Agent skill

Better Auth Scaffold

by pproenca in pproenca/dot-skills

Scaffolds a Better Auth setup in a Next.js (App Router) + Drizzle project — lib/auth.ts, lib/auth-client.ts, the /api/auth/[...all] route handler, middleware.ts, .env.example, and a permissions…

MITAuto-check: notesDatabases

Install Better Auth Scaffold

skills CLI
$ npx skills add pproenca/dot-skills --skill better-auth-scaffold -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install pproenca/dot-skills better-auth-scaffold --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/pproenca/dot-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.experimental/better-auth-scaffold .claude/skills/better-auth-scaffold && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
better-auth-scaffold
GitHub stars
215
Token cost
~1.6k tokens
SKILL.md length
607 words
Files
15 (incl. references, assets)
Skills in repo
41
Repo updated
First seen
Licence
MIT

At a glance

Scaffolds a Better Auth setup in a Next.js (App Router) + Drizzle project — lib/auth.ts, lib/auth-client.ts, the /api/auth/[...all] route handler, middleware.ts, .env.example, and a permissions…

  • Works in 5 steps: Resolve parameters. Read config.json… → Render each template. For each template… → Write output files. Before writing,… → …
  • Even when the user doesnt explicitly say scaffold — phrases like set up Better Auth
  • SKILL.md covers When to Apply, Setup, Available Templates and How to Use, plus 3 more sections
  • Calls npx and openssl

What it does

Better Auth Scaffold is an agent skill from pproenca/dot-skills. Scaffolds a Better Auth setup in a Next.js (App Router) + Drizzle project — lib/auth.ts, lib/auth-client.ts, the /api/auth/[...all] route handler, middleware.ts, .env.example, and a permissions module. Produces convention-enforced templates for three plugin presets (minimal, social, advanced with twoFactor+magicLink). Trigger even when the user doesn't explicitly say "scaffold" — phrases like "set up Better Auth", "wire up auth", "initialize auth in this project", or "add auth to Next.js" should pull this in…

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 17 other files, including reference files and assets (for example `config.json`, `gotchas.md` and `metadata.json`).

It sits in Databases, covering Project scaffolding and ORMs and data access. It works with Better Auth and Next.js. The repository describes itself as: A collection of AI agent skills following the Agent Skills open format. The licence is MIT.

When your agent uses it

  • Even when the user doesnt explicitly say scaffold — phrases like set up Better Auth
  • Initialize auth in this project
  • Add auth to Next.js should pull this in

Example prompts

  • “t explicitly say”
  • “— phrases like”
  • “wire up auth”
  • “/better-auth-scaffold”

Requirements

  • Node.js

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Resolve parameters. Read config.json first; for any missing required parameter (db_provider, app_name), ask the user via AskUserQuestion.
  2. Render each template. For each template file
  3. Write output files. Before writing, check if the target file already exists
  4. Run the CLI sequence. After all files are written
  5. Print next steps. Tell the user to

What it can do on your machine

Read from SKILL.md and the folder at commit cf93c57. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • openssl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Better Auth Scaffold loads about 1.6k tokens when it runs, and up to ~3.5k if it reads all its reference files. Until then it costs about 155 tokens; SKILL.md has 607 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~155
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:82
    - Fill in `.env.local` (copy from `.env.example`)

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from pproenca/dot-skills at commit cf93c57, republished under its MIT licence (© pproenca). 607 words, ~1,642 tokens.

Download SKILL.mdSave it as .claude/skills/better-auth-scaffold/SKILL.md (or your agent's skills folder). This skill also uses 14 other files; get the full folder from GitHub.
name
better-auth-scaffold
description
Scaffolds a Better Auth setup in a Next.js (App Router) + Drizzle project — lib/auth.ts, lib/auth-client.ts, the /api/auth/[...all] route handler, middleware.ts, .env.example, and a permissions module. Produces convention-enforced templates for three plugin presets (minimal, social, advanced with twoFactor+magicLink). Trigger even when the user doesn't explicitly say "scaffold" — phrases like "set up Better Auth", "wire up auth", "initialize auth in this project", or "add auth to Next.js" should pull this in. Pairs with the `better-auth` skill, which covers the rules these templates encode.

