Better Auth Joins Vercel: What It Means for the Auth Ecosystem

TL;DR
Vercel acquires the open-source authentication framework that became the go-to Next.js auth solution. HN weighs in on open source sustainability and vendor lock-in concerns.
Official Sources#
| Resource | Link |
|---|---|
| Better Auth Joins Vercel Announcement | better-auth.com/blog/better-auth-joins-vercel |
| Better Auth Documentation | better-auth.com/docs |
| Better Auth GitHub | github.com/better-auth/better-auth |
| Vercel Blog | vercel.com/blog |
| Auth.js Documentation | authjs.dev |
Better Auth, the framework-agnostic authentication library that grew from a side project to the default auth choice for many Next.js developers, is joining Vercel. The announcement dropped today and immediately hit the Hacker News front page.
What Is Better Auth?#
Better Auth is an open-source authentication framework created by Bereket Engida. Unlike managed auth services, it runs in your own backend and lets you own your user data. It supports:
- Multiple auth providers (OAuth, email/password, passkeys)
- Multi-tenant organizations
- RBAC and permissions
- Database adapters for Postgres, MySQL, SQLite, MongoDB
- Framework adapters for Next.js, Nuxt, SvelteKit, and more
The project launched in September 2024 and quickly gained traction. It filled a gap left by Auth.js (formerly NextAuth.js), which many developers found difficult to extend for complex use cases like multi-tenant organizations.
In a notable move, Better Auth recently acquired Auth.js/NextAuth.js itself - the library that Engida originally used before building Better Auth.
The Vercel Acquisition#
According to the announcement, Vercel will provide resources for Engida to focus full-time on the open-source framework. The partnership also includes work on an "Agent Auth Protocol" for AI agent authentication - a timely focus as agentic workflows become more common.
Vercel's post emphasizes that Better Auth will remain "open source, framework and platform agnostic."
What HN Is Saying#
The Hacker News thread (discussion link) surfaced familiar tensions around open source acquisitions.
The skeptics showed up immediately. One commenter wrote: "So, it's just a matter of time until they destroy this project in favour of their cloud interests." Another said they nearly used Better Auth recently and are "so glad I dodged the bullet."
The roll-your-own contingent made their case. "Auth is not hard to roll yourself. Crypto: don't do it. Auth? Easy peasy," claimed one developer. Others pushed back hard, pointing out that auth extends far beyond username/password - you need account recovery, MFA, passkeys, registration flows, progressive profiling, SAML integration, and more. "You're distracted from your core application by feature requests for your login system."
KeyCloak got multiple mentions as the safer long-term bet. It's a CNCF project, so there's no acquisition risk. But commenters noted it "shows its age" with a clunky interface and some uptime issues.
The Ory stack discussion got heated. One developer complained that self-hosted Ory is "aggressively gimped" with SSO features locked behind licensing. An Ory team member responded defensively, pointing out that "open source development needs to be paid by someone."
Some developers see the upside. "Better Auth is great, I use it for all my projects. Congrats to the team!" Multiple people noted that Better Auth already maintained next-auth security patches, so Vercel involvement could mean more resources for the ecosystem.
The LLM angle emerged. One commenter joked about rolling auth with LLMs, prompting a reply: "It's one of those things you shouldn't trust LLMs to such an extent; that part should be very solid because the consequences of bad practices are getting to front page of hacker news."
The Broader Pattern#
This acquisition fits a pattern we've seen repeatedly in the developer tools space. An open-source project gains traction by solving a real problem. The maintainer(s) get stretched thin between maintenance and monetization. A larger company acquires them, promising resources and continued open-source commitment.
Sometimes it works out (React under Facebook, TypeScript under Microsoft). Sometimes the community feels burned (the Ory discussion in this thread provides a counterexample).
The key question for Better Auth users: will Vercel keep the framework truly platform-agnostic? Better Auth's database adapters mean it's relatively easy to switch providers if things go sideways. But auth is deeply integrated into applications - migration is never painless.
What This Means for Developers#
If you're already using Better Auth: The short-term outlook is positive. More full-time focus on the framework, no immediate changes to the open-source model. Watch for any dependencies on Vercel-specific features over the next 6-12 months.
If you're choosing an auth solution today:
- Better Auth remains a solid choice if you want to own your auth layer. The Vercel backing could mean better long-term maintenance.
- KeyCloak (CNCF) is the safe choice if you want zero acquisition risk and need enterprise features like SAML/SCIM.
- Managed services (Auth0, Clerk, FusionAuth) trade vendor lock-in for reduced maintenance burden.
- Roll your own makes sense for internal apps or if you have specific requirements that libraries can't meet.
If your stack is already moving toward Vercel's agent tooling, it's worth reading about the Agent Auth Protocol context in Vercel's broader agentic infrastructure stack and how it fits alongside a database layer like Neon Postgres if you're picking a full backend, not just an auth library.
My Take#
The acquisition makes strategic sense for Vercel. Auth is a pain point for Next.js developers, and owning the solution (plus the agent auth protocol work) strengthens their platform story.
For the open-source ecosystem, the acquisition of Auth.js by Better Auth, followed by Vercel acquiring Better Auth, consolidates a lot of the JavaScript auth ecosystem under one roof. That's either efficient or concerning depending on your perspective.
The HN thread reveals a real tension: developers want open-source solutions maintained by full-time engineers, but they're suspicious when money enters the picture. There's no easy answer here. Somebody has to pay for the work.
Better Auth's framework-agnostic design and database adapter model mean you're not locked to Vercel's infrastructure. That's the right kind of portability to have when your auth provider gets acquired.
FAQ#
Is Better Auth still open source after the Vercel acquisition?#
Yes. Vercel's announcement states Better Auth will remain open source and framework/platform agnostic. The database adapter model means it is not tied to Vercel-specific infrastructure.
Does this affect projects already using Better Auth?#
Not in the short term. The framework's API and self-hosted model are unchanged. Teams should watch for any new features that lean on Vercel-specific infrastructure over the next 6-12 months.
What is the "Agent Auth Protocol" mentioned in the announcement?#
It is a joint effort between Better Auth and Vercel focused on authentication for AI agents rather than human users, addressing how agents authenticate and are authorized to act on a user's behalf.
What are the alternatives to Better Auth?#
KeyCloak (a CNCF project, no acquisition risk), managed services like Auth0 or Clerk, and Auth.js (which Better Auth itself acquired) are the main alternatives, each trading off self-hosting control against maintenance burden.
Continue Reading#
- Adam (YC W25): Open Source AI CAD That Generates OpenSCAD from Text
- Vercel Passport Is GA: Deployments That Know Who Your Users Are
Sources#
Get the next deep dive like this in your inbox
One email a week on News and the rest of the AI dev stack. Free.
Read next
Gleam Moves to Tangled: What the ATProto Code Forge Means for Developers
The Gleam programming language has migrated to Tangled, a new ATProto-based code hosting platform. Here's what this means for developers and the future of decentralized forges.
6 min readOpen-Weight AI's Kubernetes Moment: Why the Ecosystem Will Win
Tobi Knaup, co-founder of Mesosphere, argues that open-weight AI has reached the same inflection point as Kubernetes in 2014. We break down the argument, the HN reaction, and what it means for developers building on open models.
8 min readGodot Bans AI-Authored Code Contributions - What It Means for Open Source
The Godot Foundation has established a policy banning autonomous AI agent code and substantial AI-generated contributions, citing reviewer burnout and concerns about maintainer mentorship.
6 min readNew here? Start with
Technical content at the intersection of AI and development. Building with AI agents, Claude Code, and modern dev tools - then showing you exactly how it works.






