Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Better Auth has raised $5M. I don’t think it’s great to see a truly free project get absorbed into a commercial venture.


> I don’t think it’s great to see a truly free project get absorbed into a commercial venture.

Auth.js and NextAuth.js didn't seem to be in a healthy state. Work on NextAuth.js v5 began way back in May 2023.[1][2] NextAuth.js v5 was renamed to Auth.js in August 2023.[3] v5.0.0-beta.0 was released in October 2023.[4] Balázs Orbán, the main contributor to Auth.js and NextAuth.js, quit in January 2025.[5][6] v5 is still in beta after all this time. It never had a stable release.

[1] https://github.com/nextauthjs/next-auth/pull/7443

[2] https://github.com/nextauthjs/next-auth/discussions/8487

[3] https://github.com/nextauthjs/next-auth/commit/a996ab57e8ffc...

[4] https://www.npmjs.com/package/next-auth/v/5.0.0-beta.0

[5] https://github.com/nextauthjs/next-auth/commits?author=balaz...

[6] https://x.com/balazsorban44/status/1943635445235040488


That may be true but doesn't contradict the point of the parent commenter.

If Auth.js wanted to give up, that would be fine (although disappointing, since multiple options is always healthy, especially for something as critical as auth)

but this deal where they are "becoming part of BetterAuth" and recommending that new users use BetterAuth on the project README is concerning to me


Fair concern but I don’t think Auth.js was ever “truly free,” considering it was supported by many companies (big or small) including someone like Clerk even running ads on the docs site.

We started Better Auth with the vision of making high-quality auth (with simple abstractions, great docs, extensive set of features...) and make it accessible to everyone . It didn’t start as a commercial venture, at first it was a purely oss project I created. The reason it evolved into a commercial venture is that we saw new ways to make owning your auth even more accessible and scalable for companies.

The reason we’re bringing Auth.js under Better Auth is that the Auth.js team is moving on, and we don’t want the project to be abandoned, that would hurt trust in open-source auth as a whole. We’ve already seen that happen at smaller scaller with Lucia. If that weren’t the case, we’d actually benefit from Auth.js being deprecated, since we’re effectively the next most people would go for and we wouldn't have to take this risk and responsibilities.


Not only is Auth.js truly free, it's truly abandoned.


Exactly


Full disclosure, I work for FusionAuth, a commercial auth vendor which sponsored NextAuth.

People gotta eat. It's not like NextAuth didn't have commercial support from sponsors. I'm not privy to the details of how much money was involved, but you can read other comments about Clerk and Vercel and how they influenced the project.

I wrote more about the difficulties of OSS business models here a few years ago: https://www.mooreds.com/wordpress/archives/3438


while i agree, in this case at least it looks like the money raised is for a future SaaS auth solution built on top of the open-source project


Which will invariably lead to that open source project to become less and less useful if implemented separately from the SaaS platform. I’ve seen this game plan often enough.

Good for them, bad for the rest of us.


> I’ve seen this game plan often enough.

I probably haven't been around as long as you. Could you provide an example of one that comes to mind?


Auth.js: Vercel hired the lead dev and it stopped improving, leading to better-auth


Isn’t Vercel’s CEO an investor of Clerk? A direct competitor to all these FOSS auth libraries.


Yes, see: https://news.ycombinator.com/item?id=45393382

Now better-auth had raised $5M so they can't undercut Clerky by too much or they'll fail


Time for Vercel to hire the lead dev of Better Auth next?


I bet Vercel buys better-auth and makes it a first party auth solution


thebestmotherfuckingauth.com


Elasticsearch

Redis

Mongo

Bitnami


Gitlab

SourceGraph


Cockroach


prisma


We all know how this ends. The open source project ends up being crippled to the point it's no longer useful.


Not outright crippled; just strategically neglected compared to the paid variant, unless it’s effectively useless without paying. And then Vercel steps in, buys the whole thing, and Better Auth becomes „Next.js“ first, ideally only fully effective on Vercel.


I would say once a company becomes vc funded, it will have some different priorities.

Although Deno seems to be working out good so far. They are providing value to the general JS eco system. And yes there is Deno deploy, but competent sysadmin and DevOP people will have no trouble running it on their own and scaling.


Thing is though, where will they get their returns?

consulting? deploy hosted? (why not just use cf workers/vercel/etc.)

if there was a way for the industry to support these things by everyone pitching in, that'd probably be the best but I don't see that happening soon




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: