Agent skill

Better Auth Best Practices

by latitude-dev in latitude-dev/latitude-llm

Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.

MITAuto-check passedBackend & APIs

Install Better Auth Best Practices

skills CLI
$ npx skills add latitude-dev/latitude-llm --skill better-auth-best-practices -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install latitude-dev/latitude-llm better-auth-best-practices --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/latitude-dev/latitude-llm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/better-auth-best-practices .claude/skills/better-auth-best-practices && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
better-auth-best-practices
GitHub stars
4.7k
Used in
7 other repos
Token cost
~1.6k tokens
SKILL.md length
574 words
Files
1
Skills in repo
28
Repo updated
First seen
Licence
MIT

At a glance

Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.

  • Works in 6 steps: Install: npm install better-auth → Set env vars: BETTER_AUTH_SECRET and… → Create auth.ts with database + config → …
  • Users mention Better Auth
  • SKILL.md covers Setup Workflow, Quick Reference, Core Config Options and Database, plus 10 more sections
  • Calls npx, npm and openssl; needs BETTER_AUTH_SECRET

What it does

Better Auth Best Practices is an agent skill from latitude-dev/latitude-llm. Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables. Use when users mention Better Auth, betterauth, auth.ts, or need to set up TypeScript authentication with email/password, OAuth, or plugin configuration.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Secrets management, Authentication and ORMs and data access. It works with Better Auth, TypeScript and Prisma. The repository describes itself as: Open-source observability for AI agents. Find where your agents fail, dispatch your coding agent to fix it, and verify the fix against real traces. The licence is MIT.

When your agent uses it

  • Users mention Better Auth
  • Need to set up TypeScript authentication with email/password
  • Plugin configuration

Example prompts

  • “/better-auth-best-practices”

Requirements

  • Node.js
  • A credential in BETTER_AUTH_SECRET

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Install: npm install better-auth
  2. Set env vars: BETTER_AUTH_SECRET and BETTER_AUTH_URL
  3. Create auth.ts with database + config
  4. Create route handler for your framework
  5. Run npx @better-auth/cli@latest migrate
  6. Verify: call GET /api/auth/ok — should return { status: "ok" }

What it can do on your machine

Read from SKILL.md and the folder at commit 12e8591. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • npm
    • openssl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • better-auth.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • BETTER_AUTH_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Better Auth Best Practices loads about 1.6k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 574 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from latitude-dev/latitude-llm at commit 12e8591, republished under its MIT licence (© latitude-dev). 574 words, ~1,628 tokens.

Download SKILL.mdSave it as .claude/skills/better-auth-best-practices/SKILL.md (or your agent's skills folder).
name
better-auth-best-practices
description
Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables. Use when users mention Better Auth, betterauth, auth.ts, or need to set up TypeScript authentication with email/password, OAuth, or plugin configuration.

Better Auth Integration Guide

Always consult better-auth.com/docs for code examples and latest API.


Setup Workflow

  1. Install: npm install better-auth
  2. Set env vars: BETTER_AUTH_SECRET and BETTER_AUTH_URL
  3. Create auth.ts with database + config
  4. Create route handler for your framework
  5. Run npx @better-auth/cli@latest migrate
  6. Verify: call GET /api/auth/ok — should return { status: "ok" }

Quick Reference

Environment Variables
  • BETTER_AUTH_SECRET - Encryption secret (min 32 chars). Generate: openssl rand -base64 32
  • BETTER_AUTH_URL - Base URL (e.g., https://example.com)

Only define baseURL/secret in config if env vars are NOT set.

File Location

CLI looks for auth.ts in: ./, ./lib, ./utils, or under ./src. Use --config for custom path.

CLI Commands
  • npx @better-auth/cli@latest migrate - Apply schema (built-in adapter)
  • npx @better-auth/cli@latest generate - Generate schema for Prisma/Drizzle
  • npx @better-auth/cli mcp --cursor - Add MCP to AI tools

Re-run after adding/changing plugins.


Core Config Options

OptionNotes
appNameOptional display name
baseURLOnly if BETTER_AUTH_URL not set
basePathDefault /api/auth. Set / for root.
secretOnly if BETTER_AUTH_SECRET not set
databaseRequired for most features. See adapters docs.
secondaryStorageRedis/KV for sessions & rate limits
emailAndPassword{ enabled: true } to activate
socialProviders{ google: { clientId, clientSecret }, ... }
pluginsArray of plugins
trustedOriginsCSRF whitelist

Database

Direct connections: Pass pg.Pool, mysql2 pool, better-sqlite3, or bun:sqlite instance.

ORM adapters: Import from better-auth/adapters/drizzle, better-auth/adapters/prisma, better-auth/adapters/mongodb.

Critical: Better Auth uses adapter model names, NOT underlying table names. If Prisma model is User mapping to table users, use modelName: "user" (Prisma reference), not "users".


