Better Auth Skill
Better Auth is comprehensive, framework-agnostic authentication/authorization framework for TypeScript with built-in email/password, social OAuth, and powerful plugin ecosystem for advanced features.
When to Use
- Implementing auth in TypeScript/JavaScript applications
- Adding email/password or social OAuth authentication
- Setting up 2FA, passkeys, magic links, advanced auth features
- Building multi-tenant apps with organization support
- Managing sessions and user lifecycle
- Working with any framework (Next.js, Nuxt, SvelteKit, Remix, Astro, Hono, Express, etc.)
Quick Start
Installation
npm install better-auth
# or pnpm/yarn/bun add better-auth
Environment Setup
Create .env:
BETTER_AUTH_SECRET=<generated-secret-32-chars-min>
BETTER_AUTH_URL=http://localhost:3000
Basic Server Setup
Create auth.ts (root, lib/, utils/, or under src/app/server/):
import { betterAuth } from "better-auth";
export const auth = betterAuth({
database: {
// See references/database-integration.md
},
emailAndPassword: {
enabled: true,
autoSignIn: true
},
socialProviders: {
github: {
clientId: process.env.GITHUB_CLIENT_ID!,
clientSecret: process.env.GITHUB_CLIENT_SECRET!,
}
}
});
Database Schema
npx @better-auth/cli generate # Generate schema/migrations
npx @better-auth/cli migrate # Apply migrations (Kysely only)
Mount API Handler
Next.js App Router:
// app/api/auth/[...all]/route.ts
import { auth } from "@/lib/auth";
import { toNextJsHandler } from "better-auth/next-js";
export const { POST, GET } = toNextJsHandler(auth);
Other frameworks: See references/email-password-auth.md#framework-setup
Client Setup
Create auth-client.ts:
import { createAuthClient } from "better-auth/client";
export const authClient = createAuthClient({
baseURL: process.env.NEXT_PUBLIC_BETTER_AUTH_URL || "http://localhost:3000"
});
Basic Usage
// Sign up
await authClient.signUp.email({
email: "user@example.com",
password: "secure123",
name: "John Doe"
});
// Sign in
await authClient.signIn.email({
email: "user@example.com",
password: "secure123"
});
// OAuth
await authClient.signIn.social({ provider: "github" });
// Session
const { data: session } = authClient.useSession(); // React/Vue/Svelte
const { data: session } = await authClient.getSession(); // Vanilla JS
Feature Selection Matrix
Auth Method Selection Guide
Choose Email/Password when:
- Building standard web app with traditional auth
- Need full control over user credentials
- Targeting users who prefer email-based accounts
Choose OAuth when:
- Want quick signup with minimal friction
- Users already have social accounts
- Need access to social profile data
Choose Passkeys when:
- Want passwordless experience
- Targeting modern browsers/devices
- Security is top priority
Choose Magic Link when:
- Want passwordless without WebAuthn complexity
- Targeting email-first users
- Need temporary access links
Combine Multiple Methods when:
- Want flexibility for different user preferences
- Building enterprise apps with various auth requirements
- Need progressive enhancement (start simple, add more options)
Core Architecture
Better Auth uses client-server architecture:
- Server (
better-auth): Handles auth logic, database ops, API routes
- Client (
better-auth/client): Provides hooks/methods for frontend
- Plugins: Extend both server/client functionality
Implementation Checklist
Reference Documentation
Core Authentication
Advanced Features
- Advanced Features - 2FA/MFA, passkeys, magic links, organizations, rate limiting, session management
Scripts
scripts/better_auth_init.py - Initialize Better Auth configuration with interactive setup
Resources
1---2name: better-auth3description: Implement authentication and authorization with Better Auth - a framework-agnostic TypeScript authentication framework. Features include email/password authentication with verification, OAuth providers (Google, GitHub, Discord, etc.), two-factor authentication (TOTP, SMS), passkeys/WebAuthn suppo...4license: MIT5---6# Better Auth Skill
7
8Better Auth is comprehensive, framework-agnostic authentication/authorization framework for TypeScript with built-in email/password, social OAuth, and powerful plugin ecosystem for advanced features.
9
10## When to Use
11
12- Implementing auth in TypeScript/JavaScript applications
13- Adding email/password or social OAuth authentication
14- Setting up 2FA, passkeys, magic links, advanced auth features
15- Building multi-tenant apps with organization support
16- Managing sessions and user lifecycle
17- Working with any framework (Next.js, Nuxt, SvelteKit, Remix, Astro, Hono, Express, etc.)
