Security and privacy decision
Userbase
Because Userbase is open-source and exposes a small browser SDK with server-side storage needs, a competent developer can self-host a minimal replacement in a few weeks and maintain it; keep paying only if you want the hosted convenience and managed support.
Visit website↗$7.42/mo
$89/yr
Read off the official pricing page.
$20one-off6 h to build
$35/mo6 h/mo upkeep
On cash alone, building overtakes the subscription at 5 seats.
Open-source builds that already do this
Every project below is open source and already does this job today. Fork one, self-host it, or take the parts you need - the build prompt further down assumes an empty file, and this is the shortcut past that. Licences differ; check the one on each card before you ship. All Userbase alternatives, with the arithmetic →
What a replacement has to do
- Add user accounts and encrypted client-side persistence to a static site: client-side signup/signin with key derivation, client-side encryption/decryption of user data, client APIs to open/insert/update/delete encrypted items, server endpoints to store/retrieve encrypted blobs and handle Stripe subscriptions and file upload proxies.
What it still won’t have
- Hosted uptime, SLA and managed scaling
- Vendor-run maintenance, security patching, and support
- One-click Stripe + billing convenience and hosted backups
- Operational telemetry, analytics, and team-managed incident response
What remains hard
- Product polish and ongoing maintenance
First-year cost
Keep paying
Paying is—cheaper in year one.
On cash alone, building overtakes the subscription at 5 seats.
Money you would actually spend
Time you would spend
—
What you would spend
What we assumed
The verdict above measures whether you could build it. This one is only about money.
Runnable build prompt
Build a minimal self-hosted Userbase-compatible service: use Node.js + Express for the API server, PostgreSQL for metadata, S3-compatible object storage for encrypted blobs, and a small JavaScript SDK for the browser. Implement: init, signUp, signIn, signOut, openDatabase, insertItem, updateItem, deleteItem, uploadFile/getFile; client-side key derivation and AES-GCM encryption/decryption stored in IndexedDB; server endpoints to store/retrieve encrypted blobs and handle Stripe webhooks (purchaseSubscription/cancelSubscription). Out of scope: real-time sync, multi-region scaling, and admin UI. Include error handling, input validation, automated tests for core endpoints, and deployment scripts (Docker + docker-compose).
How we checked
How the score was reached
- Self-host verdict base92
- An open-source build was found+5
- 5 cited sources+3
- Price verified on pricing page+3
- Evidence score99
The base comes from the verdict. Everything under it is a check that either happened or did not, and each one is a fact frozen in this record rather than a judgement made at render time - so the same evidence always produces the same number.
How scoring works →Cited sources · 5
Every page the run actually retrieved.
- official productUserbase homepage
- official pricingUserbase pricing
- official docsUserbase SDK docs
- open sourcelogto-io/logto
- open sourceauthgear/authgear-server
Integrity checks
What held up, and what did not.




