Commit Graph
788 Commits
Author SHA1 Message Date
Bereket Engida a8686cf552 chore: release v1.5.0-beta.14 2026-02-16 13:40:28 -08:00
Joél SolanoandGitHub cf8322707c feat: auth cli (#7964) 2026-02-15 07:44:50 +00:00
Alex YangandGitHub d5955d6ab2 chore: bump version (#7882) 2026-02-12 13:27:12 +00:00
Alex YangandGitHub c5803173fe test: use vitest best practice (#7888) 2026-02-10 06:32:03 +00:00
Alex Yang 4163102121 chore: release v1.5.0-beta.13 2026-02-07 09:36:29 -08:00
Alex Yang dd6dc4601f chore: release v1.5.0-beta.12 2026-02-06 17:25:17 -08:00
Alex YangandGitHub 3b2b9834c5 fix(cli): add .env.local to dotenv (#7831) 2026-02-07 00:14:55 +00:00
SaviruGitHubAlex YangPaola Estefanía de CamposTim Kellerclaude[bot] <41898282+claude[bot]@users.noreply.github.com>Alex YangTaesucopilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
5c6ccfa688 docs: update to React Router v7 and improve docs (#7457)
Co-authored-by: Alex Yang <himself65@outlook.com>
Co-authored-by: Paola Estefanía de Campos <84341268+Paola3stefania@users.noreply.github.com>
Co-authored-by: Tim Keller <36288711+tjkeller-xyz@users.noreply.github.com>
Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com>
Co-authored-by: Alex Yang <himself65@users.noreply.github.com>
Co-authored-by: Taesu <166604494+bytaesu@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
2026-02-05 18:46:34 +00:00
Dylan VanmaliandGitHub ed68d3d3c9 feat: awaitable social provider config (#4829) 2026-02-04 21:56:28 +00:00
TaesuandGitHub e439dfe33b chore(cli): move better-sqlite3 to devDeps (#7771) 2026-02-03 08:30:41 +00:00
Alex Yang 00c95728f1 Revert "feat: make name field optional (#7617)"
This reverts commit e0df7c9e38.
2026-02-02 10:52:19 -08:00
Alex Yang f82960b984 chore: release v1.5.0-beta.11 2026-01-30 16:44:59 -08:00
TaesuandGitHub e0df7c9e38 feat: make name field optional (#7617) 2026-01-29 23:42:52 +00:00
Alex Yang 9780a773fe chore: release v1.5.0-beta.10 2026-01-27 17:57:35 -08:00
Alex YangandGitHub 1251787f72 feat: remove deprecated API (#7623) 2026-01-28 01:49:50 +00:00
jyc.devandGitHub b7d50de695 fix: check jsconfig.json in getPathAliases (#7650) 2026-01-28 00:56:38 +00:00
Alex YangandGitHub c1f046f588 chore: bump version (#7646) 2026-01-27 23:12:31 +00:00
Alex YangandGitHub b0a6fb89c4 chore: bump version (#7626) 2026-01-27 21:05:02 +00:00
Alex YangandGitHub 6b03411662 chore: enable sourcemap for packages (#7622) 2026-01-26 22:37:58 +00:00
Paola Estefanía de CamposandGitHub b3cce69ad1 fix(cli): update MCP URL from Chonkie to Inkeep (#7585) 2026-01-26 17:18:38 +00:00
Paola Estefanía de CamposandGitHub 041dc17b2a fix(mcp): remove local mpc (#7574) 2026-01-23 18:04:12 +00:00
TaesuandGitHub 3057e8dff6 chore: remove unused CHANGELOG.md files (#7559) 2026-01-22 22:41:54 +00:00
Bereket EngidaandGitHub 8318640286 fix(cli): use inkeep remote mcp url (#7543) 2026-01-22 19:11:46 +00:00
Alex Yang 6295dfcd34 chore: release v1.5.0-beta.9 2026-01-20 19:38:14 -08:00
Alex YangandGitHub 80a1c7daca chore: bump deps (#7508) 2026-01-20 23:55:35 +00:00
Alex YangandGitHub f53eb498d9 chore: bump deps (#7475) 2026-01-19 23:56:56 +00:00
Alex YangandGitHub 1668a33372 fix: /minimal includes unexpected deps (#7467) 2026-01-19 20:32:29 +00:00
c200e8292b chore: fix opencode tag and MCP command structure (#7451)
Co-authored-by: Bereket Engida <Bekacru@gmail.com>
2026-01-17 20:15:00 -08:00
Alex Yang 9806a932c2 chore: release v1.5.0-beta.8 2026-01-16 20:27:30 -08:00
Alex Yang c7e826e20f chore: release v1.5.0-beta.7 2026-01-14 14:25:47 -08:00
Alex YangandGitHub 531b9d56a5 chore: add lint rule useConst (#7369) 2026-01-14 14:18:18 -08:00
Alex YangandGitHub 983c8d20d1 chore: fix lint warnings (#7336) 2026-01-13 11:54:10 -08:00
Paola Estefanía de CamposandGitHub 25dfcff66c feat(mcp): add setup_auth tool (#7307) 2026-01-13 11:05:39 -08:00
Alex Yang 74357c5392 chore: release v1.5.0-beta.6 2026-01-12 15:21:20 -08:00
Alex Yang 244e4142f7 chore: release v1.5.0-beta.5 2026-01-12 12:11:24 -08:00
Alex YangandGitHub 7ab73b1c08 refactor(core): split utils into small files (#7288) 2026-01-12 10:57:51 -08:00
Alex Yang 23ac747b72 chore: release v1.5.0-beta.4 2026-01-12 02:47:34 -08:00
Wonsuk ChoiandGitHub b35a860af8 chore: add --coverage.provider=istanbul to coverage script (#7262) 2026-01-11 10:55:54 -08:00
Alex Yang ec50ee27b4 chore: release v1.5.0-beta.3 2026-01-10 02:10:36 -08:00
TaesuandGitHub a84918e98e chore(cli): bump drizzle-orm (#7172) 2026-01-08 12:10:23 +09:00
Alex YangandGitHub a17468438d docs: build regression after format (#7110) 2026-01-04 01:28:36 +08:00
Alex YangandGitHub 8b01d6abac chore: format markdown (#7103) 2026-01-03 16:55:39 +08:00
4588fb4d84 chore(cli): export schema generators via /api subpath (#7082)
Co-authored-by: Alex Yang <himself65@outlook.com>
2026-01-02 15:43:28 +08:00
Alex Yang 59fac14aed chore: release v1.5.0-beta.2 2025-12-31 21:06:57 +08:00
Alex YangandGitHub 58b5d51ee1 docs: fix mcp config name (#7067) 2025-12-31 00:59:03 +08:00
Alex YangandGitHub ebb889ff84 chore: move @better-auth/utils to catalog (#6981) 2025-12-24 21:38:06 +08:00
Alex Yang 41cb291b8c chore: release v1.5.0-beta.1 2025-12-23 23:56:13 +08:00
Alex YangandGitHub 5471295282 fix(cli): cmd info --json unexpected exit with 1 (#6949) 2025-12-23 18:39:55 +08:00
Bereket Engida 9d784407ca chore: release v1.4.8-beta.7 2025-12-22 11:40:01 -08:00
Dylan VanmaliandGitHub 686fba4e11 feat(oauth-provider): an oauth 2.1 compliant plugin (#4163)
An upgrade to oidc-provider plugin that makes it oauth2.1 compliant and has a configuration that is secure by default.

