All paths are relative to AuthConfig::base_path (/api/auth by default). The table is generated from the instance’s own OpenAPI model with every plugin enabled; a real instance serves only the routes of the plugins you register (list them with auth.registered_routes() or the OpenAPI plugin). Request and response bodies are documented on each feature’s page, and in full — with schemas — by the OpenAPI document.
Conventions: unless noted, endpoints need a session (cookie, bearer token or an API key with enable_session_for_api_keys). State-changing requests carrying cookies need a trusted Origin (Security). Server-only operations — API-key verification, JWT signing, organization addMember, … — are not HTTP routes; see Server-side calls.
The core plugins are installed on every instance. POST /sign-up/email and POST /sign-in/email require EmailPasswordPlugin; /sign-in/social and the OAuth endpoints require registered providers.
Session management
| Method |
Path |
Description |
GET |
/get-session |
Current session and user, or null |
POST |
/get-session |
Same, performing a deferred refresh (needs defer_session_refresh) |
GET |
/list-sessions |
List all active sessions of the user (fresh session required) |
POST |
/revoke-other-sessions |
Revoke all other sessions for the user except the current one |
POST |
/revoke-session |
Revoke a single session |
POST |
/revoke-sessions |
Revoke all sessions for the user |
POST |
/sign-out |
Sign out the current user |
POST |
/update-session |
Update the current session |
Email and password sign-in; the passwordless and federated routes are listed under each plugin
| Method |
Path |
Description |
POST |
/sign-in/email |
Sign in with email and password |
POST |
/sign-in/social |
Sign in with a social provider |
POST |
/sign-up/email |
Sign up a user using email and password |
User management
| Method |
Path |
Description |
POST |
/change-email |
Change the email address (opt in) |
POST |
/delete-user |
Delete the user |
GET |
/delete-user/callback |
Callback to complete user deletion with verification token |
POST |
/update-user |
Update the current user |
Password reset and change
| Method |
Path |
Description |
POST |
/change-password |
Change the password of the user |
POST |
/request-password-reset |
Send a password reset email to the user |
POST |
/reset-password |
Reset the password for a user |
GET |
/reset-password/{token} |
Redirects the user to the callback URL with the token |
POST |
/verify-password |
Verify the current user’s password |
Email verification
| Method |
Path |
Description |
POST |
/send-verification-email |
Send a verification email to the user |
GET |
/verify-email |
Verify the email of the user |
Linked accounts and provider tokens
| Method |
Path |
Description |
GET |
/account-info |
Get the account info provided by the provider |
GET |
/callback/{id} |
OAuth provider callback (code exchange) |
POST |
/callback/{id} |
OAuth provider callback for response_mode=form_post |
POST |
/get-access-token |
Get a valid access token, doing a refresh if needed |
POST |
/link-social |
Link a social account to the user |
GET |
/list-accounts |
List linked accounts |
POST |
/refresh-token |
Refresh the access token using a refresh token |
POST |
/unlink-account |
Unlink an account |
Health and error pages
| Method |
Path |
Description |
GET |
/error |
Error page (or redirect) for OAuth failures |
GET |
/ok |
Check if the API is working |
| Method |
Path |
Description |
POST |
/admin/ban-user |
Ban a user |
POST |
/admin/create-user |
Create a new user |
GET |
/admin/get-user |
Get an existing user |
POST |
/admin/has-permission |
Check if the user has permission |
POST |
/admin/impersonate-user |
Impersonate a user |
POST |
/admin/list-user-sessions |
List user sessions |
GET |
/admin/list-users |
List users |
POST |
/admin/remove-user |
Delete a user and all their sessions and accounts. Cannot be undone. |
POST |
/admin/revoke-user-session |
Revoke a user session |
POST |
/admin/revoke-user-sessions |
Revoke all user sessions |
POST |
/admin/set-role |
Set the role of a user |
POST |
/admin/set-user-password |
Set a user’s password |
POST |
/admin/stop-impersonating |
