[{"data":1,"prerenderedAt":720},["ShallowReactive",2],{"categories-init":3,"stack-better-auth-self-hosted":4},true,{"stack_id":5,"slug":6,"name":7,"tagline":8,"long_description":9,"key_features":10,"use_cases":17,"pros":23,"cons":28,"cover_image_url":33,"scores":34,"options":48,"additions":420,"option_groups":474,"multi_select_option_types":480,"tools_by_category":481,"related_stacks":602,"faqs":669,"pricing":685,"system_requirements":700,"experience_level":625,"project_type":715,"stack_type_slug":610,"stack_type_icon_url":611,"published_date":130,"last_updated_date":33,"seo_meta":716},179,"better-auth-self-hosted","BetterAuth Self-Hosted","A self-hosted BetterAuth server: sign-in, sessions, and OAuth for your apps on infrastructure you run.","**BetterAuth** is an open-source TypeScript authentication framework. By default it lives inside your app: a route handler mounted at \u002Fapi\u002Fauth that stores users, sessions, and accounts in the app's own database. This stack runs it the other way, as a **dedicated auth server**: a small Node service whose only job is authentication, with PostgreSQL behind it and Docker packaging both.\n\nWhat makes that work is the **OAuth 2.1 Provider plugin**. It turns the BetterAuth instance into an authorization server with OpenID Connect: your apps register as clients, send users to the auth server to sign in, and receive signed tokens they verify against its JWKS endpoint. One login then covers every app that trusts the server, the way a hosted identity provider works, and the MCP plugin extends the same server to MCP servers and agent tools. Email and password, social providers, magic links, passkeys, two-factor authentication, and organizations all come from the same plugin system.\n\nWhat you give up is the **hosted dashboard**. The admin plugin exposes user management as APIs (list, ban, impersonate, revoke sessions) but ships no interface, so teams build a small admin page, run a community dashboard such as Better Auth Studio, or pay for the vendor's Better Auth Infrastructure, which adds a managed dashboard, audit logs, abuse protection, and email and SMS sending on top of the server you still run yourself.\n\nThe stack suits **several apps that should share one login**, products that need identity data on their own infrastructure, and TypeScript teams who want auth reviewed as code rather than configured in a vendor console. A single app with one backend usually doesn't need a separate server: mounting BetterAuth inside that backend is simpler, and the project stacks list it as an authentication option for exactly that.",[11,12,13,14,15,16],"OAuth 2.1 Provider plugin: one BetterAuth server signs users in for every app that trusts it","OpenID Connect with signed JWTs that clients verify through the server's JWKS endpoint","Email and password, social login, magic links, passkeys, and two-factor authentication as plugins","Users, sessions, accounts, and OAuth clients stored in your own PostgreSQL","Admin plugin APIs for listing, banning, and impersonating users and revoking sessions","Docker packaging for the auth server and PostgreSQL, portable across any VPS or cloud instance",[18,19,20,21,22],"Several apps or subdomains that should share one login","Products replacing Clerk or Auth0 to remove per-user pricing","Teams whose data-residency rules keep identity data off third-party services","Authorization for MCP servers and AI agent tools through the MCP plugin","TypeScript teams who want auth configuration reviewed in code",[24,25,26,27],"No per-user cost at any scale; the bill is one small server","Identity data stays in a PostgreSQL database you control and can export","Standard OAuth 2.1 and OpenID Connect, so any compliant client library can sign in against it","Auth configuration lives in TypeScript under version control",[29,30,31,32],"You are the identity provider: security patches, signing keys, and uptime are yours","No admin interface ships with the server; build one, run a community dashboard, or pay for the vendor's","Younger and less proven for multi-app federation than Keycloak","A separate server adds a deploy and a redirect hop compared with embedding BetterAuth in one app",null,{"popularity":35,"learning_curve":38,"flexibility":40,"performance":43,"portability":46},{"score":36,"reasoning":37},3,"BetterAuth has become a default recommendation in TypeScript auth conversations, though recognition is still concentrated in the fullstack TypeScript ecosystem.",{"score":36,"reasoning":39},"The library API is clean and TypeScript-first, but you are the identity provider — sessions, email verification, and MFA edge cases all land on your team.",{"score":41,"reasoning":42},5,"Sessions, OAuth providers, MFA, organizations, and the OAuth 2.1 provider arrive as composable plugins configured in TypeScript.",{"score":44,"reasoning":45},4,"Auth runs on your own server next to your own PostgreSQL, with no cross-region hop to a vendor; a dedicated server adds one redirect at sign-in, and headroom scales with hardware you control.",{"score":41,"reasoning":47},"User accounts are ordinary rows in your own PostgreSQL, so the data leaves with you; adopting a managed provider later is a migration rather than a wall.",{"database":49,"orm":53,"authentication":57,"analytics":61,"coding_agent":65,"llm":69,"language":73,"frontend_framework":77,"cms":81,"hosting":85,"reverse_proxy":269,"self_hosted_paas":359},{"tools":50,"descriptions":51,"aliases":52,"see_all":33},[],{},{},{"tools":54,"descriptions":55,"aliases":56,"see_all":33},[],{},{},{"tools":58,"descriptions":59,"aliases":60,"see_all":33},[],{},{},{"tools":62,"descriptions":63,"aliases":64,"see_all":33},[],{},{},{"tools":66,"descriptions":67,"aliases":68,"see_all":33},[],{},{},{"tools":70,"descriptions":71,"aliases":72,"see_all":33},[],{},{},{"tools":74,"descriptions":75,"aliases":76,"see_all":33},[],{},{},{"tools":78,"descriptions":79,"aliases":80,"see_all":33},[],{},{},{"tools":82,"descriptions":83,"aliases":84,"see_all":33},[],{},{},{"tools":86,"descriptions":259,"aliases":265,"see_all":266},[87,131,170,211,237],{"tool_id":88,"name":89,"slug":90,"tooltip_description":91,"logo_url":92,"logo_bg":93,"pricing_model":94,"learning_curve_score":98,"popularity_score":36,"hosting_assignment_type":33,"hosting_provider_restriction":99,"hosting_target_restriction":99,"hosting_compatible_tool_ids":33,"parent_tool_id":33,"category":100,"subcategory":103,"categories":107,"subcategories":110,"flexibility_score":36,"performance_score":44,"portability_score":44,"is_featured":112,"tags":113,"score_reasonings":123,"published_date":129,"last_updated_date":130},52,"Hetzner","hetzner","German cloud and dedicated server provider offering VPS, bare-metal servers, and storage at prices far below the big clouds, with data centers in the EU, the US, and Singapore.","https:\u002F\u002Fassets.tekyous.dev\u002Flogos\u002Ftools\u002Fhetzner.svg","white",{"slug":95,"display_name":96,"description":97},"paid","Paid","No meaningful free tier — a subscription or one-time purchase is required to use the tool.",2,"open",{"category_id":41,"name":101,"slug":102},"Hosting & Cloud","hosting-cloud",{"subcategory_id":104,"name":105,"slug":106},42,"VPS & Servers","vps-and-servers",[108],{"category_id":41,"name":101,"slug":102,"is_primary":3,"display_order":109},0,[111],{"subcategory_id":104,"name":105,"slug":106,"category_id":41,"is_primary":3,"display_order":109},false,[114,119],{"tag_id":115,"name":116,"slug":117,"tag_type":118},12,"Self-hostable","self-hostable","feature",{"tag_id":120,"name":121,"slug":122,"tag_type":118},21,"Multi-region","multi-region",{"learning_curve":124,"flexibility":125,"performance":126,"portability":127,"popularity":128},"Standard VPS setup; any developer comfortable with Linux can deploy in an afternoon.","Standard VPS; configure anything on Linux; no managed abstraction layer constraining choices.","Competitive hardware at low cost; dedicated and VPS servers deliver strong baseline performance.","Standard Linux VPS; highly portable with no managed-service abstraction to escape.","Popular among European developers and cost-conscious teams; strong reputation for value.","2026-05-29","2026-09-27",{"tool_id":132,"name":133,"slug":134,"tooltip_description":135,"logo_url":136,"logo_bg":93,"pricing_model":137,"learning_curve_score":98,"popularity_score":36,"hosting_assignment_type":33,"hosting_provider_restriction":99,"hosting_target_restriction":99,"hosting_compatible_tool_ids":33,"parent_tool_id":33,"category":141,"subcategory":142,"categories":146,"subcategories":148,"flexibility_score":44,"performance_score":44,"portability_score":36,"is_featured":112,"tags":150,"score_reasonings":164,"published_date":129,"last_updated_date":130},53,"Railway","railway","Modern PaaS for deploying apps, databases, and workers. Git-based deployment with infrastructure as code approach.","https:\u002F\u002Fassets.tekyous.dev\u002Flogos\u002Ftools\u002Frailway.svg",{"slug":138,"display_name":139,"description":140},"usage_based","Usage-Based","Pricing scales with consumption: API calls, data volume, compute time, or similar metered units.",{"category_id":41,"name":101,"slug":102},{"subcategory_id":143,"name":144,"slug":145},41,"App Hosting","app-hosting",[147],{"category_id":41,"name":101,"slug":102,"is_primary":3,"display_order":109},[149],{"subcategory_id":143,"name":144,"slug":145,"category_id":41,"is_primary":3,"display_order":109},[151,152,156,160],{"tag_id":115,"name":116,"slug":117,"tag_type":118},{"tag_id":153,"name":154,"slug":155,"tag_type":118},13,"Free Tier","free-tier",{"tag_id":157,"name":158,"slug":159,"tag_type":118},20,"Auto-scaling","auto-scaling",{"tag_id":161,"name":162,"slug":163,"tag_type":118},24,"Docker Compatible","docker-compatible",{"learning_curve":165,"performance":166,"portability":167,"flexibility":168,"popularity":169},"Git-push deploys work out of the box; most apps go live with zero configuration.","Container-based deployment mirrors the underlying cloud infrastructure performance.","Docker-based deployment is reasonably portable; switching to another host is manageable.","Dockerfile-based; supports any language, framework, and service composition.","Growing popularity for simple deployments; well-regarded in indie developer communities.",{"tool_id":171,"name":172,"slug":173,"tooltip_description":174,"logo_url":175,"logo_bg":93,"pricing_model":176,"learning_curve_score":180,"popularity_score":36,"hosting_assignment_type":33,"hosting_provider_restriction":99,"hosting_target_restriction":99,"hosting_compatible_tool_ids":33,"parent_tool_id":33,"category":181,"subcategory":182,"categories":183,"subcategories":185,"flexibility_score":36,"performance_score":36,"portability_score":36,"is_featured":112,"tags":187,"score_reasonings":205,"published_date":129,"last_updated_date":130},168,"Render","render","Fully managed cloud platform with Git-push deployments, managed Postgres, static sites, background workers, and cron jobs, all from one dashboard without writing infrastructure code.","https:\u002F\u002Fassets.tekyous.dev\u002Flogos\u002Ftools\u002Frender.svg",{"slug":177,"display_name":178,"description":179},"freemium","Freemium","A free tier is available; additional features, usage limits, or managed hosting require a paid plan.",1,{"category_id":41,"name":101,"slug":102},{"subcategory_id":143,"name":144,"slug":145},[184],{"category_id":41,"name":101,"slug":102,"is_primary":3,"display_order":109},[186],{"subcategory_id":143,"name":144,"slug":145,"category_id":41,"is_primary":3,"display_order":109},[188,189,194,195,199,200],{"tag_id":153,"name":154,"slug":155,"tag_type":118},{"tag_id":190,"name":191,"slug":192,"tag_type":193},40,"Web","web","platform",{"tag_id":157,"name":158,"slug":159,"tag_type":118},{"tag_id":196,"name":197,"slug":198,"tag_type":118},23,"Git-based","git-based",{"tag_id":161,"name":162,"slug":163,"tag_type":118},{"tag_id":201,"name":202,"slug":203,"tag_type":204},28,"Web Development","web-development","use_case",{"learning_curve":206,"flexibility":207,"performance":208,"popularity":209,"portability":210},"Render is among the most beginner-accessible deployment platforms available. No Dockerfile, no CLI, no YAML — connect a repo, and the platform builds and deploys automatically. The dashboard is clean and self-explanatory. Developers new to cloud deployment consistently cite Render as the easiest on-ramp to production hosting.","Covers the standard web app deployment pattern well: HTTP services, workers, cron, databases, and static sites. Docker is supported, and private networking is first-class. However the platform does not offer managed Kubernetes, GPU machines, or fine-grained infrastructure control. Advanced networking, multi-region active-active, and custom VM configurations are out of scope.","Flat-rate VMs with up to 32 GB RAM and 8 CPUs are available for demanding workloads, and zero-downtime deploys keep services live during updates. The free tier's 30–50 second cold start after inactivity is a significant limitation for demos and hobby projects, but paid tiers are always-on. Performance is competitive for a PaaS but not benchmark-leading.","Render is the most commonly cited Heroku replacement in developer communities as of 2026. It appears regularly in Reddit discussions, dev tooling newsletters, and startup stack comparisons. Growth has been strong since Heroku removed its free tier in 2022, though it remains smaller than Railway in developer mindshare.","Workloads on Render can be containerised and moved to any Docker-compatible host with modest effort. Managed Postgres exports standard pg_dump files. However the per-service model and render.yaml configuration are Render-specific; migrating a multi-service app requires translating cron, worker, and networking config into a new platform's conventions.",{"tool_id":212,"name":213,"slug":214,"tooltip_description":215,"logo_url":216,"logo_bg":93,"pricing_model":217,"learning_curve_score":98,"popularity_score":44,"hosting_assignment_type":33,"hosting_provider_restriction":99,"hosting_target_restriction":99,"hosting_compatible_tool_ids":33,"parent_tool_id":33,"category":218,"subcategory":219,"categories":220,"subcategories":222,"flexibility_score":44,"performance_score":44,"portability_score":44,"is_featured":112,"tags":224,"score_reasonings":231,"published_date":129,"last_updated_date":130},166,"DigitalOcean","digitalocean","Developer-focused cloud platform offering VPS (Droplets), managed Kubernetes, App Platform PaaS, and managed databases. Known for simple pricing and excellent