Better Auth

TypeScript authentication framework that runs inside your own app and database, extended with plugins.

Works with AI agents:llms.txt
Ask your AI about this, with this page as the source:ChatGPT ↗Claude ↗Perplexity ↗

Better Auth is an authentication and authorization library for TypeScript. It runs inside your own server process and writes users, sessions and accounts to your own database, so there is no separate auth service to call and no per-user bill from a vendor.

You create one auth instance with your database connection and the sign-in methods you want, then mount its handler on a catch-all route, usually /api/auth/*. A client library gives React, Vue, Svelte and other front ends typed methods and hooks. Sessions are classic cookie sessions backed by a session table, with an optional short-lived cookie cache or Redis secondary storage to avoid a database read on every request. It ships integration guides for Next.js, Nuxt, SvelteKit, Astro, React Router, TanStack Start, Hono, Express, Fastify, NestJS, Elysia and Expo.

Out of the box you get email and password and dozens of social providers. Plugins add two-factor auth, passkeys, organizations with teams, an admin API, API keys, SAML/OIDC SSO, SCIM provisioning and Stripe subscriptions, each with its own tables. A CLI generates or applies the schema for the built-in Kysely adapter, Prisma, Drizzle or MongoDB on PostgreSQL, MySQL, SQLite or MS SQL. An optional paid Infrastructure service adds a dashboard, abuse protection and managed email and SMS.

It only works for TypeScript/JavaScript back ends; a Python, Ruby or PHP server cannot use it. You run the migrations, sending of emails and upgrades yourself, and there are no prebuilt sign-in screens in the core library.

Where it fits

How Better Auth itself is built

3 tools, from its own code, website and Product Hunt page.

Who uses it

6 makers' products, each linked to the source that shows it, and 94 open-source projects that declare it in their code.

The maker says so 6Declared in code 94How evidence is collected →
RybbitThe open source Google Analytics replacement

“It came out of nowhere and became popular for a good reason - it's really good!”

AuthenticationMaker says so · source ↗
ClarmTurn visitors into pipeline, automatically

“We love open source auth, tackling a really old problem in a clean, nice way.”

AuthenticationMaker says so · source ↗
BeplanSocial media scheduler for influencers & agencies

“Better-Auth gave us a clean, flexible auth layer with minimal code. Performance, adaptability, and dev-experience were all wins.”

AuthenticationMaker says so · source ↗
PicMotionAITurn your images into scroll-stopping videos using AI

“Authentication is always a time sink, but not with better_auth. Simple, secure, and extendable. Got magic links and login flow done in under an hour.”

AuthenticationMaker says so · source ↗

Open source: a project that declares Better Auth as a dependency in its public code — verifiable, but not necessarily a live product.

What makers say

4 makers on why they use Better Auth, in their own words on Product Hunt.

Authentication is always a time sink, but not with better_auth. Simple, secure, and extendable. Got magic links and login flow done in under an hour.
PicMotionAISep 2026 ↗
Better-Auth gave us a clean, flexible auth layer with minimal code. Performance, adaptability, and dev-experience were all wins.
BeplanSep 2026 ↗
It came out of nowhere and became popular for a good reason - it's really good!
RybbitSep 2026 ↗
We love open source auth, tackling a really old problem in a clean, nice way.
ClarmSep 2026 ↗

Loved and watch-outs

Themes that recur in makers' words and Hacker News comments, each linked to what it summarises, with how Product Hunt tags its reviews.

Most loved
  • A library that keeps users and sessions in your own database, with no vendor dependency and no per-user fees. HNHN 2HN 3HN 4
  • Plugins cover OAuth providers, magic links, RBAC, SSO and SAML, going well beyond Auth.js. HNHN 2HN 3PH
  • Hackable and transparent, so custom flows such as iframe login work without fighting hidden internals. HNHN 2PH
  • Setup is quick, with login flows done in an hour, and it saves money for projects that outgrew Clerk pricing. PHHNHN 2
Watch-outs
  • Built-in assumptions force hacks, such as OIDC providers without email or request-header-based admin scripts. HNHN 2
  • Code quality felt rushed, with few tests and little logging, and audit logs need the managed service. HNHN 2
  • Breaking changes appear in patch releases, and the OpenAPI spec gets little care for non-JS clients. HN
  • Its move to Vercel leaves some users wary about future direction and planning backups. HNHN 2

Reliability and open issues

Most wanted on GitHubOpen on 2026-10-04 in better-auth/better-auth, with activity in the last year — issues and feature requests by 👍.

Who switches

Public pull requests on GitHub since Oct 2024 whose title says "X to Y" — real code changes moving a project from one tool to another, by developers in general. Open a row to see the pull requests.

Clerk → Better Auth33 PRs
Supabase → Better Auth19 PRs
Auth0 → Better Auth4 PRs
Better Auth → Supabase5 PRs
Better Auth → Clerk4 PRs
Better Auth → WorkOS3 PRs

Alternatives to Better Auth

All alternatives by situation →

Questions makers ask about Better Auth

Which frameworks does Better Auth work with?

It is framework-agnostic TypeScript with documented integrations for Next.js, Nuxt, SvelteKit, Astro, React Router v7, TanStack Start, SolidStart, Hono, Express, Fastify, NestJS, Elysia, Convex, Electron and Expo. source ↗

Which databases can it store users in?

PostgreSQL, MySQL, SQLite and MS SQL through its built-in Kysely adapter, or your existing Prisma, Drizzle or MongoDB setup via adapters. Community adapters cover others, and it can also run with stateless sessions and no database. source ↗

How do database migrations work?

The CLI's migrate command creates or alters the tables directly when you use the built-in Kysely adapter. With Prisma or Drizzle you run generate to produce the schema and apply it through your ORM's own migrations. Plugins add their own tables, so re-run it after adding one. source ↗

Can I migrate my users from Clerk, Auth0, Supabase Auth or WorkOS?

Yes. The docs have step-by-step guides for moving from Auth.js, Auth0, Clerk, Supabase Auth and WorkOS, including password hashes and social accounts. Active sessions are invalidated by the move. source ↗

Does it support enterprise SSO and SCIM?

Yes, as plugins. The SSO plugin supports OIDC, OAuth2 and SAML 2.0 providers, and a separate SCIM plugin provisions users and groups from a directory. Self-service SSO setup for your customers is offered through the enterprise program. source ↗

Is rate limiting built in?

Yes. In production it limits client requests to 100 per 10 seconds by default, configurable per endpoint and with custom storage. It is off in development, and server-side calls through auth.api are not limited. source ↗

How long do sessions last?

Sessions expire after 7 days by default and are extended whenever they are used after the update interval (one day by default). Both values are configurable, and refresh can be disabled or deferred for read-replica setups. source ↗

Is Better Auth free?

Yes — it is free, open-source software.

Is Better Auth open source or self-hostable?

Open source, and you can self-host it. source ↗

Can AI coding agents work with Better Auth?

It serves an llms.txt docs index.

Who uses Better Auth?

6 makers' products we track, each with a source, and 94 open-source projects declare it in their code. source ↗