All skills
onmax avatar

/nuxt-better-auth

@de09c7b official
by Maxonmax/nuxt-skills715 stars
38

Guides authentication in Nuxt apps using @nuxtjs/better-auth. Use when installing or configuring the module, using its client or server APIs, protecting routes, refreshing sessions, or integrating Better Auth plugins.

Use this Skill: https://skilld.dev/gh/onmax/nuxt-skills/nuxt-better-auth

This session only. Nothing lands on disk.

referencesinstallation.md

≈503 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Installation and configuration

Happy path

npx nuxi module add @nuxtjs/better-auth

Required files:

  • server/auth.config.ts
  • app/auth.config.ts or the equivalent file inside your srcDir
  • .env with NUXT_BETTER_AUTH_SECRET

Environment variables

NUXT_BETTER_AUTH_SECRET=replace-with-a-random-32-character-secret

Set the public site URL when the deployment platform cannot detect it:

NUXT_PUBLIC_SITE_URL=https://your-domain.com

BETTER_AUTH_SECRET is still accepted as a fallback. Prefer NUXT_BETTER_AUTH_SECRET.

For non-destructive secret rotation, keep the current and previous secrets in Better Auth's versioned variable:

BETTER_AUTH_SECRETS=2:current-secret-must-be-at-least-32-characters,1:previous-secret-must-be-at-least-32-characters

Minimal module setup

export default defineNuxtConfig({
  modules: ['@nuxtjs/better-auth'],
})

Minimal server config

import { defineServerAuth } from '@nuxtjs/better-auth/config'

export default defineServerAuth({
  emailAndPassword: {
    enabled: true,
  },
})

Minimal client config

import { defineClientAuth } from '@nuxtjs/better-auth/config'

export default defineClientAuth({})

Module-owned values

  • Do not set secret manually in defineServerAuth(). The module injects it.
  • Do not set baseURL manually in full mode. The module resolves it.
  • Use auth.clientOnly = true only when Better Auth runs on an external backend.
  • For database-backed auth with the shortest setup, prefer NuxtHub.

NuxtHub setup

export default defineNuxtConfig({
  modules: ['@nuxthub/core', '@nuxtjs/better-auth'],
  hub: { db: 'sqlite' },
})

See references/database.md for schema setup.

Client-only mode

For external auth backends:

export default defineNuxtConfig({
  modules: ['@nuxtjs/better-auth'],
  auth: {
    clientOnly: true,
  },
})

See references/client-only.md for full setup.

Source: SKILL.md on GitHub

No alerts8d4 checks · Risk SAFE
  • Gen Agent Trust Hub8d

    This skill provides comprehensive documentation and guidance for integrating the @nuxtjs/better-auth module into Nuxt.js applications. It covers installation, client and server-side API usage, database integration with NuxtHub, and route protection strategies. The skill follows security best practices, such as recommending environment variables for secret management and local path validation for redirects. No malicious patterns or security risks were identified.

  • Socket8d

    No alerts

  • Snyk8d

    Risk: LOW · No issues

  • Runlayer7mo

    1/9 files flagged

Signed by skilld at de09c7b. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated last week
  • Nuxt
  • TypeScript
  • better-auth
  • authentication
  • composables
  • route-protection
  • server-auth
  • nuxthub

README badge

README badge for onmax/nuxt-skills/nuxt-better-auth

Nuxt authentication module built on Better Auth, providing useUserSession composable, server route protection, and plugin integration for login/signup flows. Currently alpha status. Targets Nuxt 4+ apps implementing session-based auth with support for Better Auth plugins like passkey and 2FA.

Generated from the current SKILL.md.

Is this production-ready?
No. The module is in alpha (v0.0.2-alpha.19) and APIs may change. Not recommended for production use.
What versions of Nuxt does this support?
Nuxt 4 and later.
Can I use this with an external auth backend?
Yes, via clientOnly mode. This allows you to connect to auth providers outside Nuxt with CORS handling.
Does this support multi-factor authentication and passkeys?
Yes, through Better Auth plugins for 2FA, passkey, and admin functionality.
How do I protect API routes and pages?
Use `requireUserSession()` on the server side for API routes, and `routeRules` or `definePageMeta` with the `auth` property for page protection.

Generated from the current SKILL.md. These answers refresh after source changes.