Two newer options bracket Auth.js 259,565 . Clerk 11,600 is a hosted service that gives you the whole thing — sign-up screens, multi-factor, organizations, an admin dashboard — for money and a dependency on someone else's uptime. Better Auth 178,426 is a self-hosted framework that owns your schema and ships sessions, passwords and two-factor.
// lib/auth.ts
export const auth = betterAuth({
database: prismaAdapter(new PrismaClient()),
emailAndPassword: { enabled: true },
});
// app/api/auth/[...all]/route.ts
export const { GET, POST } = toNextJsHandler(auth);
// anywhere on the server
const session = await auth.api.getSession({ headers: await headers() });That last line takes headers rather than a cookie store, so it works unchanged in pages, actions and route handlers. Better Auth's documentation makes this section's point for it: in proxy.ts use getSessionCookie(), which reads the cookie without validating it, purely to redirect. Clerk inverts the split — @clerk/nextjs ships <ClerkProvider>, <SignIn /> and a server-side auth() returning { userId, redirectToSignIn }, and the password hashes live at Clerk rather than in your MongoDB 1,815 .
| Auth.js | Better Auth | Clerk | |
|---|---|---|---|
| npm 2,036 version | 5.0.0-beta.32 | 1.7.5 | 7.9.4 |
| License | MIT | MIT | MIT client, hosted service |
| Data lives | your database | your database | Clerk's servers |
| Sign-in UI | you write it | you write it | shipped components |
| Cost | free | free | free to 50,000 users |
Clerk's Pro tier is $25 per month (September 2026) covering 50,000 monthly retained users, then $0.02 per extra user; B2B organizations add $100 per month. "Retained" excludes visitors who never come back.
Choose on the basis of who should own the password hashes: if the answer is "not us, ever", Clerk removes a whole category of incident.