Skip to content

Plugins

Plugins add sign-in methods, token types, security controls and administration features. Each page below documents the plugin’s schema requirements, a complete builder example, its HTTP endpoints with request and response examples, and every configuration option.

How registration works — and which core plugins are always installed — is covered in Plugin concepts. To write your own, see Writing a plugin.

Plugin Purpose Schema
Email and password Credentials, password reset, custom hashing none
Username Sign in with a username, with validation and normalization policy username
Anonymous Temporary guest identities that upgrade to real accounts anonymous
Magic link Single-use sign-in links by email none
Email OTP One-time codes for sign-in, verification, password reset and email change none
Phone number Phone verification, OTP and password sign-in phone-number
Passkey WebAuthn passkeys (platform and security keys) passkey
Sign in with Ethereum Wallet sign-in (ERC-4361) siwe
Google One Tap Verify Google One Tap credentials none
Plugin Purpose
Social sign-on 36 built-in OAuth/OIDC providers
Generic OAuth Any OIDC or OAuth 2.0 server
OAuth popup Popup-window sign-in for SPAs and embedded apps
OAuth proxy One registered callback for preview and staging hosts
Plugin Purpose Schema
Two-factor TOTP, OTP and backup codes as a second factor two-factor
Device authorization Sign in a CLI or TV through a browser (RFC 8628) device-authorization
Plugin Purpose Schema
Bearer Authorization: Bearer session tokens none
JWT Signed JWTs and a JWKS endpoint for other services jwt
One-time token Short-lived single-use session handoff none
Multi-session Several signed-in accounts per browser none
Custom session Reshape the /get-session response none
Last login method Remember which method a visitor used last last-login-method (optional)
Plugin Purpose Schema
API key Scoped, rate-limited, expiring credentials for users and organizations api-key
Plugin Purpose
CAPTCHA Turnstile, reCAPTCHA, hCaptcha, CaptchaFox or Vercel BotID before auth writes
Have I Been Pwned Reject breached passwords
Plugin Purpose Schema
Admin User management, roles, bans and impersonation admin
Organization Organizations, members, invitations, roles, teams organization (+ organization-teams, organization-dynamic-roles)
Plugin Purpose
OpenAPI OpenAPI document and interactive API reference for your instance
  • Paths are relative to /api/auth (your base_path).
  • Schema values are alibi generate --plugins … names; see Database.
  • Examples use AppAuthSchema and SqlxStore<AppAuthSchema> from the installation guide. SeaORM works identically.
  • Config structs can be built with ..Default::default(); plugins that use builder methods list them.
  • Numeric options that mirror JavaScript numbers (OTP lengths, lifetimes in seconds) are f64, so write 300.0, not 300.

For client plugins, see the official Better Auth plugin guides.