Better Auth - Complete Authentication
TypeScript-first authentication library with 40+ OAuth providers and 20+ plugins.
Agent Workflow (MANDATORY)
Before ANY implementation, use TeamCreate to spawn 3 agents:
- fuse-ai-pilot:explore-codebase - Analyze existing auth setup and patterns
- fuse-ai-pilot:research-expert - Verify latest Better Auth docs via Context7/Exa
- mcp__context7__query-docs - Check providers/plugins availability
After implementation, run fuse-ai-pilot:sniper for validation.
Overview
When to Use
- Implementing authentication in TypeScript/JavaScript applications
- Need OAuth providers (Google, GitHub, Discord, Apple, Microsoft, etc.)
- Adding 2FA, magic links, passkeys, or phone authentication
- Enterprise SSO with SAML, SCIM provisioning, or organizations
- Integrating payments with Stripe or Polar subscriptions
- Web3 authentication with Sign-In with Ethereum (SIWE)
- Migrating from Auth.js, Clerk, Auth0, Supabase, or WorkOS
Why Better Auth
| Feature |
Benefit |
| Framework agnostic |
Next.js, SvelteKit, Nuxt, Remix, Astro, Expo, NestJS |
| Plugin architecture |
Add only the features you need (20+ plugins) |
| Full TypeScript |
End-to-end type safety, inference included |
| Self-hosted |
Your data stays on your infrastructure |
| Database flexible |
Prisma, Drizzle, MongoDB, PostgreSQL, MySQL, SQLite |
| Enterprise ready |
SSO, SCIM, organizations, audit logs |
Coverage
OAuth Providers (40+)
Google, GitHub, Discord, Apple, Microsoft, Slack, Spotify, Twitter/X, Facebook, LinkedIn, GitLab, Bitbucket, Dropbox, Twitch, Reddit, TikTok, and 25+ more documented in providers/.
Plugins (20+)
| Plugin |
Purpose |
| 2FA |
TOTP authenticator, backup codes |
| Magic Link |
Passwordless email login |
| Passkey |
WebAuthn biometric authentication |
| Organization |
Multi-tenant, roles, invitations |
| SSO |
Enterprise SAML/OIDC single sign-on |
| SCIM |
Directory sync, user provisioning |
| Stripe |
Subscription billing integration |
| API Key |
Machine-to-machine authentication |
| JWT/Bearer |
Token-based API authentication |
Database Adapters
Prisma, Drizzle, MongoDB, raw SQL (PostgreSQL, MySQL, SQLite), and community adapters.
SOLID Architecture (Next.js 16)
Components organized in modules/auth/ following separation of concerns:
- Services:
betterAuth configuration and initialization
- Hooks:
createAuthClient for client-side auth state
- API Route:
app/api/auth/[...all]/route.ts handler
- Proxy:
proxy.ts for route protection (replaces middleware)
Reference Guide
| Need |
Reference |
| Initial setup |
installation.md, server-config.md |
| Client usage |
client.md, session.md |
| OAuth providers |
providers/overview.md, individual provider docs |
| Add plugins |
plugins/overview.md, individual plugin docs |
| Database setup |
adapters/prisma.md, adapters/drizzle.md |
| Enterprise SSO |
plugins/sso.md, guides/saml-okta.md |
| Payments |
plugins/stripe.md, plugins/polar.md |
| Migration |
guides/clerk-migration.md, other migration guides |
| Complete examples |
examples/ for full implementations |
Best Practices
- Plugins on demand - Only add plugins you actually need
- Type-safe client - Use generated types from server config
- Session caching - Enable session caching for performance
- Rate limiting - Configure rate limits for auth endpoints
- Secure cookies - Use secure, httpOnly, sameSite cookies
- Database indexes - Add indexes on user lookup fields
Concepts
Core concepts explained in concepts/:
- Sessions - Token management, refresh, revocation
- Database - Schema design, migrations, adapters
- Plugins - Extension system, composition
- OAuth - Provider configuration, callbacks
- Security - CSRF, rate limiting, password hashing
- Cookies - Session storage, cross-domain
Converted and distributed by TomeVault — claim your Tome and manage your conversions.
