Which auth platform do AI models recommend to developers?
Clerk was named in 49 of 50 AI answers and first in 29. Auth0, WorkOS and Supabase Auth follow across 10 models and 5 developer-auth questions.
Figure 01 · Edition 2026-09
Authentication for developers
How often each product was named, and how often it appeared first.
- ClerkNamed: 98%Named first: 58%
- Auth0Named: 94%Named first: 8%
- WorkOSNamed: 80%Named first: 18%
- Supabase AuthNamed: 74%Named first: 0%
- Firebase AuthNamed: 42%Named first: 2%
- AuthKitNamed: 36%Named first: 0%
- KindeNamed: 34%Named first: 8%
- PropelAuthNamed: 30%Named first: 0%
Top 8 by answer share · 50 answers
10 models · 5 prompts · Memetik Index, 2026-09
Shares use all 50 answers as the denominator. Multiple products can appear in one answer. First position does not measure recommendation strength.
Key findings
Clerk leads in every one of the 10 models, so its lead doesn't depend on which model a developer asks.
Auth0 is the name models add and seldom the name they open with. Its 86-point gap between named and named first is the widest in the category.
Supabase Auth and AuthKit appear in many answers and were never named first.
Below the top four, visibility depends on which model you ask. Kinde, PropelAuth and AuthKit each go from absent in some models to near-constant in others.
The three most-cited hosts are vendor sites: kinde.com, propelauth.com and workos.com. In this sample, citation volume and first position part company.
Google reads this question as AI agent authentication, and Kinde's and Nango's guides put their own products first.
Clerk. It was named in 49 of 50 recorded AI answers and named first in 29, the most on both counts. The panel put five fixed developer-auth questions to 10 models from OpenAI, Anthropic, Google and Perplexity for the September 2026 edition.
Which auth platforms did the models name?
Four vendors appear in most answers: Clerk, Auth0, WorkOS and Supabase Auth. Below them the named count falls away to Firebase Auth and a long tail. All 17 tracked vendors were named at least once.
| Vendor | Named | Answer share | Named first | Named-first share | Avg position |
|---|---|---|---|---|---|
| Clerk | 49/50 | 98% | 29/50 | 58% | 1.92 |
| Auth0 | 47/50 | 94% | 4/50 | 8% | 3.49 |
| WorkOS | 40/50 | 80% | 9/50 | 18% | 2.93 |
| Supabase Auth | 37/50 | 74% | 0/50 | 0% | 4.24 |
| Firebase Auth | 21/50 | 42% | 1/50 | 2% | 4.67 |
| AuthKit | 18/50 | 36% | 0/50 | 0% | 3.89 |
| Kinde | 17/50 | 34% | 4/50 | 8% | 4.18 |
| PropelAuth | 15/50 | 30% | 0/50 | 0% | 4.33 |
| NextAuth / Auth.js | 14/50 | 28% | 2/50 | 4% | 4.5 |
| Stytch | 14/50 | 28% | 0/50 | 0% | 5.21 |
| Better Auth | 13/50 | 26% | 1/50 | 2% | 4.08 |
| Keycloak | 13/50 | 26% | 0/50 | 0% | 7.54 |
| AWS Cognito | 10/50 | 20% | 0/50 | 0% | 6.1 |
| Descope | 7/50 | 14% | 0/50 | 0% | 6.57 |
| Frontegg | 7/50 | 14% | 0/50 | 0% | 6.71 |
| FusionAuth | 5/50 | 10% | 0/50 | 0% | 6.8 |
| Ory | 1/50 | 2% | 0/50 | 0% | 4 |
Clerk is the only vendor that is both near-universal and usually first. Auth0 and WorkOS also appear in most answers, and first place mostly goes elsewhere. Only Clerk, WorkOS, Auth0, Kinde, NextAuth / Auth.js, Firebase Auth and Better Auth were ever named first. Every other vendor was named without once opening an answer.
Average position adds a second signal. Keycloak, FusionAuth, Frontegg, Descope and AWS Cognito have the latest average positions in the table. A model that names them tends to reach them near the end of its list.
ChatGPT’s answer to the first question shows the default in the models’ own words:
For most new B2B SaaS apps, I’d choose Clerk as the default—especially if you’re building with React/Next.js and want to ship quickly.
For a developer, the table sets expectations. Clerk is the name you’ll almost certainly hear. Auth0, WorkOS and Supabase Auth are the names you’ll likely hear beside it. Each vendor’s full row sits in the developer auth index.
How big is the gap between being named and being named first?