Stop impersonating and restore the admin session |
POST |
/admin/unban-user |
Unban a user |
POST |
/admin/update-user |
Update a user’s details |
| Method |
Path |
Description |
POST |
/delete-anonymous-user |
Delete an anonymous user |
POST |
/sign-in/anonymous |
Sign in anonymously |
| Method |
Path |
Description |
POST |
/api-key/create |
Create a new API key for a user |
POST |
/api-key/delete |
Delete an existing API key |
GET |
/api-key/get |
Retrieve an existing API key by ID |
GET |
/api-key/list |
List all API keys for the authenticated user or for a specific organization |
POST |
/api-key/update |
Update an existing API key by ID |
| Method |
Path |
Description |
GET |
/device |
Verify user code and get device authorization status |
POST |
/device/approve |
Approve device authorization |
POST |
/device/code |
Request a device and user code |
POST |
/device/deny |
Deny device authorization |
POST |
/device/token |
Exchange device code for access token |
| Method |
Path |
Description |
POST |
/email-otp/change-email |
Verify new email with OTP and change the email if verification is successful |
POST |
/email-otp/check-verification-otp |
Verify an email with an OTP |
POST |
/email-otp/request-email-change |
Request email change with verification OTP sent to the new email |
POST |
/email-otp/request-password-reset |
Request password reset with email and OTP |
POST |
/email-otp/reset-password |
Reset password with email and OTP |
POST |
/email-otp/send-verification-otp |
Send a verification OTP to an email |
POST |
/email-otp/verify-email |
Verify email with OTP |
POST |
/forget-password/email-otp |
Deprecated: Use /email-otp/request-password-reset instead. |
POST |
/sign-in/email-otp |
Sign in with email and OTP |
| Method |
Path |
Description |
GET |
/jwks |
Get the JSON Web Key Set |
GET |
/token |
Get a JWT token |
| Method |
Path |
Description |
GET |
/magic-link/verify |
Verify magic link |
POST |
/sign-in/magic-link |
Sign in with magic link |
| Method |
Path |
Description |
GET |
/multi-session/list-device-sessions |
List the sessions remembered by this browser |
POST |
/multi-session/revoke |
Revoke a device session |
POST |
/multi-session/set-active |
Set the active session |
| Method |
Path |
Description |
GET |
/oauth-popup/start |
Start an OAuth flow inside a popup window |
| Method |
Path |
Description |
GET |
/callback/{provider}/oauth-proxy |
Complete a proxied OAuth sign-in on the originating host |
GET |
/oauth-proxy-callback |
Legacy proxy callback |
| Method |
Path |
Description |
POST |
/one-tap/callback |
Use this endpoint to authenticate with Google One Tap |
| Method |
Path |
Description |
GET |
/one-time-token/generate |
Issue a single-use token for the current session |
POST |
/one-time-token/verify |
Exchange a token for its session |
| Method |
Path |
Description |
POST |
/organization/accept-invitation |
Accept an invitation to an organization |
POST |
/organization/add-team-member |
The newly created member |
POST |
/organization/cancel-invitation |
Cancel a pending invitation |
POST |
/organization/check-slug |
Check whether an organization slug is available |
POST |
/organization/create |
Create an organization |
POST |
/organization/create-role |
Create a dynamic role |
POST |
/organization/create-team |
Create a new team within an organization |
POST |
/organization/delete |
Delete an organization |
POST |
/organization/delete-role |
Delete a dynamic role |
GET |
/organization/get-active-member |
Get the member details of the active organization |
GET |
/organization/get-active-member-role |
The caller’s role in the active organization |
GET |
/organization/get-full-organization |
Get the full organization |
GET |
/organization/get-invitation |
Get an invitation by ID |
GET |
/organization/get-organization |
Get the organization metadata |
GET |
/organization/get-role |
Read a dynamic role |
POST |
/organization/has-permission |
Check if the user has permission |
POST |
/organization/invite-member |
Create an invitation to an organization |
POST |
/organization/leave |
Leave an organization |
GET |
/organization/list |
List all organizations |
GET |
/organization/list-invitations |
