Skip to content

Introduction

Alibi is an authentication framework for Rust backends. It implements the HTTP contract of Better Auth — the same endpoints, payloads, cookies and error codes — on top of your own database, your own models and your own web framework.

You assemble an auth instance from four parts:

Part What it does Where to configure it
AuthConfig Secrets, base URL, trusted origins, session, cookie and account policy Options
A store Reads and writes your user, session, account and verification models SQLx, SeaORM, no database
Plugins Add sign-in methods and features: passwords, OAuth, passkeys, organizations, API keys Plugin catalog
A framework adapter Mounts the auth routes and extracts the current session Axum, Poem, other
use alibi::plugins::{EmailPasswordPlugin, TwoFactorPlugin};
use alibi::{AuthBuilder, AuthResult, AuthSchema, BetterAuth};
async fn build<S: AuthSchema>(builder: AuthBuilder<S>) -> AuthResult<BetterAuth<S>> {
builder
.plugin(EmailPasswordPlugin::new().enable_signup(true))
.plugin(TwoFactorPlugin::new())
.build()
.await
}

Install Alibi 0.1.1 from crates.io. See Installation for the library dependency and matching schema generator.

HTTP request
│
▼
Framework adapter (Axum / Poem / your own) builds an AuthRequest
│
▼
Transport disabled paths → body limit → rate limit → plugin HTTP hooks
│
▼
Routing CORS preflight → custom middleware → route lookup
│
▼
Protection origin and CSRF checks → plugin before_request → endpoint hooks
│
▼
Handler the plugin that owns the route, reading and writing your store
│
▼
Completion plugin after_request → CORS headers → AuthResponse (status, body, every Set-Cookie)

Every route is owned by exactly one plugin. The builder installs the core plugins for sessions, users, accounts, password reset and email verification; everything else you register explicitly. Credential sign-in stays disabled until you add EmailPasswordPlugin.

Area Capabilities
Credentials Email and password, usernames, phone numbers, anonymous users
Passwordless Magic links, email OTP, passkeys, Sign in with Ethereum
Social and federated 36 built-in OAuth providers, generic OAuth/OIDC, Google One Tap, popup flows, OAuth proxy
Second factors TOTP, email OTP and backup codes
Sessions and tokens Cookie caches, secondary storage, stateless sessions, bearer tokens, JWTs, one-time tokens, multiple sessions
Machine access API keys, device authorization
Administration Admin, organizations, teams and roles
Hardening Rate limiting, CSRF and origin checks, CAPTCHA, compromised-password checks

HTTP behavior targets better-auth@1.7.7 and is verified by running the official TypeScript client against both the pinned upstream runtime and this implementation. Rust-specific APIs — schemas, plugin builders, delivery callbacks, framework extractors, server-side dispatch — are native to this crate. See Compatibility for the exact boundary and what is out of scope.

  1. Install the crate, generate a schema and start a server.
  2. Sign up, sign in and read a session.
  3. Understand users and accounts, sessions and cookies.
  4. Add features from the plugin catalog.
  5. Harden the deployment with security and rate limiting.

Alibi serves the same API as the TypeScript server, so the official client works unchanged. See the Better Auth client setup and frontend guides. For browsers on a different origin, read Cross-origin applications.