Function
The database, the email sender and the secrets
The configured auth instance
Email and password (verified before first sign-in, 8–128 characters,
other sessions revoked on reset), Google with account linking by verified
address, account deletion confirmed by an emailed link that only works in
the account's own session, Turnstile on the three form endpoints, rate limits stored in the
database, and nextCookies last so Server Actions set cookies.
A password that actually changes notifies the account either way it
changed: onPasswordReset covers the emailed reset link, and an after
hook covers the Profile form, which Better Auth offers no callback for. A
refused attempt notifies nobody — after hooks run for those too, so the
outcome is read rather than assumed.
An email change takes two links, because sendChangeEmailConfirmation is
set and the learner's address is verified: an approval goes to the address
on file first, and only when it is opened does a verification go to the new
one. The address moves when that second link is opened, so neither a
hijacked session nor a mistyped address can move an account on its own.
Builds the Better Auth instance the application runs on.