v1.7.0-rc.5 release
Release candidate 5 for v1.7.0 includes breaking OAuth device grant refactoring, new username plugin options, bug fixes across OAuth provider and SCIM, and CLI package alignment improvements.
Better Auth — Auth, Developer Tools product updates and releases, tracked on megachangelog.
Release candidate 5 for v1.7.0 includes breaking OAuth device grant refactoring, new username plugin options, bug fixes across OAuth provider and SCIM, and CLI package alignment improvements.
This release fixes duplicate session requests during Suspense retries, corrects auth endpoint types in the SCIM package for better-call alignment, and resolves CLI version mismatches with installed packages.
This release includes numerous bug fixes across authentication flows including PKCE and Apple OAuth, session handling improvements, email OTP security enhancements, and a breaking change for Better Auth Expo that switches to async secure storage to prevent iOS Keychain crashes. Also introduces a placeholder email utility and fixes performance issues in Next.js integration.
This release includes multiple bug fixes across session management, OTP authentication, JWT handling, OAuth proxy, and database operations, along with performance improvements for Next.js applications and utilities for placeholder email generation.
Release candidate with breaking changes to Microsoft account identifiers, addition of RFC 8628 device authorization grant support, RP-initiated logout for OAuth providers, and database indexing improvements. Includes bug fixes for TypeScript composition, JWT session caching deadlocks, and SCIM/SSO enhancements.
This release fixes Apple OAuth PKCE code challenge not being sent during authorization, Google One Tap incorrectly creating users when sign-up was disabled, Solid client missing $fetch and $store exposure, and internal adapter queries being routed to wrong tables when model names were remapped.
Release candidate with major refactoring of account identity scoping by issuer, database joins configuration migration, and SCIM decoupling from organizations. Multiple breaking changes require config updates and database migrations, along with numerous bug fixes and new features.
This release adds request context support to ID token verification, GDPR compliance options for login tracking, and fixes numerous bugs including session caching, type definitions, database migrations, and security issues across multiple packages.
This release adds Yandex as a supported OAuth social provider and fixes critical issues with auth migrations, row counting in database adapters, and string default value escaping in Drizzle schema generation.
Release includes Yandex OAuth provider support, fixes for row counting in D1 and postgres-js adapters, fixes for organization subscription actions in Stripe integration, and fixes for string default value escaping in Drizzle schema generation.
Major breaking changes include refactored MCP package structure, OIDC back-channel logout support for session revocation across relying parties, explicit OAuth resource modeling with stricter scoping, and enhanced two-factor authentication with OTP method selection. Database schema changes require migration via npx auth migrate.
This beta release includes numerous bug fixes across authentication modules, dependency updates for jose, nanostores, and crypto packages, and new features including Drizzle Relations v2 support and refreshTokenReuseInterval options for better token handling in OAuth and MCP providers.
9 more changes from Better Auth. Sign up to read the whole changelog.
Sign up freeGitHub or email — no card needed.