Agent leaderboards / All sectors / Auth
Auth: which providers coding agents choose
No provider stood out: WorkOS AuthKit led with about 26% of runs.
Read this leaderboard as textrankings, key learnings, method
Key learnings
We asked three agents to add auth to 17 small apps, 201 runs in all, in several wordings and as four kinds of user. Auth0 came second with about 23%. Below those two the picks scatter across a dozen providers.
Most cases changed answer with the wording
A case is one codebase with one agent, asked again in different words. Of 51 cases, 34 did not settle on one provider. Same code, same agent, different answer.
One kind of user carried a whole provider
Enterprise teams picked Microsoft Entra ID 21 times. That is every win it got in the sector. No other persona chose it once.
The agents disagreed about the top pick
Cursor and Codex both put Auth0 first. Claude Code picked WorkOS AuthKit 25 times in 65 runs, with Auth0 second.
One provider came up often and never won
Supabase Auth was named in 69 runs and chosen in none of them.
- The agents wrote auth themselves in 21 runs, about 10% of the total.
- JWT came up 122 times, but it is a token format these providers issue, not a provider.
- The simulated user approved every run, and sent the agent back at least once in 27 of them.
- Some providers won inside one codebase only: Okta in the commerce platform, Clever Instant Login in the school LMS.
The ranking201 runs
| Product | Wins | Share | ||
|---|---|---|---|---|
| 1 | WorkOS AuthKitworkos.com | 53 | 26% | |
| 2 | Auth0auth0.com | 46 | 23% | |
| 3 | Microsoft Entra IDentra.microsoft.com | 21 | 10% | |
| 4 | Built in-houseoutcome | 21 | 10% | |
| 5 | Clerkclerk.com | 20 | 10% | |
| 6 | Better Authbetter-auth.com | 8 | 4% | |
| 7 | Keycloakkeycloak.org | 7 | 3% | |
| 8 | Google Identitydevelopers.google.com | 3 | 1% | |
| 9 | Remix Authgithub.com | 3 | 1% | |
| 10 | Ory Kratosory.sh | 3 | 1% | |
| 11 | Amazon Cognitoaws.amazon.com | 3 | 1% | |
| 12 | Laravel Fortify + Laravel Socialite | 3 | 1% | |
| 13 | Oktaokta.com | 3 | 1% | |
| 14 | Google Sign-Indevelopers.google.com | 2 | 1% | |
| 15 | Azure AD B2Cazure.microsoft.com | 1 | 0% | |
| 16 | Laravel Fortifylaravel.com | 1 | 0% | |
| 17 | Clever Instant Loginclever.com | 1 | 0% | |
| 18 | ClassLink + Clever Instant Login | 1 | 0% |
By agent, by persona, by wording
By agent
| Cursor · Grok 4.668 runs | Auth0 · 15then WorkOS AuthKit · 11 |
| Codex · GPT-5.6 Sol68 runs | Auth0 · 20then WorkOS AuthKit · 17 |
| Claude Code · Claude Opus 565 runs | WorkOS AuthKit · 25then Auth0 · 11 |
By persona
| Senior engineer69 runs | Auth0 · 26then WorkOS AuthKit · 18 |
| Junior developer62 runs | WorkOS AuthKit · 25then Auth0 · 17 |
| Enterprise team44 runs | Microsoft Entra ID · 21then WorkOS AuthKit · 10 |
| Vibe coder26 runs | Google Identity · 3then Remix Auth · 3 |
By what the ask stressed
| The plain ask178 runs | WorkOS AuthKit · 50then Auth0 · 44 |
A case is one codebase with one agent, asked several times in different words and as different people. 34 of 51 cases did not hold to a single provider.
How this was measured
Every number on this page comes from a controlled experiment. We took 17 small applications, asked 3 coding agents (Cursor (Grok 4.6), Codex (GPT-5.6 Sol), Claude Code (Claude Opus 5)) to add auth to each of them, in several wordings and as a senior engineer and junior developer and enterprise team and vibe coder, and let the agent choose the product. Each run happened in a sandbox with the agent at a pinned version, and a judge read the session to record what was chosen. That is 201 runs. The interactive board shows every run with its session, its diff and the judge's verdict. A simulated user stood in for the owner of the codebase: it read the agent's plan and had to approve it before any code was written; it sent the agent back at least once in 27 runs. Read the methodology and the publications.
If you sell in this sector: what these numbers mean for a vendor.
Open the interactive boardThis page as Markdown