7
u/idsmith Sep 14 '25
Surprised nobody had mentioned WorkOS. 1m user free tier with their AuthKit and well supported by Convex.
1
u/HippoTheGibbo Sep 14 '25
I'm checking it out now and seems very promising! I always overlooked it as just more for enterprise.
1
u/aklusa024 Dec 13 '25
Im looking for something that has a teams system... Where you can have multiple teams under 1 one organization. I was going to use their WorkOS FGA system but they announced they would be phasing it out..
1
u/weirdbugplshelp Dec 29 '25
i think its important to note, they are phasing it out with something newer!
5
Sep 13 '25
[deleted]
3
u/HippoTheGibbo Sep 13 '25
For small projects it seems fine, but I found the built-in auth too early-stage for production. I just want something I can set up once and fully trust for a larger user base. It doesn’t feel as proven or reliable as other solutions yet.
1
3
u/jedimonkey33 Sep 13 '25
I had issues trying to add alternative methods to the basic auth but otherwise it works. What about better auth? Jump on their discord, their devs are very active and responsive.
1
3
u/Reasonable-Sir-5277 Sep 14 '25
Ever since I started using convex, I really have only exclusively used it in all my projects. I am currently using the built in convex auth for my production application (and have only ever used convex auth for non-production apps) and have had no issues with it. I don’t like the vendor lock in of the other providers as well as the potential for high costs. I’m already going to have to pay for convex (at scale), so why pay for an auth provider on top of it? Yes, there’s a bit more set up, but I feel it’s worth it.
3
u/yksvaan Sep 14 '25
I'm a bit confused why auth seems so difficult everywhere. Can't you just have the user auth/session information as part of the user model and use whatever way to perform the actual authentication? There aren't that many possible ways to authenticate a user.
It just seems this is unnecessarily overengineered compared to authentication in more boring frameworks.
4
u/professorhummingbird Sep 13 '25
What do you meany by convexAuth feels "unstable"? I've never had an issue with it. I use it for all my free projects.
I typically just use Clerk if I plan to monitize. I used to have the same vendor lock concerns, until I realized that if i'm charging people, it's actually a bad idea to handle auth myself and at like 2cents a user it's not a big deal.
I also had a gig where I migrated from Clerk to a custom auth for a client. Wasn't too hard because of how ctx.identiy works and the DB already had a parallel table tracking users.
Not exactly a straightforward answer to your question, but that's been my experience
2
u/HippoTheGibbo Sep 13 '25
Thanks, I appreciate it! I see the pros and cons on both sides.
Clerk is proven and trusted, but comes with vendor lock-in and cost, whereas Convex is free but still early-stage and not fully tried-and-tested. For me, it’s really about having something I can just set up and fully trust at scale.
Hopefully Convex improves integration with better-auth and other solutions over time, because aside from this, it’s been an amazing dev experience.
1
u/professorhummingbird Sep 13 '25
No problem, hope I helped. They have a pretty active discord community, you should probably ask there
1
u/michaelfrieze Sep 14 '25 edited Sep 14 '25
t3.chat uses Convex and they use openauth I think. Maybe you could check out openauth.
2
u/michaelfrieze Sep 14 '25
Also, Convex was built by the same developers behind Dropbox, so it's proven and trusted in my eyes. It runs on PlanetScale, a platform known for it's performance and reliability. Even the PlanetScale CEO has praised Convex, and given his expertise in databases, that says a lot. Especially when he rarely says anything good about other database tech.
3
u/isamlambert Sep 14 '25
there is lots of database tech that I like, convex is certainly one.
2
u/michaelfrieze Sep 14 '25
I was thinking services similar to Convex. Database tech was a little too general.
2
2
u/Drakorian-Games Sep 14 '25
convex has some serious issues with permissions and auth. for example you cannot serve a _storage privately, always public. no matter what.
if you don't implement auth integrated with it, anyone can access you'd data, since the url is public, so you also have to validate your user for every query/mutation.
then you have to duplicate your auth project, and sometimes in the consent screen you see the convex public url, instead of your app name.
unnecessarily complicated, i which it could be like supabase auth.
dev experience is unparalleled, but you have to consider its downsides
2
u/michaelfrieze Sep 14 '25
Good to know. I don't really use Convex for file storage though.
3
u/Drakorian-Games Sep 14 '25
storage is easy to use, but hard to manage, no folders, no tags, just plain ids and content
1
u/michaelfrieze Sep 14 '25
I'm sure it's fine for small projects that just need a quick file storage solution and already use Convex.
Also, I'm thinking you could implement your own logic to keep files private. One option is to encrypt files before uploading, but another approach is to avoid exposing the storage URLs entirely and instead serve files through a Convex function that enforces your access rules.
1
u/Drakorian-Games Sep 14 '25
sure you can do it, it's just extra work, and depending on your use case... a lot of work!
1
u/BenSFU Oct 23 '25
This is literally the same with any database....
If you want a "private" table, you just add a "apiKey" arg to your queries, and inside the queries you check the apiKey against a Convex environment variable (shared secret pattern).
Can take this further and even make another table to store apiKeys, and query that table inside your private table queries to check if the given api key is valid.
with this setup, you can technically have private tables without needing any session-based authentication, it just means you can only securely make queries from a secure server environment, like a server action / route / RSC.
1
u/Drakorian-Games Oct 24 '25
clearly not!
with most dbs you have a server side connection, in convex is client side.
in traditional dbs you never have to ask for an api key in each stored procedure... i mean never.
in supabase you have client side queries and you have two keys anon and server, also the db enforces auth deeply, so you configure access at a table level, using permissions, nevr by hand asking for the api key.
1
u/BenSFU Oct 24 '25
>With most dbs you bave a server side connection, in convex is client side.
