Rank #3 of 5 in Auth & Identity
Access
Install
npm install better-authShowcase


Try itExperimental
See what an agent can do with Better Auth before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; the live MCP handshake runs real requests from our edge, right now — including, where the server allows it, one real read-only tool call (bring your own key for auth-gated servers); sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).
$mcp-probe → https://mcp.better-auth.com/mcplive — run just now from our edge$ press ▶ run to send one JSON-RPC initialize from our edge
Verified integrations
Connections to other tracked products — hover a chip for the verbatim evidence quote behind it.
By theme — the product's score on each story themeBy theme
Agent auth — stories about agent auth in this arenaAgent authevidence →
Stories about agent auth in this arena
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Deployment control — stories about deployment control in this arenaDeployment controlevidence →
Stories about deployment control in this arena
Enterprise sso — stories about enterprise sso in this arenaEnterprise ssoevidence →
Stories about enterprise sso in this arena
Events webhooks — stories about events webhooks in this arenaEvents webhooksevidence →
Stories about events webhooks in this arena
Framework integration — stories about framework integration in this arenaFramework integrationevidence →
Stories about framework integration in this arena
Mfa passwordless — stories about mfa passwordless in this arenaMfa passwordlessevidence →
Stories about mfa passwordless in this arena
Oauth oidc — stories about oauth oidc in this arenaOauth oidcevidence →
Stories about oauth oidc in this arena
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Orgs multitenant — stories about orgs multitenant in this arenaOrgs multitenantevidence →
Stories about orgs multitenant in this arena
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Rbac permissions — stories about rbac permissions in this arenaRbac permissionsevidence →
Stories about rbac permissions in this arena
Session management — stories about session management in this arenaSession managementevidence →
Stories about session management in this arena
User migration — stories about user migration in this arenaUser migrationevidence →
Stories about user migration in this arena
Story verdicts — every judged story with its evidenceStory verdicts
What’s free: 8 free · 0 paid · 0 enterprise · 27 not stated in evidence
Follow the green: where the map greys out is where Better Auth stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agent auth — stories about agent auth in this arenaAgent auth
Stories about agent auth in this arena
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
✓8/10
unlocks → Webhooks · Machine-readable spec · Versioning policy · API sandbox · Require asynchronous human approval (e.g. CIBA-style confirmation) before an autonomous agent completes a sensitive transaction · Capture tamper-evident audit logs of authentication and admin activity and stream or export them to my SIEM · Subscribe to webhooks or event streams for auth events (sign-ups, sign-ins, user changes) to keep my systems in sync · Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pages
Subscribe to events via webhooks
—–
Build against official SDKs
~6/10
Issue scoped/least-privilege API credentials for an agent
~6/10
Connect an agent via an official MCP server
✓8/10
Download a machine-readable API spec (OpenAPI or equivalent)
—0/10
Rely on versioned APIs with a documented deprecation policy
—0/10
Test against a sandbox environment without touching production data
—0/10
Explore an interactive API reference with runnable examples
—0/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
—–
Operate the product with natural-language commands
~4/10
Plug MCP servers into this product so it can use their tools
n/an/a
Get AI-generated insights and suggestions from my data inside the product
n/an/a
Set up automations that run autonomously in the background
n/an/a
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Deployment control — stories about deployment control in this arenaDeployment control
Stories about deployment control in this arena
Enterprise sso — stories about enterprise sso in this arenaEnterprise sso
Stories about enterprise sso in this arena
Events webhooks — stories about events webhooks in this arenaEvents webhooks
Stories about events webhooks in this arena
Framework integration — stories about framework integration in this arenaFramework integration
Stories about framework integration in this arena
Mfa passwordless — stories about mfa passwordless in this arenaMfa passwordless
Stories about mfa passwordless in this arena
Rely on built-in protection against bots, credential stuffing, and brute-force attacks on the auth flows
~6/10
Require multi-factor authentication with TOTP authenticator apps and backup codes, with step-up enforcement where needed
~7/10
Offer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methods
