Token导航 LogoToken导航TokenDH.com
研究检索敏感数据github未标认证来源可访问许可证需确认审计提醒

better-authBetter Auth 认证

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

682

周安装

29

GitHub Stars

11

下载量

239
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:better-auth(Better Auth 认证)
来源仓库:https://github.com/fusengine/agents
仓库路径:skills/better-auth
安装命令:
npx skills add https://github.com/fusengine/agents --skill better-auth
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/fusengine/agents --skill better-auth

简介

better-auth 用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查,适合梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。

  • 适用于 Better Auth 认证相关的安全检查与漏洞排查,使用时不能把工具输出直接当最终结论。
  • 通过 npx skills add 命令从指定 GitHub 仓库安装,支持主流宿主环境集成。
  • 涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。
  • 适用宿主包括 Codex、Claude、Cursor、Gemini CLI,接入前应确认版本、权限和运行环境要求。

SKILL.md

Better Auth - Complete Authentication

TypeScript-first authentication library with 40+ OAuth providers and 20+ plugins.

Agent Workflow (MANDATORY)

Before ANY implementation, use TeamCreate to spawn 3 agents:

  1. fuse-ai-pilot:explore-codebase - Analyze existing auth setup and patterns
  2. fuse-ai-pilot:research-expert - Verify latest Better Auth docs via Context7/Exa
  3. mcp__context7__query-docs - Check providers/plugins availability

After implementation, run fuse-ai-pilot:sniper for validation.


Overview

When to Use

  • Implementing authentication in TypeScript/JavaScript applications
  • Need OAuth providers (Google, GitHub, Discord, Apple, Microsoft, etc.)
  • Adding 2FA, magic links, passkeys, or phone authentication
  • Enterprise SSO with SAML, SCIM provisioning, or organizations
  • Integrating payments with Stripe or Polar subscriptions
  • Web3 authentication with Sign-In with Ethereum (SIWE)
  • Migrating from Auth.js, Clerk, Auth0, Supabase, or WorkOS

Why Better Auth

FeatureBenefit
Framework agnosticNext.js, SvelteKit, Nuxt, Remix, Astro, Expo, NestJS
Plugin architectureAdd only the features you need (20+ plugins)
Full TypeScriptEnd-to-end type safety, inference included
Self-hostedYour data stays on your infrastructure
Database flexiblePrisma, Drizzle, MongoDB, PostgreSQL, MySQL, SQLite
Enterprise readySSO, SCIM, organizations, audit logs

Coverage

OAuth Providers (40+)

Google, GitHub, Discord, Apple, Microsoft, Slack, Spotify, Twitter/X, Facebook, LinkedIn, GitLab, Bitbucket, Dropbox, Twitch, Reddit, TikTok, and 25+ more documented in providers/.

Plugins (20+)

PluginPurpose
2FATOTP authenticator, backup codes
Magic LinkPasswordless email login
PasskeyWebAuthn biometric authentication
OrganizationMulti-tenant, roles, invitations
SSOEnterprise SAML/OIDC single sign-on
SCIMDirectory sync, user provisioning
StripeSubscription billing integration
API KeyMachine-to-machine authentication
JWT/BearerToken-based API authentication

Database Adapters

Prisma, Drizzle, MongoDB, raw SQL (PostgreSQL, MySQL, SQLite), and community adapters.


SOLID Architecture (Next.js 16)

Components organized in modules/auth/ following separation of concerns:

  • Services: betterAuth configuration and initialization
  • Hooks: createAuthClient for client-side auth state
  • API Route: app/api/auth/[...all]/route.ts handler
  • Proxy: proxy.ts for route protection (replaces middleware)

Reference Guide

NeedReference
Initial setupinstallation.md, server-config.md
Client usageclient.md, session.md
OAuth providersproviders/overview.md, individual provider docs
Add pluginsplugins/overview.md, individual plugin docs
Database setupadapters/prisma.md, adapters/drizzle.md
Enterprise SSOplugins/sso.md, guides/saml-okta.md
Paymentsplugins/stripe.md, plugins/polar.md
Migrationguides/clerk-migration.md, other migration guides
Complete examplesexamples/ for full implementations

Best Practices

  1. Plugins on demand - Only add plugins you actually need
  2. Type-safe client - Use generated types from server config
  3. Session caching - Enable session caching for performance
  4. Rate limiting - Configure rate limits for auth endpoints
  5. Secure cookies - Use secure, httpOnly, sameSite cookies
  6. Database indexes - Add indexes on user lookup fields

Concepts

Core concepts explained in concepts/:

  • Sessions - Token management, refresh, revocation
  • Database - Schema design, migrations, adapters
  • Plugins - Extension system, composition
  • OAuth - Provider configuration, callbacks
  • Security - CSRF, rate limiting, password hashing
  • Cookies - Session storage, cross-domain

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

36.07%
按下载量换算86

Claude

32.49%
按下载量换算78

Cursor

19.71%
按下载量换算47

Gemini CLI

9.57%
按下载量换算23

安全审计

Gen Agent Trust Hub

可疑

Socket

通过

Snyk

可疑

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills