megachangelog
Better Auth logo

Better Auth Changelog

Better Auth — Auth, Developer Tools product updates and releases, tracked on megachangelog.


Improvement1.7.6

v1.7.6

Better Auth v1.7.6 adds support for customizable banned user messages and Vercel BotID captcha provider for authentication. This release fixes critical bugs including React hydration mismatches, password length validation, overlapping auth query requests, model identity issues across multiple adapters, and OAuth social account linking.

authcaptchasecurityadaptersbug-fixes
Improvement1.7.5

v1.7.5 Release

This release adds database schema name support for direct PostgreSQL connections and includes multiple bug fixes across better-auth packages, including improvements to server-side logging, database migrations, index validation, and adapter initialization.

postgresqldatabasebug-fixesadapterslogging
Improvement1.7.4

v1.7.4: OpenTelemetry configuration, Vitest 5 support, and stability fixes

This release adds experimental OpenTelemetry instrumentation controls, Vitest 5 support for testing utilities, and fixes critical bugs including Metro bundling issues, multibyte session storage in Expo, and stale session data problems during concurrent updates.

testingobservabilitysession-managementstabilityexpo
Improvement1.7.3

v1.7.3 - Schema stability and provider improvements

Restored 1.6 account core schema to avoid disruptive backfills for existing users, added Cloudflare as a built-in social provider with PKCE support, enabled schema validation by default with clearer error messaging, and fixed numerous OAuth provider integrations and edge cases across multiple packages.

authoauthprovidersschemasecurity
Fix1.7.2

v1.7.2

Bug fix release addressing user ban expiration handling, client type compatibility, session data validation, database migration issues, and URL validation improvements across multiple packages including core auth, OAuth provider, and database adapters.

authbug-fixesdatabaseoauthsecurity
Fix1.7.1

Bug fixes and dependency updates

Multiple bug fixes across core authentication, SCIM provisioning, SSO integration, CIMD caching, database adapters, and OAuth provider functionality. Bundled dependencies updated to latest compatible releases with no breaking changes to existing projects.

bug-fixesdatabasescimssooauth
Breaking1.7.0

v1.7.0 - Major Breaking Changes & OAuth/MCP Overhaul

Better Auth 1.7 introduces significant breaking changes including account scoping by issuer, restructured MCP as a separate package with OAuth foundation, OAuth provider back-channel logout support, and configuration changes for joins and identity handling. Account-related APIs require schema regeneration and manual migration of existing account identities before deployment.

breakingoauthmcpschemaaccount-identity
Fix1.6.30

Bug fixes and SSO domain verification improvements

Fixed concurrent cold-start requests that could lose authentication context due to async storage race conditions, and improved SSO domain verification to require verified provider domains and prevent unauthorized organization assignment via social sign-in.

authssobug-fixsecuritystorage
Fix1.7.0-rc.6

v1.7.0-rc.6 Release

Bug fix release addressing TypeScript compatibility issues, session handling, OAuth provider token validation, logout flows, and PostgreSQL schema exports across multiple packages in the Better Auth ecosystem.

authoauthtypescriptpostgresqlbugfix
Fix1.6.28

v1.6.28 Bug Fixes

Fixed duplicate session requests during React Suspense retries and restored client plugin declaration compatibility for downstream TypeScript consumers across better-auth, electron, and expo packages.

bug-fixesreacttypescriptsessionplugins
Announcement1.7.0-rc.5

v1.7.0-rc.5 release

Release candidate 5 for v1.7.0 includes breaking OAuth device grant refactoring, new username plugin options, bug fixes across OAuth provider and SCIM, and CLI package alignment improvements.

oauthbreaking-changedevice-grantbug-fixscim
Fix1.6.27

v1.6.27 Bug Fixes Release

This release fixes duplicate session requests during Suspense retries, corrects auth endpoint types in the SCIM package for better-call alignment, and resolves CLI version mismatches with installed packages.

bug-fixessessionsscimclistability
Fix1.7.0-rc.4

v1.7.0-rc.4 release with OAuth fixes and security improvements

This release includes numerous bug fixes across authentication flows including PKCE and Apple OAuth, session handling improvements, email OTP security enhancements, and a breaking change for Better Auth Expo that switches to async secure storage to prevent iOS Keychain crashes. Also introduces a placeholder email utility and fixes performance issues in Next.js integration.

oauthsessionsemail-otpsecuritybug-fixes
Fix1.6.26

v1.6.26 Release

This release includes multiple bug fixes across session management, OTP authentication, JWT handling, OAuth proxy, and database operations, along with performance improvements for Next.js applications and utilities for placeholder email generation.

sessionauthbug-fixesotpjwt
Breaking1.7.0-rc.3

v1.7.0-rc.3

Release candidate with breaking changes to Microsoft account identifiers, addition of RFC 8628 device authorization grant support, RP-initiated logout for OAuth providers, and database indexing improvements. Includes bug fixes for TypeScript composition, JWT session caching deadlocks, and SCIM/SSO enhancements.

breakingoauthdevice-flowscimsso
Fix1.6.25

v1.6.25

This release fixes Apple OAuth PKCE code challenge not being sent during authorization, Google One Tap incorrectly creating users when sign-up was disabled, Solid client missing $fetch and $store exposure, and internal adapter queries being routed to wrong tables when model names were remapped.

oauthbug-fixesauthsolid
Breaking1.7.0-rc.2

v1.7.0-rc.2

Release candidate with major refactoring of account identity scoping by issuer, database joins configuration migration, and SCIM decoupling from organizations. Multiple breaking changes require config updates and database migrations, along with numerous bug fixes and new features.

breakingauthdatabasessoscim
Improvement1.6.24

v1.6.24 Release

This release adds request context support to ID token verification, GDPR compliance options for login tracking, and fixes numerous bugs including session caching, type definitions, database migrations, and security issues across multiple packages.

authsecuritybug-fixesgdprapi
Feature1.7.0-rc.1

v1.7.0-rc.1 Release

This release adds Yandex as a supported OAuth social provider and fixes critical issues with auth migrations, row counting in database adapters, and string default value escaping in Drizzle schema generation.

oauthauthdatabasedrizzlemigration
Announcement1.6.23

v1.6.23 Release

Release includes Yandex OAuth provider support, fixes for row counting in D1 and postgres-js adapters, fixes for organization subscription actions in Stripe integration, and fixes for string default value escaping in Drizzle schema generation.

oauthdrizzlestripebillingbug-fixes
Breaking1.7.0-rc.0

v1.7.0-rc.0

Major breaking changes include refactored MCP package structure, OIDC back-channel logout support for session revocation across relying parties, explicit OAuth resource modeling with stricter scoping, and enhanced two-factor authentication with OTP method selection. Database schema changes require migration via npx auth migrate.

oauthbreakingoidcmcpauthentication
Announcement1.7.0-beta.10

v1.7.0-beta.10 Release

This beta release includes numerous bug fixes across authentication modules, dependency updates for jose, nanostores, and crypto packages, and new features including Drizzle Relations v2 support and refreshTokenReuseInterval options for better token handling in OAuth and MCP providers.

authoauthsecuritybug-fixesbeta

Sign up to see more

23 more changes from Better Auth. Sign up to read the whole changelog.

Sign up free

GitHub or email — no card needed.