EN
Back to the archive

The archive · Developer & Business Tools · Product decision · 2024–2026

Stack Auth bets open source beats Auth0/Clerk lock-in; YC S24 launch becomes Hexclave

YC S24 Stack Auth launched 100% open source against Auth0/Clerk lock-in; by 2026 it had become Hexclave with 6.8k GitHub stars.

Stack Auth

The betDevelopers will choose open source over lock-in: MIT/AGPL auth, self-hosted or managed with export anytime, expanded into the full user toolchain to earn paid hosting.Live

What the business is

Stack Auth (now Hexclave) is an open-source user-infrastructure platform: authentication, teams, RBAC, API keys, payments, emails, analytics and webhooks built on one user model, with managed hosting or self-hosting; at its 2024 launch it was an open-source Auth0/Clerk alternative selling login UI, authorization and OAuth token management.

How it started

Founders Zai and Konsti built Stack Auth in Y Combinator's Summer 2024 batch out of years of frustration with the auth incumbents: Auth0 appealed to enterprises but lagged in developer-friendliness and locked customers in, Clerk marketed directly to developers but stayed entirely proprietary, and open-source options such as Supabase Auth or Auth.js handled only authentication. Their 2024-08-08 Launch HN pitched '100% open-source, licensed under MIT and AGPL', self-hostable or managed, with data export any time and no lock-in.

What happened

The 141-comment thread stress-tested the open-core line: readers compared Stack Auth to ZITADEL, Keycloak, SuperTokens and Authgear, and one complained the documentation made the architecture unclear; the founders answered throughout. The repo then grew far past auth: by the 2026-09-04 crawl it carried 6.8k stars, 522 forks and 3,964 commits under the renamed org hexclave, marketing Hexclave as a catalog of switch-on apps — auth, teams, RBAC, API keys, payments, emails, analytics, webhooks and a data vault — with AI-agent onboarding via a skill URL.

How it ended up

Still running and expanding as of 2026-09-04: the product is now branded Hexclave with a website, dashboard, docs and Discord live, and the repo at 6.8k stars; no funding, revenue or customer-count disclosures appear in the record.

Background

Zai and Konsti built Stack Auth in Y Combinator's Summer 2024 batch out of frustration with the auth incumbents. Their diagnosis was specific: Auth0 appealed to enterprises but lagged in developer-friendliness and created vendor lock-in; Clerk marketed to developers but was entirely proprietary; and open-source options like Supabase Auth or Auth.js covered authentication only, leaving teams, permissions and user management to the developer.

The answer they launched on 2024-08-08 was 100% open source — MIT and AGPL — with self-hosting or managed hosting and no lock-in: export all data or start self-hosting at any time. Beyond login pages the platform shipped authorization (orgs, teams, permissions, RBAC), user management (impersonation, dashboard, webhooks), and 'connected accounts' that manage and refresh OAuth tokens for services users do not sign in with, such as GMail or OneDrive APIs.

The Launch HN drew 280 points and 141 comments, and the thread tested the open-core claim hard: readers compared the project to ZITADEL, Keycloak, SuperTokens and Authgear, and one asked pointedly which parts were actually open when a managed API key was involved. The founders answered each comparison, and the project kept compounding — by the 2026-09-04 crawl the repo carried 6.8k stars, 522 forks and 3,964 commits.

Somewhere in that growth the product outgrew the original pitch: the repo is now hexclave/hexclave, and Hexclave markets itself as a catalog of switch-on apps on one user model — authentication, teams, RBAC, API keys, payments, emails, analytics, webhooks and a data vault — with AI-agent onboarding as a headline feature. No funding, revenue or customer figures are disclosed in the record.

What has to be true

  • Dated platform traction: the 2024-08-08 Launch HN drew 280 points and 141 comments, with founders answering direct comparisons to ZITADEL, Keycloak and SuperTokens.
  • A verifiable trajectory: stack-auth/stack became hexclave/hexclave at 6.8k stars, 522 forks and 3,964 commits by the 2026-09-04 crawl.
  • A clear bet against a named enemy: Auth0's lock-in and Clerk's closed source made open source with export rights the differentiator, later broadened from auth into the full user stack.
  • The current README documents the expansion: auth grew into teams, RBAC, payments, emails, analytics, webhooks and a data vault, with managed and self-hosted deployment and AI-agent onboarding.

What can be applied

An open-core auth bet needs a reason to pay beyond code; expanding into teams, payments and analytics gives managed hosting a job but turns the product into a different company.

Aftermath

As of 2026-09-05 Stack Auth is live under the name Hexclave: the github.com/hexclave/hexclave repo carried 6.8k stars, 522 forks and 3,964 commits at the 2026-09-04 crawl, and the README sells a catalog of switch-on apps — authentication, teams, RBAC, API keys, payments, emails, analytics, webhooks and a data vault — on one user model, with a website, dashboard, docs and Discord live. The original open-source Auth0/Clerk alternative is still visible in the product lineage, and no funding, revenue or customer-count disclosures appear anywhere in the record.

Sources

spotted an error? The archive wants to know.

Your turn

You just read one. Describe what you are building, and see who is betting on the same thing.

Free account · 3 free questions · no card

Related cases