Introduction
Alibi is an authentication framework for Rust backends. It implements the HTTP contract of Better Auth — the same endpoints, payloads, cookies and error codes — on top of your own database, your own models and your own web framework.
You assemble an auth instance from four parts:
| Part | What it does | Where to configure it |
|---|---|---|
AuthConfig |
Secrets, base URL, trusted origins, session, cookie and account policy | Options |
| A store | Reads and writes your user, session, account and verification models | SQLx, SeaORM, no database |
| Plugins | Add sign-in methods and features: passwords, OAuth, passkeys, organizations, API keys | Plugin catalog |
| A framework adapter | Mounts the auth routes and extracts the current session | Axum, Poem, other |
use alibi::plugins::{EmailPasswordPlugin, TwoFactorPlugin};use alibi::{AuthBuilder, AuthResult, AuthSchema, BetterAuth};
async fn build<S: AuthSchema>(builder: AuthBuilder<S>) -> AuthResult<BetterAuth<S>> { builder .plugin(EmailPasswordPlugin::new().enable_signup(true)) .plugin(TwoFactorPlugin::new()) .build() .await}Install Alibi 0.1.1 from crates.io. See Installation for the library dependency and matching schema generator.
How a request flows
Section titled “How a request flows”HTTP request │ ▼Framework adapter (Axum / Poem / your own) builds an AuthRequest │ ▼Transport disabled paths → body limit → rate limit → plugin HTTP hooks │ ▼Routing CORS preflight → custom middleware → route lookup │ ▼Protection origin and CSRF checks → plugin before_request → endpoint hooks │ ▼Handler the plugin that owns the route, reading and writing your store │ ▼Completion plugin after_request → CORS headers → AuthResponse (status, body, every Set-Cookie)Every route is owned by exactly one plugin. The builder installs the core plugins for sessions, users, accounts, password reset and email verification; everything else you register explicitly. Credential sign-in stays disabled until you add EmailPasswordPlugin.
What is included
Section titled “What is included”| Area | Capabilities |
|---|---|
| Credentials | Email and password, usernames, phone numbers, anonymous users |
| Passwordless | Magic links, email OTP, passkeys, Sign in with Ethereum |
| Social and federated | 36 built-in OAuth providers, generic OAuth/OIDC, Google One Tap, popup flows, OAuth proxy |
| Second factors | TOTP, email OTP and backup codes |
| Sessions and tokens | Cookie caches, secondary storage, stateless sessions, bearer tokens, JWTs, one-time tokens, multiple sessions |
| Machine access | API keys, device authorization |
| Administration | Admin, organizations, teams and roles |
| Hardening | Rate limiting, CSRF and origin checks, CAPTCHA, compromised-password checks |
Compatibility
Section titled “Compatibility”HTTP behavior targets better-auth@1.7.7 and is verified by running the official TypeScript client against both the pinned upstream runtime and this implementation. Rust-specific APIs — schemas, plugin builders, delivery callbacks, framework extractors, server-side dispatch — are native to this crate. See Compatibility for the exact boundary and what is out of scope.
Where to go next
Section titled “Where to go next”- Install the crate, generate a schema and start a server.
- Sign up, sign in and read a session.
- Understand users and accounts, sessions and cookies.
- Add features from the plugin catalog.
- Harden the deployment with security and rate limiting.
Frontend
Section titled “Frontend”Alibi serves the same API as the TypeScript server, so the official client works unchanged. See the Better Auth client setup and frontend guides. For browsers on a different origin, read Cross-origin applications.