✓8/10
Oauth oidc — stories about oauth oidc in this arenaOauth oidc
Stories about oauth oidc in this arena
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Orgs multitenant — stories about orgs multitenant in this arenaOrgs multitenant
Stories about orgs multitenant in this arena
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Rbac permissions — stories about rbac permissions in this arenaRbac permissions
Stories about rbac permissions in this arena
Session management — stories about session management in this arenaSession management
Stories about session management in this arena
User migration — stories about user migration in this arenaUser migration
Stories about user migration in this arena
Sorted by importance (agentic first) (high → low) · 56/56 stories · click a row’s chevron for the rationale and evidence
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 8/10 | Tprobed | |
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 8/10 | Tprobed | |
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | none± | untested | none yet | |
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 9/10 | Tprobed | |
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial± | 6/10 | Tprobed | |
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Tprobed | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial± | 5/10 | Tprobed | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 4/10 | Tprobed | |
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | none | 0/10 | ||
Manage session lifecycle — expiry, refresh, and immediate server-side revocation of a compromised session C Sessions | developer | Session management — stories about session management in this arenaSession management | 3 | full | 8/10 | Cclaimed | |
Put a spec-compliant OAuth authorization flow in front of my MCP server so remote agents connect with scoped, verifiable tokens C Mcp | ai-native user | Agent auth — stories about agent auth in this arenaAgent auth | 3 | full | 8/10 | Tprobed | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | fullfree | 8/10 | Xcommunity | |
Implement standard OAuth 2.0 / OIDC flows (authorization code with PKCE, refresh tokens) without hand-rolling protocol details C Flows | developer | Oauth oidc — stories about oauth oidc in this arenaOauth oidc | 3 | full | 7/10 | Cclaimed | |
Require multi-factor authentication with TOTP authenticator apps and backup codes, with step-up enforcement where needed G Mfa | security-engineer | Mfa passwordless — stories about mfa passwordless in this arenaMfa passwordless | 3 | partial | 7/10 | Cclaimed | |
Connect enterprise identity providers over SAML and OIDC (Okta, Entra, Google Workspace) for workforce sign-in G Sso | security-engineer | Enterprise sso — stories about enterprise sso in this arenaEnterprise sso | 3 | full | 6/10 | Cclaimed | |
Define roles and permissions and have them enforced and surfaced in session tokens for authorization checks G Rbac | developer | Rbac permissions — stories about rbac permissions in this arenaRbac permissions | 3 | partial | 6/10 | Cclaimed | |
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | partialfree | 6/10 | Xcommunity | |
Give each agent its own least-privilege machine identity with narrowly scoped permissions and instant revocation, instead of sharing a human's credentials C Machine identity | ai-native user | Agent auth — stories about agent auth in this arenaAgent auth | 3 | partial | 6/10 | Cclaimed | |
Model multi-tenant B2B apps with organizations, memberships, and invitation flows out of the box C Orgs | developer | Orgs multitenant — stories about orgs multitenant in this arenaOrgs multitenant | 3 | partial | 6/10 | Xcommunity | |
Issue machine-to-machine credentials (client-credentials flow) so backend services and agents authenticate without a human in the loop C Machine identity | ai-native user | Agent auth — stories about agent auth in this arenaAgent auth | 3 | partial | 5/10 | Cclaimed | |
Protect routes with first-party framework SDKs and middleware (Next.js and peers) that verify sessions at the edge C Frameworks | developer | Framework integration — stories about framework integration in this arenaFramework integration | 3 | partial | 5/10 | Tprobed | |
Have an agent obtain short-lived, user-consented tokens for third-party APIs (token vault/exchange) so tool calls run under the user's delegated authority C Delegation | ai-native user | Agent auth — stories about agent auth in this arenaAgent auth | 3 | partial | 4/10 | Cclaimed | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | none | untested | none yet | |
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | n/a | untested | none yet | |
Control where the auth system and its user data run — self-managed deployment, private instance, or my own database C Deployment | security-engineer | Deployment control — stories about deployment control in this arenaDeployment control | 2 | fullfree | 9/10 | Xcommunity | |
