Provides Better Auth integration patterns for NestJS backend and Next.js frontend with Drizzle ORM and PostgreSQL.

MITAuto-check: notesBackend & APIs

Install Better Auth

skills CLI
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill better-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install giuseppe-trisciuoglio/developer-kit better-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/developer-kit-typescript/skills/better-auth .claude/skills/better-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
better-auth
GitHub stars
357
Token cost
~2.4k tokens
SKILL.md length
641 words
Files
25 (incl. references, assets)
Skills in repo
115
Repo updated
First seen
Licence
MIT

At a glance

Provides Better Auth integration patterns for NestJS backend and Next.js frontend with Drizzle ORM and PostgreSQL.

  • Works in 4 steps: Database Setup → Backend Setup (NestJS) → Frontend Setup (Next.js) → …
  • Setting up Better Auth with NestJS backend
  • SKILL.md covers Overview, When to Use, Quick Start and Instructions, plus 4 more sections
  • Runs TypeScript scripts from its folder; calls npm, npx and psql; needs BETTER_AUTH_SECRET and AUTH_GITHUB_CLIENT_SECRET

What it does

Better Auth is an agent skill from giuseppe-trisciuoglio/developer-kit. Provides Better Auth integration patterns for NestJS backend and Next.js frontend with Drizzle ORM and PostgreSQL. Use when setting up Better Auth with NestJS backend, integrating Next.js App Router frontend, configuring Drizzle ORM schema, implementing social login (GitHub, Google), adding plugins (2FA, Organization, SSO, Magic Link, Passkey), implementing email/password authentication with session management, or creating protected routes and middleware.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 28 other files, including reference files and assets (for example `assets/nestjs/auth.controller.ts`, `assets/nestjs/auth.guard.ts` and `assets/nestjs/auth.module.ts`).

It sits in Backend & APIs, covering Authentication. It works with Better Auth, NestJS, Next.js and Drizzle ORM. The repository describes itself as: Modular plugin marketplace for Claude Code and agentic CLIs, with validated, spec-driven skills, agents, commands, and workflows for Java, TypeScript, Python, PHP, AWS, and AI. The licence is MIT.

When your agent uses it

  • Setting up Better Auth with NestJS backend
  • Integrating Next.js App Router frontend
  • Configuring Drizzle ORM schema
  • Implementing social login (GitHub

Example prompts

  • “Use the better-auth skill to provide Better Auth integration patterns for NestJS backend and Next.js frontend with Drizzle ORM and PostgreSQL”
  • “/better-auth”

Requirements

  • Node.js
  • A credential in AUTH_GITHUB_CLIENT_SECRET
  • A credential in BETTER_AUTH_SECRET
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Glob, Grep, Bash

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Database Setup
  2. Backend Setup (NestJS)
  3. Frontend Setup (Next.js)
  4. Advanced Features

What it can do on your machine

Read from SKILL.md and the folder at commit fe73fb3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Glob
    • Grep
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (TypeScript, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • npm
    • npx
    • psql
    • openssl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • better-auth.com
    • orm.drizzle.team
    • docs.nestjs.com
    • nextjs.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • BETTER_AUTH_SECRET
    • AUTH_GITHUB_CLIENT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Better Auth loads about 2.4k tokens when it runs, and up to ~23k if it reads all its reference files. Until then it costs about 118 tokens; SKILL.md has 641 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~118
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~23k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:252
    nment Variables**: Store all secrets in `.env`, add to `.gitignore`
  • NoteMentions a .env fileSKILL.md:265
    - **Never commit secrets**: Add `.env` to `.gitignore`; never commit OAuth secrets or DB credentials
  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Edit, Glob, Grep, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from giuseppe-trisciuoglio/developer-kit at commit fe73fb3, republished under its MIT licence (© giuseppe-trisciuoglio). 641 words, ~2,380 tokens.