documentation.","https:\u002F\u002Fassets.tekyous.dev\u002Flogos\u002Ftools\u002Fdigitalocean.svg",{"slug":138,"display_name":139,"description":140},{"category_id":41,"name":101,"slug":102},{"subcategory_id":143,"name":144,"slug":145},[221],{"category_id":41,"name":101,"slug":102,"is_primary":3,"display_order":109},[223],{"subcategory_id":143,"name":144,"slug":145,"category_id":41,"is_primary":3,"display_order":109},[225,226,227,228,229,230],{"tag_id":190,"name":191,"slug":192,"tag_type":193},{"tag_id":153,"name":154,"slug":155,"tag_type":118},{"tag_id":157,"name":158,"slug":159,"tag_type":118},{"tag_id":120,"name":121,"slug":122,"tag_type":118},{"tag_id":161,"name":162,"slug":163,"tag_type":118},{"tag_id":201,"name":202,"slug":203,"tag_type":204},{"learning_curve":232,"flexibility":233,"performance":234,"popularity":235,"portability":236},"DigitalOcean is specifically designed for developers rather than enterprise ops teams. The control panel is clean, Droplets launch in under 60 seconds, and App Platform requires no infrastructure knowledge at all. Thousands of community tutorials lower the barrier for beginners.","Offers VPS, PaaS, and managed Kubernetes under one roof, covering most deployment patterns from simple static sites to complex microservices. Custom networking, firewalls, VPC peering, and a full API give teams significant control. Missing serverless functions and some niche managed services limit the ceiling slightly.","NVMe SSDs and dedicated vCPU Droplets deliver competitive single-tenant performance. The 99.99% uptime SLA holds in practice per benchmark studies. Lacks the global edge network density of Cloudflare or the ultra-low-latency primitives of AWS.","Consistently ranks in the top 5 cloud providers for developer and startup usage. Strong presence on StackOverflow, Reddit, and developer surveys. Over 600,000 active customers as of 2024. Widely used as a first production cloud by self-taught developers.","Standard Linux VMs and Docker\u002FKubernetes workloads migrate freely to any other cloud or bare metal. No proprietary runtime lock-in. Spaces is S3-compatible. App Platform lock-in is higher — migrating away requires containerizing or adapting the build pipeline.",{"tool_id":238,"name":239,"slug":240,"tooltip_description":241,"logo_url":242,"logo_bg":93,"pricing_model":243,"learning_curve_score":98,"popularity_score":36,"hosting_assignment_type":33,"hosting_provider_restriction":99,"hosting_target_restriction":99,"hosting_compatible_tool_ids":33,"parent_tool_id":33,"category":244,"subcategory":245,"categories":246,"subcategories":248,"flexibility_score":36,"performance_score":36,"portability_score":36,"is_featured":112,"tags":250,"score_reasonings":253,"published_date":129,"last_updated_date":130},169,"Hostinger","hostinger","Affordable web hosting with shared, cloud, and agency plans plus KVM VPS, on LiteSpeed servers with NVMe storage and the beginner-friendly hPanel control panel.","https:\u002F\u002Fassets.tekyous.dev\u002Flogos\u002Ftools\u002Fhostinger.svg",{"slug":95,"display_name":96,"description":97},{"category_id":41,"name":101,"slug":102},{"subcategory_id":104,"name":105,"slug":106},[247],{"category_id":41,"name":101,"slug":102,"is_primary":3,"display_order":109},[249],{"subcategory_id":104,"name":105,"slug":106,"category_id":41,"is_primary":3,"display_order":109},[251,252],{"tag_id":190,"name":191,"slug":192,"tag_type":193},{"tag_id":201,"name":202,"slug":203,"tag_type":204},{"learning_curve":254,"flexibility":255,"performance":256,"popularity":257,"portability":258},"Shared hosting on Hostinger is genuinely beginner-accessible — hPanel, one-click WordPress, and the Kodee AI assistant reduce the complexity of common tasks to a few clicks. VPS plans require Linux and SSH familiarity to get full value, but the guided setup and AI assistant lower the barrier compared to raw VPS providers like Hetzner.","Shared hosting is intentionally constrained — you run within Hostinger's stack and cannot change the server environment. VPS plans give full root access and can run any Linux workload. The range from shared to VPS covers most beginner-to-intermediate deployment needs, but there is no managed Kubernetes, serverless, or edge compute option.","LiteSpeed with NVMe SSD and built-in caching delivers strong performance for shared hosting — independent benchmarks show sub-1-second load times and 99.96%+ uptime on shared plans. KVM VPS performance is competitive for the price. Not at the level of dedicated cloud providers like DigitalOcean or Hetzner for compute-intensive workloads.","Hostinger is one of the top three most-recommended budget hosts globally, with over 3 million customers and a 4.7\u002F5 Trustpilot score. It dominates beginner and bootstrapper audiences and appears consistently in 'best cheap hosting' roundups. Less visible in developer-tool and startup-stack communities compared to cloud-native platforms.","Shared hosting creates moderate lock-in via hPanel and Hostinger-specific tooling, though WordPress sites can be migrated via standard exports. VPS instances are standard KVM Linux — fully portable to any other VPS provider. No proprietary runtime or framework dependencies on the VPS side.",{"hetzner":260,"railway":261,"render":262,"digitalocean":263,"hostinger":264},"A flat-rate root VPS where the auth server and its PostgreSQL share one small instance, from around €4-5\u002Fmo. Login traffic is light, so an entry instance carries a sizeable user base; the cost is running backups and security updates yourself, which matters more for an identity server than for most services.","Runs the auth server as an ordinary Node service with managed PostgreSQL in the same project, redeploying on git push. Railway terminates TLS itself, so the reverse proxy or PaaS choice doesn't apply. The $5\u002Fmo Hobby plan plus usage typically lands a small auth server around $10\u002Fmo, with no server to patch.","Runs the auth server as a Node web service with Render's managed PostgreSQL behind it and TLS terminated at the platform. Skip the free tier: a free service sleeps after 15 minutes idle and its free database expires after 30 days, and a sign-in that waits on a cold start is a poor first impression. Budget the $7\u002Fmo Starter instance plus the database.","A root Droplet from about $6\u002Fmo with snapshots and a cloud firewall in the panel, plus managed PostgreSQL (from about $15\u002Fmo) if you'd rather not run the identity database yourself. Managed backups with point-in-time recovery are the reason to pick it for auth specifically: that database holds every user, session, and signing key.","The lowest-cost VPS in the list, with KVM plans from around $5\u002Fmo and a beginner-friendly panel. BetterAuth's own footprint is modest, so the entry plan works; the tradeoff is fewer regions for placing the auth server near your apps' users, and backups and hardening are still yours.",{},{"kind":267,"slug":102,"name":101,"href":268},"category","\u002Ftools\u002Fcategories\u002Fhosting-cloud",{"tools":270,"descriptions":354,"aliases":358,"see_all":33},[271,303,330],{"tool_id":272,"name":273,"slug":274,"tooltip_description":275,"logo_url":276,"logo_bg":93,"pricing_model":277,"learning_curve_score":36,"popularity_score":44,"hosting_assignment_type":33,"hosting_provider_restriction":99,"hosting_target_restriction":99,"hosting_compatible_tool_ids":33,"parent_tool_id":33,"category":278,"subcategory":281,"categories":285,"subcategories":287,"flexibility_score":44,"performance_score":44,"portability_score":41,"is_featured":112,"tags":289,"score_reasonings":297,"published_date":130,"last_updated_date":33},189,"Traefik","traefik","A