Better Auth Best Practices
latitude-dev/latitude-llm
Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.
Configure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and implement 2FA sign-in flows using Better Auth's twoFactor plugin.
$ npx skills add ever-works/ever-works --skill two-factor-authentication-best-practices -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ever-works/ever-works two-factor-authentication-best-practices --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ever-works/ever-works.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/two-factor-authentication-best-practices .claude/skills/two-factor-authentication-best-practices && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "two-factor-authentication-best-practices" agent skill from https://github.com/ever-works/ever-works/tree/develop/.agents/skills/two-factor-authentication-best-practices into .claude/skills/two-factor-authentication-best-practices/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "two-factor-authentication-best-practices", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ever-works/ever-works/tree/develop/.agents/skills/two-factor-authentication-best-practicesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ever-works/ever-works --skill two-factor-authentication-best-practices -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ever-works/ever-works two-factor-authentication-best-practices --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ever-works/ever-works.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/two-factor-authentication-best-practices .agents/skills/two-factor-authentication-best-practices && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "two-factor-authentication-best-practices" agent skill from https://github.com/ever-works/ever-works/tree/develop/.agents/skills/two-factor-authentication-best-practices into .agents/skills/two-factor-authentication-best-practices/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "two-factor-authentication-best-practices", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ever-works/ever-works --skill two-factor-authentication-best-practices -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ever-works/ever-works two-factor-authentication-best-practices --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ever-works/ever-works.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/two-factor-authentication-best-practices .cursor/skills/two-factor-authentication-best-practices && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "two-factor-authentication-best-practices" agent skill from https://github.com/ever-works/ever-works/tree/develop/.agents/skills/two-factor-authentication-best-practices into .cursor/skills/two-factor-authentication-best-practices/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "two-factor-authentication-best-practices", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ever-works/ever-works.git --path .agents/skills/two-factor-authentication-best-practices--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ever-works/ever-works --skill two-factor-authentication-best-practices -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ever-works/ever-works two-factor-authentication-best-practices --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ever-works/ever-works.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/two-factor-authentication-best-practices .gemini/skills/two-factor-authentication-best-practices && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "two-factor-authentication-best-practices" agent skill from https://github.com/ever-works/ever-works/tree/develop/.agents/skills/two-factor-authentication-best-practices into .gemini/skills/two-factor-authentication-best-practices/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "two-factor-authentication-best-practices", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ever-works/ever-works two-factor-authentication-best-practicesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ever-works/ever-works --skill two-factor-authentication-best-practices -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ever-works/ever-works.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/two-factor-authentication-best-practices .github/skills/two-factor-authentication-best-practices && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "two-factor-authentication-best-practices" agent skill from https://github.com/ever-works/ever-works/tree/develop/.agents/skills/two-factor-authentication-best-practices into .github/skills/two-factor-authentication-best-practices/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "two-factor-authentication-best-practices", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ever-works/ever-works --skill two-factor-authentication-best-practices -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ever-works/ever-works two-factor-authentication-best-practices --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ever-works/ever-works.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/two-factor-authentication-best-practices .opencode/skills/two-factor-authentication-best-practices && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "two-factor-authentication-best-practices" agent skill from https://github.com/ever-works/ever-works/tree/develop/.agents/skills/two-factor-authentication-best-practices into .opencode/skills/two-factor-authentication-best-practices/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "two-factor-authentication-best-practices", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
two-factor-authentication-best-practicesConfigure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and implement 2FA sign-in flows using Better Auth's twoFactor plugin.
Two Factor Authentication Best Practices is an agent skill from ever-works/ever-works. Configure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and implement 2FA sign-in flows using Better Auth's twoFactor plugin. Use when users need MFA, multi-factor authentication, authenticator setup, or login security with Better Auth.
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Authentication. It works with Better Auth. The repository describes itself as: Ever® Works™ - The Workshop for AI. An open agentic runtime that autonomously researches, ships, and maintains entire businesses, 24/7 - https://ever.works. The licence is AGPL-3.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 11d15aa. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Two Factor Authentication Best Practices loads about 1.8k tokens when it runs. Until then it costs about 83 tokens; SKILL.md has 301 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ever-works/ever-works at commit 11d15aa, republished under its AGPL-3.0 licence (© ever-works). 301 words, ~1,803 tokens.