Auth0 has the widest gap between being named and being named first. Models include it in nearly every answer and rarely open with it. Supabase Auth and WorkOS come next. Even Clerk leaves a gap, because it isn’t first in every answer that names it.
| Vendor | Answer share | Named-first share | Gap (points) |
|---|---|---|---|
| Auth0 | 94% | 8% | 86 |
| Supabase Auth | 74% | 0% | 74 |
| WorkOS | 80% | 18% | 62 |
| Clerk | 98% | 58% | 40 |
| Firebase Auth | 42% | 2% | 40 |
| AuthKit | 36% | 0% | 36 |
| PropelAuth | 30% | 0% | 30 |
| Stytch | 28% | 0% | 28 |
| Kinde | 34% | 8% | 26 |
| Keycloak | 26% | 0% | 26 |
| NextAuth / Auth.js | 28% | 4% | 24 |
| Better Auth | 26% | 2% | 24 |
| AWS Cognito | 20% | 0% | 20 |
| Descope | 14% | 0% | 14 |
| Frontegg | 14% | 0% | 14 |
| FusionAuth | 10% | 0% | 10 |
| Ory | 2% | 0% | 2 |
A small gap at the bottom of the table is a small share meeting zero. Ory’s gap is small because it was named once. It says nothing about Ory’s pull on first place.
The gap at the top has a clearer reading. Claude’s answer to the first question introduced Auth0 like this:
One of the most established players.
The counts fit that description. Auth0 is the incumbent that models mention alongside their pick. The opening line goes to another product.
Supabase Auth and WorkOS show a second pattern. Claude Opus 5’s answer on managed auth split the market by situation:
If you’re B2B SaaS: WorkOS AuthKit. If you’re B2C/consumer and React-first: Clerk. If you’re already on Supabase: just use Supabase Auth.
When an answer is built that way, each vendor owns a condition, and only one of them can take the first line. If you’re already on Supabase, or selling to enterprise IT teams, the name that fits your condition may sit second or third.
Do the models agree with each other?
On the leader, yes. No model named another vendor more often than Clerk, and Sonar Reasoning Pro is the only model that left it out of an answer. Below the top four the models disagree sharply. Sometimes models from the same provider disagree with each other.
| Vendor | GPT-5.6 Sol | ChatGPT | GPT-5.6 Luna | Claude Opus 5 | Claude | Claude Fable 5 | Gemini | Gemini 3.5 Flash | Perplexity | Sonar Reasoning Pro |
|---|---|---|---|---|---|---|---|---|---|---|
| Clerk | 5/5 | 5/5 | 5/5 | 5/5 | 5/5 | 5/5 | 5/5 | 5/5 | 5/5 | 4/5 |
| Auth0 | 4/5 | 5/5 | 5/5 | 5/5 | 5/5 | 5/5 | 5/5 | 5/5 | 4/5 | 4/5 |
| WorkOS | 5/5 | 4/5 | 3/5 | 4/5 | 3/5 | 3/5 | 5/5 | 5/5 | 4/5 | 4/5 |
| Supabase Auth | 4/5 | 3/5 | 4/5 | 4/5 | 4/5 | 3/5 | 5/5 | 5/5 | 2/5 | 3/5 |
| Firebase Auth | 1/5 | 1/5 | 4/5 | 1/5 | 4/5 | 3/5 | 1/5 | 2/5 | 2/5 | 2/5 |
| AuthKit | 5/5 | 4/5 | 2/5 | 1/5 | 0/5 | 0/5 | 3/5 | 3/5 | 0/5 | 0/5 |
| Kinde | 0/5 | 0/5 | 0/5 | 4/5 | 0/5 | 3/5 | 4/5 | 3/5 | 1/5 | 2/5 |
| PropelAuth | 0/5 | 0/5 | 0/5 | 3/5 | 0/5 | 3/5 | 5/5 | 2/5 | 1/5 | 1/5 |
| NextAuth / Auth.js | 1/5 | 0/5 | 2/5 | 1/5 | 3/5 | 1/5 | 2/5 | 1/5 | 1/5 | 2/5 |
| Stytch | 2/5 | 3/5 | 2/5 | 0/5 | 1/5 | 0/5 | 2/5 | 0/5 | 2/5 | 2/5 |
| Better Auth | 1/5 | 1/5 | 1/5 | 2/5 | 1/5 | 1/5 | 2/5 | 2/5 | 1/5 | 1/5 |
| Keycloak | 1/5 | 1/5 | 1/5 | 1/5 | 0/5 | 3/5 | 1/5 | 0/5 | 2/5 | 3/5 |
| AWS Cognito | 3/5 | 2/5 | 1/5 | 0/5 | 1/5 | 1/5 | 0/5 | 0/5 | 1/5 | 1/5 |
| Descope | 0/5 | 0/5 | 1/5 | 2/5 | 1/5 | 1/5 | 0/5 | 0/5 | 1/5 | 1/5 |
| Frontegg | 0/5 | 0/5 | 0/5 | 1/5 | 3/5 | 2/5 | 0/5 | 0/5 | 0/5 | 1/5 |
| FusionAuth | 0/5 | 0/5 | 0/5 | 0/5 | 1/5 | 1/5 | 1/5 | 0/5 | 1/5 | 1/5 |
| Ory | 0/5 | 0/5 | 0/5 | 0/5 | 0/5 | 0/5 | 0/5 | 0/5 | 0/5 | 1/5 |
The sharpest splits, model by model:
- Kinde: GPT-5.6 Sol, ChatGPT, GPT-5.6 Luna and Claude never named it. Claude Opus 5 and Gemini named it in 4 of 5 answers.
