Agent skill

Better Auth Best Practices

by EpicenterHQ in EpicenterHQ/epicenter

Better Auth server/client setup: auth.ts, generated schema, DB adapters, sessions, cookies, env vars, and plugins.

Custom licenceAuto-check passedBackend & APIs

Install Better Auth Best Practices

skills CLI
$ npx skills add EpicenterHQ/epicenter --skill better-auth-best-practices -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install EpicenterHQ/epicenter better-auth-best-practices --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/EpicenterHQ/epicenter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/better-auth-best-practices .claude/skills/better-auth-best-practices && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
better-auth-best-practices
GitHub stars
4.8k
Token cost
~2.1k tokens
SKILL.md length
802 words
Files
1
Skills in repo
65
Repo updated
First seen
Licence
Custom licence

At a glance

Better Auth server/client setup: auth.ts, generated schema, DB adapters, sessions, cookies, env vars, and plugins.

  • Works in 6 steps: Install: bun add better-auth → Set env vars: BETTER_AUTH_SECRET and… → Create auth.ts with database + config → …
  • Mentioning Better Auth
  • SKILL.md covers Reference Repositories, Upstream Grounding, Setup Workflow and Quick Reference, plus 13 more sections
  • Calls bun and openssl; needs BETTER_AUTH_SECRET

What it does

Better Auth Best Practices is an agent skill from EpicenterHQ/epicenter. Better Auth server/client setup: auth.ts, generated schema, DB adapters, sessions, cookies, env vars, and plugins. Use when mentioning Better Auth, betterauth, auth handlers, OAuth, email/password, or session configuration.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering OAuth and OpenID Connect. It works with Better Auth. The repository describes itself as: Open-source, local-first apps.

When your agent uses it

  • Mentioning Better Auth
  • Session configuration

Example prompts

  • “/better-auth-best-practices”

Requirements

  • A credential in BETTER_AUTH_SECRET

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Install: bun add better-auth
  2. Set env vars: BETTER_AUTH_SECRET and BETTER_AUTH_URL
  3. Create auth.ts with database + config
  4. Create route handler for your framework
  5. Run bun x @better-auth/cli@latest migrate
  6. Verify: call GET /api/auth/ok — should return { status: "ok" }

What it can do on your machine

Read from SKILL.md and the folder at commit 5b4bb69. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bun
    • openssl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • better-auth.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • BETTER_AUTH_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Better Auth Best Practices loads about 2.1k tokens when it runs. Until then it costs about 63 tokens; SKILL.md has 802 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 802 words (~2,066 tokens).

“When Better Auth API signatures, adapter behavior, generated schema, plugin options, session storage, cookie behavior, or security defaults affect correctness, ask DeepWiki a narrow question against better-auth/better-auth before relying on memory. Use it to orient, then verify decisive details against…”

— opening of SKILL.md by EpicenterHQ, Custom licence
name
better-auth-best-practices
metadata.author
epicenter
metadata.version
1.0

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .agents/skills/better-auth-best-practices of EpicenterHQ/epicenter.

Open the folder on GitHubat commit 5b4bb69

Compare with similar skills

Better Auth Best Practices next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Better Auth Best Practices compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Better Auth Best Practices this skillEpicenterHQ/epicenter4.8k—~2.1kAutomated safety check: PassCustom licence
Neon Authneondatabase/agent-skills100—~3.1kAutomated safety check: PassApache-2.0
Better Auth Security Best Practicesagutinbaigo28/financial-agent-api128—~2.7kAutomated safety check: PassNone
Authenticationlatitude-dev/latitude-llm4.7k—~303Automated safety check: PassMIT
Better Autheinverne/dotfiles121—~4kAutomated safety check: NotesMIT
Better Authsecondsky/claude-skills227—~7.5kAutomated safety check: PassMIT

Similar skills

  • Neon Auth

    neondatabase/agent-skills

    Official

    Add authentication to a new app. An agent skill from neondatabase/agent-skills.

    100 GitHub stars~3.1k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Better Auth Security Best Practices

    agutinbaigo28/financial-agent-api

    Configure rate limiting, manage auth secrets, set up CSRF protection, define trusted origins, secure sessions and cookies, encrypt OAuth tokens, track IP addresses, and implement audit logging for…

    128 GitHub stars~2.7k tokensUpdated 26 days ago
    Backend & APIsAuto-check passed
  • Authentication

    latitude-dev/latitude-llm

    Sessions, sign-in/sign-up flows, OAuth, magic links, or organization context on the session.

