~/tools/supertokens
tool

SuperTokens

SuperTokens is an open source authentication and session management platform you self-host — an Auth0 and Firebase Authentication alternative that adds login, sessions, and MFA to your app through SDKs, keeping your user data on your own database.

What is SuperTokens?

SuperTokens is an open source authentication and session management platform that you add to your app with backend and frontend SDKs. A core service (written in Java, run as an HTTP service) holds the auth logic and talks to your own database, so you keep 100% of your user data instead of handing it to a login provider like Auth0 or Firebase Authentication.

What is SuperTokens best for?

Developers who want to own their login flows and user data without building auth from scratch. It fits teams that would otherwise reach for Auth0 or Amazon Cognito but don’t want per-user cloud pricing, and who prefer wiring auth into their app with SDKs rather than redirecting users to a hosted identity provider.

What can SuperTokens do?

  • Email/password login with configurable password policies
  • Passwordless login via magic links and OTP (email or SMS)
  • Social login and enterprise SSO (SAML)
  • Session management with rotating refresh tokens and configurable limits
  • Multi-factor authentication (MFA) and account linking
  • Multi-tenancy for serving multiple organizations from one deployment
  • User roles, permissions, and microservice (machine-to-machine) auth
  • SDKs for 25+ frameworks — Node.js, Python, Go on the backend; React, Angular, Vue, and mobile on the frontend

Where does SuperTokens fall short?

  • It’s open-core, not fully free. The core auth (email/password, social, passwordless, sessions) is Apache-2.0 and free at any user count, but MFA, account linking, and multi-tenancy are paid add-ons that require a license key even when you self-host — MFA is $0.01/MAU, account linking $0.005/MAU, both with a $100/month minimum.
  • It’s SDK-first, not a drop-in identity server. You integrate it into your app’s backend and frontend code, so it’s a heavier lift than dropping in a standalone IdP with a ready-made admin console and login UI like Keycloak.
  • The core runs on the JVM, which carries a higher baseline memory footprint than a lightweight Go or Rust service — worth planning for on small hosts.

Is SuperTokens free?

Partly. The open source core is free to self-host with unlimited monthly active users, covering email/password, social, and passwordless login plus session management. Advanced features — MFA, account linking, multi-tenancy — are paid even self-hosted. The managed cloud is $0.02/MAU with a $100/month minimum.

What does SuperTokens replace?

SuperTokens is a self-hosted alternative to Auth0, Okta, Firebase Authentication, and Amazon Cognito. It handles the same login, session, and MFA jobs, but runs on your infrastructure against your own database instead of billing per active user for a hosted service.

FAQ

Is SuperTokens open source? Yes — the core is licensed under Apache-2.0 and the code is public. Some enterprise features live under separate terms in the repo’s ee/ directory and require a paid license.

Can I self-host SuperTokens for free? Yes, for the core. Self-hosting email/password, social, and passwordless login plus sessions is free with no user-count limit. MFA, account linking, and multi-tenancy require a paid license even when self-hosted.

Is SuperTokens a good Auth0 alternative? For teams that want data ownership and predictable cost, yes — the free core scales to unlimited users. If you need a fully hosted, zero-integration identity platform, Auth0 or Cognito may be less work upfront.

What do I need to run SuperTokens? The core service (via Docker) plus a database (PostgreSQL or MySQL), and the backend/frontend SDKs integrated into your app. Compare it with other self-hostable identity servers like authentik.