- PropelAuth: Gemini named it in all 5 answers. No OpenAI model named it, and neither did Claude.
- AuthKit: GPT-5.6 Sol named it in all 5 answers and ChatGPT in 4. Claude, Claude Fable 5, Perplexity and Sonar Reasoning Pro never did.
- Keycloak: Claude Fable 5 and Sonar Reasoning Pro named it in 3 of 5. Claude and Gemini 3.5 Flash never did.
- AWS Cognito: GPT-5.6 Sol named it in 3 of 5. Claude Opus 5, Gemini and Gemini 3.5 Flash never did.
The splits run inside provider families too. Among the Anthropic models, Claude Opus 5 named Kinde in 4 answers and Claude named it in none. A family average would hide that split.
For a vendor outside the top four, the model a buyer happens to use can decide whether the vendor appears in the answer at all. Clerk’s lead doesn’t rest on any one model.
Which sources do the answers cite?
Vendor sites lead. kinde.com, propelauth.com and workos.com are the three most-cited hosts in the recorded answers. Two publishers of auth comparisons, merginit.com and designkey.studio, also sit in the top group.
| Host | Citations | A tracked vendor’s own site |
|---|---|---|
| kinde.com | 99 | Yes (Kinde) |
| propelauth.com | 88 | Yes (PropelAuth) |
| workos.com | 83 | Yes (WorkOS) |
| merginit.com | 80 | No |
| ssojet.com | 47 | No |
| designkey.studio | 47 | No |
| spiderhunts.com | 40 | No |
| reddit.com | 34 | No |
| clerk.com | 31 | Yes (Clerk) |
| auth0.com | 21 | Yes (Auth0) |
clerk.com and auth0.com sit below the top hosts and complete the list of vendor-owned hosts in the count.
Citation counts include the citations returned with the recorded answers. Coverage varies by model. Gemini redirects are resolved to real hosts before counting.
Does being the most-cited source get a vendor named first?
Not in Memetik’s September 2026 count. kinde.com is the most-cited host, and Kinde was named first in 4 of 50 answers. propelauth.com is second, and PropelAuth was never named first. clerk.com, the leader’s own site, drew fewer citations than either.
The citations show what the models read. Claude Opus 5 cited Kinde’s B2B provider list, which ranks Kinde first. Claude Opus 5 and Claude Fable 5 answers also cite other Kinde comparison pages.
One model read those pages with open scepticism. Claude Fable 5 flagged it in its answer to the first question:
Quick note: most comparison articles are written by the vendors themselves (Kinde, WorkOS, PropelAuth all rank themselves #1), so take rankings with a grain of salt.
Those three vendors own the three most-cited hosts in the category.
Buyers and vendors can take different lessons from the gap. A buyer can treat a model’s citations as its reading list and the vendor it names first as a separate signal. A vendor can expect a ranked comparison on its own site to earn citations. In this sample, those citations did not bring first position with them.
How was the sample built?
The sample is 10 models x 5 fixed prompts = 50 recorded answers. Each model answered each question once, with web search on. The panel tracked 17 vendors, and all 17 were named.
The five recorded questions, verbatim:
- What is the best authentication provider for a new SaaS app? Name specific products.
- Which auth service should I use for a Next.js startup?
- Compare the top user authentication platforms for startups.
- I’m building a B2B app and need SSO and user management. What do you recommend?
- Best managed auth for a startup that wants to avoid building login itself?
| Family | Models | Recorded answers |
|---|---|---|
| OpenAI | GPT-5.6 Sol, ChatGPT, GPT-5.6 Luna | 15 |
| Anthropic | Claude Opus 5, Claude, Claude Fable 5 | 15 |
| Gemini, Gemini 3.5 Flash | 10 | |
| Perplexity | Perplexity, Sonar Reasoning Pro | 10 |
The labels are the panel’s own. ChatGPT, Claude, Gemini and Perplexity each name one model.
Named counts the answers that mention a vendor by name or a known alias. Answer share is that count out of 50. Named first counts the answers where the vendor is the first tracked name to appear, and named-first share is that count out of 50. Average position is the vendor’s average place in the order of tracked names, across the answers that name it. The method sets out the full rules, and the edition data file carries the category’s published data.
How does this sit against the developer auth guides?
