All skills
onmax avatar

/nuxt-better-auth

@de09c7b official
by Maxonmax/nuxt-skills715 stars
38

Guides authentication in Nuxt apps using @nuxtjs/better-auth. Use when installing or configuring the module, using its client or server APIs, protecting routes, refreshing sessions, or integrating Better Auth plugins.

Use this Skill: https://skilld.dev/gh/onmax/nuxt-skills/nuxt-better-auth

This session only. Nothing lands on disk.

referencesroute-protection.md

≈593 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Route protection

Layers

  1. routeRules or nitro.routeRules for broad app sections
  2. definePageMeta({ auth }) for page-level overrides
  3. requireUserSession(event) for server-side enforcement

Use route rules and page meta for navigation UX. Use requireUserSession(event) for protected API routes and mutations.

Common route rules

export default defineNuxtConfig({
  routeRules: {
    '/app/**': { auth: { only: 'user', redirectTo: '/login' } },
    '/login': { auth: { only: 'guest', redirectTo: '/app' } },
    '/admin/**': { auth: { only: 'user', user: { role: 'admin' } } },
  },
})

The same auth keys work under nitro.routeRules. If both routeRules and nitro.routeRules are set, the module reads nitro.routeRules.

Matching

  • 'user': authenticated users only
  • 'guest': unauthenticated users only
  • { user: { ... } }: user must match fields
  • arrays inside a field mean OR matching
  • multiple fields mean AND matching
  • false: disable auth for that route/page

The string forms remain available as shorthand. auth: 'user' redirects to the configured login fallback, and auth: 'guest' redirects to the configured guest fallback.

Redirects

export default defineNuxtConfig({
  auth: {
    redirects: {
      login: '/login',
      guest: '/',
      authenticated: '/app',
      logout: '/goodbye',
    },
    preserveRedirect: true,
    redirectQueryKey: 'redirect',
  },
})
  • Per-route redirectTo takes precedence over auth.redirects.login and auth.redirects.guest.
  • A validated local redirect query takes precedence over auth.redirects.authenticated after sign-in or sign-up.
  • auth.redirects.logout applies after sign-out unless the caller supplies onSuccess.

Broad rules and internals

Broad rules such as '/**': { auth: 'user' } intentionally skip framework and module internals that must stay reachable:

  • /_nuxt/**
  • /_ipx/**
  • /__nuxt_devtools__/**
  • /__better-auth-devtools
  • /api/auth/**
  • /api/_better-auth/**
  • /api/_nuxt_icon/**

The same broad rules still apply to app-owned pages and app-owned /api/** handlers.

Page meta

<script setup lang="ts">
definePageMeta({
  auth: {
    only: 'user',
    redirectTo: '/login',
    user: { role: ['admin', 'owner'] },
  },
})
</script>

Page meta overrides global route rules for that page.

Source: SKILL.md on GitHub

No alerts8d4 checks · Risk SAFE
  • Gen Agent Trust Hub8d

    This skill provides comprehensive documentation and guidance for integrating the @nuxtjs/better-auth module into Nuxt.js applications. It covers installation, client and server-side API usage, database integration with NuxtHub, and route protection strategies. The skill follows security best practices, such as recommending environment variables for secret management and local path validation for redirects. No malicious patterns or security risks were identified.

  • Socket8d

    No alerts

  • Snyk8d

    Risk: LOW · No issues

  • Runlayer7mo

    1/9 files flagged

Signed by skilld at de09c7b. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated last week
  • Nuxt
  • TypeScript
  • better-auth
  • authentication
  • composables
  • route-protection
  • server-auth
  • nuxthub

README badge

README badge for onmax/nuxt-skills/nuxt-better-auth

Nuxt authentication module built on Better Auth, providing useUserSession composable, server route protection, and plugin integration for login/signup flows. Currently alpha status. Targets Nuxt 4+ apps implementing session-based auth with support for Better Auth plugins like passkey and 2FA.

Generated from the current SKILL.md.

Is this production-ready?
No. The module is in alpha (v0.0.2-alpha.19) and APIs may change. Not recommended for production use.
What versions of Nuxt does this support?
Nuxt 4 and later.
Can I use this with an external auth backend?
Yes, via clientOnly mode. This allows you to connect to auth providers outside Nuxt with CORS handling.
Does this support multi-factor authentication and passkeys?
Yes, through Better Auth plugins for 2FA, passkey, and admin functionality.
How do I protect API routes and pages?
Use `requireUserSession()` on the server side for API routes, and `routeRules` or `definePageMeta` with the `auth` property for page protection.

Generated from the current SKILL.md. These answers refresh after source changes.