Skip to content

JWT

JwtPlugin issues signed JSON Web Tokens and exposes a JWKS key set.

Generate the plugin schema and apply it with your application migrations:

Terminal window
better-auth-rs generate --plugins jwt -o src/auth_schema.rs

Use the schema, configuration, and store from installation.

use crate::auth_schema::AppAuthSchema;
use better_auth::plugins::jwt::JwtPlugin;
use better_auth::sqlx::SqlxStore;
use better_auth::{AuthConfig, AuthResult, BetterAuth};
async fn build_auth(
config: AuthConfig,
store: SqlxStore<AppAuthSchema>,
) -> AuthResult<BetterAuth<AppAuthSchema>> {
BetterAuth::<AppAuthSchema>::new(config)
.store(store)
.plugin(JwtPlugin::new())
.build()
.await
}

Authenticated callers request a JWT at /token. Services verify it with the JWKS endpoint and check issuer, audience, and expiry. Configure signing and claims with JwtPluginConfig.

JWTs do not replace database sessions. The cookie-cache guide explains the separate option to sign cached sessions with the local keyring.

See the official JWT guide.