All skills
onmax avatar

/nuxt-better-auth

@de09c7b official
by Maxonmax/nuxt-skills715 stars
38

Guides authentication in Nuxt apps using @nuxtjs/better-auth. Use when installing or configuring the module, using its client or server APIs, protecting routes, refreshing sessions, or integrating Better Auth plugins.

Use this Skill: https://skilld.dev/gh/onmax/nuxt-skills/nuxt-better-auth

This session only. Nothing lands on disk.

referencesserver-auth.md

≈924 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Server-side authentication

Helpers

These helpers are auto-imported inside server/ in full mode:

  • serverAuth(event?)
  • getUserSession(event)
  • getRequestSession(event)
  • setRequestSession(event, session)
  • refreshSessionCookieCache(event)
  • requireUserSession(event, options?)
  • createSession(event, userId)
  • setSessionCookie(event, token)

Which helper to use

Need Helper
Access raw Better Auth APIs serverAuth(event)
Read session if it exists getUserSession(event)
Reuse the same session lookup in one request getRequestSession(event)
Supply a session resolved by trusted server authentication setRequestSession(event, session)
Refresh Better Auth's cached session cookie after server-side updates refreshSessionCookieCache(event)
Enforce auth requireUserSession(event, options?)
Create a session in a custom flow createSession(event, userId)
Attach a session token cookie manually setSessionCookie(event, token)

Common API protection

export default defineEventHandler(async (event) => {
  const { user } = await requireUserSession(event, {
    user: { role: 'admin' },
  })

  return { userId: user.id }
})

requireUserSession(event) throws 401 when unauthenticated and 403 when the user match or custom rule fails.

Supply a verified request session

Use setRequestSession(event, session) when another server authentication layer verifies the request and resolves a complete AppSession for existing session helpers to reuse.

const claims = await verifyBearerToken(event)
const session = await resolveCurrentAppSession(claims)

setRequestSession(event, session)
await requireUserSession(event)

The supplied value applies only to the current request and does not set a session cookie. Authenticate the value and enforce bearer-token audience and scope restrictions before calling the helper.

Refresh cached session data

Use refreshSessionCookieCache(event) after server-side code updates data returned by auth.api.getSession(), getUserSession(event), or getRequestSession(event).

export default defineEventHandler(async (event) => {
  await updateCurrentUserProfile(event)
  await refreshSessionCookieCache(event)

  return { ok: true }
})

The helper refreshes the cached session cookie and the request-scoped getRequestSession(event) memo. It does not update the user or session record; do that first.

Matching rules

  • scalar value: exact match
  • array value: OR match
  • multiple fields: AND match
  • rule: custom callback for logic field matching cannot express
await requireUserSession(event, {
  user: { role: ['admin', 'owner'] },
  rule: ({ user }) => user.verified === true,
})

Custom server auth flow

export default defineEventHandler(async (event) => {
  const userId = await verifyCustomLogin(event)
  const session = await createSession(event, userId)
  await setSessionCookie(event, session.token)

  return { ok: true }
})

setSessionCookie(event, token) sets the Better Auth session token cookie only. It does not recreate every Better Auth sign-in side effect.

Source: SKILL.md on GitHub

No alerts8d4 checks · Risk SAFE
  • Gen Agent Trust Hub8d

    This skill provides comprehensive documentation and guidance for integrating the @nuxtjs/better-auth module into Nuxt.js applications. It covers installation, client and server-side API usage, database integration with NuxtHub, and route protection strategies. The skill follows security best practices, such as recommending environment variables for secret management and local path validation for redirects. No malicious patterns or security risks were identified.

  • Socket8d

    No alerts

  • Snyk8d

    Risk: LOW · No issues

  • Runlayer7mo

    1/9 files flagged

Signed by skilld at de09c7b. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated last week
  • Nuxt
  • TypeScript
  • better-auth
  • authentication
  • composables
  • route-protection
  • server-auth
  • nuxthub

README badge

README badge for onmax/nuxt-skills/nuxt-better-auth

Nuxt authentication module built on Better Auth, providing useUserSession composable, server route protection, and plugin integration for login/signup flows. Currently alpha status. Targets Nuxt 4+ apps implementing session-based auth with support for Better Auth plugins like passkey and 2FA.

Generated from the current SKILL.md.

Is this production-ready?
No. The module is in alpha (v0.0.2-alpha.19) and APIs may change. Not recommended for production use.
What versions of Nuxt does this support?
Nuxt 4 and later.
Can I use this with an external auth backend?
Yes, via clientOnly mode. This allows you to connect to auth providers outside Nuxt with CORS handling.
Does this support multi-factor authentication and passkeys?
Yes, through Better Auth plugins for 2FA, passkey, and admin functionality.
How do I protect API routes and pages?
Use `requireUserSession()` on the server side for API routes, and `routeRules` or `definePageMeta` with the `auth` property for page protection.

Generated from the current SKILL.md. These answers refresh after source changes.