Hanko
Hanko is an open source authentication and user management server built around passkeys — a self-hostable alternative to Auth0, Clerk, and WorkOS that gives your app passwordless login, MFA, and SSO with drop-in web components.
What is Hanko?
Hanko is an open source authentication and user management server that puts passkeys first. It handles sign-up, login, and account management for your web and mobile apps through a Go backend API and framework-agnostic web components, so you don’t build passwordless auth from scratch. It’s a self-hostable alternative to Auth0, Clerk, and WorkOS.
What is Hanko best for?
Teams building modern apps that want passkey and passwordless login as the default, not an afterthought — without handing user data to a third-party identity provider. It fits developers who want to drop in a login flow in minutes and self-host for full data control, especially teams with EU/GDPR obligations, since Hanko is built by a Germany-based team with EU hosting options.
What can Hanko do?
- Authenticate with passkeys (WebAuthn/FIDO2), email passcodes, and passwords
- Add multi-factor auth with TOTP authenticator apps and security keys
- Offer social login (Google, Apple, GitHub, custom OIDC) and SAML enterprise SSO
- Drop in Hanko Elements — CSS-customizable web components for login, registration, and profile that work with React, Vue, Angular, Svelte, Next.js, and plain HTML
- Issue JWTs and manage sessions, with webhooks and remote session revocation
- Build fully custom auth UIs against the Flow API and Frontend SDK
Where does Hanko fall short?
- Org/roles/permissions aren’t here yet. Organizations, roles, and permissions are still in development, so multi-tenant B2B apps that need built-in RBAC may find it thinner than WorkOS or Auth0 today.
- Native mobile SDKs are on the roadmap, not shipped. iOS, Android, React Native, and Flutter SDKs are planned; for now mobile integration leans on the web components and API.
- Split licensing has commercial caveats. The backend is AGPL-3.0 (copyleft), while the frontend elements and SDK are MIT — teams that can’t accept AGPL for a modified, network-served backend need a separate commercial license.
Is Hanko free?
Yes — the self-hosted server is free and open source, and you only pay for your own infrastructure. Hanko Cloud is the managed option: a free Starter tier covers 10,000 monthly active users and 2 projects, Pro is $29/month plus $0.01 per MAU above 10,000 (SAML SSO is $49/mo per connection), and Enterprise is custom-priced with an SLA and private cloud.
What does Hanko replace?
Hanko is a self-hosted alternative to Auth0, Okta, Clerk, and WorkOS. It does the same identity job — login, MFA, and SSO — but you run it on your own infrastructure, keep the user data, and skip per-MAU cloud pricing. If you’ve compared it to other open source options, it sits alongside Logto, SuperTokens, and Keycloak, with a sharper focus on passkeys.
FAQ
Is Hanko open source? Yes. The backend is licensed under AGPL-3.0 and the frontend elements and SDK under MIT, with all code public on GitHub. A commercial license is available for teams that can’t use AGPL.
Can I self-host Hanko for free? Yes. Self-hosting is free on bare metal or Docker; you only pay for the server. Hanko Cloud is the paid, managed alternative with a free tier up to 10,000 MAU.
Is Hanko a good Auth0 alternative? For teams that want passkey-first, passwordless login and data control, yes — and self-hosting avoids per-MAU pricing. If you need mature org/roles/permissions or native mobile SDKs today, check that those gaps aren’t blockers first.
What do I need to run Hanko? A server with Docker (or a Go binary), a PostgreSQL database, and SMTP for sending email passcodes. Passkeys require your app to be served over HTTPS.