Download SKILL.mdSave it as .claude/skills/better-auth/SKILL.md (or your agent's skills folder). This skill also uses 24 other files; get the full folder from GitHub.
name
better-auth
description
Provides Better Auth integration patterns for NestJS backend and Next.js frontend with Drizzle ORM and PostgreSQL. Use when setting up Better Auth with NestJS backend, integrating Next.js App Router frontend, configuring Drizzle ORM schema, implementing social login (GitHub, Google), adding plugins (2FA, Organization, SSO, Magic Link, Passkey), implementing email/password authentication with session management, or creating protected routes and middleware.
allowed-tools
Read, Write, Edit, Glob, Grep, Bash

Better Auth Integration Guide

Overview

Better Auth is a type-safe authentication framework for TypeScript supporting multiple providers, 2FA, SSO, organizations, and passkeys. This skill covers integration patterns for NestJS backend with Drizzle ORM + PostgreSQL and Next.js App Router frontend.

When to Use

  • Setting up Better Auth with NestJS backend
  • Integrating Next.js App Router frontend
  • Configuring Drizzle ORM schema with PostgreSQL
  • Implementing social login (GitHub, Google, Facebook, Microsoft)
  • Adding MFA/2FA with TOTP, passkey passwordless auth, or magic links
  • Managing trusted devices and backup codes for account recovery
  • Building multi-tenant apps with organizations or SSO
  • Creating protected routes with session management

Quick Start

Installation
bash
# Backend (NestJS)
npm install better-auth @auth/drizzle-adapter drizzle-orm pg
npm install -D drizzle-kit

# Frontend (Next.js)
npm install better-auth
4-Phase Setup
  1. Database: Install Drizzle, configure schema, run migrations
  2. Backend: Create Better Auth instance with NestJS module
  3. Frontend: Configure auth client, create pages, add middleware
  4. Plugins: Add 2FA, passkey, organizations as needed

See references/nestjs-setup.md for complete backend setup, references/plugins.md for plugin configuration.

Instructions

Phase 1: Database Setup
  1. Install dependencies

    bash
    npm install drizzle-orm pg @auth/drizzle-adapter better-auth
    npm install -D drizzle-kit
  2. Create Drizzle config (drizzle.config.ts)

    typescript
    import { defineConfig } from 'drizzle-kit';
    export default defineConfig({
      schema: './src/auth/schema.ts',
      out: './drizzle',
      dialect: 'postgresql',
      dbCredentials: { url: process.env.DATABASE_URL! },
    });
  3. Generate and run migrations

    bash
    npx drizzle-kit generate
    npx drizzle-kit migrate

    Checkpoint: Verify tables created: psql $DATABASE_URL -c "\dt" should show user, account, session, verification_token tables.

Phase 2: Backend Setup (NestJS)
  1. Create database module - Set up Drizzle connection service

  2. Configure Better Auth instance

    typescript
    // src/auth/auth.instance.ts
    import { betterAuth } from 'better-auth';
    import { drizzleAdapter } from '@auth/drizzle-adapter';
    import * as schema from './schema';
    
    export const auth = betterAuth({
      database: drizzleAdapter(schema, { provider: 'postgresql' }),
      emailAndPassword: { enabled: true },
      socialProviders: {
        github: {
          clientId: process.env.AUTH_GITHUB_CLIENT_ID!,
          clientSecret: process.env.AUTH_GITHUB_CLIENT_SECRET!,
        }
      }
    });
  3. Create auth controller

    typescript
    @Controller('auth')
    export class AuthController {
      @All('*')
      async handleAuth(@Req() req: Request, @Res() res: Response) {
        return auth.handler(req);
      }
    }

    Checkpoint: Test endpoint GET /auth/get-session returns { session: null } when unauthenticated (no error).

Phase 3: Frontend Setup (Next.js)
  1. Configure auth client (lib/auth.ts)

    typescript
    import { createAuthClient } from 'better-auth/client';
    export const authClient = createAuthClient({
      baseURL: process.env.NEXT_PUBLIC_APP_URL!
    });
  2. Add middleware (middleware.ts)

    typescript
    import { auth } from '@/lib/auth';
    export default auth((req) => {
      if (!req.auth && req.nextUrl.pathname.startsWith('/dashboard')) {
        return Response.redirect(new URL('/sign-in', req.nextUrl.origin));
      }
    });
    export const config = { matcher: ['/dashboard/:path*'] };
  3. Create sign-in page with form or social buttons

    Checkpoint: Navigating to /dashboard when logged out should redirect to /sign-in.

