Lucia
Lucia was an open source authentication library for JavaScript and TypeScript applications, distributed as an npm package rather than a hosted service. It was deprecated in March 2025, and the project now points developers to a single-file code example as a replacement for the npm package, along with a guide called the Auth Book.
Facts checked on against the sources listed at the end of this page.
Discontinued. Lucia was deprecated in March 2025. The maintainer now recommends using a single-file code reference as a replacement for the npm package, along with guidance from the project's Auth Book, rather than continuing to depend on the library itself.
- Pricing
- Open sourceFree plan: Yes, was free and open source; the npm package is deprecated but source remains on GitHub
- Open source
- YesMIT
- GitHub stars
- 10,451
- npm downloads a week
- 465kup 16% on the week before
A good fit for
- Developers researching Lucia's approach to code-first authentication before choosing a currently maintained library
- Studying the single-file authentication reference the project now recommends in place of the deprecated package
Not a good fit for
- New projects, since the npm package was deprecated in March 2025 and is no longer actively maintained
- Teams wanting a currently supported authentication library or managed service
Lucia pricing
Lucia was free and open source under the MIT license. The npm package itself is now deprecated (as of March 2025), with the project's source remaining available on GitHub for reference.
Prices in USD, checked on 27 September 2026. Current prices on lucia-auth.com.
Main features
- Code-first authentication
- Gave developers direct control over authentication logic rather than a managed service.
- Framework integration
- Used within JavaScript/TypeScript frameworks like SvelteKit and Next.js.
- Open source
- Released under the MIT license, source still available on GitHub.
- Single-file replacement guide (post-deprecation)
- The project now points to a single-file code example as an alternative to the deprecated package.
About Lucia
Lucia was a lightweight, open source authentication library for JavaScript and TypeScript applications, distributed as an npm package rather than a hosted authentication service, giving developers direct control over their authentication logic and session handling.
It was popular among developers who wanted a minimal, code-first approach to authentication rather than a full managed service, particularly within frameworks like SvelteKit and Next.js.
The project was deprecated in March 2025, with the maintainer instead pointing developers to a single-file code example intended as a complete replacement for the npm package, along with a companion resource called the Auth Book for authentication guidance more broadly.
- Made by
- Lucia (Pilcrow)
- Free plan
- Yes, was free and open source; the npm package is deprecated but source remains on GitHub
- Available on
- Node.js, JavaScript/TypeScript frameworks
Usage and activity
Weekly npm downloads of lucia, last 12 months.
Lucia alternatives
Questions about Lucia
Is Lucia still maintained?
No, it was deprecated in March 2025. The maintainer now recommends a single-file code replacement instead of the npm package.
Was Lucia free?
Yes, it was open source and free under the MIT license.
What should I use instead of Lucia now?
The project points to a single-file code example as a direct replacement, along with its Auth Book guide for broader authentication guidance.
Sources and links
Work on Lucia? Claim this listing. Something wrong or out of date? Suggest a correction. Stats come from the public GitHub and npm APIs and update every day.
