Comparison

Torii vs Clerk

Both give you drop-in authentication components, hooks, and a dashboard. The differences that matter are where your users’ data lives, whose law applies to the company holding it, and how much compliance evidence you get without an enterprise contract.

Statements about Clerk on this page were last verified in August 2026. Vendors change — check their current documentation before deciding.

Where Clerk is a fair choice

Sticker price at small scale

Clerk’s free tier is generous, and at small scale a US provider’s free tier can beat any paid plan on sticker price. If auth is a login box for a side project and no customer will ever ask where the data lives, the incumbent free tiers are hard to argue with.

Track record and ecosystem

Clerk has years of production history, a large community, and more prebuilt social login providers. Torii went GA in 2026 and ships Google, GitHub, and MitID out of the box; other corporate identity providers connect via custom OIDC on the Enterprise tier.

US-market defaults

If your company and your users are in the US, Clerk’s US data storage is a non-issue. The transfer questions this page walks through are mostly a problem for controllers subject to the GDPR.

Where Torii wins for EU teams

Jurisdiction, not just residency

Torii is a Danish company, and end-user data is stored at rest in the EU (Hetzner, Germany). Clerk is a US company storing user data in the US, which makes every end-user record a third-country transfer your DPO has to paper over — transfer mechanism, transfer impact assessment, and a watch on the court docket. With an EU processor, that workstream does not exist for core auth data.

An audit trail on every tier

Torii records an append-only, tamper-evident audit trail automatically on every tier, including the free one: sign-ins, failed attempts, impersonation with the operator’s identity, consent, data exports. Clerk’s Application Logs are a debugging feed with plan-dependent retention, and Clerk itself lists audit logs as a separate enterprise feature — which concedes that the two are different things.

GDPR operations built in

Subject-access export and account erasure are product features, not your backlog: exports cover profile, identities, sessions, and audit data as CSV, and deletion cascades scrub credentials and PII while keeping the audit chain intact. Every operation is itself audit-logged.

MitID for the Danish market

MitID sign-in is a toggle, with free test MitID in every sandbox. On a US provider, Danish eID is a do-it-yourself broker integration plus a compliance review.

Paperwork a European DPO recognises

An Article 28 data processing agreement built on Datatilsynet’s standard clauses, a public sub-processor list, and invoices from a Danish legal entity. No transfer annexes to negotiate for core processing.

The transfer problem, in one timeline

Relying on a US processor for EU personal data means relying on an EU–US transfer framework. Two have already been struck down by the EU Court of Justice: Safe Harbor in 2015 and Privacy Shield in 2020. The third, the Data Privacy Framework, was adopted in 2023 and has already been challenged before the EU courts.

We are not predicting how any pending case ends. The point is simpler: with an EU company processing your users’ data in the EU, you do not need to care. There is no bridge to defend, no framework to monitor, and no re-papering project if a ruling goes the wrong way.

What “compliance features” means in practice

When an auditor or a customer’s security questionnaire arrives, the question is never “do you have logs somewhere” — it is “show me the record”. Torii’s audit trail is recorded automatically, append-only, and filterable by actor, action, and date, with CSV export for the auditor. Nothing to instrument, nothing to wire up.

Impersonation — support staff signing in as a user — is where accountability usually breaks down. In Torii it requires a written justification, is quota-limited per billing period, and every action taken during the session is stamped with the impersonator’s identity in the audit trail.

Migrating from Clerk

You do not migrate in one leap; you run in parallel. Torii’s sandbox environments are free, so the integration can be built and tested next to your existing setup. Drop-in components and hooks cover sign-in, sign-up, user profile, and organization management.

User records move by script through the server API: email, profile data, and metadata. There is no password-hash import — password users complete a one-time reset or sign in with an emailed code, and OAuth users simply sign in again and feel nothing.

The honest gaps

Torii has no SAML SSO (Enterprise offers custom OIDC), fewer prebuilt social providers, no compliance certifications yet, and a short public track record — Torii went GA in 2026. If you need hard SAML today, Torii is not the right answer yet, and we would rather say so here than in a sales call.

Frequently asked questions

Is Clerk GDPR-compliant?

That is a question about your processing, not just theirs. Using a US processor that stores user data in the US is not forbidden — it requires a valid transfer mechanism, a transfer impact assessment, and monitoring of the legal situation. None of that is a statement about Clerk’s product quality; it is geography and jurisdiction. With an EU processor storing data in the EU, the transfer chapter of the GDPR is not triggered for core auth data in the first place.

Can I migrate users from Clerk to Torii?

Yes. User records (email, profile, metadata) move by script through Torii’s server API, and you can run both systems in parallel against a free sandbox while you switch. Password hashes do not transfer: password users do a one-time reset or sign in with an emailed code; OAuth users just sign in again.

Is Torii cheaper than Clerk?

At small scale, usually not — a US provider’s free tier can beat any paid plan on sticker price, and we will not pretend otherwise. The comparison that matters is total cost: Torii ships the audit trail and GDPR tooling on every tier instead of behind enterprise gates, and the recurring legal work of papering US transfers costs more than an auth subscription.

Does Torii support MitID?

Yes, as a toggle. Test MitID is free in every sandbox on all tiers. Production MitID runs on your own Signicat agreement plus a paid add-on — see the pricing page for details.

Run it next to what you have

The free tier includes organizations, the audit trail, and GDPR operations. Sandbox environments cost nothing, so you can see the whole surface before moving a single user.

Docs

Which language would you like us to use?