---
source_url: "https://wacht.dev/?utm_source=openai"
title: The open-source stack for AI-native apps
mirrored_at: 2026-08-18T01:00:58.994Z
host: wacht.dev
cited_in_42a: true
mirror_canonical: "https://index.42a.ai/wacht.dev/index__q__utm_source_openai"
---

> **Original source:** https://wacht.dev/?utm_source=openai

[

Wacht Bench is live. AI-assisted dev for Wacht.read the guide →

](https://wacht.dev/docs/guides/wacht-bench)

## Ship product, not plumbing.

The open-source stack for building AI-native apps — auth, tenancy, machine auth, webhooks, notifications, and an agent runtime. One user model under all of it, wired in once.

10,000 MAU free·SAML on every plan·no credit card

\[01\]identity · apis · webhooks · agents

## The stack you'd  
otherwise stitch yourself.

Six systems. One user and organization model under all of them — not six vendors stitched together.

01/identity

### Identity

`wacht auth.signIn()`

Passwordless, passkeys, MFA, OAuth, SAML SSO — with RBAC and hosted UI.

02/orgs

### Multitenancy

`wacht orgs.create()`

Workspaces, invitations, roles, domain auto-join, per-org config. Already there.

03/machine-auth

### Machine auth

`wacht api.issueKey()`

API keys, OAuth apps, and credentials — gated by scope, tenant, and rate limit.

04/webhooks

### Webhooks

`wacht webhooks.publish()`

At-least-once delivery, signed payloads, retries, and replay to any endpoint.

05/notifications

### Notifications

`wacht notify.send()`

In-app inbox and realtime streams in one API — scoped to users, orgs, and workspaces.

06/agents

### Agent runtime

`wacht agents.run()`

Sandboxed agents, your own keys, approvals and hooks on every tool call.

\[03\]sdks · next.js · react · rust

## Three lines, every stack.

Typed end-to-end. Drop the SDK into Next.js, React Router, TanStack, or a Rust service. Same API everywhere.

\[04\]prebuilt auth ui

## The actual UI surface, ready to embed.

Sign-in, consent, tenancy, account, and onboarding flows ship as drop-in components. Product logic already wired in behind them.

`$pnpm add @wacht/nextjs`Drop the components in. They already speak to your Wacht backend.

\[06\]pricing·beta

## Free forever. Real limits.

10,000 monthly active users on the house. SAML SSO included. No credit card to start.

### Starter

Free

$0forever

Real production limits, not a 14-day trial. Bring a side project, ship a launch, run a closed beta. No credit card.

What ships free

-   10,000 monthly active users
-   500 organizations
-   2,000 workspaces
-   SAML SSO (free on every plan)
-   Agents platform (BYOK + agent BYO storage)
-   Pre-built components and custom domain

Beta quotas. May change before GA. Existing usage will be honored.

❝customer / inboxdoctor

> We ditched Clerk for Wacht and it turned out to be one of the best decisions we made. It is simple, comprehensive, flexible where it matters, and the DX is exactly what we wanted while building InboxDoctor.

Sumith Bangarwa

Founder · InboxDoctor

\[07\]trust

## Open by default.  
Secure by design.

Run it yourself or hosted. Isolation, encryption, signed delivery, and enterprise auth come standard, not as an upsell.

### Open source

Read the code on GitHub. Self-host it on your own infrastructure, or run on the hosted platform. No black box.

### Tenant isolation

Every deployment is its own boundary. Users, keys, and config never cross between deployments at runtime.

### Encrypted secrets

Connection tokens and credentials are encrypted at rest and decrypted only on the request that needs them.

### Signed delivery

Webhooks are signed with HMAC over a timestamped payload, with a rotation window and at-least-once delivery.

### Enterprise auth

SAML SSO on every plan, plus RBAC, session controls, MFA policy, and per-organization security settings.

### Audit and control

API-key audit logs, full webhook delivery history, and human approval gates on every agent tool call.

\[08\]faq

## Questions, answered.

What Wacht is, what it replaces, and how teams adopt it — starting with auth and growing into the full stack.