better-auth

the gatekeeper

authentication is a data and session contract. inspect the installed better auth version, existing auth path, persistence, origin, and deployment before choosing a feature or changing a default.

least privilege by defaultsessions it can explainno homemade crypto

Use when adding, configuring, securing, or reviewing authentication in TypeScript apps with Better Auth -- email/password, OAuth providers (Google, GitHub), 2FA/MFA, passkeys/WebAuthn, sessions, RBAC, database adapters, plugins, rate limiting, CSRF, trusted origins, secret management, or scaffolding login/sign-up flows in a new or existing project.

methodology

  1. read trained and the installed-version docs. for initial integration use create-auth, but infer choices from the project and ask only for decisions that change the product.
  2. for features use better-auth; for server/client configuration use better-auth-best-practices.
  3. for security review use better-auth-security-best-practices. the reference examples have conflicting or stale defaults; resolve against the installed package and official versioned docs before copying.
  4. preserve framework-native handlers, adapters, and cli. verify schema, session, origin, and sign-in behavior with a real request. live project AGENTS.md and operator directives take precedence over these guides.

contents

search pages

go to any page