Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
aiskillstore avatar

Better Auth Best Practices

  • 1 installs
  • 404 repo stars
  • Updated August 5, 2026
  • aiskillstore/marketplace

This is a copy of better-auth-best-practices by pedronauck - installs and ranking accrue to the original listing.

better-auth-best-practices is a Claude Code skill that configures the Better Auth TypeScript authentication library, including adapters, sessions and plugins.

About

better-auth-best-practices guides configuring the Better Auth TypeScript authentication library. It covers server and client setup, database adapters, session management, plugins, email flows, security options and environment variables, plus common gotchas. A developer uses it when adding email/password or OAuth authentication to a TypeScript app.

  • Configures the Better Auth TypeScript authentication library
  • Covers server/client setup, database adapters, sessions and plugins
  • Documents env vars, security options and common gotchas

Better Auth Best Practices by the numbers

  • 1 all-time installs (skills.sh)
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
At a glance

better-auth-best-practices capabilities & compatibility

Capabilities
authentication setup · oauth config · session management · auth plugins
Works with
postgres · mysql · mongodb · redis
Use cases
api development · security audit
From the docs

What better-auth-best-practices says it does

Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.
SKILL.md
`BETTER_AUTH_SECRET` - Encryption secret (min 32 chars). Generate: `openssl rand -base64 32`
SKILL.md
npx skills add https://github.com/aiskillstore/marketplace --skill better-auth-best-practices

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs1
repo stars404
Last updatedAugust 5, 2026
Repositoryaiskillstore/marketplace

What it does

Set up and configure Better Auth in a TypeScript app, including database adapters, sessions, OAuth and plugins.

Who is it for?

Configuring Better Auth server and client, database adapters, sessions and plugins in TypeScript.

Skip if: Non-Better-Auth authentication libraries or non-TypeScript stacks.

When should I use this skill?

A developer mentions Better Auth, auth.ts, or needs TypeScript email/password or OAuth authentication.

What you get

A correctly configured Better Auth setup with the right adapter, session strategy and plugins.

  • configured auth.ts
  • database adapter and session configuration

By the numbers

  • 6-step setup workflow
  • min 32-character BETTER_AUTH_SECRET
  • 3 cookie cache strategies (compact, jwt, jwe)

Files

SKILL.mdMarkdownGitHub ↗

Better Auth Integration Guide

Always consult [better-auth.com/docs](https://better-auth.com/docs) for code examples and latest API.

---

Setup Workflow

1. Install: npm install better-auth 2. Set env vars: BETTER_AUTH_SECRET and BETTER_AUTH_URL 3. Create auth.ts with database + config 4. Create route handler for your framework 5. Run npx @better-auth/cli@latest migrate 6. Verify: call GET /api/auth/ok — should return { status: "ok" }

---

Quick Reference

Environment Variables

  • BETTER_AUTH_SECRET - Encryption secret (min 32 chars). Generate: openssl rand -base64 32
  • BETTER_AUTH_URL - Base URL (e.g., https://example.com)

Only define baseURL/secret in config if env vars are NOT set.

File Location

CLI looks for auth.ts in: ./, ./lib, ./utils, or under ./src. Use --config for custom path.

CLI Commands

  • npx @better-auth/cli@latest migrate - Apply schema (built-in adapter)
  • npx @better-auth/cli@latest generate - Generate schema for Prisma/Drizzle
  • npx @better-auth/cli mcp --cursor - Add MCP to AI tools

Re-run after adding/changing plugins.

---

Core Config Options

OptionNotes
appNameOptional display name
baseURLOnly if BETTER_AUTH_URL not set
basePathDefault /api/auth. Set / for root.
secretOnly if BETTER_AUTH_SECRET not set
databaseRequired for most features. See adapters docs.
secondaryStorageRedis/KV for sessions & rate limits
emailAndPassword{ enabled: true } to activate
socialProviders{ google: { clientId, clientSecret }, ... }
pluginsArray of plugins
trustedOriginsCSRF whitelist

---

Database

Direct connections: Pass pg.Pool, mysql2 pool, better-sqlite3, or bun:sqlite instance.

