Skip to content

One-time token

OneTimeTokenPlugin exchanges an existing session through a short-lived, single-use credential.

Use the schema, configuration, and store from installation.

use crate::auth_schema::AppAuthSchema;
use better_auth::plugins::one_time_token::OneTimeTokenPlugin;
use better_auth::sqlx::SqlxStore;
use better_auth::{AuthConfig, AuthResult, BetterAuth};
async fn build_auth(
config: AuthConfig,
store: SqlxStore<AppAuthSchema>,
) -> AuthResult<BetterAuth<AppAuthSchema>> {
BetterAuth::<AppAuthSchema>::new(config)
.store(store)
.plugin(OneTimeTokenPlugin::new())
.build()
.await
}

Import OneTimeTokenPlugin from better_auth::plugins::one_time_token. Generate a credential through /one-time-token/generate from an authenticated session, then consume it through /one-time-token/verify.

Configure expiry, generation, and storage using OneTimeTokenConfig. Pass the token over a trusted channel and avoid logging it. Consumption is a credential handoff, not a substitute for application authorization.

See the official One-time token guide.