Auth in minutes,
fully owned.
Deploy a production-grade auth service to your own Cloudflare account. Your users' data never touches our servers.
Runs on Cloudflare Workers · Powered by better-auth · Your keys, your infra
Everything you need to ship auth fast
bao bundles the security defaults most developers skip — and deploys them with one GitHub Action.
Secret rotation out of the box
Versioned secrets stored encrypted in Cloudflare KV with automated quarterly rotation. Zero-downtime, zero config.
Your infra, your data
Deploys to your Cloudflare account. Your users' data never leaves your control — a fundamental advantage over Clerk and Auth0.
Edge-native performance
Runs on Cloudflare Workers in 300+ locations worldwide. Auth requests resolve in milliseconds, not seconds.
JWKS & asymmetric keys
First-class JWKS support for service-to-service auth and token verification without sharing secrets.
Multi-tenant organisations
Built-in organisation support for B2B SaaS. Invite members, manage roles, and scope data — all included.
Payments ready
Polar payment gateway integration built in. Add subscriptions, checkouts, and a customer portal without a second service.
Up and running in three steps
- 1
Create a scoped Cloudflare API token
Limit permissions to exactly what bao needs. See the guide →
- 2
Add secrets to your GitHub repository
Paste your token and a few IDs. Step-by-step guide →
- 3
Push to deploy
The bao GitHub Action provisions your D1 database, KV namespace, and deploys your auth service automatically.
Ready to own your auth?
Join the waitlist and be among the first to get access.