10 solution docs
Better Auth solution docs
Own your users table. Passwords, magic links, Google, GitHub and Microsoft, all in your database.
Pick Better Auth and all 10 land in docs/solutions/better-auth/, next to the rules and skills that reference them.
Every Better Auth doc in the registry
Tags: account-linking · admin · authorization · better-auth · cookies · csrf · deployment · edge-runtime · email-verification · hooks · impersonation · magic-link · middleware · migration · nextjs · oauth · passwords · proxy · rate-limit · rbac · reset · revocation · roles · samesite · secrets · security · sessions · tokens · users
Account linking and email verification without account takeovers
When "Continue with Google" joins an existing password account, when it refuses, and why an unverified email address or a trusted provider list can hand one person's account to another.
better-auth · oauth · account-linking · email-verification
Better Auth on the edge: why your session check fails in middleware
Edge runtimes have no TCP sockets and no Node crypto, so a session lookup that works in a page throws in the proxy. Read the cookie there and verify in the render.
better-auth · edge-runtime · middleware · proxy
CSRF, SameSite and the cookie flags that make a session safe
What each session cookie flag actually defends against, why trustedOrigins is your CSRF check, and the three configuration changes that quietly disable both.
better-auth · csrf · cookies · samesite
Guard Better Auth's endpoints, not just your settings forms
Every /api/auth endpoint is a public URL. One hook refuses account changes from an impersonation session and asks for a recent sign-in before a password or provider is added.
better-auth · impersonation · sessions · hooks
The magic-link token: single use, ten minutes, and the scanner that clicks it first
How long the credential lives, why a corporate mail scanner burns it before the human arrives, and why the rate limiter has to be backed by your database rather than by process memory.
better-auth · magic-link · tokens · rate-limit
Moving an existing user table onto Better Auth without logging everyone out
Map your columns to the four required tables, backfill ids and accounts, and let people migrate themselves on next sign-in instead of forcing a password reset.
better-auth · migration · users · passwords
oauth-callback-url-mismatches
Password reset tokens that cannot be replayed, guessed or leaked
One hour, single use, answered the same way for every address, and kept out of logs, Referer headers and search results. What Better Auth does for you and the four things it cannot.
better-auth · passwords · reset · tokens
Modelling roles you will not regret when the admin panel grows
A role column, a ranked vocabulary in one file, and permission checks that name the action, not a boolean isAdmin scattered across forty components.
better-auth · roles · authorization · admin
Session invalidation, or why everyone got logged out on deploy
A rotated secret, a changed cookie name or a wiped database invalidates every session at once. Here is what invalidates what, and how to revoke one user on purpose.
better-auth · sessions · cookies · secrets