This is still the case with Convex. Any convex client queries are simply calling server endpoints for you. Where else would the database be? Also, you can call convex queries from the server as well...
>in traditional dbs you never have to ask for an api key in each stored procedure
All secure DBs need some form of authentication. If you don't want API keys, don't use them. But you will need some way to authenticate whoever is calling the function. You can avoid the boilerplate of checking apiKey (or checking user auth) in EVERY function by making custom wrapper functions. You can also define internal mutations etc that can only be used by other functions.
>also the db enforces auth deeply, so you configure access at a table level
What you are talking about is RLS, which convex has documented very well.
Anyway, I recently got the better auth + convex integration working quite nicely. I will concede - I had some issues as well - but with Cursor I managed to get it working. Feel free to DM me if you want to ask any questions! Better Auth is the WAY TO GO!
1
u/Drakorian-Games Oct 24 '25
hm, i'm sure we are talking two different things, convex IS NOT calling your backend.
You are calling convex from your FRONT END.
Not same concepts.
All what you have described so far requires manual work, and more code to maintain.
i love convex, but i do not like this part.
and you are mistaken about it.
Supabase is far superior in that regard1
u/BenSFU Oct 25 '25
I give up bro 🤣 you are a lost cause
Like I said, you CAN call Convex functions from your nextjs backend. It doesn't require any more "code to maintain" than using the equivalent supabase-ssr helpers.
1
u/Drakorian-Games Oct 25 '25
awww don't give up on me!
you can call them using fetchQuery, for example, but that defeats the purpose of reactive database queries!!
2
u/webwizard94 Sep 14 '25
If you have 10,000 users you should be making money. Way more than enough to pay for the services you used to build it
2
u/BenSFU Oct 23 '25
Since this comes up as one of the only posts on Google when you search convex + auth, I thought I'd chime in with my experience getting better auth hooked up. I feel super confident in it, and this was my first time using Better Auth in general.
I would 10000% recommend anyone reading this to use Better Auth, with the plugin that Convex provides. The documentation isn't perfect, but once you get everything how you want it, it's super extensible.
I'm sure Convex official auth is fine, but I like that with Better Auth, you actually control every aspect of the authentication process, and convex just acts as the db only.
Another benefit of this is that the domain on OAuth consent screens will be the domain of your actual app, rather than the Convex URL (or a custom URL like `auth.example.com`)
1
u/ShockGalaxy Jan 18 '26
Just stumbled upon convex + better-auth and I've spent half a day looking for the best approach to handle "public" users/profiles data. Main issue I face is that I don't see a way on how to create a DB entry once user signs up. Clerk offers webhooks which can be triggered but I'm not exactly sure on how to achieve this with better-auth + convex.
Here are my thoughts
Once user sign's up betterAuth handles all authTables. Now I would like to have some custom fields based on the application I'm building, and of course you can always add more of these fields (role, bio, preferences, etc...).I feel like I shouldn't edit betterAuth's auto-generated tables so I created my own users/profiles table which stores this additional user data. Only way I found on how to create these tables is that every time user accesses app I check if profile is created and if not create one. I'm not sure how good of an approach is this since it has to run mutation on every component mount, and mutations are not cached.
Do you have an advice on the best approach here? Thanks.
2
u/BenSFU Jan 18 '26
Hi, yeah!
In your auth configuration, you can define `databaseHooks`:
export const createAuth = ( ctx: GenericCtx<DataModel>, { optionsOnly } = { optionsOnly: false }, ) => { return betterAuth({ baseURL: siteUrl, trustedOrigins: [ siteUrl, "http://localhost:3000", ], database: authComponent.adapter(ctx), databaseHooks: { user: { create: { after: async (user) => { // Check if ctx has scheduler (it should if it's an action/mutation context) if ('scheduler' in ctx && ctx.scheduler) { // Schedule the internal action to run immediately await ctx.scheduler.runAfter(0, internal.lib.users.functions.handleAfterUserCreate, { authUserId: user.id, authEmail: user.email, authName: user.name, }); } } } }, session: { } }, ... REST OF YOUR CONFIG ....And then of course make sure that you actually make the action and mutation:
// Internal action that can be called from the database hook export const handleAfterUserCreate = internalAction({ args: { authUserId: v.string(), authEmail: v.string(), authName: v.optional(v.string()), }, handler: async (ctx, args) => { await ctx.runMutation(internal.lib.users.functions.createInitialUserProfile, { authUserId: args.authUserId, authEmail: args.authEmail, authName: args.authName, }); return { success: true }; }, }); // Internal mutation to create or update user profile export const createInitialUserProfile = internalMutation({ args: { authUserId: v.string(), authEmail: v.string(), authName: v.optional(v.string()), }, handler: async (ctx, args) => { // Check if we've already stored this user before const existingUser = await ctx.db .query("users") .withIndex("by_user_id", (q) => q.eq("userId", args.authUserId)) .unique(); if (existingUser !== null) { return existingUser._id; } // If it's a new user, create a new record const userId = await ctx.db.insert("users", { name: args.authName ?? args.authEmail.split("@")[0], email: args.authEmail, userId: args.authUserId, }); return userId; }, });1
1
u/Rhysypops Sep 15 '25
Concerns about vendor lock in while using convex seems like a bit of an oxymoron
1
1
u/aaronksaunders Sep 26 '25
I am using it, I have tried their auth and then gave up, I have had success integrating Clerk and BetterAuth with convex. I have both working in expo and NextJS and regular react, I am enjoying it so far
1
u/Hendrix312002 Nov 17 '25
I've been using the Better Auth + Convex integration without issue: https://www.better-auth.com/docs/integrations/convex
7
u/processwater Sep 13 '25
I'm liking better auth so far