head to head · open source
Sa-Token vs Hexclave
Sa-Token has 19,051 GitHub stars, 2,914 forks, 111 open issues and last shipped 2 days ago. Hexclave has 6,863 stars, 522 forks, 65 open issues and last shipped yesterday. Sa-Token leads on adoption by 178% (19,051 vs 6,863 stars). Sa-Token is written in Java under Apache-2.0; Hexclave is written in TypeScript under a custom or non-standard licence. Sa-Token has attracted 15% as many forks as stars, Hexclave 8%. Hexclave was the more recently maintained of the two, and both are self-hostable with no licence fee. The two share 1 topic tag (authorization), so they are genuine substitutes rather than adjacent tools.
Two open source projects, one decision. Both are free and self-hostable — the differences are community size, license terms, language stack and release pace.
← all 20902 open source comparisons
Side by side
| Sa-Token | Hexclave | |
|---|---|---|
| GitHub stars | ★ 19K | ★ 6.9K |
| License | Apache-2.0 | Custom / other |
| Written in | Java | TypeScript |
| Last push | 2026-09-18 | 2026-09-19 |
| Forks | ⑂ 2.9K | ⑂ 522 |
| Self-hosting | Yes | Yes |
| Data ownership | Your server | Your server |
pick Sa-Token if
- You weight community size — 19K stars and counting
- You want the Apache-2.0 license terms
- Your stack matches Java
- You value the larger contributor base for long-term maintenance
pick Hexclave if
- You want the Hexclave feature set and don't need the biggest community
- You prefer the Custom / other license terms
- Your stack matches TypeScript
- You evaluated both and Hexclave fits your workflow better
About Sa-Token
Sa Token is a free, open source, one stop Java authentication and authorization framework, licensed under Apache 2.0, that gives Java and Spring Boot developers login authentication, permission checks, distributed sessions, single sign on, OAuth2.0, gateway authentication, JWT integration, API key authorization and API parameter signing from a single dependency.
read the full Sa-Token overview →
About Hexclave
Hexclave is an open source user infrastructure platform written in TypeScript and distributed under a license the repository metadata lists as NOASSERTION, while the README badge states MIT / AGPLv3. It describes itself as handling everything around a product's users: authentication, teams, payments, emails, analytics, and more. The project lives in the JavaScript and TypeScript ecosystem, shipping SDKs for Next.js, React, and plain JavaScript, and it is positioned against hosted identity and user management services such as Auth0 and Clerk, both of which appear in its topic list.
read the full Hexclave overview →
More in Security & Privacy
Related comparisons
More Identity & Access Management (IAM) projects
Compare either of these against the rest of the Identity & Access Management (IAM) field.
Frequently asked questions
Is Sa-Token or Hexclave more popular?
Sa-Token has 19,051 GitHub stars and Hexclave has 6,863. Sa-Token has the larger community by that measure.
Are Sa-Token and Hexclave free?
Both are open source. Sa-Token is licensed under Apache-2.0, and Hexclave has no licence declared in this registry. Both are free to self-host.
What is the difference between Sa-Token and Hexclave?
Sa-Token is written in Java and Hexclave in TypeScript. The practical differences are community size, licence terms, language stack and release cadence — all compared in the table above.
Which should I choose, Sa-Token or Hexclave?
Choose Sa-Token if you want the larger community (19,051 stars) or its Apache-2.0 licence terms. Choose Hexclave if its feature set, stack or Custom / other licence fits better. Both are self-hostable.