For the complete documentation index, see llms.txt. Prefer markdown by appending.mdto documentation URLs or sendingAccept: text/markdown.
Configuration
Choose sign-in methods in src/config/auth.ts. Toggle password and anonymous auth, and select which OAuth providers are shown.
Authentication options are configured in src/config/auth.ts and validated against a Zod schema, so a typo fails at startup.
export const authConfig = authConfigSchema.parse({
providers: {
password: env.VITE_AUTH_PASSWORD,
anonymous: env.VITE_AUTH_ANONYMOUS,
oAuth: [
SocialProvider.GOOGLE,
SocialProvider.GITHUB,
SocialProvider.CLOUDFLARE,
],
},
}) satisfies AuthConfig;Password and anonymous
Both are toggled with public env variables:
VITE_AUTH_PASSWORD="true"
VITE_AUTH_ANONYMOUS="true"VITE_AUTH_PASSWORDshows the email and password form. Set it tofalseto hide it.VITE_AUTH_ANONYMOUSshows anonymous sign-in on the auth screens.
These are UI switches. The server enables password auth and installs the anonymous plugin independently. To prohibit a method, update src/lib/auth/server.ts too. See authentication.
Because they're VITE_ values, change them in .env.local and the vars block of wrangler.jsonc, then rebuild.
OAuth providers
The oAuth array decides which social buttons appear. Remove a provider from it to hide the button:
oAuth: [SocialProvider.GITHUB],Each provider also needs credentials in your env file:
| Provider | Variables | Where to get them? |
|---|---|---|
GOOGLE_CLIENT_ID, GOOGLE_CLIENT_SECRET | Google Cloud Console | |
| GitHub | GITHUB_CLIENT_ID, GITHUB_CLIENT_SECRET | GitHub developer settings |
| Cloudflare | CLOUDFLARE_CLIENT_ID, CLOUDFLARE_CLIENT_SECRET | Cloudflare OAuth clients |
The callback URL for every provider is:
{BETTER_AUTH_URL}/api/auth/callback/<provider>For Cloudflare, request the user-details.read scope and use the client_secret_basic token auth method.
Turnstile and rate limiting
Bot protection and throttling for auth routes are configured separately: set VITE_TURNSTILE_SITE_KEY and TURNSTILE_SECRET_KEY in your env, and tune the AUTH_RATE_LIMIT binding in wrangler.jsonc.
The auth server itself lives in src/lib/auth/server.ts. See authentication for the flows and protection boundaries, and OAuth for callback and account-linking setup.
How is this guide?
Last updated on
Overview
Better Auth authentication with ready-to-use sign-in flows, customer sessions, account recovery, social providers, and server-side access checks.
OAuth providers
Connect Google, GitHub, and Cloudflare sign-in, register the correct callback URLs, and understand trusted account linking in Edge Kit.