Skip to content

Options

AuthConfig is created explicitly and passed to both the store and the builder, so they share session, field and account policy. Builder-style methods cover the common options; the rest are public fields.

use alibi::AuthConfig;
fn auth_config(secret: &str) -> AuthConfig {
AuthConfig::new(secret)
.app_name("My application")
.base_url("https://auth.example.com")
.base_path("/api/auth")
.trusted_origin("https://app.example.com")
}

Instance-level middleware and features are registered on AuthBuilder (below).

Field / method Default Purpose Guide
AuthConfig::new(secret) / secret — Signing and encryption secret, at least 32 characters Secrets
managed_secrets(ManagedSecrets) none Versioned encryption keys with rotation Secrets
app_name(…) "Better Auth" Name used in cookie prefixes, TOTP issuers and email text —
base_url(…) http://localhost:3000 Public origin; also sets the Secure cookie flag from the scheme Installation
dynamic_base_url(DynamicBaseUrl) none Per-request base URL from an allow-list of hosts Security
base_path(…) /api/auth Where routes are mounted Installation
trusted_origin(…), trusted_origins(vec) none Origins allowed for CSRF checks, CORS and redirects (glob patterns allowed) Security
trusted_origins_resolver(…) none Async policy adding trusted origins per request Security
disabled_path(…), disabled_paths(vec) none Paths that answer 404 Security
api_error_url(…) none Default OAuth error destination Security
render_error_page true unless NODE_ENV=production Render the built-in GET /error page Security
email_provider none (set via AuthBuilder::email_provider) Default mail transport Email
awaited_notification_errors(…) Propagate Fail or log when awaited delivery fails Email
background_tasks(handler) none Run delivery in the background Email
user_validation none Admit or reject new identities Users and accounts
cookie_prefix(…) none Prefix for every cookie name Cookies
cross_sub_domain_cookies(domain), cross_sub_domain_cookies_from_base_url() off Share cookies across subdomains Cookies
session_cookie_cache(CookieCacheConfig) none Cookie-based session cache Cookies
session_expires_in, session_update_age, session_fresh_age, disable_session_refresh see Session Shortcuts for common session settings Sessions
jwt_expires_in(…) 24 hours Lifetime for core-signed JWT values JWT
advanced(AdvancedConfig), disable_csrf_check, disable_origin_check see Advanced Advanced options Security
Field Default Purpose
expires_in 7 days Session lifetime
update_age Some(1 day) Refresh at most this often (None = every read)
fresh_age Some(1 day) “Recently signed in” window; None/zero disables the check
disable_session_refresh false Never extend on read
defer_session_refresh false Report needsRefresh, refresh via POST /get-session
cookie_name better-auth.session_token Session cookie name
cookie_secure, cookie_http_only, cookie_same_site from base_url, true, Lax Cookie attributes
cookie_cache none CookieCacheConfig { enabled, max_age (300 s), strategy (Compact/Jwt/Jwe), version }
cookie_refresh_cache Disabled Stateless renewal: Disabled, Automatic, UpdateAge(seconds)
stateless false Cookie-only sessions — use session.stateless()
secondary_storage none Secondary storage backend
store_in_database, preserve_in_database false SQL persistence alongside secondary storage
additional_fields none Extra session fields
Field Default Purpose
user.additional_fields none Additional user fields
account.additional_fields none Additional account fields
account.update_account_on_sign_in true Refresh stored provider tokens at each sign-in
account.encrypt_oauth_tokens false Encrypt access/refresh tokens at rest
account.store_account_cookie, account.cookie_max_age false, session cache age Keep account data in a cookie
account.store_state_strategy Automatic OAuth state in Cookie or Database
account.skip_state_cookie_check false Skip state-cookie comparison (insecure)
account.account_linking see Users and accounts enabled, trusted_providers, allow_different_emails, …
verification.secondary_storage, store_in_database none, false Verification storage
verification.store_identifier plain Hash or transform stored identifiers
verification.disable_cleanup false Keep expired rows during lookup
password.require_uppercase, require_lowercase, require_numbers, require_special false Composition rules
Field Default Purpose
ip_address x-forwarded-for, /64 IPv6 grouping IpAddressConfig { headers, trusted_proxies, ipv6_subnet, localhost_fallback, disable_ip_tracking } — Sessions
trust_forwarded_host false Honor x-forwarded-host/-proto when resolving URLs
disable_csrf_check None Explicit CSRF toggle
disable_origin_check false Skip all origin and redirect validation (insecure)
disable_origin_check_paths none Per-path origin opt-out
skip_trailing_slashes false Resolve /path/ to /path
use_secure_cookies from base_url Force the __Secure- prefix and Secure
cross_sub_domain_cookies none Cookie Domain for subdomain sharing
cookies none Per-cookie CookieOverride { name, attributes }
default_cookie_attributes none CookieAttributes for every cookie
cookie_prefix none Name prefix
database.default_find_many_limit 100 Default page size
database.use_number_id false Declares numeric ids (makes invitation email verification default on)
trusted_proxy_headers none Headers trusted for the client IP behind a proxy
Method Purpose Guide
.store(store) / .store_arc(arc) The auth store (required, except with without_database) Databases
.plugin(plugin) Register a plugin Plugins
.endpoint_hook(hook) Logical-call hook Hooks
.rate_limit(RateLimitConfig) Rate-limit policy Rate limiting
.cors(CorsConfig) CORS headers Security
.csrf(CsrfConfig) Toggle request protection Security
.body_limit(BodyLimitConfig) Maximum request body Security
.email_provider(provider) Default mail transport Email
.middleware(mw) Custom Middleware (before/after request) —
.telemetry(TelemetryConfig) Opt-in telemetry Telemetry
AuthBuilder::without_database(config) In-memory store and stateless sessions No database
.build().await Validate, initialize plugins, return BetterAuth —

Plugin options live on each plugin value — see the plugin overview. AuthConfig never needs to know about them.

For exact types and any option not listed here, read the AuthConfig source. Related upstream topic: Options.