Session Management

Storage priority:

  1. If secondaryStorage defined → sessions go there (not DB)
  2. Set session.storeSessionInDatabase: true to also persist to DB
  3. No database + cookieCache → fully stateless mode

Cookie cache strategies:

  • compact (default) - Base64url + HMAC. Smallest.
  • jwt - Standard JWT. Readable but signed.
  • jwe - Encrypted. Maximum security.

Key options: session.expiresIn (default 7 days), session.updateAge (refresh interval), session.cookieCache.maxAge, session.cookieCache.version (change to invalidate all sessions).


User & Account Config

User: user.modelName, user.fields (column mapping), user.additionalFields, user.changeEmail.enabled (disabled by default), user.deleteUser.enabled (disabled by default).

Account: account.modelName, account.accountLinking.enabled, account.storeAccountCookie (for stateless OAuth).

Required for registration: email and name fields.


Email Flows

  • emailVerification.sendVerificationEmail - Must be defined for verification to work
  • emailVerification.sendOnSignUp / sendOnSignIn - Auto-send triggers
  • emailAndPassword.sendResetPassword - Password reset email handler

Show full SKILL.md (228 more words)Show less

Security

In advanced:

  • useSecureCookies - Force HTTPS cookies
  • disableCSRFCheck - ⚠️ Security risk
  • disableOriginCheck - ⚠️ Security risk
  • crossSubDomainCookies.enabled - Share cookies across subdomains
  • ipAddress.ipAddressHeaders - Custom IP headers for proxies
  • database.generateId - Custom ID generation or "serial"/"uuid"/false

Rate limiting: rateLimit.enabled, rateLimit.window, rateLimit.max, rateLimit.storage ("memory" | "database" | "secondary-storage").


Hooks

Endpoint hooks: hooks.before / hooks.after - Array of { matcher, handler }. Use createAuthMiddleware. Access ctx.path, ctx.context.returned (after), ctx.context.session.

Database hooks: databaseHooks.user.create.before/after, same for session, account. Useful for adding default values or post-creation actions.

Hook context (ctx.context): session, secret, authCookies, password.hash()/verify(), adapter, internalAdapter, generateId(), tables, baseURL.


Plugins

Import from dedicated paths for tree-shaking:

import { twoFactor } from "better-auth/plugins/two-factor"

NOT from "better-auth/plugins".

Popular plugins: twoFactor, organization, passkey, magicLink, emailOtp, username, phoneNumber, admin, apiKey, bearer, jwt, multiSession, sso, oauthProvider, oidcProvider, openAPI, genericOAuth.

Client plugins go in createAuthClient({ plugins: [...] }).


Client

Import from: better-auth/client (vanilla), better-auth/react, better-auth/vue, better-auth/svelte, better-auth/solid.

Key methods: signUp.email(), signIn.email(), signIn.social(), signOut(), useSession(), getSession(), revokeSession(), revokeSessions().


Type Safety

Infer types: typeof auth.$Infer.Session, typeof auth.$Infer.Session.user.

For separate client/server projects: createAuthClient<typeof auth>().


Common Gotchas

  1. Model vs table name - Config uses ORM model name, not DB table name
  2. Plugin schema - Re-run CLI after adding plugins
  3. Secondary storage - Sessions go there by default, not DB
  4. Cookie cache - Custom session fields NOT cached, always re-fetched
  5. Stateless mode - No DB = session in cookie only, logout on cache expiry
  6. Change email flow - Sends to current email first, then new email

Resources

© latitude-dev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/better-auth-best-practices of latitude-dev/latitude-llm.

Open the folder on GitHubat commit 12e8591

Used in 8 other repositories

We found 8 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 7 other GitHub owners. This page covers the copy in latitude-dev/latitude-llm, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Better Auth Best Practices next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Better Auth Best Practices compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Better Auth Best Practices this skilllatitude-dev/latitude-llm4.7k7 repos~1.6kAutomated safety check: PassMIT
Create Auth Skilldeadlock-mod-manager/deadlock-mod-manager5744 repos~3.4kAutomated safety check: PassGPL-3.0
Better Auth Best Practicesviclafouch/meme-studio1105 repos~1.5kAutomated safety check: PassNone
Better Autheinverne/dotfiles121—~4kAutomated safety check: NotesMIT
Node Backend Development Guidelinesdiet103/claude-code-infrastructure-showcase10k2 repos~2kAutomated safety check: PassMIT
Add Backendahpxex/open-dashboard146—~3.6kAutomated safety check: PassMIT

Similar skills

  • Create Auth Skill

    deadlock-mod-manager/deadlock-mod-manager

    Scaffold and implement authentication in TypeScript/JavaScript apps using Better Auth.

    574 GitHub starsUsed in 4 repos~3.4k tokens
    DatabasesAuto-check passed
  • Better Auth Best Practices

    viclafouch/meme-studio

    Skill for integrating Better Auth - the comprehensive TypeScript authentication framework.

    110 GitHub starsUsed in 5 repos~1.5k tokens
    DatabasesAuto-check passed
  • Better Auth

    einverne/dotfiles

    Guide for implementing Better Auth - a framework-agnostic authentication and authorization framework for TypeScript.