.claude/skills/two-factor-authentication-best-practices/SKILL.md (or your agent's skills folder).twoFactor() plugin to server config with issuertwoFactorClient() plugin to client confignpx @better-auth/cli migratetwoFactorSecret column exists on user tableimport { betterAuth } from 'better-auth';
import { twoFactor } from 'better-auth/plugins';
export const auth = betterAuth({
appName: 'My App',
plugins: [
twoFactor({
issuer: 'My App'
})
]
});import { createAuthClient } from 'better-auth/client';
import { twoFactorClient } from 'better-auth/client/plugins';
export const authClient = createAuthClient({
plugins: [
twoFactorClient({
onTwoFactorRedirect() {
window.location.href = '/2fa';
}
})
]
});Requires password verification. Returns TOTP URI (for QR code) and backup codes.
const enable2FA = async (password: string) => {
const { data, error } = await authClient.twoFactor.enable({
password
});
if (data) {
// data.totpURI — generate a QR code from this
// data.backupCodes — display to user
}
};twoFactorEnabled is not set to true until first TOTP verification succeeds. Override with skipVerificationOnEnable: true (not recommended).
import QRCode from 'react-qr-code';
const TotpSetup = ({ totpURI }: { totpURI: string }) => {
return <QRCode value={totpURI} />;
};Accepts codes from one period before/after current time:
const verifyTotp = async (code: string) => {
const { data, error } = await authClient.twoFactor.verifyTotp({
code,
trustDevice: true
});
};twoFactor({
totpOptions: {
digits: 6, // 6 or 8 digits (default: 6)
period: 30 // Code validity period in seconds (default: 30)
}
});import { betterAuth } from 'better-auth';
import { twoFactor } from 'better-auth/plugins';
import { sendEmail } from './email';
export const auth = betterAuth({
plugins: [
twoFactor({
otpOptions: {
sendOTP: async ({ user, otp }, ctx) => {
await sendEmail({
to: user.email,
subject: 'Your verification code',
text: `Your code is: ${otp}`
});
},
period: 5, // Code validity in minutes (default: 3)
digits: 6, // Number of digits (default: 6)
allowedAttempts: 5 // Max verification attempts (default: 5)
}
})
]
});Send: authClient.twoFactor.sendOtp(). Verify: authClient.twoFactor.verifyOtp({ code, trustDevice: true }).
Configure how OTP codes are stored in the database:
twoFactor({
otpOptions: {
storeOTP: 'encrypted' // Options: "plain", "encrypted", "hashed"
}
});For custom encryption:
twoFactor({
otpOptions: {
storeOTP: {
encrypt: async (token) => myEncrypt(token),
decrypt: async (token) => myDecrypt(token)
}
}
});Generated automatically when 2FA is enabled. Each code is single-use.
const BackupCodes = ({ codes }: { codes: string[] }) => {
return (
<div>
<p>Save these codes in a secure location:</p>
<ul>
{codes.map((code, i) => (
<li key={i}>{code}</li>
))}
</ul>
</div>
);
};Invalidates all previous codes:
const regenerateBackupCodes = async (password: string) => {
const { data, error } = await authClient.twoFactor.generateBackupCodes({
password
});
// data.backupCodes contains the new codes
};const verifyBackupCode = async (code: string) => {
const { data, error } = await authClient.twoFactor.verifyBackupCode({
code,
trustDevice: true
});
};twoFactor({
backupCodeOptions: {
amount: 10, // Number of codes to generate (default: 10)
length: 10, // Length of each code (default: 10)
storeBackupCodes: 'encrypted' // Options: "plain", "encrypted"
}
});Response includes twoFactorRedirect: true when 2FA is required:
signIn.email({ email, password })context.data.twoFactorRedirect in onSuccesstrue, redirect to /2fa verification pageconst signIn = async (email: string, password: string) => {
const { data, error } = await authClient.signIn.email(
{ email, password },
{
onSuccess(context) {
if (context.data.twoFactorRedirect) {
window.location.href = '/2fa';
}
}
}
);
};Server-side: check "twoFactorRedirect" in response when using auth.api.signInEmail.
Pass trustDevice: true when verifying. Default trust duration: 30 days (trustDeviceMaxAge). Refreshes on each sign-in.
Flow: credentials → session removed → temporary 2FA cookie (10 min default) → verify → session created.
twoFactor({
twoFactorCookieMaxAge: 600 // 10 minutes in seconds (default)
});Built-in: 3 requests per 10 seconds for all 2FA endpoints. OTP has additional attempt limiting:
twoFactor({
otpOptions: {
allowedAttempts: 5 // Max attempts per OTP code (default: 5)
}
});TOTP secrets: encrypted with auth secret. Backup codes: encrypted by default. OTP: configurable ("plain", "encrypted", "hashed"). Uses constant-time comparison for verification.
2FA can only be enabled for credential (email/password) accounts.
