{"slug":"api-auth-better-auth-drizzle-hono","title":"api-auth-better-auth-drizzle-hono","summary":"Better Auth patterns, sessions, OAuth","platform":"Claude","tags":[],"authorName":"LLM Mart","authorSlug":"llm-mart","score":0,"source":"github","price":null,"verified":false,"createdAt":"2026-09-29T15:27:52.749265Z","repo":{"url":"https://github.com/agents-inc/skills","stars":24,"forks":8,"license":"MIT","updatedAt":"2026-09-07T17:50:55Z"},"bodyHtml":"<hr>\n<h2>name: api-auth-better-auth-drizzle-hono\ndescription: Better Auth patterns, sessions, OAuth</h2>\n<h1>Authentication with Better Auth</h1>\n<blockquote>\n<p><strong>Quick Guide:</strong> Use Better Auth (v1.5+) for type-safe, self-hosted authentication in TypeScript apps. It provides email/password, OAuth, 2FA, sessions, stateless auth, and organization multi-tenancy. Plugin architecture enables progressive complexity. Mount auth handler before session-dependent middleware, configure CORS first for cross-origin deployments, and always run schema generation after adding plugins.</p>\n</blockquote>\n<hr>\n<p>&lt;critical_requirements&gt;</p>\n<h2>CRITICAL: Before Using This Skill</h2>\n<blockquote>\n<p><strong>All code must follow project conventions in CLAUDE.md</strong> (kebab-case, named exports, import ordering, <code>import type</code>, named constants)</p>\n</blockquote>\n<p><strong>(You MUST mount Better Auth handler on the auth route BEFORE any other middleware that depends on session)</strong></p>\n<p><strong>(You MUST configure CORS middleware BEFORE auth routes when client and server are on different origins)</strong></p>\n<p><strong>(You MUST use environment variables for ALL secrets (clientId, clientSecret, BETTER_AUTH_SECRET) - NEVER hardcode)</strong></p>\n<p><strong>(You MUST run <code>npx auth@latest generate</code> then your ORM migration tool after adding plugins)</strong></p>\n<p><strong>(You MUST use <code>auth.$Infer.Session</code> types for type-safe session access in middleware)</strong></p>\n<p>&lt;/critical_requirements&gt;</p>\n<hr>\n<p><strong>Auto-detection:</strong> Better Auth, betterAuth, createAuthClient, auth.handler, auth.api.getSession, socialProviders, twoFactor plugin, organization plugin, drizzleAdapter, session management, OAuth providers, stateless sessions, cookieCache, genericOAuth, oAuthProvider, passkey, SCIM</p>\n<p><strong>When to use:</strong></p>\n<ul>\n<li>Building self-hosted authentication (no vendor lock-in)</li>\n<li>Need email/password + OAuth + 2FA in one solution</li>\n<li>Multi-tenant SaaS with organization/team management</li>\n<li>Type-safe session management</li>\n<li>Projects requiring database-stored or stateless sessions</li>\n</ul>\n<p><strong>When NOT to use:</strong></p>\n<ul>\n<li>Need managed authentication with zero maintenance (consider hosted auth solutions)</li>\n<li>Simple static sites without user accounts</li>\n<li>Projects where serverless cold starts are critical (though stateless mode helps)</li>\n</ul>\n<p><strong>Key patterns covered:</strong></p>\n<ul>\n<li>Server configuration (auth.ts) with plugins</li>\n<li>Session middleware and type-safe route protection</li>\n<li>Email/password authentication flows</li>\n<li>OAuth providers (GitHub, Google, Generic OAuth)</li>\n<li>Two-factor authentication (TOTP)</li>\n<li>Organization and multi-tenancy</li>\n<li>Session strategies: database, cookie cache, stateless</li>\n<li>Database adapter integration</li>\n<li>Client-side useSession hook</li>\n<li>Performance: experimental joins, cookie caching, stateless sessions</li>\n</ul>\n<p><strong>Detailed Resources:</strong></p>\n<ul>\n<li><a href=\"examples/core.md\">examples/core.md</a> - Sign up, sign in, client setup, database adapter</li>\n<li><a href=\"examples/oauth.md\">examples/oauth.md</a> - GitHub, Google, Generic OAuth providers</li>\n<li><a href=\"examples/two-factor.md\">examples/two-factor.md</a> - TOTP setup, enable, verify</li>\n<li><a href=\"examples/organizations.md\">examples/organizations.md</a> - Multi-tenancy, invitations</li>\n<li><a href=\"examples/sessions.md\">examples/sessions.md</a> - Session config, cookie caching, stateless</li>\n<li><a href=\"reference.md\">reference.md</a> - Decision frameworks, anti-patterns, version notes</li>\n</ul>\n<hr>\n\n<hr>\n\n<hr>\n<p>&lt;red_flags&gt;</p>\n<h2>RED FLAGS</h2>\n<ul>\n<li>Hardcoded secrets (clientId/clientSecret in source) - must use environment variables</li>\n<li>CORS configured after auth routes - preflight requests will fail</li>\n<li>Missing <code>BETTER_AUTH_SECRET</code> env