cloud-native reverse proxy that auto-discovers routes from Docker container labels, updating its configuration live as containers start and stop.","https:\u002F\u002Fassets.tekyous.dev\u002Flogos\u002Ftools\u002Ftraefik.svg",{"slug":177,"display_name":178,"description":179},{"category_id":115,"name":279,"slug":280},"DevOps & CI\u002FCD","devops-cicd",{"subcategory_id":282,"name":283,"slug":284},57,"Web Servers & Reverse Proxies","web-servers-reverse-proxies",[286],{"category_id":115,"name":279,"slug":280,"is_primary":3,"display_order":109},[288],{"subcategory_id":282,"name":283,"slug":284,"category_id":115,"is_primary":3,"display_order":109},[290,294,295,296],{"tag_id":291,"name":292,"slug":293,"tag_type":118},11,"Open Source","open-source",{"tag_id":115,"name":116,"slug":117,"tag_type":118},{"tag_id":161,"name":162,"slug":163,"tag_type":118},{"tag_id":190,"name":191,"slug":192,"tag_type":193},{"learning_curve":298,"flexibility":299,"performance":300,"popularity":301,"portability":302},"Basic Docker label routing is quick to pick up, but understanding the provider model, middleware chains, and dashboard takes more upfront investment than Caddy's flat config file, especially for anyone unfamiliar with label-driven tooling.","Native providers for Docker, Kubernetes, Swarm, Consul, and ECS plus a composable middleware system cover most container-routing scenarios, though its module ecosystem is narrower than NGINX's after two decades of third-party extensions.","Built in Go with an efficient routing engine, it performs comparably to Caddy for typical self-hosted and mid-scale container workloads.","It's the de facto reverse proxy for the Docker\u002FKubernetes self-hosting community and powers routing inside Coolify and Dokploy, with a large and actively growing GitHub following, though still behind NGINX's decades-long install base.","MIT licensed, ships as a single binary and official Docker image, and runs identically across any VPS, Kubernetes cluster, or cloud provider with no lock-in.",{"tool_id":304,"name":305,"slug":306,"tooltip_description":307,"logo_url":308,"logo_bg":309,"pricing_model":310,"learning_curve_score":180,"popularity_score":36,"hosting_assignment_type":33,"hosting_provider_restriction":99,"hosting_target_restriction":99,"hosting_compatible_tool_ids":33,"parent_tool_id":33,"category":313,"subcategory":314,"categories":315,"subcategories":317,"flexibility_score":36,"performance_score":44,"portability_score":41,"is_featured":112,"tags":319,"score_reasonings":324,"published_date":130,"last_updated_date":33},188,"Caddy","caddy","A modern web server and reverse proxy written in Go, best known for provisioning and renewing HTTPS certificates automatically with zero configuration.","https:\u002F\u002Fassets.tekyous.dev\u002Flogos\u002Ftools\u002Fcaddy.svg","dark",{"slug":311,"display_name":292,"description":312},"open_source","Source code is publicly available and free to use, modify, and distribute. No paid plans from the project itself.",{"category_id":115,"name":279,"slug":280},{"subcategory_id":282,"name":283,"slug":284},[316],{"category_id":115,"name":279,"slug":280,"is_primary":3,"display_order":109},[318],{"subcategory_id":282,"name":283,"slug":284,"category_id":115,"is_primary":3,"display_order":109},[320,321,322,323],{"tag_id":291,"name":292,"slug":293,"tag_type":118},{"tag_id":115,"name":116,"slug":117,"tag_type":118},{"tag_id":161,"name":162,"slug":163,"tag_type":118},{"tag_id":190,"name":191,"slug":192,"tag_type":193},{"learning_curve":325,"flexibility":326,"performance":327,"popularity":328,"portability":329},"A working reverse proxy with HTTPS is typically a few lines of Caddyfile, and automatic certificate provisioning removes the TLS setup step entirely, making it one of the easiest reverse proxies to get running for the first time.","The Caddyfile and JSON config cover most reverse-proxy and static-serving needs well, but its plugin ecosystem and edge-case module coverage are considerably smaller than NGINX's after two decades of third-party modules.","Built in Go with a modern, concurrent architecture and native HTTP\u002F3 support, it performs well for typical self-hosted and small-to-mid traffic workloads, though it hasn't accumulated NGINX's extreme-scale benchmark track record.","It's a well-known, growing choice in the self-hosted community specifically for its automatic-HTTPS pitch, but its adoption and star count remain well behind NGINX's decades-long dominance.","Apache 2.0 licensed, distributed as a single static binary with an official Docker image, and runs identically on any VPS or OS with zero vendor lock-in.",{"tool_id":331,"name":332,"slug":333,"tooltip_description":334,"logo_url":335,"logo_bg":309,"pricing_model":336,"learning_curve_score":36,"popularity_score":41,"hosting_assignment_type":33,"hosting_provider_restriction":99,"hosting_target_restriction":99,"hosting_compatible_tool_ids":33,"parent_tool_id":33,"category":337,"subcategory":338,"categories":339,"subcategories":341,"flexibility_score":41,"performance_score":41,"portability_score":41,"is_featured":112,"tags":343,"score_reasonings":348,"published_date":130,"last_updated_date":33},187,"NGINX","nginx","The most widely deployed web server and reverse proxy on the internet, known for event-driven performance under high concurrency.","https:\u002F\u002Fassets.tekyous.dev\u002Flogos\u002Ftools\u002Fnginx.svg",{"slug":177,"display_name":178,"description":179},{"category_id":115,"name":279,"slug":280},{"subcategory_id":282,"name":283,"slug":284},[340],{"category_id":115,"name":279,"slug":280,"is_primary":3,"display_order":109},[342],{"subcategory_id":282,"name":283,"slug":284,"category_id":115,"is_primary":3,"display_order":109},[344,345,346,347],{"tag_id":291,"name":292,"slug":293,"tag_type":118},{"tag_id":115,"name":116,"slug":117,"tag_type":118},{"tag_id":161,"name":162,"slug":163,"tag_type":118},{"tag_id":190,"name":191,"slug":192,"tag_type":193},{"learning_curve":349,"flexibility":350,"performance":351,"popularity":352,"portability":353},"Basic reverse-proxy blocks are simple to copy-paste, but real production setups (upstream health checks, TLS automation, rewrite rules, rate limiting) require understanding NGINX's directive-based config language in depth, and there's no built-in automatic HTTPS to lean on.","A vast module ecosystem and a fully declarative config language let it act as a reverse proxy, load balancer, cache, static file server, or WAF front-end, with third-party modules covering nearly any edge case.","Its event-driven, non-blocking architecture was purpose-built to solve the C10k problem, and it remains a top performer in every major reverse-proxy benchmark for throughput and memory efficiency under concurrent load.","It has been the most widely deployed web server on the public internet for years, appears in essentially every stack survey, and has the largest surrounding tutorial and community knowledge base of any web server.","The open-source core is free, packaged for every OS and as an official Docker image, and runs identically on any VPS or cloud provider with no vendor lock-in.",{"traefik":355,"caddy":356,"nginx":357},"Configures itself from Docker labels on the auth container and renews Let's Encrypt certificates automatically. The BetterAuth setting to