The archive · Developer & Business Tools · Product decision · 2024–2026
Stack Auth bets open source beats Auth0/Clerk lock-in; YC S24 launch becomes Hexclave
YC S24 Stack Auth launched 100% open source against Auth0/Clerk lock-in; by 2026 it had become Hexclave with 6.8k GitHub stars.
Stack Auth
What the business is
Stack Auth (now Hexclave) is an open-source user-infrastructure platform: authentication, teams, RBAC, API keys, payments, emails, analytics and webhooks built on one user model, with managed hosting or self-hosting; at its 2024 launch it was an open-source Auth0/Clerk alternative selling login UI, authorization and OAuth token management.
How it started
Founders Zai and Konsti built Stack Auth in Y Combinator's Summer 2024 batch out of years of frustration with the auth incumbents: Auth0 appealed to enterprises but lagged in developer-friendliness and locked customers in, Clerk marketed directly to developers but stayed entirely proprietary, and open-source options such as Supabase Auth or Auth.js handled only authentication. Their 2024-08-08 Launch HN pitched '100% open-source, licensed under MIT and AGPL', self-hostable or managed, with data export any time and no lock-in.
What happened
The 141-comment thread stress-tested the open-core line: readers compared Stack Auth to ZITADEL, Keycloak, SuperTokens and Authgear, and one complained the documentation made the architecture unclear; the founders answered throughout. The repo then grew far past auth: by the 2026-09-04 crawl it carried 6.8k stars, 522 forks and 3,964 commits under the renamed org hexclave, marketing Hexclave as a catalog of switch-on apps — auth, teams, RBAC, API keys, payments, emails, analytics, webhooks and a data vault — with AI-agent onboarding via a skill URL.
How it ended up
Still running and expanding as of 2026-09-04: the product is now branded Hexclave with a website, dashboard, docs and Discord live, and the repo at 6.8k stars; no funding, revenue or customer-count disclosures appear in the record.
Background
Zai and Konsti built Stack Auth in Y Combinator's Summer 2024 batch out of frustration with the auth incumbents. Their diagnosis was specific: Auth0 appealed to enterprises but lagged in developer-friendliness and created vendor lock-in; Clerk marketed to developers but was entirely proprietary; and open-source options like Supabase Auth or Auth.js covered authentication only, leaving teams, permissions and user management to the developer.
The answer they launched on 2024-08-08 was 100% open source — MIT and AGPL — with self-hosting or managed hosting and no lock-in: export all data or start self-hosting at any time. Beyond login pages the platform shipped authorization (orgs, teams, permissions, RBAC), user management (impersonation, dashboard, webhooks), and 'connected accounts' that manage and refresh OAuth tokens for services users do not sign in with, such as GMail or OneDrive APIs.
The Launch HN drew 280 points and 141 comments, and the thread tested the open-core claim hard: readers compared the project to ZITADEL, Keycloak, SuperTokens and Authgear, and one asked pointedly which parts were actually open when a managed API key was involved. The founders answered each comparison, and the project kept compounding — by the 2026-09-04 crawl the repo carried 6.8k stars, 522 forks and 3,964 commits.
Somewhere in that growth the product outgrew the original pitch: the repo is now hexclave/hexclave, and Hexclave markets itself as a catalog of switch-on apps on one user model — authentication, teams, RBAC, API keys, payments, emails, analytics, webhooks and a data vault — with AI-agent onboarding as a headline feature. No funding, revenue or customer figures are disclosed in the record.
What has to be true
- Dated platform traction: the 2024-08-08 Launch HN drew 280 points and 141 comments, with founders answering direct comparisons to ZITADEL, Keycloak and SuperTokens.
- A verifiable trajectory: stack-auth/stack became hexclave/hexclave at 6.8k stars, 522 forks and 3,964 commits by the 2026-09-04 crawl.
- A clear bet against a named enemy: Auth0's lock-in and Clerk's closed source made open source with export rights the differentiator, later broadened from auth into the full user stack.
- The current README documents the expansion: auth grew into teams, RBAC, payments, emails, analytics, webhooks and a data vault, with managed and self-hosted deployment and AI-agent onboarding.
What can be applied
An open-core auth bet needs a reason to pay beyond code; expanding into teams, payments and analytics gives managed hosting a job but turns the product into a different company.
Aftermath
As of 2026-09-05 Stack Auth is live under the name Hexclave: the github.com/hexclave/hexclave repo carried 6.8k stars, 522 forks and 3,964 commits at the 2026-09-04 crawl, and the README sells a catalog of switch-on apps — authentication, teams, RBAC, API keys, payments, emails, analytics, webhooks and a data vault — on one user model, with a website, dashboard, docs and Discord live. The original open-source Auth0/Clerk alternative is still visible in the product lineage, and no funding, revenue or customer-count disclosures appear anywhere in the record.
Sources
- Launch HN: Stack Auth (YC S24) – An Open-Source Auth0/Clerk Alternative (280 points, 141 comments)
- hexclave/hexclave (formerly stack-auth/stack) — user infrastructure platform (6.8k stars, 522 forks, 3,964 commits)
spotted an error? The archive wants to know.
Your turn
You just read one. Describe what you are building, and see who is betting on the same thing.
Free account · 3 free questions · no card