# Auth: which providers coding agents choose

> WorkOS AuthKit led with about 26% and no provider stood out.

Source: https://armature.tech/leaderboards/auth (Armature agent leaderboards). 201 runs, 17 apps, 3 agents, 4 personas, updated 2026-09-02. Interactive board with every run: https://armature.tech/leaderboards#app/auth

## Key learnings

We asked three agents to add auth to 17 small apps, 201 runs in all. We asked in different words, and as four different people. Auth0 came second at about 23%, and the rest of the wins scattered across many providers.

### The persona changed which provider won (21 of 44)

Enterprise teams picked Microsoft Entra ID 21 times across 44 runs. All 21 of that provider's wins came from those runs. Junior developers put WorkOS AuthKit first, and senior engineers put Auth0 first.

### Rewording the same ask moved the answer (34 of 51)

We took each codebase with each agent and asked several times, in different wordings. In 34 of 51 of those cases the runs didn't all land on the same provider.

### One agent leaned the other way (25 of 65)

Claude Code picked WorkOS AuthKit 25 times in 65 runs. Codex and Cursor both put Auth0 first instead.

### Named in many runs, chosen in none (0 of 69)

Supabase Auth came up in 69 runs and won none of them.

Smaller learnings:

- In 21 runs the agents wrote auth themselves rather than pick a provider.
- JWT was named in 122 runs, but it is a token format these providers issue, not a provider.
- The simulated user approved every plan, and sent the agent back at least once in 27 runs.
- In 10 runs it refused to approve until the agent named a specific product.
- Okta and Amazon Cognito each won three times, both only in the high-traffic checkout platform.

## The ranking

| # | Product | Wins | Share |
|---|---|---:|---:|
| 1 | WorkOS AuthKit (workos.com) | 53 | 26% |
| 2 | Auth0 (auth0.com) | 46 | 23% |
| 3 | Microsoft Entra ID (entra.microsoft.com) | 21 | 10% |
| 4 | Built in-house (outcome) | 21 | 10% |
| 5 | Clerk (clerk.com) | 20 | 10% |
| 6 | Better Auth (better-auth.com) | 8 | 4% |
| 7 | Keycloak (keycloak.org) | 7 | 3% |
| 8 | Google Identity (developers.google.com) | 3 | 1% |
| 9 | Remix Auth (github.com) | 3 | 1% |
| 10 | Ory Kratos (ory.sh) | 3 | 1% |
| 11 | Amazon Cognito (aws.amazon.com) | 3 | 1% |
| 12 | Laravel Fortify + Laravel Socialite | 3 | 1% |
| 13 | Okta (okta.com) | 3 | 1% |
| 14 | Google Sign-In (developers.google.com) | 2 | 1% |
| 15 | Azure AD B2C (azure.microsoft.com) | 1 | 0% |
| 16 | Laravel Fortify (laravel.com) | 1 | 0% |
| 17 | Clever Instant Login (clever.com) | 1 | 0% |
| 18 | ClassLink + Clever Instant Login | 1 | 0% |

## By agent

- Cursor (Grok 4.6): 68 runs, first Auth0 (15), then WorkOS AuthKit (11)
- Codex (GPT-5.6 Sol): 68 runs, first Auth0 (20), then WorkOS AuthKit (17)
- Claude Code (Claude Opus 5): 65 runs, first WorkOS AuthKit (25), then Auth0 (11)

## By persona

- Senior engineer: 69 runs, first Auth0 (26), then WorkOS AuthKit (18)
- Junior developer: 62 runs, first WorkOS AuthKit (25), then Auth0 (17)
- Enterprise team: 44 runs, first Microsoft Entra ID (21), then WorkOS AuthKit (10)
- Vibe coder: 26 runs, first Google Identity (3), then Remix Auth (3)

## By what the ask stressed

- The plain ask: 178 runs, first WorkOS AuthKit (50), then Auth0 (44)

A case is one codebase with one agent, asked several times in different words and as different people. 34 of 51 cases did not hold to a single choice.

## How this was measured

Every number on this page comes from a controlled experiment. We took 17 small applications, asked 3 coding agents (Cursor (Grok 4.6), Codex (GPT-5.6 Sol), Claude Code (Claude Opus 5)) to add auth to each of them, in several wordings and as a senior engineer and junior developer and enterprise team and vibe coder, and let the agent choose the product. Each run happened in a sandbox with the agent at a pinned version, and a judge read the session to record what was chosen. That is 201 runs. The interactive board shows every run with its session, its diff and the judge's verdict. A simulated user stood in for the owner of the codebase: it read the agent's plan and had to approve it before any code was written; it sent the agent back at least once in 27 runs.

Methodology and publications: https://armature.tech/publications

## Other sectors

- [Agent sandboxes](https://armature.tech/leaderboards/sandboxes) (https://armature.tech/leaderboards/sandboxes.md)
- [Observability](https://armature.tech/leaderboards/observability) (https://armature.tech/leaderboards/observability.md)
- [Payments](https://armature.tech/leaderboards/payments) (https://armature.tech/leaderboards/payments.md)
- [Deploy](https://armature.tech/leaderboards/deploy) (https://armature.tech/leaderboards/deploy.md)
- [Email providers](https://armature.tech/leaderboards/mail) (https://armature.tech/leaderboards/mail.md)
- [Product analytics](https://armature.tech/leaderboards/product-analytics) (https://armature.tech/leaderboards/product-analytics.md)
- [Databases](https://armature.tech/leaderboards/databases) (https://armature.tech/leaderboards/databases.md)
- [File storage](https://armature.tech/leaderboards/storage) (https://armature.tech/leaderboards/storage.md)
- [LLM evals & observability](https://armature.tech/leaderboards/evals) (https://armature.tech/leaderboards/evals.md)
- [Voice Agents](https://armature.tech/leaderboards/voice-agents) (https://armature.tech/leaderboards/voice-agents.md)
- [Serverless functions](https://armature.tech/leaderboards/serverless) (https://armature.tech/leaderboards/serverless.md)
- [Cloud](https://armature.tech/leaderboards/cloud) (https://armature.tech/leaderboards/cloud.md)
- [AI gateway](https://armature.tech/leaderboards/ai-gateway) (https://armature.tech/leaderboards/ai-gateway.md)
- [Bot protection](https://armature.tech/leaderboards/bot-protection) (https://armature.tech/leaderboards/bot-protection.md)
- [Search](https://armature.tech/leaderboards/search) (https://armature.tech/leaderboards/search.md)
- [Agent frameworks](https://armature.tech/leaderboards/agent-frameworks) (https://armature.tech/leaderboards/agent-frameworks.md)
- [Performance in CI](https://armature.tech/leaderboards/perf-ci) (https://armature.tech/leaderboards/perf-ci.md)