Authenticate CLIs and headless agents via the OAuth device authorization flow instead of pasting long-lived secrets C Device flow | ai-native user | Agent auth — stories about agent auth in this arenaAgent auth | 2 | full | 8/10 | Cclaimed | |
Offer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methods G Passwordless | developer | Mfa passwordless — stories about mfa passwordless in this arenaMfa passwordless | 2 | full | 8/10 | Xcommunity | |
Offer sign-in with a broad set of social and OAuth identity providers through configuration, not custom code G Flows | developer | Oauth oidc — stories about oauth oidc in this arenaOauth oidc | 2 | fullfree | 8/10 | Xcommunity | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | full | 7/10 | Tprobed | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | fullfree | 7/10 | Xcommunity | |
Turn my own application into an OAuth provider that issues tokens to third-party clients ("Sign in with my app") C Provider | developer | Oauth oidc — stories about oauth oidc in this arenaOauth oidc | 2 | full | 7/10 | Tprobed | |
Bulk-import existing users — including password hashes — and export them again, so I am never locked in C Migration | developer | User migration — stories about user migration in this arenaUser migration | 2 | partialfree | 5/10 | Xcommunity | |
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | partialfree | 5/10 | Xcommunity | |
Give each customer organization its own SSO connection with verified domains and just-in-time provisioning G Orgs | security-engineer | Orgs multitenant — stories about orgs multitenant in this arenaOrgs multitenant | 2 | partial | 5/10 | Cclaimed | |
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | partialfree | 4/10 | Xcommunity | |
Capture tamper-evident audit logs of authentication and admin activity and stream or export them to my SIEM G Audit | security-engineer | Events webhooks — stories about events webhooks in this arenaEvents webhooks | 2 | none | 0/10 | ||
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | none | 0/10 | ||
Require asynchronous human approval (e.g. CIBA-style confirmation) before an autonomous agent completes a sensitive transaction C Delegation | ai-native user | Agent auth — stories about agent auth in this arenaAgent auth | 2 | none | 0/10 | ||
Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pages C Frameworks | developer | Framework integration — stories about framework integration in this arenaFramework integration | 2 | none | 0/10 | ||
Subscribe to webhooks or event streams for auth events (sign-ups, sign-ins, user changes) to keep my systems in sync C Webhooks | developer | Events webhooks — stories about events webhooks in this arenaEvents webhooks | 2 | none | 0/10 | ||
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | n/a | untested | none yet | |
Sync users and groups from customer directories via SCIM so deprovisioning in the IdP revokes app access G Sso | security-engineer | Enterprise sso — stories about enterprise sso in this arenaEnterprise sso | 2 | none | untested | none yet | |
Follow vendor-maintained migration guides or tooling for moving off a competing auth provider without forcing password resets C Migration | founder | User migration — stories about user migration in this arenaUser migration | 1 | partial | 6/10 | Cclaimed | |
Rely on built-in protection against bots, credential stuffing, and brute-force attacks on the auth flows C Hardening | security-engineer | Mfa passwordless — stories about mfa passwordless in this arenaMfa passwordless | 1 | partial | 6/10 | Cclaimed | |
Let users and admins see active sessions and devices and revoke them individually or all at once C Sessions | security-engineer | Session management — stories about session management in this arenaSession management | 1 | partial | 5/10 | Cclaimed | |
Express fine-grained, resource-level authorization (relationship- or policy-based) beyond simple roles C Rbac | security-engineer | Rbac permissions — stories about rbac permissions in this arenaRbac permissions | 1 | partial | 4/10 | Cclaimed | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | n/a | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 34 stories with headroom
What would move Better Auth’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Agenticness — how well agents can access and operate the productDelegate tasks to a built-in AI assistant inside the product
nonemoves Built-in AIimpact 45
The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na".
Automation depth — how much of the product can run unattendedDefine rules that trigger actions automatically on events
nonemoves PA Scoreimpact 30
The evidence pack shows no documentation of an event-hook or rules-trigger system (e.g., 'on sign-up run X', webhooks, or automation rules) — only static configuration options like rate limits and session expiration.
Agenticness — how well agents can access and operate the productSubscribe to events via webhooks
nonemoves agent-readyimpact 30
No evidence of any webhook subscription feature in Better Auth's docs (rate limiting, sessions, MCP, plugins, etc.
Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples
nonemoves API qualityimpact 30
The evidence pack shows only static markdown documentation with code snippets, and a direct probe for an OpenAPI/interactive API reference (Swagger, openapi.json, etc.) found all candidate paths returning 404, indicating no interactive, runnable API reference is exposed.
Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent)
nonemoves API qualityimpact 30
The evidence pack shows an explicit probe for OpenAPI/swagger spec endpoints that all returned 404, and no documentation in the pack references an OpenAPI/machine-readable spec output for Better Auth's API surface.
Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy
nonemoves API qualityimpact 30
Missing: versioning policy documentation, deprecation/changelog process, evidence of API stability guarantees for AI/agent consumers.
Events webhooks — stories about events webhooks in this arenaCapture tamper-evident audit logs of authentication and admin activity and stream or export them to my SIEM
nonemoves PA Scoreimpact 20
The evidence pack shows only a marketing-page activity feed mockup listing generic events (session created, token revoked, 2FA enabled) with no documentation of tamper-evident logging, hashing/integrity guarantees, or any SIEM export/streaming/webhook mechanism for audit or admin activity.
Events webhooks — stories about events webhooks in this arenaSubscribe to webhooks or event streams for auth events (sign-ups, sign-ins, user changes) to keep my systems in sync
nonemoves PA Scoreimpact 20
No evidence pack item documents a webhook system or event-stream API for auth events; the only related item (docs-63) shows a UI activity-feed mockup, not a subscribable webhook/event mechanism for external systems to sync with.
Showing the top 8 of 34 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map5 surfaces · 36 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
docs34 stories
- Have an agent obtain short-lived, user-consented tokens for third-party APIs (token vault/exchange) so tool calls run under the user's delegated authority
- Authenticate CLIs and headless agents via the OAuth device authorization flow instead of pasting long-lived secrets
- Issue machine-to-machine credentials (client-credentials flow) so backend services and agents authenticate without a human in the loop
- Give each agent its own least-privilege machine identity with narrowly scoped permissions and instant revocation, instead of sharing a human's credentials
- Put a spec-compliant OAuth authorization flow in front of my MCP server so remote agents connect with scoped, verifiable tokens
- Point an agent at llms.txt or agent-oriented docs
- Run the product headlessly / in CI for automation
- Connect an agent via an official MCP server
- Use an official CLI
- Drive the product through a documented public API
- Issue scoped/least-privilege API credentials for an agent
- Build against official SDKs
- Operate the product with natural-language commands
- Control where the auth system and its user data run — self-managed deployment, private instance, or my own database
- Connect enterprise identity providers over SAML and OIDC (Okta, Entra, Google Workspace) for workforce sign-in
- Protect routes with first-party framework SDKs and middleware (Next.js and peers) that verify sessions at the edge
- Rely on built-in protection against bots, credential stuffing, and brute-force attacks on the auth flows
- Require multi-factor authentication with TOTP authenticator apps and backup codes, with step-up enforcement where needed
- Implement standard OAuth 2.0 / OIDC flows (authorization code with PKCE, refresh tokens) without hand-rolling protocol details
- Offer sign-in with a broad set of social and OAuth identity providers through configuration, not custom code
- Turn my own application into an OAuth provider that issues tokens to third-party clients ("Sign in with my app")
- Do everything through the API that I can do in the UI
- Export all of my data in open formats and leave
- Self-host the core product
- Give each customer organization its own SSO connection with verified domains and just-in-time provisioning
- Model multi-tenant B2B apps with organizations, memberships, and invitation flows out of the box
- Choose where my data is stored (region/residency)
- Control data retention and deletion
- Express fine-grained, resource-level authorization (relationship- or policy-based) beyond simple roles
- Define roles and permissions and have them enforced and surfaced in session tokens for authorization checks
- Let users and admins see active sessions and devices and revoke them individually or all at once
- Manage session lifecycle — expiry, refresh, and immediate server-side revocation of a compromised session
- Bulk-import existing users — including password hashes — and export them again, so I am never locked in
