Create Auth Skill
deadlock-mod-manager/deadlock-mod-manager
Scaffold and implement authentication in TypeScript/JavaScript apps using Better Auth.
Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.
$ npx skills add latitude-dev/latitude-llm --skill better-auth-best-practices -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install latitude-dev/latitude-llm better-auth-best-practices --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/latitude-dev/latitude-llm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/better-auth-best-practices .claude/skills/better-auth-best-practices && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "better-auth-best-practices" agent skill from https://github.com/latitude-dev/latitude-llm/tree/development/.agents/skills/better-auth-best-practices into .claude/skills/better-auth-best-practices/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "better-auth-best-practices", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/latitude-dev/latitude-llm/tree/development/.agents/skills/better-auth-best-practicesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add latitude-dev/latitude-llm --skill better-auth-best-practices -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install latitude-dev/latitude-llm better-auth-best-practices --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/latitude-dev/latitude-llm.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/better-auth-best-practices .agents/skills/better-auth-best-practices && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "better-auth-best-practices" agent skill from https://github.com/latitude-dev/latitude-llm/tree/development/.agents/skills/better-auth-best-practices into .agents/skills/better-auth-best-practices/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "better-auth-best-practices", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add latitude-dev/latitude-llm --skill better-auth-best-practices -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install latitude-dev/latitude-llm better-auth-best-practices --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/latitude-dev/latitude-llm.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/better-auth-best-practices .cursor/skills/better-auth-best-practices && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "better-auth-best-practices" agent skill from https://github.com/latitude-dev/latitude-llm/tree/development/.agents/skills/better-auth-best-practices into .cursor/skills/better-auth-best-practices/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "better-auth-best-practices", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/latitude-dev/latitude-llm.git --path .agents/skills/better-auth-best-practices--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add latitude-dev/latitude-llm --skill better-auth-best-practices -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install latitude-dev/latitude-llm better-auth-best-practices --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/latitude-dev/latitude-llm.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/better-auth-best-practices .gemini/skills/better-auth-best-practices && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "better-auth-best-practices" agent skill from https://github.com/latitude-dev/latitude-llm/tree/development/.agents/skills/better-auth-best-practices into .gemini/skills/better-auth-best-practices/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "better-auth-best-practices", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install latitude-dev/latitude-llm better-auth-best-practicesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add latitude-dev/latitude-llm --skill better-auth-best-practices -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/latitude-dev/latitude-llm.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/better-auth-best-practices .github/skills/better-auth-best-practices && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "better-auth-best-practices" agent skill from https://github.com/latitude-dev/latitude-llm/tree/development/.agents/skills/better-auth-best-practices into .github/skills/better-auth-best-practices/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "better-auth-best-practices", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add latitude-dev/latitude-llm --skill better-auth-best-practices -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install latitude-dev/latitude-llm better-auth-best-practices --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/latitude-dev/latitude-llm.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/better-auth-best-practices .opencode/skills/better-auth-best-practices && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "better-auth-best-practices" agent skill from https://github.com/latitude-dev/latitude-llm/tree/development/.agents/skills/better-auth-best-practices into .opencode/skills/better-auth-best-practices/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "better-auth-best-practices", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
better-auth-best-practicesConfigure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.
Better Auth Best Practices is an agent skill from latitude-dev/latitude-llm. Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables. Use when users mention Better Auth, betterauth, auth.ts, or need to set up TypeScript authentication with email/password, OAuth, or plugin configuration.
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Secrets management, Authentication and ORMs and data access. It works with Better Auth, TypeScript and Prisma. The repository describes itself as: Open-source observability for AI agents. Find where your agents fail, dispatch your coding agent to fix it, and verify the fix against real traces. The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 12e8591. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxnpmopensslFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
better-auth.comgithub.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
BETTER_AUTH_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Better Auth Best Practices loads about 1.6k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 574 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from latitude-dev/latitude-llm at commit 12e8591, republished under its MIT licence (© latitude-dev). 574 words, ~1,628 tokens.
.claude/skills/better-auth-best-practices/SKILL.md (or your agent's skills folder).Always consult better-auth.com/docs for code examples and latest API.
npm install better-authBETTER_AUTH_SECRET and BETTER_AUTH_URLauth.ts with database + confignpx @better-auth/cli@latest migrateGET /api/auth/ok — should return { status: "ok" }BETTER_AUTH_SECRET - Encryption secret (min 32 chars). Generate: openssl rand -base64 32BETTER_AUTH_URL - Base URL (e.g., https://example.com)Only define baseURL/secret in config if env vars are NOT set.