Phase 4: Advanced Features

Add plugins from references/plugins.md:

  • 2FA: twoFactor({ issuer: 'AppName', otpOptions: { sendOTP } })

  • Passkey: passkey({ rpID: 'domain.com', rpName: 'App' })

  • Organizations: organization({ avatar: { enabled: true } })

  • Magic Link: magicLink({ sendMagicLink })

  • SSO: sso({ saml: { enabled: true } })

    Checkpoint: After adding plugins, re-run migrations and verify new tables exist.

Examples

Example 1: Server Component with Session

Input: Display user data in a Next.js Server Component.

tsx
// app/dashboard/page.tsx
import { auth } from '@/lib/auth';
import { redirect } from 'next/navigation';

export default async function DashboardPage() {
  const session = await auth();

  if (!session) {
    redirect('/sign-in');
  }

  return (
    <div>
      <h1>Welcome, {session.user.name}</h1>
      <p>Email: {session.user.email}</p>
    </div>
  );
}

Output: Renders user info for authenticated users; redirects unauthenticated to sign-in.

Example 2: 2FA TOTP Verification with Trusted Device

Input: User has 2FA enabled and wants to sign in, marking device as trusted.

typescript
// Server: Configure 2FA with OTP sending
export const auth = betterAuth({
  plugins: [
    twoFactor({
      issuer: 'MyApp',
      otpOptions: {
        async sendOTP({ user, otp }, ctx) {
          await sendEmail({
            to: user.email,
            subject: 'Your verification code',
            body: `Code: ${otp}`
          });
        }
      }
    })
  ]
});

// Client: Verify TOTP and trust device
const verify2FA = async (code: string) => {
  const { data } = await authClient.twoFactor.verifyTotp({
    code,
    trustDevice: true  // Device trusted for 30 days
  });

  if (data) {
    router.push('/dashboard');
  }
};

Output: User authenticated; device trusted for 30 days without 2FA prompt.

Show full SKILL.md (286 more words)Show less
Example 3: Passkey Registration and Login

Input: Enable passkey (WebAuthn) authentication for passwordless login.

typescript
// Server
import { passkey } from '@better-auth/passkey';
export const auth = betterAuth({
  plugins: [
    passkey({
      rpID: 'example.com',
      rpName: 'My App',
    })
  ]
});

// Client: Register passkey
const registerPasskey = async () => {
  const { data } = await authClient.passkey.register({
    name: 'My Device'
  });
};

// Client: Sign in with autofill
const signInWithPasskey = async () => {
  await authClient.signIn.passkey({
    autoFill: true,  // Browser suggests passkey
  });
};

Output: Users can register and authenticate with biometrics, PIN, or security keys.

For more examples (backup codes, organizations, magic link, conditional UI), see references/plugins.md and references/passkey.md.

Best Practices

  1. Environment Variables: Store all secrets in .env, add to .gitignore
  2. Secret Generation: Use openssl rand -base64 32 for BETTER_AUTH_SECRET
  3. HTTPS Required: OAuth callbacks need HTTPS (use ngrok for local testing)
  4. Session Expiration: Configure based on security requirements (7 days default)
  5. Database Indexing: Add indexes on email, userId for performance
  6. Error Handling: Return generic errors without exposing sensitive details
  7. Rate Limiting: Add to auth endpoints to prevent brute force attacks
  8. Type Safety: Use npx better-auth typegen for full TypeScript coverage

