Ross ROSS = Recommend OSS · open-source software intelligence for agents

teamhanko/hanko

Modern authentication, on your terms. Open source alternative to Auth0, Clerk, WorkOS, Stytch. observed · 2026-08-28

github.com/teamhanko/hanko · homepage · Go · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

94/100

  • Activity 99
  • Release rhythm 83
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 35.0
  • age_days: 1633
  • days_rel: 37
  • days_push: 8
  • n_releases_24m: 17

Full methodology

Adoption not part of the score

9015 stars · 1014 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Hanko is an open-source authentication and user management platform built in Go, offering passwords, passkeys (WebAuthn/FIDO2), MFA, OAuth social logins, and SAML SSO through an API-first architecture. It ships with framework-agnostic web components (Hanko Elements) and JS SDKs, and can be self-hosted or used via the managed Hanko Cloud service.

Use cases

  • add passkey login to my web app
  • self-hosted alternative to Auth0 or Clerk
  • implement passwordless authentication with WebAuthn
  • add SAML SSO for enterprise customers
  • add multi-factor authentication to my app
  • migrate users from Firebase Auth with existing password hashes
  • add social login with Google and GitHub
  • manage user accounts and sessions for my SaaS

When to choose

  • you want a self-hostable, API-first auth platform with no vendor lock-in
  • you need phishing-resistant passkey/WebAuthn support out of the box
  • you need passwords, passkeys, MFA, OAuth, and SAML SSO in one solution
  • you want drop-in web components that work with React, Next.js, Angular, Vue, or Svelte
  • you need to migrate existing users (e.g., from Firebase) including password hashes

When to avoid

  • you only need to add passkeys to an existing auth system (consider Hanko's separate Passkey API instead)
  • you need fully featured organizations, roles, and permissions today (still on the roadmap)
  • you require a certified compliance-heavy enterprise IAM like Keycloak with extensive protocol plugins
  • you need native mobile SDKs for iOS, Android, React Native, or Flutter (not yet released)

Facets

service · maturity active

auth authorization api-framework http-server middleware sdk webhook security web-development apis self-hosted developer-tools go self-hosted cross-platform cloud passkeys webauthn fido2 passwordless mfa sso saml oauth user-management ciam jwt auth0-alternative web-components docker web-server

10 sources

Member repositories

RepositoryRoleHealth v2
teamhanko/hankomain94

For agents

markdown · JSON · MCP: product_card(name="teamhanko/hanko")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem