6 ms·
Better Auth – Authentication library for TypeScript
- namanyayg 2y ago[flagged]
- akaike 2y agoAuth.js is not made by Vercel. Quote: “ The Auth.js/NextAuth.js project is not provided by, nor otherwise affiliated with Vercel Inc. or its subsidiaries. Any contributions to this project by individuals affiliated with Vercel are made in their personal capacity.”
- BoorishBears 2y agoYou're not wrong but it's a very understandable mistake when the footer has a big old "powered by Vercel" logo and the creator works for them. The logo is probably just supposed to another opportunity for them to grab mind share by hosting the site for free and sticking that there, but it creates a confusing impression.
- BoorishBears 2y agoAuth.js isn't really by Vercel even if they scooped up the creator and stuck one of their "powered by" stickers on it... it does have a fun tie-in with Rauch's cartel though Clerk sponsors it extremely heavily so that when you get fed up with dealing with it, every single page has a CTA funneling you to them. Honestly the whole situation has a terrible terrible smell, but that's post-Rauch JS for you.
- bekacru 2y agoHey, author of Better Auth here. I created Better Auth because I couldn’t find any other auth library that goes beyond simple login with OAuth. Even then, the only properly maintained ones were NextAuth (Auth.js) and Lucia (which is now deprecated). I’m not sure where the idea of "too many auth libraries" is coming from.
- BoorishBears 2y agoThey're probably including libraries tied to hosted offerings, and there are a lot of them (Cognito, Firebase, Auth0, Clerk, FusionAuth, Kinde, Descope, WorkOS, and many many more) Out of curiosity, how is Better Auth funded?
- deleted 2y ago[deleted]
- aosaigh 2y agoAs someone developing with both Nuxt and Next, I find these "full-stack" JavaScript libraries and frameworks really confusing and difficult to grok. I understand the benefit of only having one ecosystem to worry about (JS/TS in Node and browser) but I'm not convinced that having backend and frontend in the same codebase is actually a good idea. It might be due to being a more "old school" full stack developer, but this new wave of of SSR-led full-stack frameworks is tricky.
- mckirk 2y agoI started a side-project in SvelteKit a while ago, and so far I still like it a lot. When I saw what projects using it look like, it somehow just intuitively 'made sense' to me. For me it's also just the right amount of 'magic' so that it's still quite flexible, but takes care of the parts that would be tedious otherwise. (I've never worked with Nuxt or Next though, so I can't directly compare them.)
- oDot 2y agoI am a big fan of Gleam language's Lustre[0], and due to its functional nature, the full stack experience is much better. Instead of becoming this mishmash of backend and frontend, there's a clear delineation between the two. They share common functionality via functions (like model and views), which is much easier to do when they're pure. You basically get the advantages of those magic frameworks without all the magic. [0]: https://blog.nestful.app/p/gleams-lustre-is-frontend-developments https://blog.nestful.app/p/gleams-lustre-is-frontend-develop...
- kgdiem 2y ago
- santa_boy 2y agoThere are so many auth libraries on the roll nowadays. I am using firebase js and it is very simple and straightforward to use. I'm not a security expert, so please advise any pitfalls that the new libraries address which cannot be done with firebase
- theodore_negusu 2y agoWhy do you give them you your data? Why would you pay for that ?
- microflash 2y agoLooks interesting. I like that you can plug your own identity provider quiet easily. One nit: They should really rename their Node integration to Express integration because that’s what it is looking from examples (and that’s what people might commonly look for).
- Recursing 2y agoDoes anyone have experience with https://lucia-auth.com https://lucia-auth.com ? OP says that it's deprecated, but it seems like it just changed from a library to a short guide on how to implement auth yourself. I'm planning to migrate our authentication and session management from auth0 to this to save costs and make things simpler.
- eezing 2y agoThis is actually very nice, thanks for posting. Not sure this will save you time and money, but it is very comprehensive.
- zarazas 2y agoI am currently self hosting former gotrue, now supabase auth and am having a hard time implementing oath and will probably try to switch to better auth. The docs look super comprehensive.
- theodore_negusu 2y agoYeah I really love the doc!
- coolThingsFirst 2y ago[flagged]
- SamAsEnd 2y agoYou should give it 1 minute before you assume it's lacking. It's the real deal.
- coolThingsFirst 2y agobst i can do 40 seconds take it or leave it
- dang 2y ago"Please don't post shallow dismissals, especially of other people's work. A good critical comment teaches us something." https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- Kiro 2y agoHow are people able to just spin up Google login using these libs? When I tried it doing it directly my site had to be reviewed multiple times by some Google rep and I had to change the privacy policy, not have any beta features etc etc. What am I missing? I find it really strange that I must fully launch my product before I can enable the most common login mechanic. It feels like a catch 22.
- deleted 2y ago[deleted]
- dagmawibabi 2y agoIt says it's better auth, but it's actually the best auth library.
- dang 2y agoRecent and related: Show HN: Comprehensive authentication library for TypeScript - https://news.ycombinator.com/item?id=41678652 https://news.ycombinator.com/item?id=41678652 - Sept 2024 (44 comments)
- WorldMaker 2y agoI've been hoping on some library to better simplify passkey auth, especially in "serverless" situations with KV DB like Deno Deploy/Netlify/et al. I'm sick of passwords and passkey should be all I need, but the high level libraries just don't seem to exist in good enough forms yet and everyone keeps instead relying on overkill vendors like Auth0/Okta.