Requires password confirmation. Revokes trusted device records:
const disable2FA = async (password: string) => {
const { data, error } = await authClient.twoFactor.disable({
password
});
};import { betterAuth } from 'better-auth';
import { twoFactor } from 'better-auth/plugins';
import { sendEmail } from './email';
export const auth = betterAuth({
appName: 'My App',
plugins: [
twoFactor({
// TOTP settings
issuer: 'My App',
totpOptions: {
digits: 6,
period: 30
},
// OTP settings
otpOptions: {
sendOTP: async ({ user, otp }) => {
await sendEmail({
to: user.email,
subject: 'Your verification code',
text: `Your code is: ${otp}`
});
},
period: 5,
allowedAttempts: 5,
storeOTP: 'encrypted'
},
// Backup code settings
backupCodeOptions: {
amount: 10,
length: 10,
storeBackupCodes: 'encrypted'
},
// Session settings
twoFactorCookieMaxAge: 600, // 10 minutes
trustDeviceMaxAge: 30 * 24 * 60 * 60 // 30 days
})
]
});© ever-works, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/two-factor-authentication-best-practices of ever-works/ever-works.
Open the folder on GitHubat commit 11d15aa
We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in ever-works/ever-works, which our catalogue first saw on October 7, 2026.
Two Factor Authentication Best Practices next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Two Factor Authentication Best Practices this skillever-works/ever-works | 158 | 2 repos | ~1.8k | Automated safety check: Pass | AGPL-3.0 | |
| Better Auth Best Practiceslatitude-dev/latitude-llm | 4.7k | 7 repos | ~1.6k | Automated safety check: Pass | MIT | |
| Neon Authneondatabase/agent-skills | 100 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Workosusenotra/notra | 256 | — | ~6.2k | Automated safety check: Pass | AGPL-3.0 | |
| Lunora Setup Authanolilab/lunora | 283 | — | ~2.8k | Automated safety check: Pass | Custom licence | |
| Authenticationlatitude-dev/latitude-llm | 4.7k | — | ~303 | Automated safety check: Pass | MIT |
latitude-dev/latitude-llm
Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.
neondatabase/agent-skills
Add authentication to a new app. An agent skill from neondatabase/agent-skills.
usenotra/notra
A skill your agent uses when the user asks for a WorkOS docs URL, term, or dashboard field (Sign-in endpoint, initiateloginuri, Redirect URI, WORKOS env vars), or is implementing, debugging, or…
anolilab/lunora
Adds authentication to a Lunora app with the auth registry item (better-auth via @lunora/auth, users and sessions in D1).
latitude-dev/latitude-llm
Sessions, sign-in/sign-up flows, OAuth, magic links, or organization context on the session.
giuseppe-trisciuoglio/developer-kit
Provides Better Auth integration patterns for NestJS backend and Next.js frontend with Drizzle ORM and PostgreSQL.
ever-works/ever-works
Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.
ever-works/ever-works
Audit and improve web accessibility following WCAG 2.2 guidelines.
ever-works/ever-works
Provides comprehensive Tailwind CSS utility-first styling patterns including responsive design, layout utilities, flexbox, grid, spacing, typography, colors, and modern CSS best practices.
ever-works/ever-works
Optimize for search engine visibility and ranking. An agent skill from ever-works/ever-works.
ever-works/ever-works
Build production-ready Express.js servers with middleware, authentication, routing, and database integration.
ever-works/ever-works
Production-tested setup for Tailwind CSS v4 with shadcn/ui, Vite, and React.
Works with
Categories
Configure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and implement 2FA sign-in flows using Better Auth's twoFactor plugin. Two Factor Authentication Best Practices is an agent skill from ever-works/ever-works. Configure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and implement 2FA sign-in flows using Better Auth's twoFactor plugin.
Two Factor Authentication Best Practices fits situations like: multi-factor authentication; authenticator setup; login security with Better Auth.
Run `npx skills add ever-works/ever-works --skill two-factor-authentication-best-practices -a claude-code`. Or copy the skill folder (.agents/skills/two-factor-authentication-best-practices in ever-works/ever-works) into .claude/skills/two-factor-authentication-best-practices in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ever-works/ever-works --skill two-factor-authentication-best-practices -a codex`. Or copy the skill folder (.agents/skills/two-factor-authentication-best-practices in ever-works/ever-works) into .agents/skills/two-factor-authentication-best-practices in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ever-works/ever-works --skill two-factor-authentication-best-practices -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/two-factor-authentication-best-practices, .gemini/skills/two-factor-authentication-best-practices, .github/skills/two-factor-authentication-best-practices and .opencode/skills/two-factor-authentication-best-practices in your project.
Going by SKILL.md and its folder, Two Factor Authentication Best Practices needs the command-line tools its instructions call (npx). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Two Factor Authentication Best Practices is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Two Factor Authentication Best Practices: Better Auth Best Practices (latitude-dev/latitude-llm, 4.7k stars), Neon Auth (neondatabase/agent-skills, 100 stars), Workos (usenotra/notra, 256 stars) and Lunora Setup Auth (anolilab/lunora, 283 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ever-works (a GitHub organization) maintains it in ever-works/ever-works, which has 158 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 5, 2026.
Source: ever-works/ever-works on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.