var - sessions will not work</li>\n<li>No schema generation after adding plugins - database errors at runtime</li>\n<li>Untyped session middleware - loses TypeScript safety, <code>c.user</code> becomes <code>any</code></li>\n<li>Using <code>auth.migrate()</code> with Drizzle adapter - only works with Kysely, use <code>generate</code> + Drizzle Kit</li>\n<li>Missing <code>c.req.raw</code> when calling <code>auth.handler()</code> - must pass the raw Web Standard Request</li>\n</ul>\n<p><strong>Gotchas &amp; Edge Cases:</strong></p>\n<ul>\n<li>Google only issues refresh tokens on first consent - use <code>accessType: \"offline\"</code> and <code>prompt: \"consent\"</code></li>\n<li>GitHub OAuth apps don't issue refresh tokens (access tokens are long-lived)</li>\n<li>Stateless sessions cannot be revoked individually - increment <code>version</code> to invalidate all</li>\n<li>Cookie cache revocation is delayed until <code>maxAge</code> expires on other devices</li>\n<li>Session cookies need <code>SameSite=None</code> + <code>Secure</code> for cross-domain deployments</li>\n<li><code>authClient.forgotPassword</code> was renamed to <code>authClient.requestPasswordReset</code> in v1.4</li>\n<li><code>InferUser</code>/<code>InferSession</code> removed in v1.5 - use generic <code>User</code> and <code>Session</code> types from <code>better-auth</code></li>\n</ul>\n<p>See <a href=\"reference.md\">reference.md</a> for anti-patterns with code examples, decision frameworks, and version notes.</p>\n<p>&lt;/red_flags&gt;</p>\n<hr>\n<p>&lt;critical_reminders&gt;</p>\n<h2>CRITICAL REMINDERS</h2>\n<blockquote>\n<p><strong>All code must follow project conventions in CLAUDE.md</strong> (kebab-case, named exports, import ordering, <code>import type</code>, named constants)</p>\n</blockquote>\n<p><strong>(You MUST mount Better Auth handler on the auth route BEFORE any other middleware that depends on session)</strong></p>\n<p><strong>(You MUST configure CORS middleware BEFORE auth routes when client and server are on different origins)</strong></p>\n<p><strong>(You MUST use environment variables for ALL secrets (clientId, clientSecret, BETTER_AUTH_SECRET) - NEVER hardcode)</strong></p>\n<p><strong>(You MUST run <code>npx auth@latest generate</code> then your ORM migration tool after adding plugins)</strong></p>\n<p><strong>(You MUST use <code>auth.$Infer.Session</code> types for type-safe session access in middleware)</strong></p>\n<p><strong>Failure to follow these rules will cause authentication failures, security vulnerabilities, or runtime errors.</strong></p>\n<p>&lt;/critical_reminders&gt;</p>\n","files":[{"path":"examples/core.md","sizeBytes":8510,"isText":true},{"path":"examples/oauth.md","sizeBytes":5330,"isText":true},{"path":"examples/organizations.md","sizeBytes":4038,"isText":true},{"path":"examples/sessions.md","sizeBytes":4392,"isText":true},{"path":"examples/two-factor.md","sizeBytes":3865,"isText":true},{"path":"examples/v1.4-features.md","sizeBytes":404,"isText":true},{"path":"reference.md","sizeBytes":6500,"isText":true},{"path":"SKILL.md","sizeBytes":11571,"isText":true}],"reviewScore":null,"reviewSummary":null,"trust":{"provenance":"trusted-source-unreviewed","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow.","bodySource":null},"bodyLocked":false,"purchaseUrl":null,"sourceUrl":null,"report":{"provenance":"trusted-source-unreviewed","screen":{"ran":true,"outcome":"notes-only","suspicious":0,"notes":1,"hiddenCharacters":false},"virusScan":{"engine":"clamav","status":"clean","scannedAt":"2026-09-29T15:28:27.539792Z","sha256":"A4F0246C4DDFF81335FCE9292F2CEB834DB4A67CA20D81EFC98F8B133262A3AD","sizeBytes":17053},"review":null,"source":{"repositoryUrl":"https://github.com/agents-inc/skills","path":"dist/plugins/api-auth-better-auth-drizzle-hono/skills/api-auth-better-auth-drizzle-hono","license":"MIT","commit":"3a51ef571e996b18294bf776d53dbdad26de0617","subtreeSha":"4B8439A101DB4B3F4420649C8FBFC4947B339855E007B2B2F8EB25CF3AF4ADC0","lastSyncedAt":"2026-09-29T15:27:48.914434Z"},"reviewedAt":"2026-09-29T15:30:06.925866Z","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow."},"install":[{"target":"skills-cli","command":"npx skills add https://github.com/agents-inc/skills/tree/main/dist/plugins/api-auth-better-auth-drizzle-hono/skills/api-auth-better-auth-drizzle-hono"},{"target":"claude-code","command":"claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install agents-inc-skills@llmmart"},{"target":"git","command":"git clone https://github.com/agents-inc/skills.git"}]}