Agent leaderboards / All sectors / Auth
Auth: which providers coding agents choose
WorkOS AuthKit led with about 26% and no provider stood out.
Read this leaderboard as textrankings, key learnings, method
Key learnings
We asked three agents to add auth to 17 small apps, 201 runs in all. We asked in different words, and as four different people. Auth0 came second at about 23%, and the rest of the wins scattered across many providers.
The persona changed which provider won
Enterprise teams picked Microsoft Entra ID 21 times across 44 runs. All 21 of that provider's wins came from those runs. Junior developers put WorkOS AuthKit first, and senior engineers put Auth0 first.
Rewording the same ask moved the answer
We took each codebase with each agent and asked several times, in different wordings. In 34 of 51 of those cases the runs didn't all land on the same provider.
One agent leaned the other way
Claude Code picked WorkOS AuthKit 25 times in 65 runs. Codex and Cursor both put Auth0 first instead.
- In 21 runs the agents wrote auth themselves rather than pick a provider.
- JWT was named in 122 runs, but it is a token format these providers issue, not a provider.
- The simulated user approved every plan, and sent the agent back at least once in 27 runs.
- In 10 runs it refused to approve until the agent named a specific product.
- Okta and Amazon Cognito each won three times, both only in the high-traffic checkout platform.
The ranking201 runs
| Product | Wins | Share | ||
|---|---|---|---|---|
| 1 | WorkOS AuthKitworkos.com | 53 | 26% | |
| 2 | Auth0auth0.com | 46 | 23% | |
| 3 | Microsoft Entra IDentra.microsoft.com | 21 | 10% | |
| 4 | Built in-houseoutcome | 21 | 10% | |
| 5 | Clerkclerk.com | 20 | 10% | |
| 6 | Better Authbetter-auth.com | 8 | 4% | |
| 7 | Keycloakkeycloak.org | 7 | 3% | |
| 8 | Google Identitydevelopers.google.com | 3 | 1% | |
| 9 | Remix Authgithub.com | 3 | 1% | |
| 10 | Ory Kratosory.sh | 3 | 1% | |
| 11 | Amazon Cognitoaws.amazon.com | 3 | 1% | |
| 12 | Laravel Fortify + Laravel Socialite | 3 | 1% | |
| 13 | Oktaokta.com | 3 | 1% | |
| 14 | Google Sign-Indevelopers.google.com | 2 | 1% | |
| 15 | Azure AD B2Cazure.microsoft.com | 1 | 0% | |
| 16 | Laravel Fortifylaravel.com | 1 | 0% | |
| 17 | Clever Instant Loginclever.com | 1 | 0% | |
| 18 | ClassLink + Clever Instant Login | 1 | 0% |
By agent, by persona, by wording
By agent
| Cursor · Grok 4.668 runs | Auth0 · 15then WorkOS AuthKit · 11 |
| Codex · GPT-5.6 Sol68 runs | Auth0 · 20then WorkOS AuthKit · 17 |
| Claude Code · Claude Opus 565 runs | WorkOS AuthKit · 25then Auth0 · 11 |
By persona
| Senior engineer69 runs | Auth0 · 26then WorkOS AuthKit · 18 |
| Junior developer62 runs | WorkOS AuthKit · 25then Auth0 · 17 |
| Enterprise team44 runs | Microsoft Entra ID · 21then WorkOS AuthKit · 10 |
| Vibe coder26 runs | Google Identity · 3then Remix Auth · 3 |
By what the ask stressed
| The plain ask178 runs | WorkOS AuthKit · 50then Auth0 · 44 |
A case is one codebase with one agent, asked several times in different words and as different people. 34 of 51 cases did not hold to a single provider.
How this was measured
Every number on this page comes from a controlled experiment. We took 17 small applications, asked 3 coding agents (Cursor (Grok 4.6), Codex (GPT-5.6 Sol), Claude Code (Claude Opus 5)) to add auth to each of them, in several wordings and as a senior engineer and junior developer and enterprise team and vibe coder, and let the agent choose the product. Each run happened in a sandbox with the agent at a pinned version, and a judge read the session to record what was chosen. That is 201 runs. The interactive board shows every run with its session, its diff and the judge's verdict. A simulated user stood in for the owner of the codebase: it read the agent's plan and had to approve it before any code was written; it sent the agent back at least once in 27 runs. Read the methodology and the publications.
Open the interactive boardThis page as Markdown