I open-sourced my Auth0 replacement

Published on October 7, 2026·3 min read min read

Every product I build ends up needing the same thing: one account that works everywhere.

CyberCTF, Cyber Courses, Cyber Bench. Different apps, same people. So I built Cyber Auth, a single sign-on for all of them. Today I'm releasing the engine behind it as an open-source template.

It's called Ostiary.

Why not Auth0?

Auth0, Clerk and friends are great products. But they come with three costs:

  • The bill scales with your users. Success gets more expensive every month.
  • Your users live in someone else's database. Leaving is a migration project.
  • It's a black box. When something behaves oddly, you open a ticket.

For a side project, fine. For the identity layer of everything you build, I wanted to own it.

What Ostiary is

A Next.js app you deploy, on top of Better Auth, the best auth library in the TypeScript ecosystem right now.

Better Auth gives you the building blocks. Ostiary assembles them into a product:

You getWhat it means
OAuth 2.1 / OpenID Connect providerAny app signs in with "Sign in with your company"
Passkeys, social sign-in, enterprise SSOModern sign-in, with DNS-verified SSO domains
Organizations and invitationsTeams out of the box
Account dashboardProfile, sessions, passkeys, connected apps
Admin consoleUsers, OAuth clients, audit log, sign-in monitoring
20 languages, light and darkReady for real users

One click

The repo ships as a Vercel template. Click Deploy, and Vercel:

  1. creates a Postgres database (Neon),
  2. asks for a secret and your email,
  3. runs the migrations during the build.

Sign up with that email and you're the admin. That's the whole setup.

Security, by default

The details that usually come later are there on day one:

  • Changing an email needs approval from the current inbox. A stolen cookie can't take the account.
  • Adding a passkey needs a sign-in from the last 10 minutes.
  • Every admin action lands in an audit log, with secrets stripped.

The name

In the early church, the ostiarius was the doorkeeper. He held the keys and decided who came in.

That's the job.

Try it

It already runs in production for the Cyber ecosystem. If you need a login for more than one app, give it a try, and tell me what breaks.

Ship the fix. Then share the patch.