Plans for the deprecation of oidc-provider plugin due to many inherent flaws in its design. Internally, plugin functions now share logic, providing for better future extensibility if new code_grants need to be written or user/client jwt or opaque tokens need to be written. Furthermore, as an oAuth 2.1 provider, it provides logic valid for an MCP server. When using the scope "openid" (optional, enabled by default), the server acts like an OpenId server able to issue id tokens and provides a /userinfo endpoint.

Features

OAuth 2.1 by default
Properly supports authorization_code, refresh_token, and client_credentials grants
PKCE by default (removes plain completely)
Public and confidential client registration
JWT plugin is required by default, but can be disabled using disableJWTPlugin flag
Access tokens can now be received in JWT verifiable format using the resource parameter (ie JWT aud field)
Id tokens are still verifiable by JWKS when using JWT Plugin, or clientSecret if disabled. Fixes issue to prevent public clients when disableJWTPlugin: true from obtaining id tokens directly even when they shouldn't be allowed an id token and should use /userinfo instead.
Protects /userinfo with scope check
Separates Refresh Token and Access token on database schema to allow multiple access tokens per refresh and multiple refresh tokens per login session.
oauthAccessToken strictly deals with opaque tokens
Opaque tokens are given only when resource parameter (aka audience) is not provided
Option to Encode and Decode refresh tokens
allowDynamicClientRegistration with allowUnauthenticatedClientRegistration flags
Separation of default expiration times
Proper creation of public and confidential clients
Prevents misconfiguration between .well-known/openid-configuration endpoint and plugin settings
scopeExpirations to assign scopes specific expiration
Custom claims through separated functions: customAccessTokenClaims, customIdTokenClaims, and customUserInfoClaims
Organizational support through activeOrganizationalId on a session such as through the organizational plugin. Attaches to oAuthClient via reference_id.
Rp-initiated logout
Account Selection via prompt=select_account.
Account Creation via prompt=create.
Prompt combinations prompt=select_account+consent and prompt=login+consent

Docs available at https://www.better-auth.com/docs/plugins/oauth-provider (pr: https://github.com/better-auth/better-auth/blob/main/docs/content/docs/plugins/oauth-provider.mdx)
2025-12-22 11:16:42 -08:00