baseURL conflated two jobs: the stable identity of the auth server and, in its object form, a per-request host allowlist whose allowedHosts already duplicated trustedOrigins. Per-request resolution was written three times (HTTP handler, auth.api path, MCP), so a config shape handled in one was silently unhandled in the others. Collapse baseURL to the canonical origin. The hosts a deployment also serves move to trustedOrigins (static array or per-request function). One boundary resolver derives the per-request serving origin (the request host when trusted, else canonical) for every entry point, so cookies and self-referential links follow the host while identity (OAuth/OIDC issuer, JWT iss/aud, social redirect_uri, Passkey rpID) stays canonical. Closes #4151 Closes #8478 Closes #8548 Co-authored-by: RaeesBhatti <10067728+RaeesBhatti@users.noreply.github.com>
Better Auth
Better Auth is a framework-agnostic authentication (and authorization) framework for TypeScript. It provides a comprehensive set of features out of the box and includes a plugin ecosystem that simplifies adding advanced functionalities with minimal code in a short amount of time. Whether you need 2FA, multi-tenant support, or other complex features, it lets you focus on building your actual application instead of reinventing the wheel.
Why Better Auth
Authentication in the TypeScript ecosystem is a half-solved problem. Other open-source libraries often require a lot of additional code for anything beyond basic authentication. Rather than just pushing third-party services as the solution, I believe we can do better as a community—hence, Better Auth.
Contribution
Better Auth is a free and open source project licensed under the MIT License. You are free to do whatever you want with it.
You could help continuing its development by:
Security
If you discover a security vulnerability within Better Auth, please send an e-mail to security@better-auth.com.
All reports will be promptly addressed, and you'll be credited accordingly.