Better Auth Scaffold (Next.js + Drizzle)

Parameterized templates for bootstrapping a Better Auth setup in a Next.js App Router project using the Drizzle adapter. Each template enforces the conventions documented in references/conventions.md — file layout, plugin ordering, env handling, runtime selection.

When to Apply

Reference these templates when:

  • Starting a new Next.js project that needs authentication
  • Adding Better Auth to an existing Next.js + Drizzle codebase
  • Refactoring a partial Better Auth setup that's missing the catch-all route, middleware, or nextCookies() ordering
  • Generating a per-feature variant (minimal, social, advanced) on top of an existing project

Setup

Required parameters
ParameterRequiredDefaultDescription
presetnominimalminimal (email+password) | social (adds Google + GitHub) | advanced (social + twoFactor + magicLink)
db_provideryes—pg | mysql | sqlite (Drizzle provider)
app_nameyes—Display name (becomes 2FA issuer in authenticator apps when preset=advanced)
Optional parameters
ParameterDefaultDescription
auth_pathlib/auth.tsServer auth module path
client_pathlib/auth-client.tsClient module path
api_route_pathapp/api/auth/[...all]/route.tsCatch-all route handler path
protected_paths["/dashboard"]Routes the middleware guards

If config.json already exists with values, the skill uses those; otherwise it asks the user.

Available Templates

TemplateOutput FileWhen to emit
auth.ts.templatelib/auth.tsAlways
auth-client.ts.templatelib/auth-client.tsAlways
route.ts.templateapp/api/auth/[...all]/route.tsAlways
middleware.ts.templatemiddleware.tsWhen protected_paths is non-empty
env.template.env.exampleAlways
db-schema-better-auth.ts.templatedb/schema/auth.tsAlways (stub — replace with output of better-auth generate)
db-index.ts.templatedb/index.tsWhen the project has no Drizzle client yet
email.ts.templatelib/email.tsWhen preset=advanced (and the file doesn't already exist)
sign-in-page.tsx.templateapp/sign-in/page.tsxWhen the project has no sign-in page (closes the middleware redirect loop)
permissions.ts.templatelib/permissions.tsOptional starter for org/admin plugin work

How to Use

  1. Resolve parameters. Read config.json first; for any missing required parameter (db_provider, app_name), ask the user via AskUserQuestion.

  2. Render each template. For each template file:

    • Read the template.
    • Substitute {{placeholder}} values ({{app_name}}, {{db_provider}}, etc.) with the resolved parameter values.
    • Apply PRESET[...] conditional blocks using these rules:
      1. Find every pair of marker lines matching // PRESET[<tags>] and // /PRESET[<tags>] (or /* PRESET[...] */ / # PRESET[...] for non-JS files — same syntax, different comment style).
      2. Parse <tags> as a comma-separated list (e.g. social,advanced).
      3. If the chosen preset value is in <tags> → remove ONLY the two marker lines; keep the lines between them.
      4. If the chosen preset value is NOT in <tags> → remove the ENTIRE block including both marker lines.
      5. Markers may be nested (e.g. PRESET[advanced] inside PRESET[minimal,social,advanced]); process from inside out.
    • For Mustache-style iteration in middleware.ts.template (// {{#protected_paths}} ... // {{/protected_paths}}), repeat the lines between the markers once per item in the list, substituting {{path}} with each value.
  3. Write output files. Before writing, check if the target file already exists:

    • If it doesn't exist → write it.
    • If it exists and is identical → no-op.
    • If it exists and differs → show a diff and ask the user (overwrite / merge / skip).
  4. Run the CLI sequence. After all files are written:

    bash
    npx @better-auth/cli@latest generate
    npx drizzle-kit generate
    npx drizzle-kit migrate

    These commands replace the placeholder db/schema/auth.ts with the real schema and apply migrations.