get right behind any proxy is the public base URL (BETTER_AUTH_URL) and the trusted origins, since OAuth redirect URIs and the token issuer are built from them.","Automatic HTTPS from a few lines of config, simpler than Traefik's labels for a single auth service. Caddy forwards the original host and protocol by default, so secure session cookies and OAuth callbacks see the public HTTPS address without extra setup.","The most familiar proxy, with TLS managed manually through Certbot. Set the forwarded protocol and host headers explicitly: without them the auth server believes it runs on plain HTTP, and secure cookies or OAuth redirect URIs come out wrong.",{},{"tools":360,"descriptions":416,"aliases":419,"see_all":33},[361,390],{"tool_id":362,"name":363,"slug":364,"tooltip_description":365,"logo_url":366,"logo_bg":309,"pricing_model":367,"learning_curve_score":36,"popularity_score":36,"hosting_assignment_type":33,"hosting_provider_restriction":99,"hosting_target_restriction":99,"hosting_compatible_tool_ids":33,"parent_tool_id":33,"category":368,"subcategory":369,"categories":373,"subcategories":375,"flexibility_score":44,"performance_score":36,"portability_score":41,"is_featured":112,"tags":377,"score_reasonings":384,"published_date":130,"last_updated_date":33},183,"Coolify","coolify","Open-source, self-hostable PaaS that brings a Heroku\u002FVercel-style git-push deploy workflow to your own server.","https:\u002F\u002Fassets.tekyous.dev\u002Flogos\u002Ftools\u002Fcoolify.svg",{"slug":311,"display_name":292,"description":312},{"category_id":41,"name":101,"slug":102},{"subcategory_id":370,"name":371,"slug":372},56,"Self-Hosted PaaS","self-hosted-paas",[374],{"category_id":41,"name":101,"slug":102,"is_primary":3,"display_order":109},[376],{"subcategory_id":370,"name":371,"slug":372,"category_id":41,"is_primary":3,"display_order":109},[378,379,380,381,382,383],{"tag_id":291,"name":292,"slug":293,"tag_type":118},{"tag_id":115,"name":116,"slug":117,"tag_type":118},{"tag_id":153,"name":154,"slug":155,"tag_type":118},{"tag_id":196,"name":197,"slug":198,"tag_type":118},{"tag_id":161,"name":162,"slug":163,"tag_type":118},{"tag_id":190,"name":191,"slug":192,"tag_type":193},{"learning_curve":385,"flexibility":386,"performance":387,"popularity":388,"portability":389},"Deploying a simple app is a git-push away once Coolify is installed, but getting there requires provisioning and SSH-connecting a server first, and troubleshooting still touches Docker and Linux server concepts that a fully managed PaaS abstracts away entirely.","Supports Nixpacks, Dockerfiles, and Docker Compose directly, plus 280+ one-click services, making it capable of hosting nearly anything that runs in a container — bounded mainly by what the underlying server's resources can handle.","There is no platform-level performance ceiling of its own; a deployment's speed and headroom are a direct function of the VPS or hardware Coolify is installed on, which can range from a budget €4\u002Fmonth instance to a large dedicated server.","A fast-growing, well-starred open-source project with strong traction in the self-hosting and indie-hacker community, though it remains a niche choice relative to mainstream managed PaaS platforms like Railway, Render, or Vercel.","Apache 2.0 licensed and built entirely on standard Docker tooling with no proprietary runtime — a Coolify-managed deployment can be moved to a different server (or off Coolify entirely, back to raw Docker Compose) with minimal friction.",{"tool_id":391,"name":392,"slug":393,"tooltip_description":394,"logo_url":395,"logo_bg":309,"pricing_model":396,"learning_curve_score":98,"popularity_score":36,"hosting_assignment_type":33,"hosting_provider_restriction":99,"hosting_target_restriction":99,"hosting_compatible_tool_ids":33,"parent_tool_id":33,"category":397,"subcategory":398,"categories":399,"subcategories":401,"flexibility_score":44,"performance_score":36,"portability_score":41,"is_featured":112,"tags":403,"score_reasonings":410,"published_date":130,"last_updated_date":33},184,"Dokploy","dokploy","Open-source, self-hostable PaaS that deploys apps, Docker Compose stacks, and managed databases across one or more of your own servers.","https:\u002F\u002Fassets.tekyous.dev\u002Flogos\u002Ftools\u002Fdokploy.svg",{"slug":311,"display_name":292,"description":312},{"category_id":41,"name":101,"slug":102},{"subcategory_id":370,"name":371,"slug":372},[400],{"category_id":41,"name":101,"slug":102,"is_primary":3,"display_order":109},[402],{"subcategory_id":370,"name":371,"slug":372,"category_id":41,"is_primary":3,"display_order":109},[404,405,406,407,408,409],{"tag_id":291,"name":292,"slug":293,"tag_type":118},{"tag_id":115,"name":116,"slug":117,"tag_type":118},{"tag_id":153,"name":154,"slug":155,"tag_type":118},{"tag_id":196,"name":197,"slug":198,"tag_type":118},{"tag_id":161,"name":162,"slug":163,"tag_type":118},{"tag_id":190,"name":191,"slug":192,"tag_type":193},{"learning_curve":411,"flexibility":412,"performance":413,"popularity":414,"portability":415},"A cleaner, single-page dashboard and a deployment-first workflow make basic app deployment quick to pick up once a server is connected, though the underlying Docker Swarm concepts still surface for multi-node scaling and advanced configuration.","Native Docker Compose support plus Dockerfile and buildpack deployment covers nearly any containerizable workload, and multi-database support extends it well beyond simple app hosting — bounded mainly by the underlying server's resources.","There is no platform-level performance ceiling of its own; deployment speed and headroom are a direct function of the VPS or hardware Dokploy is installed on.","A fast-growing open-source project with a large and rapidly increasing GitHub star count, though it is younger and currently has a smaller community than the category leader, Coolify.","Apache-2.0-licensed core built on standard Docker and Docker Swarm tooling with no proprietary runtime — a Dokploy-managed deployment can move to a different server, or off Dokploy entirely back to raw Docker Compose, with minimal friction.",{"coolify":417,"dokploy":418},"Deploys the auth server from its Docker image with PostgreSQL provisioned beside it and HTTPS from Coolify's bundled proxy, managed from a dashboard instead of a config file. Useful when the auth server shares a VPS with the apps that sign in through it, since Coolify can host those too.","The same dashboard-driven deploy as Coolify, with its own bundled proxy and one-click databases, from a newer and smaller project. Check its scheduled database backups before choosing: the PostgreSQL service it runs is the whole of your identity data.",{},{"tunnel":421},{"tools":422,"descriptions":469,"aliases":472,"preface":473,"see_all":33},[423,448],{"tool_id":424,"name":425,"slug":426,"tooltip_description":427,"logo_url":428,"logo_bg":309,"pricing_model":429,"learning_curve_score":36,"popularity_score":36,"hosting_assignment_type":33,"hosting_provider_restriction":99,"hosting_target_restriction":99,"hosting_compatible_tool_ids":33,"parent_tool_id":33,"category":430,"subcategory":431,"categories":435,"subcategories":437,"flexibility_score":44,"performance_score":44,"portability_score":98,"is_featured":112,"tags":439,"score_reasonings":442,"published_date":130,"last_updated_date":33},258,"Cloudflare Tunnel","cloudflare-tunnel","Cloudflare Tunnel