# Better Auth solution docs

- [Account linking and email verification without account takeovers](https://agenticboilerplate.com/cookbook/better-auth/account-linking-and-email-verification): When "Continue with Google" joins an existing password account, when it refuses, and why an unverified email address or a trusted provider list can hand one person's account to another.
- [Better Auth on the edge: why your session check fails in middleware](https://agenticboilerplate.com/cookbook/better-auth/better-auth-on-the-edge): Edge runtimes have no TCP sockets and no Node crypto, so a session lookup that works in a page throws in the proxy. Read the cookie there and verify in the render.
- [CSRF, SameSite and the cookie flags that make a session safe](https://agenticboilerplate.com/cookbook/better-auth/csrf-and-cookie-flags): What each session cookie flag actually defends against, why trustedOrigins is your CSRF check, and the three configuration changes that quietly disable both.
- [Guard Better Auth's endpoints, not just your settings forms](https://agenticboilerplate.com/cookbook/better-auth/guarding-the-auth-api-itself): Every /api/auth endpoint is a public URL. One hook refuses account changes from an impersonation session and asks for a recent sign-in before a password or provider is added.
- [The magic-link token: single use, ten minutes, and the scanner that clicks it first](https://agenticboilerplate.com/cookbook/better-auth/magic-link-tokens-and-scanners): How long the credential lives, why a corporate mail scanner burns it before the human arrives, and why the rate limiter has to be backed by your database rather than by process memory.
- [Moving an existing user table onto Better Auth without logging everyone out](https://agenticboilerplate.com/cookbook/better-auth/migrating-an-existing-user-table): Map your columns to the four required tables, backfill ids and accounts, and let people migrate themselves on next sign-in instead of forcing a password reset.
- [oauth-callback-url-mismatches](https://agenticboilerplate.com/cookbook/better-auth/oauth-callback-url-mismatches): 
- [Password reset tokens that cannot be replayed, guessed or leaked](https://agenticboilerplate.com/cookbook/better-auth/password-reset-tokens): One hour, single use, answered the same way for every address, and kept out of logs, Referer headers and search results. What Better Auth does for you and the four things it cannot.
- [Modelling roles you will not regret when the admin panel grows](https://agenticboilerplate.com/cookbook/better-auth/role-modelling-for-the-admin-panel): A role column, a ranked vocabulary in one file, and permission checks that name the action, not a boolean isAdmin scattered across forty components.
- [Session invalidation, or why everyone got logged out on deploy](https://agenticboilerplate.com/cookbook/better-auth/session-invalidation-and-logged-out-on-deploy): A rotated secret, a changed cookie name or a wiped database invalidates every session at once. Here is what invalidates what, and how to revoke one user on purpose.

---

Agentic Boilerplate: A Next.js repo your agent already knows. Free during launch, then $99 once.

- Site map for agents: https://agenticboilerplate.com/llms.txt
- Public API: https://agenticboilerplate.com/openapi.json
- Contact: agenticstudio@gmail.com