  5. Print next steps. Tell the user to:

    • Fill in .env.local (copy from .env.example)
    • Generate a secret: openssl rand -base64 32
    • Register OAuth redirect URIs with each provider console (for social/advanced presets)
    • Implement lib/email.ts to wire transactional email (for advanced preset)
Show full SKILL.md (95 more words)Show less

Conventions

Read references/conventions.md for the rationale behind every convention these templates encode. Highlights:

  • lib/auth.ts is server-only (import "server-only")
  • nextCookies() is ALWAYS the last plugin in the array
  • Middleware does a cookie-presence check only; real validation in pages
  • All secrets via process.env.*, never inline
  • Sliding-window sessions with cookieCache enabled
  • better-auth — Library/API Reference with 42 rules covering setup, sessions, security, plugins, and migration. The templates here are one canonical realization of those rules; read the rule for the underlying reasoning when you need to deviate.

Gotchas

See gotchas.md — initialized empty, populated as we discover them.

© pproenca, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 14 other files (references, assets) in skills/.experimental/better-auth-scaffold of pproenca/dot-skills.

  • SKILL.md
  • assets/templates/auth-client.ts.template
  • assets/templates/auth.ts.template
  • assets/templates/db-index.ts.template
  • assets/templates/db-schema-better-auth.ts.template
  • assets/templates/email.ts.template
  • assets/templates/env.template
  • assets/templates/middleware.ts.template
  • assets/templates/permissions.ts.template
  • assets/templates/route.ts.template
  • assets/templates/sign-in-page.tsx.template
  • config.json
  • gotchas.md
  • metadata.json
  • references/conventions.md

Open the folder on GitHubat commit cf93c57

Compare with similar skills

Better Auth Scaffold next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Better Auth Scaffold compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Better Auth Scaffold this skillpproenca/dot-skills215—~1.6kAutomated safety check: NotesMIT
Vite Flare Starterjezweb/claude-skills1.1k—~2.6kAutomated safety check: PassMIT
Create Auth Skilldeadlock-mod-manager/deadlock-mod-manager5744 repos~3.4kAutomated safety check: PassGPL-3.0
Add Backendahpxex/open-dashboard146—~3.6kAutomated safety check: PassMIT
Supercheck Architecturesupercheck-io/supercheck215—~1.3kAutomated safety check: PassAGPL-3.0
Better Auth Best Practicesviclafouch/meme-studio1105 repos~1.5kAutomated safety check: PassNone

Similar skills

  • Vite Flare Starter

    jezweb/claude-skills

    Scaffold a full-stack Cloudflare app from the vite-flare-starter template — React 19 + Hono + D1+Drizzle + better-auth + Tailwind v4+shadcn/ui + TanStack Query + R2 + Workers AI.

    1.1k GitHub stars~2.6k tokensUpdated 2 days ago
    DatabasesAuto-check passed
  • Create Auth Skill

    deadlock-mod-manager/deadlock-mod-manager

    Scaffold and implement authentication in TypeScript/JavaScript apps using Better Auth.

    574 GitHub starsUsed in 4 repos~3.4k tokens
    DatabasesAuto-check passed
  • Add Backend

    ahpxex/open-dashboard

    Everything about the data layer — pick one of six ready-to-run backend templates (TanStack Start + Drizzle + better-auth, Hono + Drizzle + better-auth, Hono + Prisma + better-auth, Hono + Drizzle +…

    146 GitHub stars~3.6k tokensUpdated 3 mo ago
    DatabasesAuto-check passed
  • Supercheck Architecture

    supercheck-io/supercheck

    Work on Supercheck system architecture, Next.js routes and actions, React data hooks, Drizzle schemas and migrations, app-worker boundaries, or cross-package contracts.

    215 GitHub stars~1.3k tokensUpdated today
    DatabasesAuto-check passed
  • Better Auth Best Practices

    viclafouch/meme-studio

    Skill for integrating Better Auth - the comprehensive TypeScript authentication framework.

