Better Auth vs Casdoor vs Supabase MCP: Auth Skills 2026
A. Frans
Published August 18, 2026
Table of Contents
Search the skills directory for authentication and three results dominate: Better Auth at 29,557 stars, Casdoor at 14,203, and the official Supabase MCP with about 25,000 installs. They show up in the same searches, get compared in the same threads, and answer three completely different questions.
Better Auth teaches your agent how to implement auth in your codebase. Casdoor gives your agent a connection to an identity platform. Supabase MCP gives it a connection to a managed backend where auth is one of several things it can administer. Pick the wrong one and you'll spend an afternoon discovering that the skill you installed doesn't do the category of work you had in mind.
Head-to-head
| Attribute | Better Auth | Casdoor | Supabase MCP |
|---|---|---|---|
| Type | Knowledge skill | MCP server (IAM platform) | MCP server (managed backend) |
| Trust tier | Verified | Verified | Official |
| Security status | Community-reviewed | Community-reviewed | Audited |
| Stars | 29,557 | 14,203 | 2,866 |
| Installs | ~24,000 | Not reported | ~25,000 |
| License | MIT | Apache-2.0 | Apache-2.0 |
| Live credentials needed | No | Yes | Yes |
| Agents | Claude Code, Cursor | Claude Code, Cursor, VS Code Copilot | Claude Code, Cursor |
| Last updated | 2026-08-16 | 2026-08-16 | 2026-08-15 |
Better Auth
claude skill add better-auth/better-auth
Better Auth loads authentication implementation patterns into the agent's context. No network access, no credentials, nothing to configure. You install it and the agent stops writing the kind of auth code that reviews badly.
That's a narrow description of something valuable. Auth is the area where LLMs produce the most confidently wrong code, because the internet is full of tutorial-grade examples that work in a demo and fail in production. Session tokens stored where JavaScript can read them, password reset flows without rate limiting, JWT verification that skips signature checks because a StackOverflow answer from 2019 did. A knowledge skill that biases the agent toward current practice is worth more here than in almost any other domain.
MIT licensed, 29,557 stars on better-auth/better-auth, roughly 24,000 installs, updated 2026-08-16. Community-reviewed rather than audited, which for a skill with no runtime access is a low-stakes distinction.
Limitation worth knowing: it's opinionated toward the Better Auth library's own approach. If you're on Auth.js, Lucia, or a hand-rolled setup, some of the guidance won't transfer cleanly. The general principles do.
Casdoor
claude mcp add casdoor -- npx -y casdoor/casdoor
Casdoor is a full open-source identity and access management platform, self-hostable, with an MCP interface so agents can work against it. Apache-2.0, 14,203 stars on casdoor/casdoor, updated 2026-08-16. It's the broadest agent compatibility of the three, covering VS Code Copilot alongside Claude Code and Cursor.
This is the option for teams who want SSO, multi-tenancy, and user management under their own control rather than rented from Auth0 or Okta. The MCP layer means an agent can create applications, manage providers, and query users programmatically.
The honest caveat: install count isn't reported for this one, and the star count reflects the IAM platform's overall popularity rather than usage of its agent interface. Those are different signals. A 14,000-star project with an MCP server bolted on is not the same thing as a widely-used MCP server, and I'd treat the agent integration as less battle-tested than the platform beneath it.
You're also taking on the operational weight of running an IAM service. That's a reasonable trade if you already need one. It's a bad trade if what you wanted was help writing a login form.
Supabase MCP
claude mcp add supabase -- npx -y @supabase/mcp-server
Supabase MCP is the only official-tier, audited option in this comparison. Apache-2.0, around 25,000 installs, updated 2026-08-15. It covers database and auth management together, which is the point: on Supabase those aren't separate systems, and an agent that can see both can answer questions like "which users have rows in this table but no confirmed email."
Audited status matters more here than anywhere else on this page, because this server holds credentials that reach both your user table and your application data. That is the highest-value credential in most stacks.
