ENGLISH·COURSE API
    Preparing search index...

    Function

    createAuth

    • Builds the Better Auth instance the application runs on.

      Parameters

      Returns Auth<
          {
              secret: string;
              baseURL: string;
              database: (options: BetterAuthOptions) => DBAdapter<BetterAuthOptions>;
              emailAndPassword: {
                  enabled: true;
                  requireEmailVerification: true;
                  minPasswordLength: 8;
                  maxPasswordLength: 128;
                  revokeSessionsOnPasswordReset: true;
                  sendResetPassword: (__namedParameters: {}) => Promise<void>;
                  onPasswordReset: (
                      __namedParameters: {},
                      request: Request | undefined,
                  ) => Promise<void>;
              };
              emailVerification: {
                  sendOnSignUp: true;
                  autoSignInAfterVerification: true;
                  sendVerificationEmail: (__namedParameters: {}) => Promise<void>;
              };
              user: {
                  changeEmail: {
                      enabled: true;
                      sendChangeEmailConfirmation: (__namedParameters: {}) => Promise<void>;
                  };
                  deleteUser: {
                      enabled: true;
                      sendDeleteAccountVerification: (__namedParameters: {}) => Promise<void>;
                  };
              };
              socialProviders: { google: { clientId: string; clientSecret: string } };
              account: {
                  accountLinking: { enabled: true; trustedProviders: "google"[] };
              };
              rateLimit: { enabled: boolean; storage: "database" };
              hooks: {
                  after: Middleware<
                      MiddlewareOptions,
                      (
                          inputContext: MiddlewareInputContext<MiddlewareOptions>,
                      ) => Promise<void>,
                  >;
              };
              plugins: [{}, {}];
          },
      >

      The configured auth instance

      Email and password (verified before first sign-in, 8–128 characters, other sessions revoked on reset), Google with account linking by verified address, account deletion confirmed by an emailed link that only works in the account's own session, Turnstile on the three form endpoints, rate limits stored in the database, and nextCookies last so Server Actions set cookies.

      A password that actually changes notifies the account either way it changed: onPasswordReset covers the emailed reset link, and an after hook covers the Profile form, which Better Auth offers no callback for. A refused attempt notifies nobody — after hooks run for those too, so the outcome is read rather than assumed.

      An email change takes two links, because sendChangeEmailConfirmation is set and the learner's address is verified: an approval goes to the address on file first, and only when it is opened does a verification go to the new one. The address moves when that second link is opened, so neither a hijacked session nor a mistyped address can move an account on its own.