better-auth skills
COMMUNITYLABSCO SUMMARY
create-auth-skill is the entry point: it scaffolds a new integration, detecting the framework, wiring a database adapter, adding OAuth providers and route handlers, and building the auth UI pages. better-auth-best-practices is the ongoing-configuration companion — server and client setup, database adapters, sessions, plugins, environment variables — for a project that already has Better Auth installed.
The other three each go deep on one feature: email-and-password-best-practices (verification, reset flows, password policy, hashing), organization-best-practices (multi-tenant orgs, members, invitations, roles, teams, RBAC), and two-factor-authentication-best-practices (TOTP, email/SMS OTP, backup codes, trusted devices). Each is scoped narrowly enough that an agent only loads the one feature it's actually touching, not the whole surface of the library.
READ THE FULL ANALYSIS
We have no README for this repository. Our capture has no repo_meta row for better-auth/skills, so this summary comes only from the five skills' own names and descriptions — nothing here confirms who maintains the set, how it's versioned, or how it's meant to be installed.
One of the five needs more than a local file. Four skills are labeled plain local_tool; create-auth-skill, the one most people would reach for first, is labeled account_key — some credential or account is expected before it can do its job, per our own classification. Without a README we can't say which.
Checked 19 September 2026 against better-auth/skills's own skill names and descriptions; no README was available to us.
ALSO IN THIS PACKAGE
auth-skills
Create and update auth layer for JavaScript/TypeScript projects
WHAT'S INSIDE
5 showing · 5 totalbetter-auth-best-practices
The settings that make Better Auth behave in a real project — which database it talks to, where a signed-in session is kept, which version of the documentation matches the installed library — and the traps that quietly break sign-in.
create-auth-skill
Adds login to an app that has none: it works out which framework and database the project already uses, asks what kind of sign-in you want, and writes the whole thing in for you.
email-and-password-best-practices
The email half of a password login: the confirm-your-address message and the reset link, set up so a link expires, works only once, and cannot be used to find out who has an account.
organization-best-practices
Turns a product where people sign in one by one into one where they belong to a company — members, invitations, teams and who is allowed to do what — using Better Auth's organization plugin.
two-factor-authentication-best-practices
Adds the second step at sign-in: a code from an authenticator app, or one sent by email or text message, plus the spare codes that get someone back in when the phone is lost.
HOW TO GET IT
npx skills add better-auth/skillsnpx skills add better-auth/skills --skill <name> --full-depthPick the skill name from the Skills tab — each entry there installs independently.
/plugin marketplace add better-auth/skills/plugin install auth-skills@better-auth-agent-skillsTyped inside the agent's own prompt, not in a terminal. The marketplace is called better-auth-agent-skills, which is the part after the @.