1---2name: better-auth3description: Complete Better Auth - 40+ OAuth providers, 20+ plugins, all adapters, all frameworks. Use when implementing authentication, login, OAuth, 2FA, magic links, SSO, Stripe, SCIM, or session management. Use when this capability is needed.4---56# Better Auth - Complete Authentication78TypeScript-first authentication library with 40+ OAuth providers and 20+ plugins.910## Agent Workflow (MANDATORY)1112Before ANY implementation, use `TeamCreate` to spawn 3 agents:13141. **fuse-ai-pilot:explore-codebase** - Analyze existing auth setup and patterns152. **fuse-ai-pilot:research-expert** - Verify latest Better Auth docs via Context7/Exa163. **mcp__context7__query-docs** - Check providers/plugins availability1718After implementation, run **fuse-ai-pilot:sniper** for validation.1920---2122## Overview2324### When to Use2526- Implementing authentication in TypeScript/JavaScript applications27- Need OAuth providers (Google, GitHub, Discord, Apple, Microsoft, etc.)28- Adding 2FA, magic links, passkeys, or phone authentication29- Enterprise SSO with SAML, SCIM provisioning, or organizations30- Integrating payments with Stripe or Polar subscriptions31- Web3 authentication with Sign-In with Ethereum (SIWE)32- Migrating from Auth.js, Clerk, Auth0, Supabase, or WorkOS3334### Why Better Auth3536| Feature | Benefit |37|---------|---------|38| Framework agnostic | Next.js, SvelteKit, Nuxt, Remix, Astro, Expo, NestJS |39| Plugin architecture | Add only the features you need (20+ plugins) |40| Full TypeScript | End-to-end type safety, inference included |41| Self-hosted | Your data stays on your infrastructure |42| Database flexible | Prisma, Drizzle, MongoDB, PostgreSQL, MySQL, SQLite |43| Enterprise ready | SSO, SCIM, organizations, audit logs |4445---4647## Coverage4849### OAuth Providers (40+)5051Google, GitHub, Discord, Apple, Microsoft, Slack, Spotify, Twitter/X, Facebook, LinkedIn, GitLab, Bitbucket, Dropbox, Twitch, Reddit, TikTok, and 25+ more documented in [providers/](references/providers/).5253### Plugins (20+)5455| Plugin | Purpose |56|--------|---------|57| 2FA | TOTP authenticator, backup codes |58| Magic Link | Passwordless email login |59| Passkey | WebAuthn biometric authentication |60| Organization | Multi-tenant, roles, invitations |61| SSO | Enterprise SAML/OIDC single sign-on |62| SCIM | Directory sync, user provisioning |63| Stripe | Subscription billing integration |64| API Key | Machine-to-machine authentication |65| JWT/Bearer | Token-based API authentication |6667### Database Adapters6869Prisma, Drizzle, MongoDB, raw SQL (PostgreSQL, MySQL, SQLite), and community adapters.7071---7273## SOLID Architecture (Next.js 16)7475Components organized in `modules/auth/` following separation of concerns:7677- **Services**: `betterAuth` configuration and initialization78- **Hooks**: `createAuthClient` for client-side auth state79- **API Route**: `app/api/auth/[...all]/route.ts` handler80- **Proxy**: `proxy.ts` for route protection (replaces middleware)8182---8384## Reference Guide8586| Need | Reference |87|------|-----------|88| Initial setup | [installation.md](references/installation.md), [server-config.md](references/server-config.md) |89| Client usage | [client.md](references/client.md), [session.md](references/session.md) |90| OAuth providers | [providers/overview.md](references/providers/overview.md), individual provider docs |91| Add plugins | [plugins/overview.md](references/plugins/overview.md), individual plugin docs |92| Database setup | [adapters/prisma.md](references/adapters/prisma.md), [adapters/drizzle.md](references/adapters/drizzle.md) |93| Enterprise SSO | [plugins/sso.md](references/plugins/sso.md), [guides/saml-okta.md](references/guides/saml-okta.md) |94| Payments | [plugins/stripe.md](references/plugins/stripe.md), [plugins/polar.md](references/plugins/polar.md) |95| Migration | [guides/clerk-migration.md](references/guides/clerk-migration.md), other migration guides |96| Complete examples | [examples/](references/examples/) for full implementations |9798---99100## Best Practices1011021. **Plugins on demand** - Only add plugins you actually need1032. **Type-safe client** - Use generated types from server config1043. **Session caching** - Enable session caching for performance1054. **Rate limiting** - Configure rate limits for auth endpoints1065. **Secure cookies** - Use secure, httpOnly, sameSite cookies1076. **Database indexes** - Add indexes on user lookup fields108109---110111## Concepts112113Core concepts explained in [concepts/](references/concepts/):114115- **Sessions** - Token management, refresh, revocation116- **Database** - Schema design, migrations, adapters117- **Plugins** - Extension system, composition118- **OAuth** - Provider configuration, callbacks119- **Security** - CSRF, rate limiting, password hashing120- **Cookies** - Session storage, cross-domain121122---123> Converted and distributed by [TomeVault](https://tomevault.io/claim/fusengine) — claim your Tome and manage your conversions.124<!-- tomevault:4.0:skill_md:2026-04-13 -->