---
title: "WorkOS vs theAuth: WorkOS Alternative for MCP Auth"
description: "Compare WorkOS AuthKit and theAuth for MCP authorization: WorkOS hosts the OAuth server, theAuth is an MIT library you self-host. Includes where WorkOS wins."
canonical: https://theauth.dev/compare/workos/
lastmod: 2026-10-08
---

A self-hosted WorkOS alternative for MCP authorization

# theAuth vs WorkOS

WorkOS AuthKit can act as the OAuth authorization server for your MCP server, and you verify tokens. theAuth puts the authorization server inside a library you run, and models agents as identities.

Last verified: 2026-10-08. Hosted authorization server against an MIT library.

[Get started](https://theauth.dev/get-started/) [Feature table](https://theauth.dev/compare/workos/#table)

## Short answer

### Choose WorkOS if

- You want a vendor to run the authorization server, consent flow and token issuance, and your MCP server only verifies JWTs.
- You want Client ID Metadata Documents on by default and Cross App Access support from a hosted service.
- You already use WorkOS for your users and want MCP clients to sign in against the same directory.

### Choose theAuth if

- You need to self-host the authorization server, or keep tokens and audit data in your own database.
- Your agents need an owner, scoped permissions, delegation depth limits and per-agent audit, beyond a client and a token.
- You want one library that covers human sign-in, agent identity and the MCP authorization server, in TypeScript or Go.

WorkOS and theAuth both cover MCP authorization. WorkOS keeps the server on its side and hands you a verifier. theAuth hands you the server.

## theAuth vs WorkOS feature comparison

Feature comparison of WorkOS and theAuth

| Feature | WorkOS | theAuth |
| --- | --- | --- |
| Self-hostable | Partial or different, Hosted; no self-hosting option found in the docs we checked | Yes, Yes, on your own database |
| OAuth authorization server for MCP | Yes, Yes, AuthKit as a spec-compatible server | Yes, Yes, built in |
| Client ID Metadata Documents (CIMD) | Yes, Yes, the default for new MCP clients | Yes, Yes in the Go module; opt-in and fail-closed |
| Dynamic client registration | Yes, Yes, kept for older MCP clients | Yes, RFC 7591; closed by default in Go |
| Resource indicators | Yes, Yes, with wildcard support | Yes, RFC 8707 supported |
| Agent as its own identity | Partial or different, Not found in the MCP docs we checked | Yes, Owner, token, permissions, delegation chains, budgets, audit |
| What you build | Partial or different, Bearer middleware, JWT verification and metadata endpoints | Partial or different, Storage callbacks (TypeScript) or a config struct (Go), then mount |

Check mark: yes. Dash: partial, different, or not found in the docs we checked. Cross: no. Claims about WorkOS are from its own public pages (see Sources). theAuth rows are from its repositories.

01

## Where the authorization server runs

A hosted server you verify against, or a library you mount.

WorkOS

WorkOS documents AuthKit as the OAuth authorization server for MCP. It handles authorization, token issuance and consent. Your MCP server verifies JWTs against a remote JWKS and serves the protected resource metadata endpoint. CIMD is the default for new clients, and dynamic client registration stays for older ones.

theAuth

theAuth runs the authorization server in your process. You supply storage and a way to know which user is signed in, and theAuth serves the metadata, registration, authorize and token endpoints. The tradeoff is that you operate it. See [the TypeScript guide](https://theauth.dev/guides/mcp-server-typescript/) or [the Go guide](https://theauth.dev/guides/mcp-authorization-server-go/).

02

## What an agent is

A client with a token, or an identity with an owner.

WorkOS

In the MCP material we checked, WorkOS treats the MCP client as an OAuth client that a signed-in user authorizes. It also documents Cross App Access through an ID Token JWT Authorization Grant exchange for enterprise setups.

theAuth

theAuth adds an agent layer on top of OAuth: an owner, wildcard permission patterns with constraints, delegation chains that narrow at every hop and cap their depth, budgets, and approval gates. Revoking an agent does not touch anyone else. Read the [delegation docs](https://docs.theauth.dev/delegation).

03

## Operations and billing

What you run, what you pay.

WorkOS

WorkOS operates the service, so there is no database or signing key for you to run for authorization. Plans and prices change; read its pricing page instead of a number copied here.

theAuth

The library is free under MIT, with your own database and compute. theAuth Cloud is in early access with no published prices.

## WorkOS alternative: common questions

**Is theAuth a WorkOS alternative?**

For MCP authorization and agent identity, it can be. theAuth is an open source library with its own authorization server, agent identities and human sign-in. WorkOS offers AuthKit as a hosted service, so the choice is mostly about who runs it.

**Does WorkOS support MCP?**

Yes. WorkOS documents AuthKit as an OAuth authorization server for MCP, with Client ID Metadata Documents and dynamic client registration. theAuth also ships an MCP OAuth 2.1 authorization server.

**Can I self-host WorkOS AuthKit?**

We found no self-hosting option in the WorkOS pages we checked. theAuth is MIT licensed and runs on your own database.

**Does theAuth support CIMD?**

The Go module supports Client ID Metadata Documents per the MCP spec of 2025-11-25, off by default. The TypeScript library supports dynamic client registration.

## Sources

Last verified: 2026-10-08. Competitor facts come from the public pages below. Plans, limits and prices change, so confirm there. The WorkOS pricing page is linked for reference; we state no WorkOS prices here.

- [WorkOS: MCP authorization overview](https://workos.com/docs/authkit/mcp) workos.com/docs/authkit/mcp
- [WorkOS pricing](https://workos.com/pricing) workos.com/pricing
- [theAuth repository and README](https://github.com/glincker/theauth) github.com/glincker/theauth
- [theauth-go repository and README](https://github.com/glincker/theauth-go) github.com/glincker/theauth-go

## Keep reading

[All comparisons](https://theauth.dev/compare/) [Get started](https://theauth.dev/get-started/) [MCP OAuth 2.1](https://theauth.dev/mcp-oauth/) [Agent identity](https://theauth.dev/agent-identity/) [Guides](https://theauth.dev/guides/)
