Layers main's #9607 clarification onto next's #9057 OTP-enablement rewrite. The "Sign In with 2FA" section now states that 2FA sign-in enforcement applies to the credential endpoints (/sign-in/email, /sign-in/username, /sign-in/phone-number) and that passwordless flows are not gated by default, with guidance to add custom hook handling to require it. The passwordless callout and the allowPasswordless option note that the flag does not change which sign-in methods are challenged. main's edit to the removed skipVerificationOnEnable bullet is dropped, since next deleted that option. (cherry picked from commit 6156cef51329e1c38544aa06eb5072d8a06ece7a)
Better Auth
Better Auth is a framework-agnostic authentication (and authorization) framework for TypeScript. It provides a comprehensive set of features out of the box and includes a plugin ecosystem that simplifies adding advanced functionalities with minimal code in a short amount of time. Whether you need 2FA, multi-tenant support, or other complex features, it lets you focus on building your actual application instead of reinventing the wheel.
Why Better Auth
Authentication in the TypeScript ecosystem is a half-solved problem. Other open-source libraries often require a lot of additional code for anything beyond basic authentication. Rather than just pushing third-party services as the solution, I believe we can do better as a community—hence, Better Auth.
Contribution
Better Auth is a free and open source project licensed under the MIT License. You are free to do whatever you want with it.
You could help continuing its development by:
Security
If you discover a security vulnerability within Better Auth, please send an e-mail to security@better-auth.com.
All reports will be promptly addressed, and you'll be credited accordingly.