creates an outbound-only encrypted connection from your server to Cloudflare's network, exposing self-hosted services to the internet without opening inbound ports.","https:\u002F\u002Fassets.tekyous.dev\u002Flogos\u002Ftools\u002Fcloudflare.svg",{"slug":177,"display_name":178,"description":179},{"category_id":115,"name":279,"slug":280},{"subcategory_id":432,"name":433,"slug":434},70,"Tunneling & Secure Access","tunneling-secure-access",[436],{"category_id":115,"name":279,"slug":280,"is_primary":3,"display_order":109},[438],{"subcategory_id":432,"name":433,"slug":434,"category_id":115,"is_primary":3,"display_order":109},[440,441],{"tag_id":153,"name":154,"slug":155,"tag_type":118},{"tag_id":190,"name":191,"slug":192,"tag_type":193},{"learning_curve":443,"flexibility":444,"performance":445,"popularity":446,"portability":447},"Getting a tunnel running requires a Cloudflare account, a domain on Cloudflare DNS, and configuring ingress rules for each hostname — more setup than a single-binary tunnel tool, though well documented and a common homelab pattern once learned.","Ingress rules can route many hostnames to different local services from one tunnel, Zero Trust Access adds per-hostname authentication, and the same daemon handles HTTP alongside TCP\u002FUDP via WARP.","Traffic rides Cloudflare's global Anycast network end to end, giving it the same routing and edge performance as the rest of Cloudflare's CDN.","A standard recommendation in self-hosting and homelab communities for exposing services without port forwarding, though it competes with several other tunnel tools rather than being the default name people reach for first.","Tightly coupled to a Cloudflare account and DNS zone — migrating off Cloudflare means replacing the entire exposure mechanism, not just swapping a config value.",{"tool_id":449,"name":450,"slug":450,"tooltip_description":451,"logo_url":452,"logo_bg":93,"pricing_model":453,"learning_curve_score":180,"popularity_score":44,"hosting_assignment_type":33,"hosting_provider_restriction":99,"hosting_target_restriction":99,"hosting_compatible_tool_ids":33,"parent_tool_id":33,"category":454,"subcategory":455,"categories":456,"subcategories":458,"flexibility_score":36,"performance_score":36,"portability_score":44,"is_featured":112,"tags":460,"score_reasonings":463,"published_date":130,"last_updated_date":33},259,"ngrok","ngrok is a globally distributed reverse proxy that creates secure public URLs for a local server in seconds, commonly used for local dev previews, webhook testing, and exposing self-hosted services.","https:\u002F\u002Fassets.tekyous.dev\u002Flogos\u002Ftools\u002Fngrok.svg",{"slug":177,"display_name":178,"description":179},{"category_id":115,"name":279,"slug":280},{"subcategory_id":432,"name":433,"slug":434},[457],{"category_id":115,"name":279,"slug":280,"is_primary":3,"display_order":109},[459],{"subcategory_id":432,"name":433,"slug":434,"category_id":115,"is_primary":3,"display_order":109},[461,462],{"tag_id":153,"name":154,"slug":155,"tag_type":118},{"tag_id":190,"name":191,"slug":192,"tag_type":193},{"learning_curve":464,"flexibility":465,"performance":466,"popularity":467,"portability":468},"A single CLI command produces a working public URL with no account configuration, DNS setup, or domain ownership required to get started.","Covers HTTP, TCP, and TLS tunnels plus Kubernetes ingress, with edge traffic policies for auth and rate limiting, though the deepest features sit behind paid plans.","Runs on a globally distributed edge network with solid latency for typical dev-preview and webhook workloads, without the scale of the largest CDN networks.","The name most developers reach for first when they need to expose a local server — long-standing mindshare in webhook testing and dev-preview workflows specifically.","A standalone client binary that works against any local service or cloud origin with no DNS zone or vendor account tie-in beyond ngrok itself, making it easy to drop into any project.",{"cloudflare-tunnel":470,"ngrok":471},"Makes the auth server reachable over HTTPS through an outbound-only connection, with no inbound ports or static IP, for a server on a home network or behind NAT. The public hostname becomes the base URL your apps' OAuth redirects point to, so settle it before registering clients.","The quicker-start tunnel for testing sign-in flows against an auth server on your own machine. Its free-tier limits suit development rather than a production identity server that every app depends on.",{},"Add a tunnel when you're self-hosting without a static IP or can't open inbound ports — a home server, a VPS behind restrictive network policies, or anywhere a reverse proxy alone can't reach the internet.",{"exposure":475},{"name":476,"option_types":477},"Reverse Proxy or PaaS",[478,479],"reverse_proxy","self_hosted_paas",[],{"Databases":482,"Hosting & Cloud":518,"Authentication":531,"DevOps & CI\u002FCD":567},[483],{"tool_id":190,"name":484,"slug":485,"tooltip_description":486,"logo_url":487,"logo_bg":309,"pricing_model":488,"learning_curve_score":36,"popularity_score":41,"hosting_assignment_type":489,"hosting_provider_restriction":99,"hosting_target_restriction":99,"hosting_compatible_tool_ids":33,"parent_tool_id":33,"category":490,"subcategory":493,"categories":497,"subcategories":499,"flexibility_score":41,"performance_score":44,"portability_score":41,"is_featured":3,"tags":501,"score_reasonings":512,"published_date":129,"last_updated_date":130},"PostgreSQL","postgresql","PostgreSQL is a free, open-source object-relational database known for reliability, standards compliance, and extensibility, with rich data types, JSONB, and a large ecosystem of extensions such as PostGIS and pgvector.","https:\u002F\u002Fassets.tekyous.dev\u002Flogos\u002Ftools\u002Fpostgresql.svg",{"slug":311,"display_name":292,"description":312},"deployable",{"category_id":44,"name":491,"slug":492},"Databases","databases",{"subcategory_id":494,"name":495,"slug":496},25,"OLTP Databases","oltp-databases",[498],{"category_id":44,"name":491,"slug":492,"is_primary":3,"display_order":109},[500],{"subcategory_id":494,"name":495,"slug":496,"category_id":44,"is_primary":3,"display_order":109},[502,506,507,508],{"tag_id":44,"name":503,"slug":504,"tag_type":505},"SQL","sql","technology",{"tag_id":291,"name":292,"slug":293,"tag_type":118},{"tag_id":115,"name":116,"slug":117,"tag_type":118},{"tag_id":509,"name":510,"slug":511,"tag_type":118},22,"ACID Compliant","acid-compliant",{"learning_curve":513,"flexibility":514,"performance":515,"portability":516,"popularity":517},"Standard SQL is broadly known, but CTEs, window functions, and JSONB take time to master.","Extensions like PostGIS and pgvector, custom types, and PL\u002FpgSQL cover virtually any need.","Battle-tested query planner; efficient with proper indexing and regular vacuum.","Open SQL standard with no lock-in; data and skills transfer to any SQL-compatible system.","The most popular relational database among developers per Stack Overflow 2024; rapidly