BoilerplateHub

Auth.js vs Lucia for Next.js

Auth.js and Lucia both answer the same question in a Next.js project: how do users sign in? The long-running open source auth layer formerly called NextAuth, mostly a thin wrapper around OAuth providers. No longer a library but a reference that teaches you to implement sessions yourself, with code you copy and own. The real split is ownership: Auth.js runs inside your project and leaves the operational work with you, while Lucia runs the hard parts as a service and takes a dependency in exchange.

Verdict

The real split is ownership: Auth.js runs inside your project and leaves the operational work with you, while Lucia runs the hard parts as a service and takes a dependency in exchange. For Next.js specifically, both are supported, so let the tradeoff above decide rather than the framework.

Pick Auth.js if

  • Enormous library of OAuth providers configured with a few lines each.
  • Years of production usage mean most errors already have a forum answer.
  • Adapters let you keep sessions in whichever database you already chose.

Pick Lucia if

  • You end up understanding exactly how your session cookies and tokens work.
  • Zero dependency to break, deprecate or change licence underneath you.
  • Session schema is yours, so it fits whatever data model you already have.
Comparison Auth.js Lucia
Pricing shape Free and open source. Costs are whatever your identity providers and database charge. Free. It is documentation, so there is nothing to buy or subscribe to.
Frameworks Next.js, SvelteKit Next.js, SvelteKit
In one line The long-running open source auth layer formerly called NextAuth, mostly a thin wrapper around OAuth providers. No longer a library but a reference that teaches you to implement sessions yourself, with code you copy and own.

Pricing described qualitatively because published plans change often. Checked 2026-08-23. Confirm current terms on Auth.js and Lucia.

Auth.js

Strengths

  • Enormous library of OAuth providers configured with a few lines each.
  • Years of production usage mean most errors already have a forum answer.
  • Adapters let you keep sessions in whichever database you already chose.
  • Stateless JWT sessions work without any session store at all.

Tradeoffs

  • Anything past OAuth, like invitations or roles, you design yourself.
  • Callback and adapter APIs have churned across major versions more than once.
  • Documentation lags the code, so reading the source becomes routine.
  • Debugging silent callback failures is a known rite of passage.

Lucia

Strengths

  • You end up understanding exactly how your session cookies and tokens work.
  • Zero dependency to break, deprecate or change licence underneath you.
  • Session schema is yours, so it fits whatever data model you already have.
  • Excellent teaching material even if you eventually pick a different tool.

Tradeoffs

  • Copied code means you carry the maintenance and security review forever.
  • No package upgrades, so fixes only land if you go looking for them.
  • Every provider, reset flow and rate limit is hand-rolled work.
  • Hard to justify on a team where nobody wants to own auth internals.

Same pair, different context

Frequently asked questions

Is Auth.js or Lucia better in a Next.js project?

Neither is better in the abstract. The real split is ownership: Auth.js runs inside your project and leaves the operational work with you, while Lucia runs the hard parts as a service and takes a dependency in exchange. The wrong choice here is usually recoverable, so weight speed of decision over certainty.

What is the main drawback of Auth.js?

Anything past OAuth, like invitations or roles, you design yourself. Callback and adapter APIs have churned across major versions more than once.

What is the main drawback of Lucia?

Copied code means you carry the maintenance and security review forever. No package upgrades, so fixes only land if you go looking for them.

Do Auth.js and Lucia both support Next.js?

Yes, both list support for Next.js, which is why this comparison exists as a Next.js page. Next.js has two routing systems that look similar in code but behave completely differently, and most model training data blends them.

Related comparisons