- Follow vendor-maintained migration guides or tooling for moving off a competing auth provider without forcing password resets
better-auth.com19 stories
- Have an agent obtain short-lived, user-consented tokens for third-party APIs (token vault/exchange) so tool calls run under the user's delegated authority
- Issue machine-to-machine credentials (client-credentials flow) so backend services and agents authenticate without a human in the loop
- Give each agent its own least-privilege machine identity with narrowly scoped permissions and instant revocation, instead of sharing a human's credentials
- Put a spec-compliant OAuth authorization flow in front of my MCP server so remote agents connect with scoped, verifiable tokens
- Run the product headlessly / in CI for automation
- Drive the product through a documented public API
- Issue scoped/least-privilege API credentials for an agent
- Build against official SDKs
- Control where the auth system and its user data run — self-managed deployment, private instance, or my own database
- Protect routes with first-party framework SDKs and middleware (Next.js and peers) that verify sessions at the edge
- Offer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methods
- Offer sign-in with a broad set of social and OAuth identity providers through configuration, not custom code
- Do everything through the API that I can do in the UI
- Read the product's source under an open license
- Self-host the core product
- Give each customer organization its own SSO connection with verified domains and just-in-time provisioning
- Model multi-tenant B2B apps with organizations, memberships, and invitation flows out of the box
- Express fine-grained, resource-level authorization (relationship- or policy-based) beyond simple roles
- Define roles and permissions and have them enforced and surfaced in session tokens for authorization checks
Hacker News12 stories
- Run the product headlessly / in CI for automation
- Build against official SDKs
- Control where the auth system and its user data run — self-managed deployment, private instance, or my own database
- Offer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methods
- Offer sign-in with a broad set of social and OAuth identity providers through configuration, not custom code
- Export all of my data in open formats and leave
- Read the product's source under an open license
- Self-host the core product
- Model multi-tenant B2B apps with organizations, memberships, and invitation flows out of the box
- Choose where my data is stored (region/residency)
- Control data retention and deletion
- Bulk-import existing users — including password hashes — and export them again, so I am never locked in
OpenAPI spec3 stories
Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence
11 of 20 testable claims verified · 1 contradicted → integrity 45/100
25 distinct capability claims found in Better Auth’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.
11
Verified
8
Unverified
1
Contradicted
17
Undersold
Verified (12)
“Supports multiple databases (SQLite, PostgreSQL, MySQL, and more) for storing auth data”
Control where the auth system and its user data run — self-managed deployment, private instance, or my own databasefullproof ↗
“Client SDK method to sign up users with email, password, name, and image”
“Supports multiple social/OAuth login providers including Google, GitHub, Apple, Discord”
Offer sign-in with a broad set of social and OAuth identity providers through configuration, not custom codefullproof ↗
“MCP plugin lets an app act as an OAuth authorization server/protected resource for MCP clients”
Put a spec-compliant OAuth authorization flow in front of my MCP server so remote agents connect with scoped, verifiable tokensfullproof ↗
“Organization plugin manages org members, teams, and access/permissions”
Model multi-tenant B2B apps with organizations, memberships, and invitation flows out of the boxpartialproof ↗
“API Key plugin lets you create and manage API keys to authenticate/authorize API requests”
Issue scoped/least-privilege API credentials for an agentpartialproof ↗
“Hosts a remote MCP server exposing docs search, examples, and setup help to MCP clients like Cursor and Claude Code”
“First-party integration support for Next.js, Nuxt, SvelteKit, Astro, Hono, and 20+ other frameworks”
Protect routes with first-party framework SDKs and middleware (Next.js and peers) that verify sessions at the edgepartialproof ↗
“Server-side auth.api methods let you authenticate users programmatically”
Drive the product through a documented public APIfullproof ↗
“CLI tool can test/exercise the device authorization flow”
“Supports passkeys, magic links, API keys, and JWTs as sign-in/auth methods”
Offer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methodsfullproof ↗