growing.",[519],{"tool_id":88,"name":89,"slug":90,"tooltip_description":91,"logo_url":92,"logo_bg":93,"pricing_model":520,"learning_curve_score":98,"popularity_score":36,"hosting_assignment_type":33,"hosting_provider_restriction":99,"hosting_target_restriction":99,"hosting_compatible_tool_ids":33,"parent_tool_id":33,"category":521,"subcategory":522,"categories":523,"subcategories":525,"flexibility_score":36,"performance_score":44,"portability_score":44,"is_featured":112,"tags":527,"score_reasonings":530,"published_date":129,"last_updated_date":130},{"slug":95,"display_name":96,"description":97},{"category_id":41,"name":101,"slug":102},{"subcategory_id":104,"name":105,"slug":106},[524],{"category_id":41,"name":101,"slug":102,"is_primary":3,"display_order":109},[526],{"subcategory_id":104,"name":105,"slug":106,"category_id":41,"is_primary":3,"display_order":109},[528,529],{"tag_id":115,"name":116,"slug":117,"tag_type":118},{"tag_id":120,"name":121,"slug":122,"tag_type":118},{"learning_curve":124,"flexibility":125,"performance":126,"portability":127,"popularity":128},[532],{"tool_id":533,"name":534,"slug":535,"tooltip_description":536,"logo_url":537,"logo_bg":538,"pricing_model":539,"learning_curve_score":36,"popularity_score":36,"hosting_assignment_type":540,"hosting_provider_restriction":99,"hosting_target_restriction":99,"hosting_compatible_tool_ids":33,"parent_tool_id":33,"category":541,"subcategory":33,"categories":545,"subcategories":547,"flexibility_score":41,"performance_score":44,"portability_score":41,"is_featured":112,"tags":548,"score_reasonings":561,"published_date":129,"last_updated_date":130},173,"BetterAuth","better-auth","Open-source TypeScript authentication framework that runs inside your app, covering email and password, social OAuth, passkeys, multi-tenancy, and SSO with no per-user pricing, plus an optional paid dashboard.","https:\u002F\u002Fassets.tekyous.dev\u002Flogos\u002Ftools\u002Fbetter-auth.svg","black",{"slug":177,"display_name":178,"description":179},"library",{"category_id":542,"name":543,"slug":544},9,"Authentication","authentication",[546],{"category_id":542,"name":543,"slug":544,"is_primary":3,"display_order":109},[],[549,550,551,552,555,558,560],{"tag_id":291,"name":292,"slug":293,"tag_type":118},{"tag_id":190,"name":191,"slug":192,"tag_type":193},{"tag_id":115,"name":116,"slug":117,"tag_type":118},{"tag_id":36,"name":553,"slug":554,"tag_type":505},"TypeScript","typescript",{"tag_id":98,"name":556,"slug":557,"tag_type":505},"JavaScript","javascript",{"tag_id":559,"name":543,"slug":544,"tag_type":204},34,{"tag_id":201,"name":202,"slug":203,"tag_type":204},{"learning_curve":562,"flexibility":563,"performance":564,"popularity":565,"portability":566},"BetterAuth is deliberately designed to be simpler than NextAuth and well-documented, but setting up database adapters, configuring plugins, and understanding session management still requires meaningful onboarding. Developers comfortable with Node.js and TypeScript get productive quickly; those new to auth concepts will need more time.","Plugin-based architecture lets you compose exactly the features you need. Database adapters support PostgreSQL, MySQL, SQLite, and MongoDB. Framework adapters cover Next.js, Nuxt, SvelteKit, Astro, Hono, Express, Fastify, and more. The plugin API allows custom extensions. Essentially unlimited customisation within the Node.js\u002FTypeScript runtime.","Runs inside your application process with no external network call for session checks — auth validation is a database query to your own instance. Performance is constrained by your database choice and query patterns rather than third-party API latency. Stateless session mode (v1.4+) eliminates even the database lookup for JWT-based flows.","Grew from launch to 13K+ GitHub stars within roughly a year, backed by Y Combinator (W25), and gained major momentum when the Auth.js \u002F NextAuth team merged into the project in September 2025. Weekly npm downloads in the hundreds of thousands. Still younger and less established than Auth0 or Clerk in market share.","MIT-licensed and fully self-hosted — deploy on any VPS, PaaS, or cloud provider that runs Node.js. No vendor lock-in: your user data lives in your own database, sessions are managed by your own instance, and migrating away requires only swapping the auth library rather than migrating a third-party service's data.",[568],{"tool_id":569,"name":570,"slug":571,"tooltip_description":572,"logo_url":573,"logo_bg":309,"pricing_model":574,"learning_curve_score":44,"popularity_score":41,"hosting_assignment_type":33,"hosting_provider_restriction":99,"hosting_target_restriction":99,"hosting_compatible_tool_ids":33,"parent_tool_id":33,"category":575,"subcategory":576,"categories":580,"subcategories":582,"flexibility_score":41,"performance_score":44,"portability_score":41,"is_featured":3,"tags":584,"score_reasonings":596,"published_date":129,"last_updated_date":130},72,"Docker","docker","Container platform for packaging applications and their dependencies into portable images that run the same on a laptop, in CI, and in production, with Docker Desktop, Compose, and Docker Hub.","https:\u002F\u002Fassets.tekyous.dev\u002Flogos\u002Ftools\u002Fdocker.svg",{"slug":177,"display_name":178,"description":179},{"category_id":115,"name":279,"slug":280},{"subcategory_id":577,"name":578,"slug":579},33,"Containerization","containerization",[581],{"category_id":115,"name":279,"slug":280,"is_primary":3,"display_order":109},[583],{"subcategory_id":577,"name":578,"slug":579,"category_id":115,"is_primary":3,"display_order":109},[585,586,587,588,592],{"tag_id":291,"name":292,"slug":293,"tag_type":118},{"tag_id":115,"name":116,"slug":117,"tag_type":118},{"tag_id":161,"name":162,"slug":163,"tag_type":118},{"tag_id":589,"name":590,"slug":591,"tag_type":204},36,"CI\u002FCD","ci-cd",{"tag_id":593,"name":594,"slug":595,"tag_type":193},43,"Cross-platform","cross-platform",{"learning_curve":597,"performance":598,"portability":599,"flexibility":600,"popularity":601},"Container images, networking, volumes, and multi-stage builds all need deliberate learning.","Container overhead is minimal; near-native performance for most workloads.","Open standard; containers built with Docker run on any container-compatible platform.","Any runtime, any architecture; multi-stage builds and Compose profiles support complex systems.","The standard for containerization; present in virtually every modern software project.",[603,620,638,650],{"stack_id":604,"slug":605,"name":606,"tagline":607,"experience_level":608,"project_type":609,"stack_type_slug":610,"stack_type_icon_url":611,"score_popularity":36,"score_learning_curve":98,"catalog_display_order":33,"published_date":33,"last_updated_date":33,"core_tool_previews":612},156,"strapi-self-hosted","Strapi Self-Hosted","Self-hosted Strapi: an open-source headless CMS with PostgreSQL, on a server you control.","beginner","website","infrastructure","https:\u002F\u002Fassets.tekyous.dev\u002Ficons\u002Fstack-types\u002Finfrastructure.svg",[613,614,615],{"tool_id":190,"slug":485,"name":484,"logo_url":487,"logo_bg":309},{"tool_id":569,"slug":571,"name":570,"logo_url":573,"logo_bg":309},{"tool_id":616,"slug":617,"name":618,"logo_url":619,"logo_bg":93},88,"strapi","Strapi","https:\u002F\u002Fassets.tekyous.dev\u002Flogos\u002Ftools\u002Fstrapi.svg",{"stack_id":621,"slug":622,"name":623,"tagline":624,"experience_level":625,"project_type":626,"stack_type_slug":610,"stack_type_icon_url":611,"score_popularity":41,"score_learning_curve":44,"catalog_display_order":33,"published_date":33,"last_updated_date":33,"core_tool_previews":627},219,"apache-airflow-self-hosted","Airflow Self-Hosted","Self-hosted Apache Airflow: the standard