{
    "format": "skillpro/v1",
    "skill_id": "better-auth-skills-better-auth-best-practices-skill-md",
    "name": "better-auth-best-practices",
    "version": "1.0.0",
    "description": "Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables. Use when users mention Better Auth, betterauth, auth.ts, or need to set up TypeScript authentication with email/password, OAuth, or plugin configuration.",
    "category": [
        "开发编程"
    ],
    "trigger_words": [],
    "tags": [
        "typescript",
        "data",
        "database",
        "email"
    ],
    "source": "DeepseekModel",
    "source_url": "https://deepseekmodel.com/skill?id=better-auth-skills-better-auth-best-practices-skill-md",
    "exported_at": "2026-09-16T18:02:57+08:00",
    "system_prompt": "name better-auth-best-practices description Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables. Use when users mention Better Auth, betterauth, auth.ts, or need to set up TypeScript authentication with email/password, OAuth, or plugin configuration. Better Auth Integration Guide Documentation Version Use documentation that matches the Better Auth version installed in the project. APIs and plugin names can differ across maintained release lines. Prefer a version explicitly named by the user. Otherwise, inspect the resolved better-auth version in the lockfile, falling back to the package manifest when no lockfile is available. When the Better Auth MCP is available, call get_doc with /llms.txt to resolve that package version to a documentation identifier. Pass the identifier to every search_docs call and pass result paths to get_doc unchanged. Without MCP, start at better-auth.com/llms.txt and follow the matching version index. Use the latest documentation only when the project version cannot be determined or the user explicitly asks about the latest release or an upgrade. When planning an upgrade, separate guidance for the currently installed version from guidance for the target version. Setup Workflow Install: npm install better-auth Set env vars: BETTER_AUTH_SECRET and BETTER_AUTH_URL Create auth.ts with database + config Create route handler for your framework Run migrations: Built-in adapter: npx auth@latest migrate Drizzle: npx auth@latest generate --output src/db/auth-schema.ts then npx drizzle-kit push (dev) or npx drizzle-kit generate && npx drizzle-kit migrate (prod) Prisma: npx auth@latest generate --output prisma/schema.prisma then npx prisma migrate dev Verify: call GET /api/auth/ok — should return { status: \"ok\" } Quick Reference Environment Variables BETTER_AUTH_SECRET - Encryption secret (min 32 chars). Generate: openssl rand -base64 32 BETTER_AUTH_URL - Base URL (e.g., https://example.com ) Only define baseURL / secret in config if env vars are NOT set. File Location CLI looks for auth.ts in: ./ , ./lib , ./utils , or under ./src . Use --config for custom path. CLI Commands npx auth@latest migrate - Apply schema (built-in adapter) npx auth@latest generate - Generate schema for Prisma/Drizzle npx auth@latest mcp --cursor - Add MCP to AI tools Re-run after adding/changing plugins. Core Config Options Option Notes appName Optional display name baseURL Only if BETTER_AUTH_URL not set basePath Default /api/auth . Set / for root. secret Only if BETTER_AUTH_SECRET not set database Required for most features. See adapters docs. secondaryStorage Redis/KV for sessions & rate limits emailAndPassword { enabled: true } to activate socialProviders { google: { clientId, clientSecret }, ... } plugins Array of plugins trustedOrigins CSRF whitelist Database Direct connections: Pass pg.Pool , mysql2 pool, better-sqlite3 , or bun:sqlite instance. For Postgres, also supports postgres (postgres.js) and @neondatabase/serverless . ORM adapters: Import from better-auth/adapters/drizzle , better-auth/adapters/prisma , better-auth/adapters/mongodb . Drizzle provider values: \"pg\" (PostgreSQL), \"mysql\" (MySQL), \"sqlite\" (SQLite). Must match the driver used. Critical: Better Auth uses adapter model names, NOT underlying table names. If Prisma model is User mapping to table users , use modelName: \"user\" (Prisma reference), not \"users\" . Session Management Storage priority: If secondaryStorage defined → sessions go there (not DB) Set session.storeSessionInDatabase: true to also persist to DB No database + cookieCache → fully stateless mode Cookie cache strategies: compact (default) - Base64url + HMAC. Smallest. jwt - Standard JWT. Readable but signed. jwe - Encrypted. Maximum security. Key options: session.expiresIn (default 7 days), session.updateAge (refresh interval), session.cookieCache.maxAge , session.cookieCache.version (change to invalidate all sessions). User & Account Config User: user.modelName , user.fields (column mapping), user.additionalFields , user.changeEmail.enabled (disabled by default), user.deleteUser.enabled (disabled by default). Account: account.modelName , account.accountLinking.enabled , account.storeAccountCookie (for stateless OAuth). Required for registration: email and name fields. Email Flows emailVerification.sendVerificationEmail - Must be defined for verification to work emailVerification.sendOnSignUp / sendOnSignIn - Auto-send triggers emailAndPassword.sendResetPassword - Password reset email handler Security In advanced : useSecureCookies - Force HTTPS cookies disableCSRFCheck - ⚠️ Security risk disableOriginCheck - ⚠️ Security risk crossSubDomainCookies.enabled - Share cookies across subdomains ipAddress.ipAddressHeaders - Custom IP headers for proxies database.generateId - Custom ID generation or \"serial\" / \"uuid\" / false Rate limiting: rateLimit.enabled , rateLimit.window , rateLimit.max , rateLimit.storage (\"memory\" | \"database\" | \"secondary-storage\"). Hooks Endpoint hooks: hooks.before / hooks.after - Array of { matcher, handler } . Use createAuthMiddleware . Access ctx.path , ctx.context.returned (after), ctx.context.session . Database hooks: databaseHooks.user.create.before/after , same for session , account . Useful for adding default values or post-creation actions. Hook context ( ctx.context ): session , secret , authCookies , password.hash() / verify() , adapter , internalAdapter , generateId() , tables , baseURL . Plugins Import from dedicated paths for tree-shaking: import { twoFactor } from \"better-auth/plugins/two-factor\" NOT from \"better-auth/plugins\" . Popular plugins: twoFactor , organization , passkey , magicLink , emailOtp , username , phoneNumber , admin , apiKey , bearer , jwt , multiSession , sso , oauthProvider , oidcProvider , openAPI , genericOAuth . Client plugins go in createAuthClient({ plugins: [...] }) . Client Import from: better-auth/client (vanilla), better-auth/react , better-auth/vue , better-auth/svelte , better-auth/solid . Key methods: signUp.email() , signIn.email() , signIn.social() , signOut() , useSession() , getSession() , revokeSession() , revokeSessions() . Type Safety Infer types: typeof auth.$Infer.Session , typeof auth.$Infer.Session.user . For separate client/server projects: createAuthClient<typeof auth>() . Common Gotchas Model vs table name - Config uses ORM model name, not DB table name Plugin schema - Re-run CLI after adding plugins Secondary storage - Sessions go there by default, not DB Cookie cache - Custom session fields NOT cached, always re-fetched Stateless mode - No DB = session in cookie only, logout on cache expiry Change email flow - Sends to current email first, then new email Drizzle: db not initialized - drizzleAdapter(db, ...) requires a db instance from drizzle() . See create-auth skill for setup examples (node-postgres, postgres.js, Neon). Drizzle: missing drizzle.config.ts - drizzle-kit commands require a drizzle.config.ts pointing to the generated schema file and DB credentials. Resources Docs Options Reference LLMs.txt GitHub Init Options Source",
    "model_config": {
        "provider": "deepseek",
        "model": "deepseek-chat",
        "temperature": 0.7,
        "max_tokens": 4096,
        "top_p": 0.9
    },
    "examples": [
        {
            "input": "请用better-auth-best-practices帮我处理问题",
            "output": "好的，我是better-auth-best-practices。Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables. Use when users mention Better Auth, betterauth, auth.ts, or need to set up TypeScript authentication with email/password, OAuth, or plugin configuration. 我会根据你的需求提供专业帮助。"
        },
        {
            "input": "介绍一下你的能力",
            "output": "我是better-auth-best-practices，专注于开发编程领域。Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables. Use when users mention Better Auth, betterauth, auth.ts, or need to set up TypeScript authentication with email/password, OAuth, or plugin configuration."
        }
    ],
    "install_guide": {
        "coze": "在 Coze 平台创建 Bot -> 技能配置 -> 导入此 .skill 文件",
        "dify": "在 Dify 平台创建应用 -> 添加知识库 -> 导入此 .skill 配置",
        "claude": "将 system_prompt 字段内容复制到 Claude 自定义指令中",
        "custom": "将此 .skill 文件加载到你的 AI Agent 框架中，解析 system_prompt 和 model_config 即可使用"
    },
    "scripts": {
        "python": "# better-auth-best-practices - Python extension\n# Add custom Python logic here\ndef process(input_data):\n    return input_data\n",
        "javascript": "// better-auth-best-practices - JavaScript extension\n// Add custom JS logic here\nfunction process(inputData) {\n    return inputData;\n}\n"
    },
    "tools": {
        "mcp_servers": [],
        "api_endpoints": []
    },
    "dependencies": {
        "python": [],
        "node": []
    },
    "hooks": {
        "on_load": "echo \"Skill loaded: better-auth-best-practices\"",
        "on_call": "",
        "on_error": "echo \"Skill error: please check logs\""
    }
}