From the experiment

Do coding agents recommend Auth.js?

Coding agents raised Auth.js in 128 of 520 judged authentication sessions and chose it in none of them.

Published September 23, 2026 Read as Markdown

Coding agents raised Auth.js in 128 of 520 judged authentication sessions and chose it in none of them.

This page reports what happened when Claude Code, Codex, Cursor, Grok Build CLI and Muse Code had to solve a problem in authentication inside a realistic codebase. Not what a chat assistant says about Auth.js. What an agent actually installed.

The numbers

CategoryAuthentication
Sessions in the category520
Sessions where Auth.js was chosen0
Install share0%
Raised as a candidate, not chosen128
Chosen when considered0%
Siteauthjs.dev

Which agents raised Auth.js

Every agent considered it and none adopted it. Cursor raised it most often, in 34% of its authentication sessions.

AgentSessionsRaised Auth.jsChose it
Claude Code13336 (27%)0
Codex13614 (10%)0
Cursor13345 (34%)0
Grok Build CLI5014 (28%)0
Muse Code6819 (28%)0

Which buyers it came up for

It surfaced most for requests written as vibe coder, in 70% of those sessions. Knowing which buyer already has the product in mind tells you which pages to fix first.

Who is askingSessionsRaised it
Vibe coder7150 (70%)
Junior developer16061 (38%)
Senior engineer17417 (10%)
Enterprise team1150 (0%)

What Auth.js was up against

The full ranking in authentication, from the same sessions:

#ProductRuns wonShare
1Auth011723%
2WorkOS AuthKit11723%
3Clerk6112%
4Microsoft Entra ID5511%
5Built in-house (no product adopted)489%
6Better Auth214%
7Keycloak133%
8Arctic92%

What this means

Raised 128 times and chosen none is a specific, diagnosable result, and a better starting position than being unknown. The agent has the product in mind. It reached the shortlist 128 times. Something then lost every one of those sessions.

In our data the causes, in the order they occur:

  • The quickstart does not run when pasted, so the agent abandoned it mid-integration.
  • The documentation describes an interface that changed, so the generated code failed.
  • The product name and the package name differ, so the install step went wrong.
  • The fit was genuinely wrong for the repository, which is fine and worth knowing.

All but the last are fixable in days, and the reason is written down in the session transcript.

Where these numbers come from

The 520 sessions in authentication are part of a published set of 11,878, run with real coding agents inside realistic codebases and judged blind. The full method is on one page: how we measured this.

Every authentication run can be replayed on the board.

If you work on Auth.js: the judge recorded a reason for every session where it was raised and passed over. Those reasons are in the transcripts.

<!-- generated by scripts/write-data-pages.mjs -->

Common questions

Do coding agents recommend Auth.js?

They raise it but do not choose it. Across 128 sessions where Auth.js came up as a candidate, agents chose something else every time.

Does Claude Code recommend Auth.js?

In 0 of the 133 sessions in authentication run with Claude Code, which is 0%.

Do different coding agents treat Auth.js differently?

Not much. Claude Code, Codex, Cursor, Grok Build CLI and Muse Code chose it at similar rates, between 0% and 0% of their runs.

How was this measured?

Real coding agents at pinned versions were run in sandboxes inside 91 realistic codebases and asked to solve real tasks. A simulated project owner approved or questioned each recommendation before any code was written, and a judge from a model family that builds none of the agents read every session blind.

Where this comes from

Armature ran 11,878 judged sessions with Claude Code, Codex, Cursor, Grok Build CLI and Muse Code inside 91 realistic codebases, and published every run. The numbers on this page come from that work.

Read next

All library pages