The alternative is to either force a login on every visit, or store a session token in localstorage or similar, where any XSS vulnerability opens your sessions to an easy exploit. Auth0 and Stormpath, which are the 2 of these I have looked at most closely, seem to do the 2nd of those. Not sure what these guys recommend yet but I imagine it is similar.
On mobile, this does not matter as much due to better filesystem access that an app will usually be granted compared to JS in a browser tab, where you can save your API key/JSON web token/etc.
Auth is hard, but the cost-to-benefit of outsourcing seems fundamentally limited at this time due to the storage problem on the web.