Live data from Hacker News

Show HN: Clerk – all of user management as-a-service, not just authentication

clerk.dev

61–70 of 234 posts

Re: Show HN: Clerk – all of user management as-a-service, not just authentication

#61
post #25
post #11

Earlier quoted context omitted.

This is my question as well. It's an honest question and hopefully someone can educate me. Why would anyone trust a third party with what is the most important asset, their users? Thank you in advance.

Hey, Braden one of the founders. It's a good question, and a question that gets asked a lot. Out of curiosity would you trust a more established company like Auth0 or Firebase? We hope to gain developers trust over time, and we want to build a tool that makes it dramatically easier to build out session management, and a lot of these user flows. A similar question that was asked only a few (10?) years ago, was "why wo…

You didn't answer my question.

Re: Show HN: Clerk – all of user management as-a-service, not just authentication

#62

I'm even hesitant to trust Auth0 for this, why would I trust a new company?

Also, is this permitted under the GDPR?

Yes, you (the "data controller") use them as a "data processor" and if they act compliant with the requirements of one, you're all well. Stuff like this is what the "data processor" definition is for.

Re: Show HN: Clerk – all of user management as-a-service, not just authentication

#63

Nice. If you could also add the ability to charge subscriptions from users and manage their subscription plans this would become a no-brainer. Also your pricing model could become very lucrative—you could charge a percentage of the revenue.

Definitely! We've found that developers want to apply subscriptions against either Users or Organizations, so first we're planning to build out Organization management first (create an org, invite members, setup SAML auth, etc). Subscription management will follow sometime after, and will probably look like a Stripe integration that automatically creates Stripe Customer objects for your Users and Organizations. Is th…

Both of these are definitely features I would really dig, particularly if I'm able to subscribe to whichever one I need.

If I'm building a photo-hosting app, it would be a bummer to pay for/build out a big "Organization Subscriptions" feature; if I'm building an enterprise-oriented chat application, I wouldn't want to spend many hours or dollars on individual "User Subscriptions".

But that said, I recognize splitting out those two features is more of a cherry on top; the main value here is just having them available to me in the first place. Either way, definitely keeping my eye on Clerk! Good luck folks!

Re: Show HN: Clerk – all of user management as-a-service, not just authentication

#64
post #58
post #39

Earlier quoted context omitted.

I forget what this effect is called. Every once in a while a new service comes along that tries to compete with Amazon and there is a huge cost of entrusting the new entrant.

I think I've seen the term "trust moat" used before, which I like for describing this effect.

sort of like "economic moat"...yeah I can definitely see why AWS is quickly becoming a monopoly. 10 years ago? I might have used Clerk, I guess I'm not seeing what the value proposition here is to me its:

Do I trust a new service or continue with one of the most trusted service from AWS?

Re: Show HN: Clerk – all of user management as-a-service, not just authentication

#65
post #17

Earlier quoted context omitted.

Hi dubcanada, Thanks for your questions! It's good feedback that there's no security documentation up yet. We have a lot more content coming live in the next few weeks - but let me try to hit some of the most important points: * Session management is handled with secure, httpOnly cookies. We have you set a CNAME in production so we can set cookies in a first-party context (SameSite=Lax). * Cookies are scoped only to…

SOC 2?

Not yet. We plan to pursue SOC 2 as we build out Organizations, since it's a clear requirement in a B2B context.

Re: Show HN: Clerk – all of user management as-a-service, not just authentication

#66
The pricing model has me confused:

1) Pricing is free up to 5,000 MAU

2) But the next pricing grade starts at 1,000 MAU for $49/mo + $0.05/MAU additional

so if you have 5,001 MAU you take a big leap from $0 to $249/mo

Is there a reason for that huge bump? Why doesn't the first pay tier start at 5,000 MAU?

And how is MAU even calculated? Like, aren't all users in the system active users? Or are you able to have a bunch of unactive users in the system as well not counted?

Re: Show HN: Clerk – all of user management as-a-service, not just authentication

#67
post #59
post #26

Earlier quoted context omitted.

I can answer with the opposite question. Why would you trust your homemade solution instead of heavily invested experts? Auth0 (and Okta and a thousand others) do nothing but auth and customer management and do it at 1000X the scale as most enterprises. They do it way better than your IT team could possibly do it. And support every cutting edge feature and potential use case. You can also get them to absorb indemnity…

Because I'm a software engineer who has been building stuff like this for years...

I mean, if you're an auth expert, that's awesome; but I think it's the absolute height of engineer hubris to pretend that the efforts of any one individual, no matter how talented and experienced, are able to match an entire organization of people who do nothing but this one thing.

Now, trusting this particular third-party? Definitely a big question mark! It's on them to earn your trust. But I think to say that third parties in general can't be trusted with your users is to be a little ignorant of the modern web engineering landscape. We trust a lot of people with a lot of things, and not in an unreasonable manner.

Re: Show HN: Clerk – all of user management as-a-service, not just authentication

#68
post #42
post #26

Earlier quoted context omitted.

I can answer with the opposite question. Why would you trust your homemade solution instead of heavily invested experts? Auth0 (and Okta and a thousand others) do nothing but auth and customer management and do it at 1000X the scale as most enterprises. They do it way better than your IT team could possibly do it. And support every cutting edge feature and potential use case. You can also get them to absorb indemnity…

Authentication is webdev 101. If you can't roll your own you're in the wrong industry. I really can't think of any good reason to hand crucial control of a site over to any third party, much less user authentication where one breach will potentially cost you millions and land you in jail. The whole business model seems to revolve around being a crutch for people not capable or competent of running their own services.

Building a form and hashing a password is webdev 101, but go look at the feature set offered by Auth0 or other CIAM platforms. Passwordless auth, MFA, compliance management, customer profiling, workflows, threat detection, analytics. And then think about how much they charge for doing this all for you out of the box versus hiring a dev team and running them forever to support it.

Re: Show HN: Clerk – all of user management as-a-service, not just authentication

#69
post #25
post #11

Earlier quoted context omitted.

This is my question as well. It's an honest question and hopefully someone can educate me. Why would anyone trust a third party with what is the most important asset, their users? Thank you in advance.

Hey, Braden one of the founders. It's a good question, and a question that gets asked a lot. Out of curiosity would you trust a more established company like Auth0 or Firebase? We hope to gain developers trust over time, and we want to build a tool that makes it dramatically easier to build out session management, and a lot of these user flows. A similar question that was asked only a few (10?) years ago, was "why wo…

I can't speak for anyone else, but I would trust a service like this a lot more if i could easily export all my data. I would do so on a regular basis, basically as a backup.

The other concern is what happens if you shut down or decide to change your plan to be prohibitively expensive? (I'm not implying that's the case for you, but it's a consideration that has to be made). There have been vendors in the past that have abruptly shut down without warning, leaving their customers scrambling to build or find alternatives. In all honesty, I'd rather build an authentication system from the beginning than having to take my service down at a critical time.

This is actually a really interesting product though, and i would definitely consider it on future projects.

Re: Show HN: Clerk – all of user management as-a-service, not just authentication

#70

As someone who uses Django which has user management out of the box, why would I use a service like this?

Django does not have this feature-set out of the box, that's for sure.

Laravel does if you count installing their starter kit as out of the box.
Post reply on HN