Back to Skills

better-auth

Provides Better Auth integration patterns for NestJS backend and Next.js frontend with Drizzle ORM and PostgreSQL. Use when setting up Better Auth with NestJS backend, integrating Next.js App Router frontend, configuring Drizzle ORM schema, implementing social login (GitHub, Google), adding plugins (2FA, Organization, SSO, Magic Link, Passkey), implementing email/password authentication with session management, or creating protected routes and middleware.

318stars37forksUpdated 8/5/2026

Security Assessment

Safe(93/100)
Security Score93/100

About better-auth

The better-auth skill provides integration patterns for Better Auth, a type-safe TypeScript authentication framework, across a NestJS backend and a Next.js App Router frontend using Drizzle ORM with PostgreSQL. It solves the problem of standing up production-grade authentication — email/password, social login, and advanced factors — without hand-rolling insecure plumbing, by supplying a structured four-phase setup plus ready-made asset files and reference guides.

The skill walks through database setup (Drizzle config, schema, migrations with a verification checkpoint), backend setup (a Better Auth instance wired into a NestJS module and a catch-all auth controller), frontend setup (auth client, route-protecting middleware, sign-in pages), and advanced features (2FA/TOTP, passkeys, magic links, organizations, and SSO). It ships asset files for NestJS services, controllers, guards, modules, and schema, and for Next.js middleware, session hooks, and pages, alongside reference documents for setup, schema, social providers, MFA, passkeys, plugins, examples, and best practices. The best-practices reference is notably security-conscious: it instructs storing secrets in environment variables and never committing them, generating strong secrets, requiring HTTPS in production, validating OAuth redirect URLs to prevent open redirects, relying on Better Auth's built-in password hashing and CSRF protection, adding rate limiting against brute force, using a scalable session store like Redis, and always implementing email verification.

The target users are full-stack TypeScript developers building NestJS and Next.js applications who need multi-provider authentication, multi-tenant organizations, or passwordless flows. Because it documents standard credential handling through environment variables and official tooling, and actively promotes defensive practices rather than any exfiltration or bypass, it is a safe, guidance-oriented skill.

FAQ

What stack does this skill target?

A NestJS backend and a Next.js App Router frontend, using Better Auth with Drizzle ORM and PostgreSQL. Better Auth is a type-safe TypeScript authentication framework supporting multiple providers, 2FA, SSO, organizations, and passkeys.

What authentication methods can I implement?

Email/password with session management, social login (GitHub, Google, Facebook, Microsoft), MFA/2FA with TOTP, passwordless passkeys, magic links, trusted devices with backup codes, and multi-tenant apps via organizations or SSO.

What are the prerequisites and known limitations?

Better Auth requires Node.js 18+ for Next.js App Router support and TypeScript 5+. Passkeys and OAuth callbacks require HTTPS and compatible browsers, some OAuth providers need specific redirect URL formats, and organization features require additional database tables.

How does it handle secrets and security?

It instructs storing secrets and OAuth credentials in environment variables, never committing them (add .env to .gitignore), generating strong secrets, using HTTPS in production, validating redirect URLs, relying on Better Auth's built-in password hashing and CSRF protection, and adding rate limiting to auth endpoints.

All Files

25 files
assets/env.example1.8 KB
View
assets/nestjs/database.service.ts0.5 KB
View
references/best-practices.md4.4 KB
View
assets/nestjs/auth.controller.ts1.6 KB
View
assets/nextjs/auth-client.ts0.5 KB
View
references/examples.md7.8 KB
View
references/schema.md9.1 KB
View
assets/nestjs/auth.guard.ts1.5 KB
View
assets/nextjs/auth-route.ts0.1 KB
View
assets/nestjs/auth.module.ts0.5 KB
View
assets/nextjs/dashboard-page.tsx2.2 KB
View
references/nestjs-setup.md9.6 KB
View
SKILL.md9.3 KB
View
assets/nestjs/auth.schema.ts2.8 KB
View
assets/nextjs/middleware.ts0.4 KB
View
references/nextjs-setup.md11.9 KB
View
assets/nestjs/auth.service.ts1.5 KB
View
assets/nextjs/sign-in-page.tsx6.3 KB
View
references/passkey.md10.1 KB
View
assets/nestjs/database.module.ts0.2 KB
View
assets/nextjs/use-session.ts0.8 KB
View
references/patterns.md2.8 KB
View
references/mfa-2fa.md7.6 KB
View
references/social-providers.md9.1 KB
View
references/plugins.md9.4 KB
View

Install better-auth

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill