# Next.js boilerplate with Better Auth

> Self-hosted, TypeScript-native authentication that lives in your own database. Email and password, magic links, and Google, GitHub and Microsoft sign-in (each on when its keys are set), with sign-up, password reset, account settings, a role column the admin panel can trust, and server-side session helpers with no vendor session service in the request path.

Own your users table. Passwords, magic links, Google, GitHub and Microsoft, all in your database.

- **Category:** Sign in
- **Pricing:** Free and open source (MIT). You pay only for your own Postgres and the sign-in emails you send. Google, GitHub and Microsoft sign-in are free.
- **Best for:** Teams who want the user table in their own database, joinable with their own data. No per-MAU bill and no third-party outage in the login path.
- **Requires:** orm, database, email
- **Conflicts with:** clerk, supabase-auth
- **Vendor docs:** https://better-auth.com/docs

## Trade-offs

- You own the security surface. Nobody rotates your signing secret, patches your session logic or answers a pen-test questionnaire for you.
- No hosted UI. Sign-in and sign-up screens are yours to build and style, which is why this battery ships real ones instead of a redirect.
- Email deliverability is your problem. A reset or magic link that lands in spam is an outage for that person.
- Each OAuth provider is an app you register and keep alive yourself: callback URLs per environment, and a Microsoft client secret that expires.
- Enterprise features other vendors sell as a plan tier (SAML, SCIM, audit log) are plugins or your own code here.
- Upgrades are yours to run. New Better Auth minors sometimes add columns, so regenerating the schema is part of every upgrade.

## Known fixes it ships

- [Account linking and email verification without account takeovers](https://agenticboilerplate.com/cookbook/better-auth/account-linking-and-email-verification): When "Continue with Google" joins an existing password account, when it refuses, and why an unverified email address or a trusted provider list can hand one person's account to another.
- [Better Auth on the edge: why your session check fails in middleware](https://agenticboilerplate.com/cookbook/better-auth/better-auth-on-the-edge): Edge runtimes have no TCP sockets and no Node crypto, so a session lookup that works in a page throws in the proxy. Read the cookie there and verify in the render.
- [CSRF, SameSite and the cookie flags that make a session safe](https://agenticboilerplate.com/cookbook/better-auth/csrf-and-cookie-flags): What each session cookie flag actually defends against, why trustedOrigins is your CSRF check, and the three configuration changes that quietly disable both.
- [Guard Better Auth's endpoints, not just your settings forms](https://agenticboilerplate.com/cookbook/better-auth/guarding-the-auth-api-itself): Every /api/auth endpoint is a public URL. One hook refuses account changes from an impersonation session and asks for a recent sign-in before a password or provider is added.
- [The magic-link token: single use, ten minutes, and the scanner that clicks it first](https://agenticboilerplate.com/cookbook/better-auth/magic-link-tokens-and-scanners): How long the credential lives, why a corporate mail scanner burns it before the human arrives, and why the rate limiter has to be backed by your database rather than by process memory.
- [Moving an existing user table onto Better Auth without logging everyone out](https://agenticboilerplate.com/cookbook/better-auth/migrating-an-existing-user-table): Map your columns to the four required tables, backfill ids and accounts, and let people migrate themselves on next sign-in instead of forcing a password reset.
- [oauth-callback-url-mismatches](https://agenticboilerplate.com/cookbook/better-auth/oauth-callback-url-mismatches): 
- [Password reset tokens that cannot be replayed, guessed or leaked](https://agenticboilerplate.com/cookbook/better-auth/password-reset-tokens): One hour, single use, answered the same way for every address, and kept out of logs, Referer headers and search results. What Better Auth does for you and the four things it cannot.
- [Modelling roles you will not regret when the admin panel grows](https://agenticboilerplate.com/cookbook/better-auth/role-modelling-for-the-admin-panel): A role column, a ranked vocabulary in one file, and permission checks that name the action, not a boolean isAdmin scattered across forty components.
- [Session invalidation, or why everyone got logged out on deploy](https://agenticboilerplate.com/cookbook/better-auth/session-invalidation-and-logged-out-on-deploy): A rotated secret, a changed cookie name or a wiped database invalidates every session at once. Here is what invalidates what, and how to revoke one user on purpose.

## Generate it

[Build a repo with Better Auth](https://agenticboilerplate.com/build?b=better-auth)

---

Agentic Boilerplate: A Next.js repo your agent already knows. Free during launch, then $99 once.

- Site map for agents: https://agenticboilerplate.com/llms.txt
- Public API: https://agenticboilerplate.com/openapi.json
- Contact: agenticstudio@gmail.com