    110 GitHub starsUsed in 5 repos~1.5k tokens
    DatabasesAuto-check passed
  • Daoyou Data Layer

    ChurchTao/Daoyou

    Daoyou Drizzle/PostgreSQL、事务、V6 角色与宗门归属、统一背包、Redis 战局和回放归档指南。Use when modifying schema, migrations, repositories, persistence mappers, resource commits or durable game models.

    120 GitHub stars~1.9k tokensUpdated yesterday
    DatabasesAuto-check passed

More from pproenca/dot-skills

All 41 skills in this repo
  • Audio Voice Recovery

    pproenca/dot-skills

    Audio forensics and voice recovery guidelines for CSI-level audio analysis.

    215 GitHub stars~3.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Codemod React Pipeline

    pproenca/dot-skills

    Guided, scripted pipeline for running JSX/TSX/React codemods safely across large legacy codebases.

    215 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Dev Rfc

    pproenca/dot-skills

    Create well-structured RFCs and technical proposals for software projects.

    215 GitHub stars~3.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Dx Harness

    pproenca/dot-skills

    Developer-experience friction auditing and fixing — slow onboarding, repeated manual setup steps, missing bootstrap/reset/seed scripts, undiscoverable conventions.

    215 GitHub stars~1.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Language Spec Author

    pproenca/dot-skills

    Turn a rough idea for a language into a complete, implementable specification — a DSL, query, config/data, template, or protocol language — by interviewing the author dimension by dimension until…

    215 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Python Pep Author

    pproenca/dot-skills

    Drafting Python Enhancement Proposals (PEPs) — proposing a Python language feature, a standard library change, an interoperability standard, or an informational/process document for the Python…

    215 GitHub stars~2.1k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Better Auth Scaffold

What does Better Auth Scaffold do?

Scaffolds a Better Auth setup in a Next.js (App Router) + Drizzle project — lib/auth.ts, lib/auth-client.ts, the /api/auth/[...all] route handler, middleware.ts, .env.example, and a permissions…. Better Auth Scaffold is an agent skill from pproenca/dot-skills.example, and a permissions module.

When should I use Better Auth Scaffold?

Better Auth Scaffold fits situations like: even when the user doesnt explicitly say scaffold — phrases like set up Better Auth; initialize auth in this project; add auth to Next.js should pull this in.

How do I install Better Auth Scaffold in Claude Code?

Run `npx skills add pproenca/dot-skills --skill better-auth-scaffold -a claude-code`. Or copy the skill folder (skills/.experimental/better-auth-scaffold in pproenca/dot-skills) into .claude/skills/better-auth-scaffold in your project. Claude Code loads it when a task matches its description.

How do I install Better Auth Scaffold in Codex?

Run `npx skills add pproenca/dot-skills --skill better-auth-scaffold -a codex`. Or copy the skill folder (skills/.experimental/better-auth-scaffold in pproenca/dot-skills) into .agents/skills/better-auth-scaffold in your project. Codex loads it when a task matches its description.

Can I use Better Auth Scaffold in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pproenca/dot-skills --skill better-auth-scaffold -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/better-auth-scaffold, .gemini/skills/better-auth-scaffold, .github/skills/better-auth-scaffold and .opencode/skills/better-auth-scaffold in your project.

What does Better Auth Scaffold need to run?

Going by SKILL.md and its folder, Better Auth Scaffold needs the command-line tools its instructions call (npx and openssl). Our summary lists: Node.js.

Does Better Auth Scaffold access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Better Auth Scaffold safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Better Auth Scaffold use?

Better Auth Scaffold is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Better Auth Scaffold use?

About 1.6k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.

What are the alternatives to Better Auth Scaffold?

Skills that share tags, products or a category with Better Auth Scaffold: Vite Flare Starter (jezweb/claude-skills, 1.1k stars), Create Auth Skill (deadlock-mod-manager/deadlock-mod-manager, 574 stars), Add Backend (ahpxex/open-dashboard, 146 stars) and Supercheck Architecture (supercheck-io/supercheck, 215 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Better Auth Scaffold?

pproenca (a GitHub user) maintains it in pproenca/dot-skills, which has 215 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on August 15, 2026.

Source: pproenca/dot-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.