Plugins
Choose a plugin below for its schema requirements, complete builder example, and endpoints.
| Plugin | Purpose |
|---|---|
| API key | Issue, manage, and verify scoped API credentials. |
| Admin | Administrative user management, bans, impersonation, and role-based permissions. |
| Anonymous | Create a temporary user identity before full account registration. |
| Bearer | Authenticate requests with session tokens in the Authorization header. |
| CAPTCHA | Verify challenges before authentication writes. |
| Custom session | Customize session response data. |
| Device authorization | Authorize a CLI or constrained device through a browser on another device. |
| Email OTP | Authenticate or verify email with a one-time code. |
| Have I Been Pwned | Check password choices against the compromised-password range API. |
| JWT | Issue signed JSON Web Tokens and expose a JWKS key set. |
| Last login method | Remember which authentication method a visitor last used. |
| Magic link | Sign in through a single-use link delivered to an email address. |
| Multi-session | Keep multiple signed-in identities on one browser or device. |
| OAuth popup | Complete popup OAuth sign-in for trusted app origins. |
| OAuth proxy | Proxy OAuth callbacks for environments with a separate production auth origin. |
| One Tap | Verify Google One Tap credentials on the Rust server. |
| One-time token | Exchange an existing session through a short-lived, single-use credential. |
| OpenAPI | Inspect your configured authentication API and generate an API reference. |
| Organization | Organizations, invitations, membership, roles, and optional teams. |
| Passkey | WebAuthn registration and authentication using passkeys. |
| Phone number | Verify phone numbers and authenticate with phone credentials. |
| Sign in with Ethereum | Verify wallet identities using application policies. |
| Two-factor authentication | TOTP, email OTP challenges, and backup codes for a second authentication factor. |
| Username | Username sign-in through the email/password plugin. |
The builder supplies core modules for sessions, accounts, users, and verification. Email/password login stays disabled until configured. Explicit registration replaces the corresponding default; see plugin concepts.
Frontend
Section titled “Frontend”For frontend and client usage, see the official Better Auth guide: Plugins.