Constraints and Warnings

Security Notes
  • Never commit secrets: Add .env to .gitignore; never commit OAuth secrets or DB credentials
  • Validate redirect URLs: Always validate OAuth redirect URLs to prevent open redirects
  • Hash passwords: Better Auth handles password hashing automatically; never implement custom hashing
  • Session storage: For production, use Redis or another scalable session store
  • HTTPS Only: Always use HTTPS for authentication in production
  • Email Verification: Always implement email verification for password-based auth
Known Limitations
  • Better Auth requires Node.js 18+ for Next.js App Router support
  • Some OAuth providers require specific redirect URL formats
  • Passkeys require HTTPS and compatible browsers
  • Organization features require additional database tables

Resources

Documentation
Reference Implementations
  • references/nestjs-setup.md - Complete NestJS backend setup
  • references/nextjs-setup.md - Complete Next.js frontend setup
  • references/plugins.md - Plugin configuration (2FA, passkey, organizations, SSO, magic link)
  • references/mfa-2fa.md - Detailed MFA/2FA guide
  • references/passkey.md - Detailed passkey implementation
  • references/schema.md - Drizzle schema reference
  • references/social-providers.md - Social provider configuration

© giuseppe-trisciuoglio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 24 other files (references, assets) in plugins/developer-kit-typescript/skills/better-auth of giuseppe-trisciuoglio/developer-kit.

  • SKILL.md
  • assets/env.example
  • assets/nestjs/auth.controller.ts
  • assets/nestjs/auth.guard.ts
  • assets/nestjs/auth.module.ts
  • assets/nestjs/auth.schema.ts
  • assets/nestjs/auth.service.ts
  • assets/nestjs/database.module.ts
  • assets/nestjs/database.service.ts
  • assets/nextjs/auth-client.ts
  • assets/nextjs/auth-route.ts
  • assets/nextjs/dashboard-page.tsx
  • assets/nextjs/middleware.ts
  • assets/nextjs/sign-in-page.tsx
  • assets/nextjs/use-session.ts
  • references/best-practices.md
  • references/examples.md
  • … and 8 more

Open the folder on GitHubat commit fe73fb3

Compare with similar skills

Better Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Better Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Better Auth this skillgiuseppe-trisciuoglio/developer-kit357—~2.4kAutomated safety check: NotesMIT
ImplementAI-Unified-Process/marketplace142—~4.7kAutomated safety check: WarnApache-2.0
Supabase Development and Debuggingsupabase/agent-skills2.7k3 repos~3.6kAutomated safety check: PassMIT
Supabasecurvenote/curvenote1705 repos~2.2kAutomated safety check: PassCustom licence
Andrej Karpathy Perspectivenazarli-shabnam/clevis1702 repos~3.8kAutomated safety check: PassMIT
Neon Authneondatabase/agent-skills100—~3.1kAutomated safety check: PassApache-2.0

Similar skills

  • Implement

    AI-Unified-Process/marketplace

    Implements use cases across a NestJS backend with Drizzle ORM over PostgreSQL and a Next.js App Router frontend wired to that API.

    142 GitHub stars~4.7k tokensUpdated 6 days ago
    DatabasesAuto-check: warnings
  • Official

    General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.

    2.7k GitHub starsUsed in 3 repos~3.6k tokens
    Backend & APIsAuto-check passed
  • Supabase

    curvenote/curvenote

    A skill your agent uses when doing ANY task involving Supabase.

    170 GitHub starsUsed in 5 repos~2.2k tokens
    Backend & APIsAuto-check passed
  • Andrej Karpathy Perspective

    nazarli-shabnam/clevis

    Andrej Karpathy的思维框架与表达方式。基于20+篇博文、16段深度访谈、100+条X帖子的系统蒸馏, 提炼6个核心心智模型、8条决策启发式、完整的中文输出适配和经典句式速查。

    170 GitHub starsUsed in 2 repos~3.8k tokens
    Backend & APIsAuto-check passed
  • Neon Auth

    neondatabase/agent-skills

    Official

    Add authentication to a new app. An agent skill from neondatabase/agent-skills.

    100 GitHub stars~3.1k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Authentication

    latitude-dev/latitude-llm

    Sessions, sign-in/sign-up flows, OAuth, magic links, or organization context on the session.

