Do coding agents recommend JWT?
JWT came up in 61% of judged authentication sessions and was adopted in none: on this board it is substrate, not a candidate.
JWT came up in 61% of judged authentication sessions and was adopted in none: on this board it is substrate, not a candidate.
This page reports what happened when Claude Code, Codex and Cursor had to solve a problem in authentication inside a realistic codebase. Not what a chat assistant says about JWT. What an agent actually installed.
The numbers
| Category | Authentication |
| Sessions in the category | 201 |
| Sessions where JWT was chosen | 0 |
| Install share | 0% |
| Raised as a candidate, not chosen | 122 |
| Chosen when considered | 0% |
| Site | jwt.io |
Which agents raised JWT
JWT came up in 61% of authentication sessions and was adopted in none. At that rate it is not a candidate that keeps losing: it is the thing already in the repository, or the standard the alternatives get measured against. Claude Code named it in 77% of its sessions.
| Agent | Sessions | Raised JWT | Chose it |
|---|---|---|---|
| Claude Code | 65 | 50 (77%) | 0 |
| Codex | 68 | 35 (51%) | 0 |
| Cursor | 68 | 37 (54%) | 0 |
Which buyers it came up for
It surfaced most for requests written as senior engineer, in 74% of those sessions. Knowing which buyer already has the product in mind tells you which pages to fix first.
| Who is asking | Sessions | Raised it |
|---|---|---|
| Vibe coder | 26 | 16 (62%) |
| Junior developer | 62 | 24 (39%) |
| Senior engineer | 69 | 51 (74%) |
| Enterprise team | 44 | 31 (70%) |
What JWT was up against
The full ranking in authentication, from the same sessions:
| # | Product | Runs won | Share |
|---|---|---|---|
| 1 | WorkOS AuthKit | 53 | 26% |
| 2 | Auth0 | 46 | 23% |
| 3 | Microsoft Entra ID | 21 | 10% |
| 4 | Built in-house (no product adopted) | 21 | 10% |
| 5 | Clerk | 20 | 10% |
| 6 | Better Auth | 8 | 4% |
| 7 | Keycloak | 7 | 3% |
| 8 | Google Identity | 3 | 1% |
What this means
Read this row as context, not as a loss. On this board JWT is the thing underneath rather than one of the candidates: the database already in the repository, the protocol the alternatives implement, or the runtime they all run on. Our judge has an explicit rule for the clearest case: a vendor-neutral standard is never recorded as the winner, because it is the wiring and not the destination.
Where that reading does not apply, the causes below are the ones we see.
In our data the causes, in the order they occur:
- The quickstart does not run when pasted, so the agent abandoned it mid-integration.
- The documentation describes an interface that changed, so the generated code failed.
- The product name and the package name differ, so the install step went wrong.
- The fit was genuinely wrong for the repository, which is fine and worth knowing.
All but the last are fixable in days, and the reason is written down in the session transcript.
Where these numbers come from
The 201 sessions in authentication are part of a published set of 5,292, run with real coding agents inside realistic codebases and judged blind. The full method is on one page: how we measured this.
Every authentication run can be replayed on the board.
If you work on JWT: the judge recorded a reason for every session where it was raised and passed over. Those reasons are in the transcripts.
<!-- generated by scripts/write-data-pages.mjs -->
Common questions
Do coding agents recommend JWT?
They raise it but do not choose it. Across 122 sessions where JWT came up as a candidate, agents chose something else every time.
Does Claude Code recommend JWT?
In 0 of the 65 sessions in authentication run with Claude Code, which is 0%.
Do different coding agents treat JWT differently?
Not much. The three agents chose it at similar rates, between 0% and 0% of their runs.
How was this measured?
Real coding agents at pinned versions were run in sandboxes inside 51 realistic codebases and asked to solve real tasks. A simulated project owner approved or questioned each recommendation before any code was written, and a judge from a model family that builds none of the agents read every session blind.
Where this comes from
Armature ran 5,292 judged sessions with Claude Code, Codex and Cursor inside 51 realistic codebases, and published every run. The numbers on this page come from that work.