ORM adapters: Import from better-auth/adapters/drizzle, better-auth/adapters/prisma, better-auth/adapters/mongodb.

Critical: Better Auth uses adapter model names, NOT underlying table names. If Prisma model is User mapping to table users, use modelName: "user" (Prisma reference), not "users".

---

Session Management

Storage priority: 1. If secondaryStorage defined → sessions go there (not DB) 2. Set session.storeSessionInDatabase: true to also persist to DB 3. No database + cookieCache → fully stateless mode

Cookie cache strategies:

  • compact (default) - Base64url + HMAC. Smallest.
  • jwt - Standard JWT. Readable but signed.
  • jwe - Encrypted. Maximum security.

Key options: session.expiresIn (default 7 days), session.updateAge (refresh interval), session.cookieCache.maxAge, session.cookieCache.version (change to invalidate all sessions).

---

User & Account Config

User: user.modelName, user.fields (column mapping), user.additionalFields, user.changeEmail.enabled (disabled by default), user.deleteUser.enabled (disabled by default).

Account: account.modelName, account.accountLinking.enabled, account.storeAccountCookie (for stateless OAuth).

Required for registration: email and name fields.

---

Email Flows

  • emailVerification.sendVerificationEmail - Must be defined for verification to work
  • emailVerification.sendOnSignUp / sendOnSignIn - Auto-send triggers
  • emailAndPassword.sendResetPassword - Password reset email handler

---

Security

In `advanced`:

  • useSecureCookies - Force HTTPS cookies
  • disableCSRFCheck - ⚠️ Security risk
  • disableOriginCheck - ⚠️ Security risk
  • crossSubDomainCookies.enabled - Share cookies across subdomains
  • ipAddress.ipAddressHeaders - Custom IP headers for proxies
  • database.generateId - Custom ID generation or "serial"/"uuid"/false

Rate limiting: rateLimit.enabled, rateLimit.window, rateLimit.max, rateLimit.storage ("memory" | "database" | "secondary-storage").

---

Hooks

Endpoint hooks: hooks.before / hooks.after - Array of { matcher, handler }. Use createAuthMiddleware. Access ctx.path, ctx.context.returned (after), ctx.context.session.

Database hooks: databaseHooks.user.create.before/after, same for session, account. Useful for adding default values or post-creation actions.

Hook context (`ctx.context`): session, secret, authCookies, password.hash()/verify(), adapter, internalAdapter, generateId(), tables, baseURL.

---

Plugins

Import from dedicated paths for tree-shaking:

import { twoFactor } from "better-auth/plugins/two-factor"

NOT from "better-auth/plugins".

Popular plugins: twoFactor, organization, passkey, magicLink, emailOtp, username, phoneNumber, admin, apiKey, bearer, jwt, multiSession, sso, oauthProvider, oidcProvider, openAPI, genericOAuth.

Client plugins go in createAuthClient({ plugins: [...] }).

---

Client

Import from: better-auth/client (vanilla), better-auth/react, better-auth/vue, better-auth/svelte, better-auth/solid.

Key methods: signUp.email(), signIn.email(), signIn.social(), signOut(), useSession(), getSession(), revokeSession(), revokeSessions().

---

Type Safety

Infer types: typeof auth.$Infer.Session, typeof auth.$Infer.Session.user.

For separate client/server projects: createAuthClient<typeof auth>().

---

Common Gotchas

1. Model vs table name - Config uses ORM model name, not DB table name 2. Plugin schema - Re-run CLI after adding plugins 3. Secondary storage - Sessions go there by default, not DB 4. Cookie cache - Custom session fields NOT cached, always re-fetched 5. Stateless mode - No DB = session in cookie only, logout on cache expiry 6. Change email flow - Sends to current email first, then new email

---

Resources

Related skills

FAQ

What environment variables are required?

BETTER_AUTH_SECRET (min 32 chars) and BETTER_AUTH_URL for the base URL.

How are plugins imported?

From dedicated paths for tree-shaking, e.g. better-auth/plugins/two-factor, not the barrel better-auth/plugins.

Backend & APIsbackendintegrations

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.