    4.7k GitHub stars~303 tokensUpdated 2 days ago
    Backend & APIsAuto-check passed

More from giuseppe-trisciuoglio/developer-kit

All 115 skills in this repo
  • Nestjs Drizzle Crud Generator

    giuseppe-trisciuoglio/developer-kit

    Generates complete CRUD modules for NestJS applications with Drizzle ORM.

    357 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Actuator

    giuseppe-trisciuoglio/developer-kit

    Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services.

    357 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Crud Patterns

    giuseppe-trisciuoglio/developer-kit

    Provides and generates complete CRUD workflows for Spring Boot 3 services.

    357 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Security JWT

    giuseppe-trisciuoglio/developer-kit

    Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based…

    357 GitHub stars~3.9k tokensUpdated 1 mo ago
    Auto-check: notes
  • AWS CLI Beast

    giuseppe-trisciuoglio/developer-kit

    Provides advanced AWS CLI patterns for managing EC2, Lambda, S3, DynamoDB, RDS, VPC, IAM, and CloudWatch.

    357 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check: notes
  • PR Review Comments

    giuseppe-trisciuoglio/developer-kit

    Posts review findings from a JSON file as inline comments on a GitHub Pull Request, attaching each comment to its file and line.

    357 GitHub stars~1k tokensUpdated 1 mo ago
    Auto-check: notes

Categories

Questions about Better Auth

What does Better Auth do?

Provides Better Auth integration patterns for NestJS backend and Next.js frontend with Drizzle ORM and PostgreSQL. Better Auth is an agent skill from giuseppe-trisciuoglio/developer-kit.js frontend with Drizzle ORM and PostgreSQL.

When should I use Better Auth?

Better Auth fits situations like: setting up Better Auth with NestJS backend; integrating Next.js App Router frontend; configuring Drizzle ORM schema; implementing social login (GitHub.

How do I install Better Auth in Claude Code?

Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill better-auth -a claude-code`. Or copy the skill folder (plugins/developer-kit-typescript/skills/better-auth in giuseppe-trisciuoglio/developer-kit) into .claude/skills/better-auth in your project. Claude Code loads it when a task matches its description.

How do I install Better Auth in Codex?

Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill better-auth -a codex`. Or copy the skill folder (plugins/developer-kit-typescript/skills/better-auth in giuseppe-trisciuoglio/developer-kit) into .agents/skills/better-auth in your project. Codex loads it when a task matches its description.

Can I use Better Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add giuseppe-trisciuoglio/developer-kit --skill better-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/better-auth, .gemini/skills/better-auth, .github/skills/better-auth and .opencode/skills/better-auth in your project.

What does Better Auth need to run?

Going by SKILL.md and its folder, Better Auth needs TypeScript for the scripts in its folder, the command-line tools its instructions call (npm, npx, psql and openssl) and credentials named BETTER_AUTH_SECRET and AUTH_GITHUB_CLIENT_SECRET. Our summary lists: Node.js; A credential in AUTH_GITHUB_CLIENT_SECRET; A credential in BETTER_AUTH_SECRET. Its frontmatter pre-approves these tools: Read, Write, Edit, Glob, Grep, Bash.

Does Better Auth access the network?

SKILL.md names 4 domains. As links in the text: better-auth.com, orm.drizzle.team, docs.nestjs.com and nextjs.org. This is read from the text; nothing was executed.

Is Better Auth safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Better Auth use?

Better Auth is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Better Auth use?

About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 21k tokens, read only when the agent opens those files.

What are the alternatives to Better Auth?

Skills that share tags, products or a category with Better Auth: Implement (AI-Unified-Process/marketplace, 142 stars), Supabase Development and Debugging (supabase/agent-skills, 2.7k stars), Supabase (curvenote/curvenote, 170 stars) and Andrej Karpathy Perspective (nazarli-shabnam/clevis, 170 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Better Auth?

giuseppe-trisciuoglio (a GitHub user) maintains it in giuseppe-trisciuoglio/developer-kit, which has 357 GitHub stars. The repository holds 115 skills in this directory. The repository was last updated on September 10, 2026.

Source: giuseppe-trisciuoglio/developer-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.