AuthConfig is created explicitly and passed to both the store and the builder, so they share session, field and account policy. Builder-style methods cover the common options; the rest are public fields.
fn auth_config (secret : & str ) -> AuthConfig {
. app_name ( "My application" )
. base_url ( "https://auth.example.com" )
. trusted_origin ( "https://app.example.com" )
Instance-level middleware and features are registered on AuthBuilder (below ).
Field / method
Default
Purpose
Guide
AuthConfig::new(secret) / secret
—
Signing and encryption secret, at least 32 characters
Secrets
managed_secrets(ManagedSecrets)
none
Versioned encryption keys with rotation
Secrets
app_name(…)
"Better Auth"
Name used in cookie prefixes, TOTP issuers and email text
—
base_url(…)
http://localhost:3000
Public origin; also sets the Secure cookie flag from the scheme
Installation
dynamic_base_url(DynamicBaseUrl)
none
Per-request base URL from an allow-list of hosts
Security
base_path(…)
/api/auth
Where routes are mounted
Installation
trusted_origin(…), trusted_origins(vec)
none
Origins allowed for CSRF checks, CORS and redirects (glob patterns allowed)
Security
trusted_origins_resolver(…)
none
Async policy adding trusted origins per request
Security
disabled_path(…), disabled_paths(vec)
none
Paths that answer 404
Security
api_error_url(…)
none
Default OAuth error destination
Security
render_error_page
true unless NODE_ENV=production
Render the built-in GET /error page
Security
email_provider
none (set via AuthBuilder::email_provider)
Default mail transport
Email
awaited_notification_errors(…)
Propagate
Fail or log when awaited delivery fails
Email
background_tasks(handler)
none
Run delivery in the background
Email
user_validation
none
Admit or reject new identities
Users and accounts
cookie_prefix(…)
none
Prefix for every cookie name
Cookies
cross_sub_domain_cookies(domain), cross_sub_domain_cookies_from_base_url()
off
Share cookies across subdomains
Cookies
session_cookie_cache(CookieCacheConfig)
none
Cookie-based session cache
Cookies
session_expires_in, session_update_age, session_fresh_age, disable_session_refresh
see Session
Shortcuts for common session settings
Sessions
jwt_expires_in(…)
24 hours
Lifetime for core-signed JWT values
JWT
advanced(AdvancedConfig), disable_csrf_check, disable_origin_check
see Advanced
Advanced options
Security
Field
Default
Purpose
expires_in
7 days
Session lifetime
update_age
Some(1 day)
Refresh at most this often (None = every read)
fresh_age
Some(1 day)
“Recently signed in” window; None/zero disables the check
disable_session_refresh
false
Never extend on read
defer_session_refresh
false
Report needsRefresh, refresh via POST /get-session
cookie_name
better-auth.session_token
Session cookie name
cookie_secure, cookie_http_only, cookie_same_site
from base_url, true, Lax
Cookie attributes
cookie_cache
none
CookieCacheConfig { enabled, max_age (300 s), strategy (Compact/Jwt/Jwe), version }
cookie_refresh_cache
Disabled
Stateless renewal: Disabled, Automatic, UpdateAge(seconds)
stateless
false
Cookie-only sessions — use session.stateless()
secondary_storage
none
Secondary storage backend
store_in_database, preserve_in_database
false
SQL persistence alongside secondary storage
additional_fields
none
Extra session fields
Field
Default
Purpose
user.additional_fields
none
Additional user fields
account.additional_fields
none
Additional account fields
account.update_account_on_sign_in
true
Refresh stored provider tokens at each sign-in
account.encrypt_oauth_tokens
false
Encrypt access/refresh tokens at rest
account.store_account_cookie, account.cookie_max_age
false, session cache age
Keep account data in a cookie
account.store_state_strategy
Automatic
OAuth state in Cookie or Database
account.skip_state_cookie_check
false
Skip state-cookie comparison (insecure )
account.account_linking
see Users and accounts
enabled, trusted_providers, allow_different_emails, …
verification.secondary_storage, store_in_database
none, false
Verification storage
verification.store_identifier
plain
Hash or transform stored identifiers
verification.disable_cleanup
false
Keep expired rows during lookup
password.require_uppercase, require_lowercase, require_numbers, require_special
false
Composition rules
Field
Default
Purpose
ip_address
x-forwarded-for, /64 IPv6 grouping
IpAddressConfig { headers, trusted_proxies, ipv6_subnet, localhost_fallback, disable_ip_tracking } — Sessions
trust_forwarded_host
false
Honor x-forwarded-host/-proto when resolving URLs
disable_csrf_check
None
Explicit CSRF toggle
disable_origin_check
false
Skip all origin and redirect validation (insecure )
disable_origin_check_paths
none
Per-path origin opt-out
skip_trailing_slashes
false
Resolve /path/ to /path
use_secure_cookies
from base_url
Force the __Secure- prefix and Secure
cross_sub_domain_cookies
none
Cookie Domain for subdomain sharing
cookies
none
Per-cookie CookieOverride { name, attributes }
default_cookie_attributes
none
CookieAttributes for every cookie
cookie_prefix
none
Name prefix
database.default_find_many_limit
100
Default page size
database.use_number_id
false
Declares numeric ids (makes invitation email verification default on)
trusted_proxy_headers
none
Headers trusted for the client IP behind a proxy
Method
Purpose
Guide
.store(store) / .store_arc(arc)
The auth store (required, except with without_database)
Databases
.plugin(plugin)
Register a plugin
Plugins
.endpoint_hook(hook)
Logical-call hook
Hooks
.rate_limit(RateLimitConfig)
Rate-limit policy
Rate limiting
.cors(CorsConfig)
CORS headers
Security
.csrf(CsrfConfig)
Toggle request protection
Security
.body_limit(BodyLimitConfig)
Maximum request body
Security
.email_provider(provider)
Default mail transport
Email
.middleware(mw)
Custom Middleware (before/after request)
—
.telemetry(TelemetryConfig)
Opt-in telemetry
Telemetry
AuthBuilder::without_database(config)
In-memory store and stateless sessions
No database
.build().await
Validate, initialize plugins, return BetterAuth
—
Plugin options live on each plugin value — see the plugin overview . AuthConfig never needs to know about them.
For exact types and any option not listed here, read the AuthConfig source . Related upstream topic: Options .