18
19## Quick Start
20
21### Installation
22
23```bash
24npm install better-auth
25# or pnpm/yarn/bun add better-auth
26```
27
28### Environment Setup
29
30Create `.env`:
31```env
32BETTER_AUTH_SECRET=<generated-secret-32-chars-min>
33BETTER_AUTH_URL=http://localhost:3000
34```
35
36### Basic Server Setup
37
38Create `auth.ts` (root, lib/, utils/, or under src/app/server/):
39
40```ts
41import { betterAuth } from "better-auth";
42
43export const auth = betterAuth({
44 database: {
45 // See references/database-integration.md
46 },
47 emailAndPassword: {
48 enabled: true,
49 autoSignIn: true
50 },
51 socialProviders: {
52 github: {
53 clientId: process.env.GITHUB_CLIENT_ID!,
54 clientSecret: process.env.GITHUB_CLIENT_SECRET!,
55 }
56 }
57});
58```
59
60### Database Schema
61
62```bash
63npx @better-auth/cli generate # Generate schema/migrations
64npx @better-auth/cli migrate # Apply migrations (Kysely only)
65```
66
67### Mount API Handler
68
69**Next.js App Router:**
70```ts
71// app/api/auth/[...all]/route.ts
72import { auth } from "@/lib/auth";
73import { toNextJsHandler } from "better-auth/next-js";
74
75export const { POST, GET } = toNextJsHandler(auth);
76```
77
78**Other frameworks:** See references/email-password-auth.md#framework-setup
79
80### Client Setup
81
82Create `auth-client.ts`:
83
84```ts
85import { createAuthClient } from "better-auth/client";
86
87export const authClient = createAuthClient({
88 baseURL: process.env.NEXT_PUBLIC_BETTER_AUTH_URL || "http://localhost:3000"
89});
90```
91
92### Basic Usage
93
94```ts
95// Sign up
96await authClient.signUp.email({
97 email: "user@example.com",
98 password: "secure123",
99 name: "John Doe"
100});
101
102// Sign in
103await authClient.signIn.email({
104 email: "user@example.com",
105 password: "secure123"
106});
107
108// OAuth
109await authClient.signIn.social({ provider: "github" });
110
111// Session
112const { data: session } = authClient.useSession(); // React/Vue/Svelte
113const { data: session } = await authClient.getSession(); // Vanilla JS
114```
115
116## Feature Selection Matrix
117
118| Feature | Plugin Required | Use Case | Reference |
119|---------|----------------|----------|-----------|
120| Email/Password | No (built-in) | Basic auth | [email-password-auth.md](./references/email-password-auth.md) |
121| OAuth (GitHub, Google, etc.) | No (built-in) | Social login | [oauth-providers.md](./references/oauth-providers.md) |
122| Email Verification | No (built-in) | Verify email addresses | [email-password-auth.md](./references/email-password-auth.md#email-verification) |
123| Password Reset | No (built-in) | Forgot password flow | [email-password-auth.md](./references/email-password-auth.md#password-reset) |
124| Two-Factor Auth (2FA/TOTP) | Yes (`twoFactor`) | Enhanced security | [advanced-features.md](./references/advanced-features.md#two-factor-authentication) |
125| Passkeys/WebAuthn | Yes (`passkey`) | Passwordless auth | [advanced-features.md](./references/advanced-features.md#passkeys-webauthn) |
126| Magic Link | Yes (`magicLink`) | Email-based login | [advanced-features.md](./references/advanced-features.md#magic-link) |
127| Username Auth | Yes (`username`) | Username login | [email-password-auth.md](./references/email-password-auth.md#username-authentication) |
128| Organizations/Multi-tenant | Yes (`organization`) | Team/org features | [advanced-features.md](./references/advanced-features.md#organizations) |
129| Rate Limiting | No (built-in) | Prevent abuse | [advanced-features.md](./references/advanced-features.md#rate-limiting) |
130| Session Management | No (built-in) | User sessions | [advanced-features.md](./references/advanced-features.md#session-management) |
131
132## Auth Method Selection Guide
133
134**Choose Email/Password when:**
135- Building standard web app with traditional auth
136- Need full control over user credentials
137- Targeting users who prefer email-based accounts
138
139**Choose OAuth when:**
140- Want quick signup with minimal friction
141- Users already have social accounts
142- Need access to social profile data
143
144**Choose Passkeys when:**
145- Want passwordless experience
146- Targeting modern browsers/devices
147- Security is top priority
148
149**Choose Magic Link when:**
150- Want passwordless without WebAuthn complexity
151- Targeting email-first users
152- Need temporary access links
153
154**Combine Multiple Methods when:**
155- Want flexibility for different user preferences
156- Building enterprise apps with various auth requirements
157- Need progressive enhancement (start simple, add more options)
158
159## Core Architecture
160
161Better Auth uses client-server architecture:
1621. **Server** (`better-auth`): Handles auth logic, database ops, API routes
1632. **Client** (`better-auth/client`): Provides hooks/methods for frontend
1643. **Plugins**: Extend both server/client functionality
165
166## Implementation Checklist
167
168- [ ] Install `better-auth` package
169- [ ] Set environment variables (SECRET, URL)
170- [ ] Create auth server instance with database config
171- [ ] Run schema migration (`npx @better-auth/cli generate`)
172- [ ] Mount API handler in framework
173- [ ] Create client instance
174- [ ] Implement sign-up/sign-in UI
175- [ ] Add session management to components
176- [ ] Set up protected routes/middleware
177- [ ] Add plugins as needed (regenerate schema after)
178- [ ] Test complete auth flow
179- [ ] Configure email sending (verification/reset)
180- [ ] Enable rate limiting for production
181- [ ] Set up error handling
182
183## Reference Documentation
184
185### Core Authentication
186- [Email/Password Authentication](./references/email-password-auth.md) - Email/password setup, verification, password reset, username auth
187- [OAuth Providers](./references/oauth-providers.md) - Social login setup, provider configuration, token management
188- [Database Integration](./references/database-integration.md) - Database adapters, schema setup, migrations
189
190### Advanced Features
191- [Advanced Features](./references/advanced-features.md) - 2FA/MFA, passkeys, magic links, organizations, rate limiting, session management
192
193## Scripts
194
195- `scripts/better_auth_init.py` - Initialize Better Auth configuration with interactive setup
196
197## Resources
198
199- Docs: https://www.better-auth.com/docs
200- GitHub: https://github.com/better-auth/better-auth
201- Plugins: https://www.better-auth.com/docs/plugins
202- Examples: https://www.better-auth.com/docs/examples