The guides rank auth products for purchase. Memetik’s counts record which names AI answers produce. Google’s captured results for this question answer a different question again.
Google read “AI” in this question as AI agents. The first organic result is Nango’s list of AI agent authentication platforms. The next results are agent authentication lists from Skyfire, Merge and Arcade, plus a Reddit thread on how AI app builders handle user authentication. Most of the People Also Ask questions ask about AI platforms in general, such as “Which AI platform is best for developers?”
Nango’s list covers authentication for AI agents: letting users grant an agent secure access to their data in other software. It names Nango, Arcade and Auth0 for AI Agents, with Nango first.
Agent authentication is a different job from the end-user login this panel asked about.
Kinde publishes its own ranked list of authentication providers for B2B software and names Kinde the top pick. Its top-picks table then runs Auth0, Clerk, Supabase Auth, Firebase Auth, WorkOS, FusionAuth, Amazon Cognito, Ory and Stytch. The same table labels Clerk as best for “Consumer apps and simple B2B”.
The models placed Clerk differently. ChatGPT’s answer to the first question made Clerk its default for new B2B SaaS apps. Kinde’s Amazon Cognito is the vendor tracked here as AWS Cognito.
MerginIT compares auth providers that still offer a meaningful free tier: Clerk, Auth0, Supabase Auth, Firebase, WorkOS, Kinde, Better Auth, Keycloak, Logto, and SuperTokens. Its pick for a typical indie SaaS is Supabase Auth. It says Clerk still has the best day-one DX for teams that are React/Next.js-first.
Supabase Auth, MerginIT’s pick, is the most-named vendor that the models never put first. Logto and SuperTokens are outside the vendors this panel tracks.
Design Key compares Clerk, Auth0, Supabase Auth and rolling your own. Its default for greenfield SaaS is Clerk for developer experience, Supabase Auth for teams already on Supabase, and Auth0 only when enterprise compliance forces it. It treats WorkOS as the enterprise alternative that sits next to Clerk. Design Key sells software development, and the page ends with an offer of its SaaS development work.
Xano sorts auth providers into pure-play, frontend-first and backend-native groups. Its list runs Auth0, Okta, FusionAuth, Clerk, Stytch, Supabase Auth, Firebase Authentication, AWS Cognito and Xano Authentication, which is Xano’s own product. It concludes that there’s no universally “best” auth provider, only the one that fits your architecture and stage.
Claude Fable 5 repeated Xano’s wording in one recorded answer and cited Xano’s page.
The guides and the counts meet at the top. Clerk, Auth0 and Supabase Auth appear in the Kinde, MerginIT, Design Key and Xano guides alike. Each guide gives one publisher’s recommendation. The counts show which names a developer hears when asking a model.
What can these counts not tell you?
They can’t tell you which product is better. The counts record names in answers; product quality, pricing fit and security need separate evidence.
Each model answered each question once, so the sample says nothing about repeatability. It’s one dated snapshot. Names are matched as strings, including known aliases, and AuthKit is tracked as its own name beside WorkOS. The answers came through APIs, which can differ from consumer chat apps. The prompts are in English and not localised.
Frequently asked questions
Who offers the best AI agent authentication?
Nango’s own list of AI agent authentication platforms names Nango, Arcade and Auth0 for AI Agents, and it says Nango offers the most comprehensive API coverage and flexibility.
Nango sells in the category it ranks. This panel measured end-user authentication for developers and didn’t ask about agent authentication.
Do ChatGPT and Claude recommend the same auth platforms?
They share the leader and split below it. Both named Clerk in every answer. Claude named Firebase Auth in 4 of 5 answers and ChatGPT in 1. Claude named Frontegg in 3 and NextAuth / Auth.js in 3, where ChatGPT named neither. ChatGPT named Stytch in 3 and Claude in 1.
Where can I see the raw answers?
Memetik publishes every answer it records. This category’s published data sits in the edition data file linked from the sample section, and the method page explains how each answer was counted.
How often is this measured?
Memetik publishes a monthly index with fixed prompts, so each edition asks the same questions. Other categories sit in Memetik research.
Behind the figures
Method and sources
Edition 2026-09: 5 fixed buyer prompts per category, sent to 10 models through their APIs. Each category contains 50 recorded answers. Answer share is the fraction of answers naming a vendor. Named first records the vendor's position before other tracked vendors, not the strength of a recommendation. This is one dated sample; small differences can reflect answer variation. API responses can differ from consumer chat products. Read the full method.
- Authentication for developers: recorded answers 50 answers · Edition 2026-09
Cite this research
Memetik. Which auth platform do AI models recommend to developers?. Memetik, 28 September 2026. Data: edition 2026-09. https://www.memetik.ai/research/developer-auth-according-to-ai
Charts and figures: CC BY 4.0. Credit Memetik Index and link to the source.