data-pipeline scheduler on your infrastructure.","intermediate","data_pipeline",[628,629,633,634],{"tool_id":190,"slug":485,"name":484,"logo_url":487,"logo_bg":309},{"tool_id":143,"slug":630,"name":631,"logo_url":632,"logo_bg":309},"redis","Redis","https:\u002F\u002Fassets.tekyous.dev\u002Flogos\u002Ftools\u002Fredis.svg",{"tool_id":569,"slug":571,"name":570,"logo_url":573,"logo_bg":309},{"tool_id":542,"slug":635,"name":636,"logo_url":637,"logo_bg":309},"apache-airflow","Apache Airflow","https:\u002F\u002Fassets.tekyous.dev\u002Flogos\u002Ftools\u002Fapache-airflow.svg",{"stack_id":639,"slug":640,"name":641,"tagline":642,"experience_level":625,"project_type":643,"stack_type_slug":610,"stack_type_icon_url":611,"score_popularity":44,"score_learning_curve":36,"catalog_display_order":33,"published_date":33,"last_updated_date":33,"core_tool_previews":644},150,"n8n-self-hosted","n8n Self-Hosted","Self-hosted n8n on your own server, with full control over the database, the host, and how it's exposed to the internet.","automation",[645,646,649],{"tool_id":190,"slug":485,"name":484,"logo_url":487,"logo_bg":309},{"tool_id":509,"slug":647,"name":647,"logo_url":648,"logo_bg":309},"n8n","https:\u002F\u002Fassets.tekyous.dev\u002Flogos\u002Ftools\u002Fn8n.svg",{"tool_id":569,"slug":571,"name":570,"logo_url":573,"logo_bg":309},{"stack_id":651,"slug":652,"name":653,"tagline":654,"experience_level":655,"project_type":33,"stack_type_slug":610,"stack_type_icon_url":611,"score_popularity":41,"score_learning_curve":44,"catalog_display_order":33,"published_date":33,"last_updated_date":33,"core_tool_previews":656},222,"gitlab-self-hosted","GitLab Self-Hosted","Self-hosted GitLab with Docker: your code, your CI, your infrastructure.","advanced",[657,658,659,664,668],{"tool_id":190,"slug":485,"name":484,"logo_url":487,"logo_bg":309},{"tool_id":143,"slug":630,"name":631,"logo_url":632,"logo_bg":309},{"tool_id":660,"slug":661,"name":662,"logo_url":663,"logo_bg":93},152,"gitlab","GitLab","https:\u002F\u002Fassets.tekyous.dev\u002Flogos\u002Ftools\u002Fgitlab.svg",{"tool_id":665,"slug":666,"name":667,"logo_url":663,"logo_bg":93},165,"gitlab-cicd","GitLab CI\u002FCD",{"tool_id":569,"slug":571,"name":570,"logo_url":573,"logo_bg":309},[670,673,676,679,682],{"question":671,"answer":672},"Why self-host BetterAuth instead of using Clerk or Auth0?","Per-user pricing and data location. Clerk is free up to 50,000 monthly retained users per app and bills per user beyond that; Auth0 is free up to 25,000 monthly active users, with paid plans from $35\u002Fmo that scale with users. Every sign-in also passes through their servers. A self-hosted BetterAuth server has no per-user bill at any scale and keeps credentials in your own PostgreSQL. The vendor's own paid option, Better Auth Infrastructure, doesn't change that: it adds a managed dashboard, audit logs, and email sending while the auth server stays yours. The trade is that you become the identity provider, with patches, signing keys, and uptime on your side.",{"question":674,"answer":675},"Do I need a separate auth server, or can BetterAuth live inside my app?","For one app with one backend, embed it: BetterAuth mounts as a route handler in that backend and needs nothing else to run. A dedicated server earns its place when several apps or subdomains should share one login, when services in other languages need to verify the same users, or when MCP servers and agent tools need OAuth authorization. It costs an extra deploy and a redirect to the auth server at sign-in, so start embedded and split it out when a second app needs the same accounts.",{"question":677,"answer":678},"What does the server need to run?","BetterAuth publishes no hardware floor, since it's a library; the estimate prices what this stack deploys, one Node service plus PostgreSQL. 1 vCPU and 1 GB of RAM run it to start, and 2 GB is comfortable once the database grows and sign-in traffic has peaks. Password hashing is the one CPU-heavy step, so a burst of logins spikes the processor briefly. 20 GB of SSD covers the database for a long time.",{"question":680,"answer":681},"What needs backing up, and how do upgrades work?","PostgreSQL holds everything that matters: users, accounts, sessions, registered OAuth clients, and the signing keys behind every issued token. Lose it and every app's users are gone and every token stops verifying, so schedule backups and test a restore. The container itself is rebuildable. Upgrades are a package version bump, and releases that change the schema ship with the BetterAuth CLI's migrate command; back up first, run the migration, then deploy the new version.",{"question":683,"answer":684},"BetterAuth or Keycloak for a self-hosted identity server?","Both run your own identity provider for several apps. Keycloak is the mature Java server with an admin console, SAML federation, and LDAP or Active Directory integration built in, at the cost of a heavier footprint (its official sizing starts at about 1.25 GB of memory per instance) and configuration through its UI. BetterAuth covers OAuth 2.1 and OpenID Connect with a lighter footprint and configuration in TypeScript, but no admin UI of its own. Choose Keycloak for enterprise federation; choose BetterAuth when the team is TypeScript-first and the apps need standard OAuth sign-in.",{"summary":686,"starting_cost_label":687,"has_free_tier":3,"line_items":688},"BetterAuth and PostgreSQL are open source, so the recurring cost is one small server at $4-20\u002Fmo on any of the hosting options. There's no per-user charge at any scale, which is the comparison that matters: Clerk is free up to 50,000 monthly retained users per app and Auth0 up to 25,000 monthly active users, and both bill per user beyond that. A managed admin dashboard is the one optional extra, through Better Auth Infrastructure's Pro plan at $20\u002Fmo.","From ~$5\u002Fmo",[689,693,697],{"label":690,"cost":691,"note":692},"Server (VPS or cloud)","$4-20\u002Fmo","1 GB of RAM runs the Node auth server and PostgreSQL to start; 2 GB is comfortable. Login traffic is light, so an entry instance on any provider works.",{"label":694,"cost":695,"note":696},"BetterAuth + PostgreSQL","Free (open source)","No per-user or per-sign-in pricing, the main reason to run it instead of a hosted identity provider.",{"label":698,"cost":695,"note":699},"Exposure (reverse proxy or PaaS)","Traefik, Caddy, NGINX, Coolify, and Dokploy all self-host free, with free Let's Encrypt certificates.",{"is_official":112,"source_url":33,"items":701,"notes":714},[702,705,708,711],{"label":703,"value":704},"CPU","1 vCPU",{"label":706,"value":707},"RAM","1 GB to start, 2 GB comfortable",{"label":709,"value":710},"Disk","20 GB SSD",{"label":712,"value":713},"OS","Any Linux with Docker","BetterAuth is a library with no published floor; the estimate prices what this stack deploys, a dedicated Node auth server plus PostgreSQL. Password hashing is the one CPU-heavy step, so login bursts spike the processor briefly.","web_app",{"title":717,"description":718,"og_image":33,"canonical":719},"BetterAuth Self-Hosted: Tools, Pricing & How to Deploy | Tekyous","A self-hosted BetterAuth server: sign-in, sessions, and OAuth for your apps on infras… Compare BetterAuth Self-Hosted tools, pricing & how to deploy on Tekyous.","https:\u002F\u002Ftekyous.dev\u002Fstacks\u002Fbetter-auth-self-hosted",1790518806163]