycloak, Amazon Cognito and Firebase Authentication with Google Identity Platform.

Clerk, the most-named product in this panel, is not on Descope’s list.

Auth0’s page in the same results is not a comparison. It is a launch post for Auth0 Organizations, which represents the teams, business customers and partners that use your applications as organizations in Auth0.

Those guides rank products for purchase and argue for their author. What none of them has is added here: named and named-first counts across ten models, the per-model split, and the citation trail that shows how those guides feed the answers.

What these counts cannot tell you

The counts measure presence in AI answers. They say nothing about product quality, uptime, support, security, pricing fairness or fit with a particular stack. Being named is also not the same as being recommended, because an answer can name a product to warn against it.

Each count comes from one response per prompt-and-model pair, in one dated snapshot. Answers change between editions. Names are matched as strings. Auth0 counts answers that say Okta. Supabase Auth counts any mention of Supabase, and Firebase Auth any mention of Firebase, so a reference to the wider platform counts too. An answer that says WorkOS AuthKit counts for both WorkOS and AuthKit. The panel labels are API models, and API answers can differ from the consumer chat apps with similar names. All five prompts are in English. Citation counts reflect the citations returned in the recorded API responses, and coverage varies by model. No vendor can pay to appear, be reordered or be removed.

Frequently asked questions

Who are the top SSO providers?

WorkOS is the product these models most often tie to enterprise SSO, and Auth0 is the established alternative. ChatGPT summed up the WorkOS trade-off in one line: “Enterprise SSO and directory sync are charged per connection”. The WorkOS and Auth0 entries above carry the captured pricing and feature detail for each.

This panel does not measure adoption. It measures how often AI models name a product. On that measure Clerk, Auth0, WorkOS and Supabase Auth are the four names most answers include, and Clerk is the one most answers open with.

What are some good 3rd-party authentication apps?

If the question means third-party auth services a SaaS app plugs into, the ranked list above is the answer, led by Clerk, Auth0, WorkOS and Supabase Auth. If it means authenticator apps that generate one-time codes on a phone, the panel did not ask about them and has no counts for them.

Is Clerk a good fit for B2B SaaS?

For early B2B, the models treat Clerk as the default.

Clerk supports organizations, roles and permissions, along with an organization switcher and member management components, per PropelAuth’s guide.

PropelAuth’s guide also says SCIM, granular org-level roles and machine-to-machine auth are the areas to examine as you move upmarket.

If SCIM is a day-one requirement, compare WorkOS and Auth0 alongside it.

Is AuthKit the same as WorkOS?

AuthKit is a WorkOS product, not a separate company. Kinde’s comparison describes it as WorkOS’s user management product.

The panel counts the two names separately, and an answer that says WorkOS AuthKit counts for both, so do not add the two counts together.

Can a vendor pay to rank on this list?

No. The order comes only from the counts in the recorded answers. No position is sold, sponsored or influenced, and vendors cannot pay to appear, be reordered or be removed.

How this list is ordered

The order is the measurement, not an assessment of the products. Answer share is the share of recorded answers that named the tool. Named first is the share where it appeared before any other tracked tool. Both are counts from one dated edition and are published in full on the category page.

A tool appears here only if it was named in the edition and its record carries a sourced claim. A product that was never named is not listed, and no position is sold.

Where to check it