Skip to content

Plugins

Choose a plugin below for its schema requirements, complete builder example, and endpoints.

Plugin Purpose
API key Issue, manage, and verify scoped API credentials.
Admin Administrative user management, bans, impersonation, and role-based permissions.
Anonymous Create a temporary user identity before full account registration.
Bearer Authenticate requests with session tokens in the Authorization header.
CAPTCHA Verify challenges before authentication writes.
Custom session Customize session response data.
Device authorization Authorize a CLI or constrained device through a browser on another device.
Email OTP Authenticate or verify email with a one-time code.
Have I Been Pwned Check password choices against the compromised-password range API.
JWT Issue signed JSON Web Tokens and expose a JWKS key set.
Last login method Remember which authentication method a visitor last used.
Magic link Sign in through a single-use link delivered to an email address.
Multi-session Keep multiple signed-in identities on one browser or device.
OAuth popup Complete popup OAuth sign-in for trusted app origins.
OAuth proxy Proxy OAuth callbacks for environments with a separate production auth origin.
One Tap Verify Google One Tap credentials on the Rust server.
One-time token Exchange an existing session through a short-lived, single-use credential.
OpenAPI Inspect your configured authentication API and generate an API reference.
Organization Organizations, invitations, membership, roles, and optional teams.
Passkey WebAuthn registration and authentication using passkeys.
Phone number Verify phone numbers and authenticate with phone credentials.
Sign in with Ethereum Verify wallet identities using application policies.
Two-factor authentication TOTP, email OTP challenges, and backup codes for a second authentication factor.
Username Username sign-in through the email/password plugin.

The builder supplies core modules for sessions, accounts, users, and verification. Email/password login stays disabled until configured. Explicit registration replaces the corresponding default; see plugin concepts.

For frontend and client usage, see the official Better Auth guide: Plugins.