CLI looks for auth.ts in: ./, ./lib, ./utils, or under ./src. Use --config for custom path.
npx @better-auth/cli@latest migrate - Apply schema (built-in adapter)npx @better-auth/cli@latest generate - Generate schema for Prisma/Drizzlenpx @better-auth/cli mcp --cursor - Add MCP to AI toolsRe-run after adding/changing plugins.
| Option | Notes |
|---|---|
appName | Optional display name |
baseURL | Only if BETTER_AUTH_URL not set |
basePath | Default /api/auth. Set / for root. |
secret | Only if BETTER_AUTH_SECRET not set |
database | Required for most features. See adapters docs. |
secondaryStorage | Redis/KV for sessions & rate limits |
emailAndPassword | { enabled: true } to activate |
socialProviders | { google: { clientId, clientSecret }, ... } |
plugins | Array of plugins |
trustedOrigins | CSRF whitelist |
Direct connections: Pass pg.Pool, mysql2 pool, better-sqlite3, or bun:sqlite instance.
ORM adapters: Import from better-auth/adapters/drizzle, better-auth/adapters/prisma, better-auth/adapters/mongodb.
Critical: Better Auth uses adapter model names, NOT underlying table names. If Prisma model is User mapping to table users, use modelName: "user" (Prisma reference), not "users".
Storage priority:
secondaryStorage defined → sessions go there (not DB)session.storeSessionInDatabase: true to also persist to DBcookieCache → fully stateless modeCookie cache strategies:
compact (default) - Base64url + HMAC. Smallest.jwt - Standard JWT. Readable but signed.jwe - Encrypted. Maximum security.Key options: session.expiresIn (default 7 days), session.updateAge (refresh interval), session.cookieCache.maxAge, session.cookieCache.version (change to invalidate all sessions).
User: user.modelName, user.fields (column mapping), user.additionalFields, user.changeEmail.enabled (disabled by default), user.deleteUser.enabled (disabled by default).
Account: account.modelName, account.accountLinking.enabled, account.storeAccountCookie (for stateless OAuth).
Required for registration: email and name fields.
emailVerification.sendVerificationEmail - Must be defined for verification to workemailVerification.sendOnSignUp / sendOnSignIn - Auto-send triggersemailAndPassword.sendResetPassword - Password reset email handlerIn advanced:
useSecureCookies - Force HTTPS cookiesdisableCSRFCheck - ⚠️ Security riskdisableOriginCheck - ⚠️ Security risk crossSubDomainCookies.enabled - Share cookies across subdomainsipAddress.ipAddressHeaders - Custom IP headers for proxiesdatabase.generateId - Custom ID generation or "serial"/"uuid"/falseRate limiting: rateLimit.enabled, rateLimit.window, rateLimit.max, rateLimit.storage ("memory" | "database" | "secondary-storage").
Endpoint hooks: hooks.before / hooks.after - Array of { matcher, handler }. Use createAuthMiddleware. Access ctx.path, ctx.context.returned (after), ctx.context.session.
Database hooks: databaseHooks.user.create.before/after, same for session, account. Useful for adding default values or post-creation actions.
Hook context (ctx.context): session, secret, authCookies, password.hash()/verify(), adapter, internalAdapter, generateId(), tables, baseURL.
Import from dedicated paths for tree-shaking:
import { twoFactor } from "better-auth/plugins/two-factor"NOT from "better-auth/plugins".
Popular plugins: twoFactor, organization, passkey, magicLink, emailOtp, username, phoneNumber, admin, apiKey, bearer, jwt, multiSession, sso, oauthProvider, oidcProvider, openAPI, genericOAuth.
Client plugins go in createAuthClient({ plugins: [...] }).
Import from: better-auth/client (vanilla), better-auth/react, better-auth/vue, better-auth/svelte, better-auth/solid.
Key methods: signUp.email(), signIn.email(), signIn.social(), signOut(), useSession(), getSession(), revokeSession(), revokeSessions().
Infer types: typeof auth.$Infer.Session, typeof auth.$Infer.Session.user.
For separate client/server projects: createAuthClient<typeof auth>().
© latitude-dev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/better-auth-best-practices of latitude-dev/latitude-llm.
Open the folder on GitHubat commit 12e8591
We found 8 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 7 other GitHub owners. This page covers the copy in latitude-dev/latitude-llm, which our catalogue first saw on October 7, 2026.
