All skills
neondatabase avatar

/neon-auth

@9fd97c5 official

Add authentication to a new app. Use for "add auth", "add login", Neon Auth (Managed Better Auth), identity routing, sign-up, sign-in, password reset, email OTP, magic links, organizations, phone OTP, OAuth, passkeys, MFA, trusted domains, invalid domain, and @neondatabase/auth. No existing identity: default to Managed Better Auth. Keep working Better Auth, Clerk, Supabase Auth, or another IdP. User asked to migrate from Supabase Auth: Managed Better Auth. A required plugin outside Managed support: self-managed Better Auth on a Neon Function or the existing app host. Also use for auth APIs in @neondatabase/neon-js.

Use this Skill: https://skilld.dev/gh/neondatabase/agent-skills/neon-auth

This session only. Nothing lands on disk.

referencesself-managed.md

≈509 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Self-managed Better Auth

Use this page only after SKILL.md routed here: a required feature is outside Managed Auth, and the installed Better Auth version documents that flow. If that check fails, keep the current identity.

Keep existing Better Auth

If the app already runs Better Auth, keep that server, its clients, users, and sessions. It works with Lakebase Postgres, Functions, Object Storage, and the AI Gateway. Do not migrate it to Managed Auth unless the user asks.

New self-managed server

Host it on the existing app (Vercel route handlers, or similar) when that host already serves /api/auth. Use a Neon Function when the auth server should sit next to Postgres, or when the Function itself must be an OAuth authorization server (MCP). Function hosting follows the neon-functions skill (region, claim, neon.ts, neon deploy --env <file>).

Keep Lakebase Postgres as the auth database. Use better-auth and better-auth/client. Fetch upstream docs for the installed version:

Do not pass plugins into @neondatabase/auth. Replacing only the client package while Managed Auth is still the backend does not add plugins.

MCP OAuth (Cursor, Claude, and similar clients self-authorizing) is neon-functions references/mcp.md. That can sit beside existing Clerk or Managed login. Do not migrate the whole app's identity unless that was the request.

Function JWT verification, CORS, and direct browser calls: neon-functions and https://neon.com/docs/compute/functions/authentication.md.

There is no documented universal import from Managed neon_auth into a self-managed Better Auth schema. Inventory users, credentials, sessions, memberships, and application foreign keys before changing existing state. Agree a cutover plan with the owner. Do not promise drop-in session continuity.

Source: SKILL.md on GitHub

No alerts14d3 checks · Risk SAFE
  • Gen Agent Trust Hub14d

    The skill provides comprehensive instructions for implementing authentication using Neon Auth (Managed Better Auth). It follows security best practices, including secret management and origin validation, and relies on official vendor packages and documentation.

  • Socket14d

    No alerts

  • Snyk14d

    Risk: LOW · No issues

Signed by skilld at 9fd97c5. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last week.

Activeupdated 2 weeks ago
Other metadata
metadata
{
  "parent": "neon",
  "source": "https://github.com/neondatabase/agent-skills/tree/main/skills/neon-auth"
}

README badge

README badge for neondatabase/agent-skills/neon-auth