Plugins add sign-in methods, token types, security controls and administration features. Each page below documents the plugin’s schema requirements, a complete builder example, its HTTP endpoints with request and response examples, and every configuration option.
How registration works — and which core plugins are always installed — is covered in Plugin concepts. To write your own, see Writing a plugin.
| Plugin |
Purpose |
Schema |
| Email and password |
Credentials, password reset, custom hashing |
none |
| Username |
Sign in with a username, with validation and normalization policy |
username |
| Anonymous |
Temporary guest identities that upgrade to real accounts |
anonymous |
| Magic link |
Single-use sign-in links by email |
none |
| Email OTP |
One-time codes for sign-in, verification, password reset and email change |
none |
| Phone number |
Phone verification, OTP and password sign-in |
phone-number |
| Passkey |
WebAuthn passkeys (platform and security keys) |
passkey |
| Sign in with Ethereum |
Wallet sign-in (ERC-4361) |
siwe |
| Google One Tap |
Verify Google One Tap credentials |
none |
| Plugin |
Purpose |
Schema |
| Two-factor |
TOTP, OTP and backup codes as a second factor |
two-factor |
| Device authorization |
Sign in a CLI or TV through a browser (RFC 8628) |
device-authorization |
| Plugin |
Purpose |
Schema |
| Bearer |
Authorization: Bearer session tokens |
none |
| JWT |
Signed JWTs and a JWKS endpoint for other services |
jwt |
| One-time token |
Short-lived single-use session handoff |
none |
| Multi-session |
Several signed-in accounts per browser |
none |
| Custom session |
Reshape the /get-session response |
none |
| Last login method |
Remember which method a visitor used last |
last-login-method (optional) |
| Plugin |
Purpose |
Schema |
| API key |
Scoped, rate-limited, expiring credentials for users and organizations |
api-key |
| Plugin |
Purpose |
| CAPTCHA |
Turnstile, reCAPTCHA, hCaptcha, CaptchaFox or Vercel BotID before auth writes |
| Have I Been Pwned |
Reject breached passwords |
| Plugin |
Purpose |
Schema |
| Admin |
User management, roles, bans and impersonation |
admin |
| Organization |
Organizations, members, invitations, roles, teams |
organization (+ organization-teams, organization-dynamic-roles) |
| Plugin |
Purpose |
| OpenAPI |
OpenAPI document and interactive API reference for your instance |
- Paths are relative to
/api/auth (your base_path).
- Schema values are
alibi generate --plugins … names; see Database.
- Examples use
AppAuthSchema and SqlxStore<AppAuthSchema> from the installation guide. SeaORM works identically.
- Config structs can be built with
..Default::default(); plugins that use builder methods list them.
- Numeric options that mirror JavaScript numbers (OTP lengths, lifetimes in seconds) are
f64, so write 300.0, not 300.
For client plugins, see the official Better Auth plugin guides.