    121 GitHub stars~4k tokensUpdated 29 days ago
    Backend & APIsAuto-check: notes
  • Node Backend Development Guidelines

    diet103/claude-code-infrastructure-showcase

    Sets layered architecture and coding rules for Node.js, Express and TypeScript microservices, covering routes, controllers, services, repositories, Prisma, Sentry and Zod.

    10k GitHub starsUsed in 2 repos~2k tokens
    Backend & APIsAuto-check passed
  • Add Backend

    ahpxex/open-dashboard

    Everything about the data layer — pick one of six ready-to-run backend templates (TanStack Start + Drizzle + better-auth, Hono + Drizzle + better-auth, Hono + Prisma + better-auth, Hono + Drizzle +…

    146 GitHub stars~3.6k tokensUpdated 3 mo ago
    DatabasesAuto-check passed
  • NestJS Expert

    Jeffallan/claude-skills

    Scaffolds NestJS modules, controllers, services, DTOs and guards for TypeScript backends, with validation, JWT and Passport auth, Swagger docs and unit and E2E tests.

    12k GitHub stars~2k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed

More from latitude-dev/latitude-llm

All 28 skills in this repo
  • Artifact Designer

    latitude-dev/latitude-llm

    Create, validate, preview, and publish self-contained HTML artifacts.

    4.7k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • CI Watchdog

    latitude-dev/latitude-llm

    Continuously monitor GitHub PR CI checks and automatically fix failures until all checks pass.

    4.7k GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Temporal Developer

    latitude-dev/latitude-llm

    This skill should be used when the user asks to "create a Temporal workflow", "write a Temporal activity", "debug stuck workflow", "fix non-determinism error", "Temporal Python", "Temporal…

    4.7k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Docs

    latitude-dev/latitude-llm

    Review the current conversation context and git changes, then persist durable repository knowledge into dev-docs/.md by domain and into AGENTS.md for cross-cutting repo rules.

    4.7k GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Managing Maintenance Windows

    latitude-dev/latitude-llm

    Enables or disables Latitude production maintenance mode by redirecting all publicly exposed production services to the Better Stack status page.

    4.7k GitHub stars~802 tokensUpdated yesterday
    Auto-check passed
  • Mintlify Preview

    latitude-dev/latitude-llm

    Run the public Mintlify product docs site locally for live preview.

    4.7k GitHub stars~813 tokensUpdated yesterday
    Auto-check passed

Questions about Better Auth Best Practices

What does Better Auth Best Practices do?

Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables. Better Auth Best Practices is an agent skill from latitude-dev/latitude-llm. Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.

When should I use Better Auth Best Practices?

Better Auth Best Practices fits situations like: users mention Better Auth; need to set up TypeScript authentication with email/password; plugin configuration.

How do I install Better Auth Best Practices in Claude Code?

Run `npx skills add latitude-dev/latitude-llm --skill better-auth-best-practices -a claude-code`. Or copy the skill folder (.agents/skills/better-auth-best-practices in latitude-dev/latitude-llm) into .claude/skills/better-auth-best-practices in your project. Claude Code loads it when a task matches its description.

How do I install Better Auth Best Practices in Codex?

Run `npx skills add latitude-dev/latitude-llm --skill better-auth-best-practices -a codex`. Or copy the skill folder (.agents/skills/better-auth-best-practices in latitude-dev/latitude-llm) into .agents/skills/better-auth-best-practices in your project. Codex loads it when a task matches its description.

Can I use Better Auth Best Practices in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add latitude-dev/latitude-llm --skill better-auth-best-practices -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/better-auth-best-practices, .gemini/skills/better-auth-best-practices, .github/skills/better-auth-best-practices and .opencode/skills/better-auth-best-practices in your project.

What does Better Auth Best Practices need to run?

Going by SKILL.md and its folder, Better Auth Best Practices needs the command-line tools its instructions call (npx, npm and openssl) and credentials named BETTER_AUTH_SECRET. Our summary lists: Node.js; A credential in BETTER_AUTH_SECRET.

Does Better Auth Best Practices access the network?

SKILL.md names 2 domains. As links in the text: better-auth.com and github.com. This is read from the text; nothing was executed.

Is Better Auth Best Practices safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Better Auth Best Practices use?

Better Auth Best Practices is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Better Auth Best Practices use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Better Auth Best Practices?

Skills that share tags, products or a category with Better Auth Best Practices: Create Auth Skill (deadlock-mod-manager/deadlock-mod-manager, 574 stars), Better Auth Best Practices (viclafouch/meme-studio, 110 stars), Better Auth (einverne/dotfiles, 121 stars) and Node Backend Development Guidelines (diet103/claude-code-infrastructure-showcase, 10k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Better Auth Best Practices?

latitude-dev (a GitHub organization) maintains it in latitude-dev/latitude-llm, which has 4,714 GitHub stars. The repository holds 28 skills in this directory. The repository was last updated on October 7, 2026.

Source: latitude-dev/latitude-llm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.