OpenStatus
openstatus is adding the enterprise surface without giving up the self-host story
A side-by-side editorial comparison of SuperTokens and Auth0 — release velocity, themes, recent moves, and the top alternatives to consider.
SuperTokens is building v12 in canary around one hard problem: migrating existing users
The visible releases are all v12.0.x canary builds — no stable v12 in the window. The work concentrates on account linking and a MIGRATED mode for core user directories, with supporting changes for SAML signature-wrapping protection, an activity_log table, and OpenTelemetry span annotations.
Auth0 builds the identity control plane for enterprise AI agents
Auth0's changelog has tilted toward the enterprise-AI surface while continuing its steady CIAM grind. The headline move is Cross App Access (XAA), an open standard for passing authorization between apps and AI agents, now in Open Early Access for resource apps that want to expose MCP servers and APIs. Around it sit third-party-app governance (per-org GA, self-service delegation) and conventional additions like anonymous sessions and Google One Tap.
The visible releases are all v12.0.x canary builds — no stable v12 in the window. The work concentrates on account linking and a MIGRATED mode for core user directories, with supporting changes for SAML signature-wrapping protection, an activity_log table, and OpenTelemetry span annotations.
The migration-mode thread is the spine here. First new core user directories were allowed to be created as MIGRATED, then the transition into MIGRATED was blocked while inconsistent users exist, then account linking itself was reopened for exploration. That sequence reads as a team discovering that letting a running deployment switch identity models mid-flight is where the correctness risk lives, and adding guardrails before shipping it. Everything else in the window is scaffolding around that: audit-shaped activity logging, tracing annotations, and CI cleanup.
A stable v12 looks gated on the account-linking and migration-mode work settling; expect further canaries tightening the conditions under which a deployment is allowed to change modes before any general release.
Auth0's changelog has tilted toward the enterprise-AI surface while continuing its steady CIAM grind. The headline move is Cross App Access (XAA), an open standard for passing authorization between apps and AI agents, now in Open Early Access for resource apps that want to expose MCP servers and APIs. Around it sit third-party-app governance (per-org GA, self-service delegation) and conventional additions like anonymous sessions and Google One Tap.
The through-line is governance for machine-to-machine and agent-to-app access: centralizing IT control over which third-party apps and agents can reach a tenant's APIs. Auth0 is layering agent-era standards (XAA, MCP exposure) on top of its existing enterprise SSO and organizations model rather than shipping a separate product. Expect continued build-out of the consent and policy surface as XAA moves from Early Access toward GA.
XAA likely graduates from Open Early Access toward GA with a consuming-app counterpart to this resource-app release, plus tighter Okta and OIDC enterprise-connection coverage.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either SuperTokens or Auth0.
openstatus is adding the enterprise surface without giving up the self-host story
Casdoor ships a minor version per commit, and every one of them is login-flow repair
Authelia's 4.39 line is a long hardening run, not a feature line
Buildkite is rebuilding its CI surface for agents first and clearing the v3 baseline out of the way.
Semgrep is spending its releases on parser breadth and scan startup, not new product surface.
A marketing blog, not a changelog: Unleash is recasting feature flags as agent governance
See all SuperTokens alternatives → · See all Auth0 alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Auth0 is currently shipping more aggressively (velocity 7.5 vs 2.5), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Auth0 is currently shipping more aggressively (velocity 7.5 vs 2.5), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top SuperTokens alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "SuperTokens alternatives" section above for the current picks, or visit /alternatives/supertokens for the full list with editorial commentary on each.
Top Auth0 alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Auth0 alternatives" section above for the current picks, or visit /alternatives/auth0 for the full list with editorial commentary on each.