List an organization’s invitations |
GET |
/organization/list-members |
List an organization’s members |
GET |
/organization/list-roles |
List an organization’s dynamic roles |
GET |
/organization/list-team-members |
List the members of the given team. |
GET |
/organization/list-teams |
List all teams in an organization |
GET |
/organization/list-user-invitations |
List all invitations a user has received |
GET |
/organization/list-user-teams |
List teams for a user. Without parameters, returns teams for the current user across every organization they belong to. Pass organizationId to scope the result to a specific organization. Pass userId to list teams for another member; this requires member:update permission in the target organization (the explicit organizationId if provided, otherwise the session’s active organization). |
POST |
/organization/reject-invitation |
Reject an invitation to an organization |
POST |
/organization/remove-member |
Remove a member from an organization |
POST |
/organization/remove-team |
Remove a team from an organization |
POST |
/organization/remove-team-member |
Remove a member from a team |
POST |
/organization/set-active |
Set the active organization |
POST |
/organization/set-active-team |
Set the active team for the current active organization |
POST |
/organization/update |
Update an organization |
POST |
/organization/update-member-role |
Update the role of a member in an organization |
POST |
/organization/update-role |
Update a dynamic role |
POST |
/organization/update-team |
Update an existing team in an organization |
| Method |
Path |
Description |
POST |
/passkey/delete-passkey |
Delete a specific passkey |
GET |
/passkey/generate-authenticate-options |
Generate authentication options for a passkey |
GET |
/passkey/generate-register-options |
Generate registration options for a new passkey |
GET |
/passkey/list-user-passkeys |
List all passkeys for the authenticated user |
POST |
/passkey/update-passkey |
Update a specific passkey’s name |
POST |
/passkey/verify-authentication |
Verify authentication of a passkey |
POST |
/passkey/verify-registration |
Verify registration of a new passkey |
| Method |
Path |
Description |
POST |
/phone-number/request-password-reset |
Request OTP for password reset via phone number |
POST |
/phone-number/reset-password |
Reset password using phone number OTP |
POST |
/phone-number/send-otp |
Use this endpoint to send OTP to phone number |
POST |
/phone-number/verify |
Use this endpoint to verify phone number |
POST |
/sign-in/phone-number |
Use this endpoint to sign in with phone number |
| Method |
Path |
Description |
POST |
/siwe/get-nonce |
Alias of /siwe/nonce |
POST |
/siwe/nonce |
Issue a Sign-In with Ethereum nonce |
POST |
/siwe/verify |
Verify a signed SIWE message and sign in |
| Method |
Path |
Description |
POST |
/two-factor/disable |
Use this endpoint to disable two factor authentication. |
POST |
/two-factor/enable |
Enable two factor authentication. Pass method ‘totp’ (default) to set up an authenticator app (returns TOTP URI and backup codes), or ‘otp’ to enable email/SMS-based codes immediately. |
POST |
/two-factor/generate-backup-codes |
Generate new backup codes for two-factor authentication |
POST |
/two-factor/get-totp-uri |
Use this endpoint to get the TOTP URI |
POST |
/two-factor/send-otp |
Send two factor OTP to the user |
POST |
/two-factor/verify-backup-code |
Verify a backup code for two-factor authentication |
POST |
/two-factor/verify-otp |
Verify two factor OTP |
POST |
/two-factor/verify-totp |
Verify two factor TOTP |
| Method |
Path |
Description |
POST |
/is-username-available |
Check whether a username is free |
POST |
/sign-in/username |
Sign in with username |
Bearer, CAPTCHA, Have I Been Pwned, Last login method and Custom session add behavior to existing routes (headers, checks, response shaping) rather than their own paths. OpenAPI serves GET /open-api/generate-schema, the HTML reference (GET /reference by default) and the native GET /__test/openapi.json document. JWT’s key set path is configurable (/jwks by default).
The official client exposes these routes as typed methods; see the Better Auth client documentation.