“Auth configuration lives entirely in version-controlled, type-safe code rather than a hosted dashboard”
Control where the auth system and its user data run — self-managed deployment, private instance, or my own databasefullproof ↗
Unverified (10)
“Two-factor authentication with backup codes for account recovery”
Require multi-factor authentication with TOTP authenticator apps and backup codes, with step-up enforcement where neededpartialproof ↗
“JWT plugin exposes endpoints to issue JWTs and a JWKS endpoint for verification”
Implement standard OAuth 2.0 / OIDC flows (authorization code with PKCE, refresh tokens) without hand-rolling protocol detailsfullproof ↗
“Provides a guided migration path from Auth0 covering passwords, social accounts, and 2FA”
Follow vendor-maintained migration guides or tooling for moving off a competing auth provider without forcing password resetspartialproof ↗
“Users can revoke their own sessions to log out of other devices/browsers”
Let users and admins see active sessions and devices and revoke them individually or all at oncepartialproof ↗
“Users can revoke their own sessions to log out of other devices/browsers”
Manage session lifecycle — expiry, refresh, and immediate server-side revocation of a compromised sessionfullproof ↗
“Built-in configurable rate limiter to prevent abuse of auth endpoints”
Rely on built-in protection against bots, credential stuffing, and brute-force attacks on the auth flowspartialproof ↗
“SSO plugin supports OpenID Connect, OAuth2, and SAML 2.0 identity providers”
Connect enterprise identity providers over SAML and OIDC (Okta, Entra, Google Workspace) for workforce sign-infullproof ↗
“Device Authorization plugin implements OAuth 2.0 Device Authorization Grant (RFC 8628) for TVs, CLIs, IoT devices”
Authenticate CLIs and headless agents via the OAuth device authorization flow instead of pasting long-lived secretsfullproof ↗
“Configurable session expiry and rolling update-age for session refresh”
Manage session lifecycle — expiry, refresh, and immediate server-side revocation of a compromised sessionfullproof ↗
“2FA can use TOTP authenticator apps by default or OTP via email/SMS”
Require multi-factor authentication with TOTP authenticator apps and backup codes, with step-up enforcement where neededpartialproof ↗
Contradicted (1)
“Built-in credential auth with sessions, email verification, and password reset included”
Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pagesnoneproof ↗
Undersold (17)
Have an agent obtain short-lived, user-consented tokens for third-party APIs (token vault/exchange) so tool calls run under the user's delegated authoritypartialproof ↗
Issue machine-to-machine credentials (client-credentials flow) so backend services and agents authenticate without a human in the looppartialproof ↗
Give each agent its own least-privilege machine identity with narrowly scoped permissions and instant revocation, instead of sharing a human's credentialspartialproof ↗
Point an agent at llms.txt or agent-oriented docsfullproof ↗
Run the product headlessly / in CI for automationpartialproof ↗
Operate the product with natural-language commandspartialproof ↗
Turn my own application into an OAuth provider that issues tokens to third-party clients ("Sign in with my app")fullproof ↗
Do everything through the API that I can do in the UIfullproof ↗
Export all of my data in open formats and leavepartialproof ↗
Give each customer organization its own SSO connection with verified domains and just-in-time provisioningpartialproof ↗
Choose where my data is stored (region/residency)partialproof ↗
Express fine-grained, resource-level authorization (relationship- or policy-based) beyond simple rolespartialproof ↗
Define roles and permissions and have them enforced and surfaced in session tokens for authorization checkspartialproof ↗
Bulk-import existing users — including password hashes — and export them again, so I am never locked inpartialproof ↗
Claims outside our story set (3)
Real capability claims found in Better Auth’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.
“Built-in email and password authentication support”
source ↗“Supports non-destructive rotation of the auth secret without downtime or DB migration”
source ↗“Admin plugin lets admins create users, manage roles, ban/unban, and impersonate users”
source ↗
Business model
Open-source (MIT) TypeScript authentication framework that runs inside your own app and database — no per-MAU pricing; the company (now part of Vercel) monetizes adjacent infrastructure, not the framework.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Try Experimental
Run it in the microterminal →Recorded agent sessions — and a live MCP handshake where the vendor ships one.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
Agent surface uptime MCP 100% · llms.txt 100% (30d, checked every 6h since Sep 8 '26)
