Authentication
For the complete documentation index, see llms.txt. Prefer markdown by appending .md to documentation URLs or sending Accept: text/markdown.

Configuration

Choose sign-in methods in src/config/auth.ts. Toggle password and anonymous auth, and select which OAuth providers are shown.

Authentication options are configured in src/config/auth.ts and validated against a Zod schema, so a typo fails at startup.

src/config/auth.ts
export const authConfig = authConfigSchema.parse({
  providers: {
    password: env.VITE_AUTH_PASSWORD,
    anonymous: env.VITE_AUTH_ANONYMOUS,
    oAuth: [
      SocialProvider.GOOGLE,
      SocialProvider.GITHUB,
      SocialProvider.CLOUDFLARE,
    ],
  },
}) satisfies AuthConfig;

Password and anonymous

Both are toggled with public env variables:

.env.local
VITE_AUTH_PASSWORD="true"
VITE_AUTH_ANONYMOUS="true"
  • VITE_AUTH_PASSWORD shows the email and password form. Set it to false to hide it.
  • VITE_AUTH_ANONYMOUS shows anonymous sign-in on the auth screens.

These are UI switches. The server enables password auth and installs the anonymous plugin independently. To prohibit a method, update src/lib/auth/server.ts too. See authentication.

Because they're VITE_ values, change them in .env.local and the vars block of wrangler.jsonc, then rebuild.

OAuth providers

The oAuth array decides which social buttons appear. Remove a provider from it to hide the button:

src/config/auth.ts
oAuth: [SocialProvider.GITHUB],

Each provider also needs credentials in your env file:

ProviderVariablesWhere to get them?
GoogleGOOGLE_CLIENT_ID, GOOGLE_CLIENT_SECRETGoogle Cloud Console
GitHubGITHUB_CLIENT_ID, GITHUB_CLIENT_SECRETGitHub developer settings
CloudflareCLOUDFLARE_CLIENT_ID, CLOUDFLARE_CLIENT_SECRETCloudflare OAuth clients

The callback URL for every provider is:

{BETTER_AUTH_URL}/api/auth/callback/<provider>

For Cloudflare, request the user-details.read scope and use the client_secret_basic token auth method.

Turnstile and rate limiting

Bot protection and throttling for auth routes are configured separately: set VITE_TURNSTILE_SITE_KEY and TURNSTILE_SECRET_KEY in your env, and tune the AUTH_RATE_LIMIT binding in wrangler.jsonc.

The auth server itself lives in src/lib/auth/server.ts. See authentication for the flows and protection boundaries, and OAuth for callback and account-linking setup.

How is this guide?

Last updated on

On this page

Ship globally on the edge. In minutes.Try Edge Kit