npm better-auth 1.7.3
v1.7.3

4 hours ago

Upgrading from 1.7.0–1.7.2:

We restored the 1.6 account schema to avoid requiring a disruptive backfill for existing users. We recognize the cost to users who already migrated and are committed to keeping the core schema stable throughout v1.

If you applied the 1.7 issuer schema, follow the upgrade guide for the required cleanup. No backfill is needed.

better-auth

Features

  • Added Cloudflare as a built-in social provider with client-secret and PKCE support. (#9908)
  • Enabled schema validation during initialization by default, including in production, and rejected authentication requests on detected mismatches. (#11178)
  • Added isPasswordCompromised for checking passwords against Have I Been Pwned in custom server-side flows. (#11147)

Bug Fixes

  • Aligned generated OpenAPI required fields with runtime validation. (#11066)
  • Handled malformed custom-scheme callback URLs without excessive processing. (#11060)
  • Improved Auth0 domain normalization to avoid slow trailing-slash processing. (#11188)
  • Prevented generic OAuth discovery failures from taking down the authentication API. (#10978)
  • Tracked email OTP sign-ins in the last login method plugin. (#10963)
  • Fixed callback hooks being skipped after proxied OAuth sign-ins and preserved server state when callback cookies are unavailable. The legacy /oauth-proxy-callback endpoint is deprecated and will be removed in the next minor release. (#10988)
  • Fixed getSession failures when cookie caching is disabled and cached session cookies remain. (#11120)
  • Fixed TOTP re-enrollment replacing an active authenticator and its backup codes. (#11037)
  • Prevented duplicate session requests and hydration mismatches in Nuxt useFetch. (#11084)
  • Improved dynamic organization role permission check performance. (#11069)
  • Added type-safe Nuxt useFetch integration for the Vue client's useSession hook. (#11085)
  • Restored compatibility with 1.6 account schemas by identifying accounts with (providerId, accountId) instead of issuer. (#11153)

For detailed changes, see CHANGELOG

@better-auth/core

Features

  • Added Cloudflare as a built-in social provider with client-secret and PKCE support. (#9908)
  • Added initialization-time schema validation and actionable mismatch guidance for Drizzle and Prisma adapters. (#11179)
  • Enabled schema validation during initialization by default, including in production, and rejected authentication requests on detected mismatches. (#11178)
  • Added custom token endpoint authentication strategies for providers with non-standard request parameters. (#11101)

Bug Fixes

  • Restored optional consumeOne and incrementOne methods for custom database adapters. (#11189)
  • Fixed TikTok sign-in and token refresh with the documented clientKey and clientSecret options. (#11102)
  • Improved request IP validation performance. (#11068)
  • Improved PayPal authorization code and refresh token requests, including PKCE handling. (#11129)
  • Improved Reddit token requests with OAuth-compliant Basic authentication and redirect protection. (#11134)
  • Restored compatibility with 1.6 account schemas by identifying accounts with (providerId, accountId) instead of issuer. (#11153)

For detailed changes, see CHANGELOG

auth

Features

  • Added Cloudflare as a built-in social provider with client-secret and PKCE support. (#9908)
  • Added diagnostics in auth generate for required fields in existing Prisma schemas that Better Auth never writes. (#11179)
  • Added Codex as a supported target for configuring the Better Auth documentation MCP server. (#11100)
  • Added schema diagnostics to auth migrate and auth generate, blocking migrations when required columns that Better Auth never writes need manual repair. (#11178)

Bug Fixes

  • Updated auth info to report installed dependency versions instead of declared specifiers. (#11126)
  • Allowed auth init to complete when generated setup groups have no dependencies. (#11140)
  • Skipped unsupported dependency specifiers during auth upgrade with a clear warning. (#11127)

For detailed changes, see CHANGELOG

@better-auth/drizzle-adapter

Features

  • Added initialization-time schema validation and actionable mismatch guidance for Drizzle and Prisma adapters. (#11179)

For detailed changes, see CHANGELOG

@better-auth/test-utils

Bug Fixes

  • Improved adapter test suite performance by avoiding redundant cleanup queries. (#10762)
  • Updated adapter test suites to remove issuer-specific account requirements. (#11153)

For detailed changes, see CHANGELOG

@better-auth/cimd

Bug Fixes

  • Fixed CIMD client metadata discovery failures with ERR_INVALID_IP_ADDRESS on supported Node.js versions. (#10730)

For detailed changes, see CHANGELOG

@better-auth/expo

Bug Fixes

  • Prevented Expo apps from sending unauthenticated requests during interrupted cookie storage updates. (#11099)

For detailed changes, see CHANGELOG

@better-auth/kysely-adapter

Features

  • Enabled database schema validation by default and rejected authentication requests when the live schema does not match. (#11178)

For detailed changes, see CHANGELOG

@better-auth/oauth-provider

Bug Fixes

  • Allowed native OAuth clients using localhost loopback redirects to use ephemeral callback ports. (#11090)

For detailed changes, see CHANGELOG

@better-auth/prisma-adapter

Features

  • Added initialization-time schema validation and actionable mismatch guidance for Drizzle and Prisma adapters. (#11179)

For detailed changes, see CHANGELOG

@better-auth/sso

Bug Fixes

  • Restored compatibility with 1.6 account schemas by identifying accounts with (providerId, accountId) instead of issuer. (#11153)

For detailed changes, see CHANGELOG

Contributors

Thanks to everyone who contributed to this release:

@BetterAndBetterII, @bytaesu, @erikpr1994, @gustavovalverde, @harshil1712, @onmax, @Salman-Arshad, @starslingdev[bot], @supercell02, @thisismert

Full changelog: v1.7.2...v1.7.3

Don't miss a new better-auth release

NewReleases is sending notifications on new releases.