Gustavo Valverde 74cdffddde refactor(oauth-provider)!: replace client type with application_type
Client registration carried two overlapping profile fields. `type`
(web/native/user-agent-based) was a better-auth invention with no RFC 7591
standing, validated only for self-consistency against the auth method;
`application_type` is the OIDC Registration field, and the one MCP clients
are told to send.

Registration accepted both without cross-checking, so a client could declare
`type: "web"` alongside `application_type: "native"` and be stored claiming
two profiles. Collapsing to `application_type` removes the ambiguity and
gives the field a real column rather than the untyped metadata bag.

`user-agent-based` has no successor: a browser app registers with
`token_endpoint_auth_method: "none"`, which already marks it public. PKCE
enforcement reads `application_type` for the native case that `type` used to
cover, so a native client stays public whatever auth method it registered
with.
2026-07-28 19:36:09 -04:00

Better Auth

Better Auth is a framework-agnostic authentication (and authorization) framework for TypeScript. It provides a comprehensive set of features out of the box and includes a plugin ecosystem that simplifies adding advanced functionalities with minimal code in a short amount of time. Whether you need 2FA, multi-tenant support, or other complex features, it lets you focus on building your actual application instead of reinventing the wheel.

Why Better Auth

Authentication in the TypeScript ecosystem is a half-solved problem. Other open-source libraries often require a lot of additional code for anything beyond basic authentication. Rather than just pushing third-party services as the solution, I believe we can do better as a community—hence, Better Auth.

Contribution

Better Auth is a free and open source project licensed under the MIT License. You are free to do whatever you want with it.

You could help continuing its development by:

Security

If you discover a security vulnerability within Better Auth, please send an e-mail to security@better-auth.com.

All reports will be promptly addressed, and you'll be credited accordingly.

S
Description
No description provided
Readme
252 MiB
Latest
2026-04-16 05:05:30 -05:00
Languages
TypeScript 99.4%
CSS 0.3%
MDX 0.2%