Auth.js and Lucia both answer the same question in a SvelteKit project: how do users sign in? The long-running open source auth layer formerly called NextAuth, mostly a thin wrapper around OAuth providers. No longer a library but a reference that teaches you to implement sessions yourself, with code you copy and own. The real split is ownership: Auth.js runs inside your project and leaves the operational work with you, while Lucia runs the hard parts as a service and takes a dependency in exchange.
The real split is ownership: Auth.js runs inside your project and leaves the operational work with you, while Lucia runs the hard parts as a service and takes a dependency in exchange. For SvelteKit specifically, both are supported, so let the tradeoff above decide rather than the framework.
| Comparison | Auth.js | Lucia |
|---|---|---|
| Pricing shape | Free and open source. Costs are whatever your identity providers and database charge. | Free. It is documentation, so there is nothing to buy or subscribe to. |
| Frameworks | Next.js, SvelteKit | Next.js, SvelteKit |
| In one line | The long-running open source auth layer formerly called NextAuth, mostly a thin wrapper around OAuth providers. | No longer a library but a reference that teaches you to implement sessions yourself, with code you copy and own. |
Pricing described qualitatively because published plans change often. Checked 2026-08-23. Confirm current terms on Auth.js and Lucia.
Strengths
Tradeoffs
Strengths
Tradeoffs
Neither is better in the abstract. The real split is ownership: Auth.js runs inside your project and leaves the operational work with you, while Lucia runs the hard parts as a service and takes a dependency in exchange. Decide on the tradeoff you can live with, then stop reading comparisons and ship.
Anything past OAuth, like invitations or roles, you design yourself. Callback and adapter APIs have churned across major versions more than once.
Copied code means you carry the maintenance and security review forever. No package upgrades, so fixes only land if you go looking for them.
Yes, both list support for SvelteKit, which is why this comparison exists as a SvelteKit page. SvelteKit moved fast enough that training data contains three incompatible generations of it: Sapper, SvelteKit 1.0, and SvelteKit 2 on Svelte 5.