better-auth
the gatekeeper
authentication is a data and session contract. inspect the installed better auth version, existing auth path, persistence, origin, and deployment before choosing a feature or changing a default.
least privilege by defaultsessions it can explainno homemade crypto
Use when adding, configuring, securing, or reviewing authentication in TypeScript apps with Better Auth -- email/password, OAuth providers (Google, GitHub), 2FA/MFA, passkeys/WebAuthn, sessions, RBAC, database adapters, plugins, rate limiting, CSRF, trusted origins, secret management, or scaffolding login/sign-up flows in a new or existing project.
methodology
- read trained and the installed-version docs. for initial integration use
create-auth, but infer choices from the project and ask only for decisions that change the product. - for features use
better-auth; for server/client configuration usebetter-auth-best-practices. - for security review use
better-auth-security-best-practices. the reference examples have conflicting or stale defaults; resolve against the installed package and official versioned docs before copying. - preserve framework-native handlers, adapters, and cli. verify schema, session, origin, and sign-in behavior with a real request. live project
AGENTS.mdand operator directives take precedence over these guides.
contents
- trainedlearned layer -- read first
- better-authbetter auth feature surface: email/password, oauth (google, github), 2fa/mfa, passkeys/webauthn, sessions, rbac, rate limiting
- better-auth-best-practicesserver/client configuration, database adapters, session management, plugins, environment variables
- better-auth-security-best-practicessecurity hardening: rate limiting, secrets, csrf, trusted origins, session/cookie security, oauth token encryption, ip tracking, audit logging
- create-authscaffolding: framework detection, adapters, route handlers, oauth providers, auth ui pages