    4.7k GitHub stars~303 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Better Auth

    einverne/dotfiles

    Guide for implementing Better Auth - a framework-agnostic authentication and authorization framework for TypeScript.

    121 GitHub stars~4k tokensUpdated 1 mo ago
    Backend & APIsAuto-check: notes
  • Better Auth

    secondsky/claude-skills

    Skill for integrating Better Auth - comprehensive TypeScript authentication framework for Cloudflare D1, Next.js, Nuxt, and 15+ frameworks.

    227 GitHub stars~7.5k tokensUpdated 12 days ago
    Backend & APIsAuto-check passed
  • Configuring Better Auth

    aiskillstore/marketplace

    Implement OAuth 2.1 / OIDC authentication using Better Auth with MCP assistance.

    433 GitHub stars~1.9k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from EpicenterHQ/epicenter

All 65 skills in this repo
  • Agent Instructions

    EpicenterHQ/epicenter

    Write and maintain repository guidance across AGENTS.md, CLAUDE.md, and .agents/skills.

    4.8k GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed
  • Consult Claude

    EpicenterHQ/epicenter

    Assign Claude Code a read-only investigation, recommendation, or finished text draft.

    4.8k GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

    4.8k GitHub stars~896 tokensUpdated 2 days ago
    Auto-check passed
  • Cohesion Over Testability

    EpicenterHQ/epicenter

    Collapse test-shaped production boundaries while preserving behavior and coverage.

    4.8k GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Collapse Pass

    EpicenterHQ/epicenter

    Remove indirection that does not earn its boundary across a diff or package.

    4.8k GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Error Handling

    EpicenterHQ/epicenter

    Apply Wellcrafted Result patterns to fallible operations and preserve failures at boundaries.

    4.8k GitHub stars~1.4k tokensUpdated 2 days ago
    Auto-check passed

Works with

Categories

Questions about Better Auth Best Practices

What does Better Auth Best Practices do?

Better Auth server/client setup: auth.ts, generated schema, DB adapters, sessions, cookies, env vars, and plugins. Better Auth Best Practices is an agent skill from EpicenterHQ/epicenter.ts, generated schema, DB adapters, sessions, cookies, env vars, and plugins.

When should I use Better Auth Best Practices?

Better Auth Best Practices fits situations like: mentioning Better Auth; session configuration.

How do I install Better Auth Best Practices in Claude Code?

Run `npx skills add EpicenterHQ/epicenter --skill better-auth-best-practices -a claude-code`. Or copy the skill folder (.agents/skills/better-auth-best-practices in EpicenterHQ/epicenter) into .claude/skills/better-auth-best-practices in your project. Claude Code loads it when a task matches its description.

How do I install Better Auth Best Practices in Codex?

Run `npx skills add EpicenterHQ/epicenter --skill better-auth-best-practices -a codex`. Or copy the skill folder (.agents/skills/better-auth-best-practices in EpicenterHQ/epicenter) into .agents/skills/better-auth-best-practices in your project. Codex loads it when a task matches its description.

Can I use Better Auth Best Practices in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add EpicenterHQ/epicenter --skill better-auth-best-practices -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/better-auth-best-practices, .gemini/skills/better-auth-best-practices, .github/skills/better-auth-best-practices and .opencode/skills/better-auth-best-practices in your project.

What does Better Auth Best Practices need to run?

Going by SKILL.md and its folder, Better Auth Best Practices needs the command-line tools its instructions call (bun and openssl) and credentials named BETTER_AUTH_SECRET. Our summary lists: A credential in BETTER_AUTH_SECRET.

Does Better Auth Best Practices access the network?

SKILL.md names 2 domains. As links in the text: better-auth.com and github.com. This is read from the text; nothing was executed.

Is Better Auth Best Practices safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Better Auth Best Practices use?

Better Auth Best Practices has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Better Auth Best Practices use?

About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Better Auth Best Practices?

Skills that share tags, products or a category with Better Auth Best Practices: Neon Auth (neondatabase/agent-skills, 100 stars), Better Auth Security Best Practices (agutinbaigo28/financial-agent-api, 128 stars), Authentication (latitude-dev/latitude-llm, 4.7k stars) and Better Auth (einverne/dotfiles, 121 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Better Auth Best Practices?

EpicenterHQ (a GitHub organization) maintains it in EpicenterHQ/epicenter, which has 4,822 GitHub stars. The repository holds 65 skills in this directory. The repository was last updated on October 8, 2026.

Source: EpicenterHQ/epicenter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.