Better Auth vs Cerbos
Better Auth scores higher on the AgentReady, 57/100 against 46/100. They differ on 10 of the 41 signals. Which ones decides whether an agent can adopt them without a person watching.
What each one is
Better Auth. A framework-agnostic, universal authentication and authorization framework for TypeScript.
Cerbos. Authorization management platform for applications, APIs, AI agents, MCP servers, services, and workloads.
Where Better Auth is ahead
Better Auth passes structured api reference, authentication documented, pricing understandable and limits / constraints documented, and Cerbos does not. That is understand, whether an agent can read the docs and work out how the API behaves before calling it.
It also holds adopt: self-service signup, free trial or free allowance and cli available. Cerbos misses those.
Where Cerbos is ahead
Cerbos passes llms-full.txt / full agent docs, and Better Auth does not. That is discover, whether an agent can find the product at all without being told it exists.
It also holds adopt: copyable quickstart. Better Auth misses it.
And on operate, observable execution. Better Auth misses it.
What neither does
Both fail clear canonical domain, openapi / spec quality, request examples provided, response examples provided, errors and status codes documented, no mandatory sales call, agent-compatible signup flow, programmatic credential creation, fast time to first request, structured, predictable output, machine-readable errors, retry behavior documented, idempotency support, rate-limit behavior predictable, agent compatibility verified. If your agent needs any of those, you will be building it yourself either way.
Score, pillar by pillar
The AgentReady splits into four pillars, scored separately, because a product can be easy to find and still impossible to adopt.
Discover. Cerbos leads 93 to 87. Better Auth misses clear canonical domain, llms-full.txt / full agent docs; Cerbos misses clear canonical domain.
Understand is whether an agent can read the docs and work out how the API behaves before calling it. Better Auth leads 54 to 15. Better Auth misses openapi / spec quality, request examples provided, response examples provided, errors and status codes documented; Cerbos misses structured api reference, openapi / spec quality, authentication documented, pricing understandable, request examples provided, response examples provided, errors and status codes documented, limits / constraints documented.
Adopt. Better Auth leads 62 to 40. Better Auth misses no mandatory sales call, agent-compatible signup flow, programmatic credential creation, fast time to first request, copyable quickstart; Cerbos misses self-service signup, no mandatory sales call, agent-compatible signup flow, programmatic credential creation, free trial or free allowance, fast time to first request, cli available.
Operate. Cerbos leads 35 to 24. Better Auth misses structured, predictable output, machine-readable errors, retry behavior documented, idempotency support, rate-limit behavior predictable, observable execution, agent compatibility verified; Cerbos misses structured, predictable output, machine-readable errors, retry behavior documented, idempotency support, rate-limit behavior predictable, agent compatibility verified.
Pricing
Better Auth starts at $0/month and has a free tier. Cerbos does not publish one.
| Better Auth plans | Cerbos plans |
|---|---|
| Starter $0/month | - |
| Pro $20/month | - |
| Enterprise Custom | - |
Signal by signal
| Signal | Better Auth | Cerbos |
|---|---|---|
| AgentReady | 57 | 46 |
| Discovery | 87 | 93 |
| Understanding | 54 | 15 |
| Adoption | 62 | 40 |
| Operability | 24 | 35 |
| Public API | Yes | Yes |
| MCP server | Yes | Yes |
| OpenAPI spec | Yes | Unknown |
| CLI | Yes | Unknown |
| llms.txt | Yes | Yes |
| Self-serve signup | Yes | Unknown |
| Free tier | Yes | Unknown |
Which to pick
Better Auth clears more of the signals an agent needs, so it is the safer default for unattended use. Full profiles: Better Auth and Cerbos. Alternatives to each: Better Auth, Cerbos.
An agent can fetch this as data: POST /v1/compare {"slugs": ["better-auth", "cerbos"]}