Built on better-auth + Cloudflare Workers

Auth in minutes,
fully owned.

Deploy a production-grade auth service to your own Cloudflare account. Your users' data never touches our servers.

Read the docs →

Runs on Cloudflare Workers · Powered by better-auth · Your keys, your infra

Everything you need to ship auth fast

bao bundles the security defaults most developers skip — and deploys them with one GitHub Action.

🔐

Secret rotation out of the box

Versioned secrets stored encrypted in Cloudflare KV with automated quarterly rotation. Zero-downtime, zero config.

🏠

Your infra, your data

Deploys to your Cloudflare account. Your users' data never leaves your control — a fundamental advantage over Clerk and Auth0.

Edge-native performance

Runs on Cloudflare Workers in 300+ locations worldwide. Auth requests resolve in milliseconds, not seconds.

🔑

JWKS & asymmetric keys

First-class JWKS support for service-to-service auth and token verification without sharing secrets.

🏢

Multi-tenant organisations

Built-in organisation support for B2B SaaS. Invite members, manage roles, and scope data — all included.

💳

Payments ready

Polar payment gateway integration built in. Add subscriptions, checkouts, and a customer portal without a second service.

Up and running in three steps

  1. 1

    Create a scoped Cloudflare API token

    Limit permissions to exactly what bao needs. See the guide →

  2. 2

    Add secrets to your GitHub repository

    Paste your token and a few IDs. Step-by-step guide →

  3. 3

    Push to deploy

    The bao GitHub Action provisions your D1 database, KV namespace, and deploys your auth service automatically.

Ready to own your auth?

Join the waitlist and be among the first to get access.