Better Auth Best Practices next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Better Auth Best Practices this skilllatitude-dev/latitude-llm | 4.7k | 7 repos | ~1.6k | Automated safety check: Pass | MIT | |
| Create Auth Skilldeadlock-mod-manager/deadlock-mod-manager | 574 | 4 repos | ~3.4k | Automated safety check: Pass | GPL-3.0 | |
| Better Auth Best Practicesviclafouch/meme-studio | 110 | 5 repos | ~1.5k | Automated safety check: Pass | None | |
| Better Autheinverne/dotfiles | 121 | — | ~4k | Automated safety check: Notes | MIT | |
| Node Backend Development Guidelinesdiet103/claude-code-infrastructure-showcase | 10k | 2 repos | ~2k | Automated safety check: Pass | MIT | |
| Add Backendahpxex/open-dashboard | 146 | — | ~3.6k | Automated safety check: Pass | MIT |
deadlock-mod-manager/deadlock-mod-manager
Scaffold and implement authentication in TypeScript/JavaScript apps using Better Auth.
viclafouch/meme-studio
Skill for integrating Better Auth - the comprehensive TypeScript authentication framework.
einverne/dotfiles
Guide for implementing Better Auth - a framework-agnostic authentication and authorization framework for TypeScript.
diet103/claude-code-infrastructure-showcase
Sets layered architecture and coding rules for Node.js, Express and TypeScript microservices, covering routes, controllers, services, repositories, Prisma, Sentry and Zod.
ahpxex/open-dashboard
Everything about the data layer — pick one of six ready-to-run backend templates (TanStack Start + Drizzle + better-auth, Hono + Drizzle + better-auth, Hono + Prisma + better-auth, Hono + Drizzle +…
Jeffallan/claude-skills
Scaffolds NestJS modules, controllers, services, DTOs and guards for TypeScript backends, with validation, JWT and Passport auth, Swagger docs and unit and E2E tests.
latitude-dev/latitude-llm
Create, validate, preview, and publish self-contained HTML artifacts.
latitude-dev/latitude-llm
Continuously monitor GitHub PR CI checks and automatically fix failures until all checks pass.
latitude-dev/latitude-llm
This skill should be used when the user asks to "create a Temporal workflow", "write a Temporal activity", "debug stuck workflow", "fix non-determinism error", "Temporal Python", "Temporal…
latitude-dev/latitude-llm
Review the current conversation context and git changes, then persist durable repository knowledge into dev-docs/.md by domain and into AGENTS.md for cross-cutting repo rules.
latitude-dev/latitude-llm
Enables or disables Latitude production maintenance mode by redirecting all publicly exposed production services to the Better Stack status page.
latitude-dev/latitude-llm
Run the public Mintlify product docs site locally for live preview.
Works with
Categories
Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables. Better Auth Best Practices is an agent skill from latitude-dev/latitude-llm. Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.
Better Auth Best Practices fits situations like: users mention Better Auth; need to set up TypeScript authentication with email/password; plugin configuration.
Run `npx skills add latitude-dev/latitude-llm --skill better-auth-best-practices -a claude-code`. Or copy the skill folder (.agents/skills/better-auth-best-practices in latitude-dev/latitude-llm) into .claude/skills/better-auth-best-practices in your project. Claude Code loads it when a task matches its description.
Run `npx skills add latitude-dev/latitude-llm --skill better-auth-best-practices -a codex`. Or copy the skill folder (.agents/skills/better-auth-best-practices in latitude-dev/latitude-llm) into .agents/skills/better-auth-best-practices in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add latitude-dev/latitude-llm --skill better-auth-best-practices -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/better-auth-best-practices, .gemini/skills/better-auth-best-practices, .github/skills/better-auth-best-practices and .opencode/skills/better-auth-best-practices in your project.
Going by SKILL.md and its folder, Better Auth Best Practices needs the command-line tools its instructions call (npx, npm and openssl) and credentials named BETTER_AUTH_SECRET. Our summary lists: Node.js; A credential in BETTER_AUTH_SECRET.
SKILL.md names 2 domains. As links in the text: better-auth.com and github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Better Auth Best Practices is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Better Auth Best Practices: Create Auth Skill (deadlock-mod-manager/deadlock-mod-manager, 574 stars), Better Auth Best Practices (viclafouch/meme-studio, 110 stars), Better Auth (einverne/dotfiles, 121 stars) and Node Backend Development Guidelines (diet103/claude-code-infrastructure-showcase, 10k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
latitude-dev (a GitHub organization) maintains it in latitude-dev/latitude-llm, which has 4,714 GitHub stars. The repository holds 28 skills in this directory. The repository was last updated on October 7, 2026.
Source: latitude-dev/latitude-llm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.