One directory-specific trap: there's also a community-tier supabase-mcp-server from a different author, unreviewed, last updated 2026-05-08. The names are nearly identical. The official one is supabase-mcp with the @supabase/mcp-server package. Install the other by accident and you've handed an unreviewed third party a path to your production database.
Which one, by situation
You're writing auth code in your own app. Better Auth. It's the only one of the three that helps with this, and the other two won't. Cost of being wrong here is low, so install it early.
You need self-hosted SSO across several internal apps. Casdoor, and accept that you're adopting an IAM platform rather than a skill. Evaluate it as infrastructure.
Your app runs on Supabase. Supabase MCP, without much debate. Official tier, audited, and it already knows the shape of your project.
You're building an MCP server that itself needs to authenticate users. None of these three. That's a different problem, covered below.
The rest of the auth-adjacent directory
Four more skills come up in auth searches, and their condition varies a lot.
Composio at 29,716 stars handles authentication as part of connecting agents to 1,000+ external toolkits. Verified, MIT, updated 2026-08-16. If your problem is "my agent needs to authenticate to Slack, Gmail, and Notion," this is the right layer, and it has nothing to do with authenticating your users.
MCP Boilerplate is a Cloudflare-hosted remote MCP server template with user authentication and payment handling built in. Verified tier, MIT, 1,024 stars, but last updated 2026-02-04. Six months is a long time in MCP specification terms.
remote-mcp-server-with-auth is a GitHub OAuth template for remote MCP servers. Community tier, unreviewed, 299 stars, and last updated 2025-07-11. That's over a year stale for a template whose entire job is implementing an OAuth flow correctly. Auth code that hasn't been touched in a year isn't necessarily broken, but it's the one category where I wouldn't copy from a stale template without reading every line.
Jetski adds authentication, analytics, and prompt visibility to MCP servers with low configuration. Community tier, unreviewed, 211 stars, updated 2026-04-29. Interesting idea, early-stage.
The stance
Better Auth is the one most people should install, and it's the one that gets discussed least because it doesn't do anything visible. It has no credentials, no dashboard, no setup. It just makes the agent's auth code better, which is where the actual risk lives for most teams.
Casdoor and Supabase MCP are infrastructure decisions wearing skill clothing. You don't choose them by comparing star counts against Better Auth; you choose them because you've already decided to run Casdoor or to build on Supabase, and the MCP server is how your agent talks to a thing you already committed to.
The comparison people search for is real, but the answer to it is usually "install Better Auth, and then separately decide whether you need an MCP server at all."
If you're wiring up your first one, the walkthrough in how to add authentication with Claude skills covers the mechanics, and building MCP servers covers the case where you're on the other side of the connection.
FAQ
Can I install all three?
Yes, and there's no conflict. Better Auth adds context; the other two add tools. The practical limit is context budget rather than compatibility, and Better Auth is cheap enough that it rarely competes for room.
Does Better Auth work if I'm not using the Better Auth library?
Partly. The general practice guidance transfers to any stack. The library-specific API examples don't. If you're on Auth.js or Lucia, expect to correct the agent when it reaches for Better Auth's API surface.
Is community-reviewed good enough for an auth skill?
For a knowledge-only skill like Better Auth, yes. For anything holding live credentials, read the source first. Casdoor is community-reviewed and does hold credentials, which is a reason to review its MCP layer rather than a reason to avoid it. All three are open source, so that review is possible.
What's the difference between Supabase MCP and supabase-mcp-server?
Author and trust tier. supabase-mcp is official, audited, maintained by supabase-community. supabase-mcp-server is community tier, unreviewed, from an independent author, last updated 2026-05-08. Both are Apache-2.0. Check the package name before you install: the official one pulls @supabase/mcp-server.
Which handles multi-tenancy best?
Casdoor, by a distance. Multi-tenant identity is its core design rather than a feature added later, and if you need per-tenant SSO configuration, neither of the other two is a real candidate.
Share this article
⚙Related Tools
📄Related Articles
Get More AI Tool Guides
New comparisons and guides every week. Join thousands of professionals staying ahead of the AI curve.