new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

Better Auth · all subjects

sessions & cookies

16 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

Stateless session management without database

Better Auth can work without any database by using stateless session management. See the Stateless Session Management documentation for details.

Cognito access token refresh with auth.api.getAccessToken

auth.api.getAccessToken refreshes an expired access token automatically when the provider account has a refresh token and a known accessTokenExpiresAt. It returns the valid access token and ID token. If you need the refresh token in the response, use the /refresh-token endpoint instead.

Cognito token storage in database-less setups

In database-less setups with storeAccountCookie enabled, Better Auth stores provider account data including OAuth token material in an encrypted account_data cookie. Token refresh responses set an updated cookie, so server-side callers must forward the returned Set-Cookie header to the browser. Cognito JWTs can be large; Better Auth chunks oversized account cookies, but browsers and proxies can enforce total header limits. Use database-backed account storage for large token payloads or production flows that need durable token storage.

Cognito refresh token behavior

Cognito returns a refresh token after a successful authorization code grant. Later refresh-token grants return new access and ID tokens. Cognito only returns a new refresh token when refresh token rotation is enabled in the app client; otherwise, the original refresh token remains valid and Better Auth keeps using it.

Update middleware after Clerk migration

Replace Clerk middleware with Better Auth middleware using getSessionCookie from 'better-auth/cookies'. The middleware checks for sessionCookie and redirects: authenticated users on /login or /signup go to /dashboard, unauthenticated users trying to access /dashboard go to /login.

Cookie-cache session binding to session_token

The cached session is now tied to the `session_token` cookie.

Refresh-token replay handling with reuse window

The OAuth provider can replay the same refresh response for duplicate refresh requests during `refreshTokenReuseInterval`. Strict refresh-token replay handling remains the default. Set `refreshTokenReuseInterval` only when a client can retry a refresh request with an old token after another local session already rotated it. OAuth Provider keeps strict replay handling at `0`; `mcp()` defaults the interval to 30 seconds for every client.

Sign-out hooks with external session stores

`session.delete` hooks now run on sign-out even with `secondaryStorage` and `preserveSessionInDatabase`.

Session sign-out revokes session tokens

When a session ends, the access tokens tied to it are now revoked. They read as inactive at introspection and userinfo. Before, they lived until they expired. The server also sends a logout message to each app that registered a logout URL. Expect session-bound tokens to stop working at sign-out. On serverless platforms, set `advanced.backgroundTasks.handler` so sending logout messages does not slow down sign-out.

RP-Initiated Logout can require browser confirmation

In 1.6, `/oauth2/end-session` accepted only `GET` requests and rejected requests without an `id_token_hint`. In 1.7, the endpoint also accepts form-encoded `POST` requests. For browser navigation without a valid hint, Better Auth asks the user to confirm before ending the current session. The same browser confirmation is required when the hint refers to a different session than the browser session. API calls receive a protocol error when confirmation is required. The confirmation flow preserves the existing redirect rule: `post_logout_redirect_uri` must exactly match a registered URI. If your browser flow expected a missing or invalid hint to fail immediately, update its flow and tests to handle the confirmation page. Standard clients that send a valid hint do not need changes. Enable `enable_end_session` only for trusted clients, and register every allowed post-logout redirect URI exactly.

OAuth response caching disabled

Token, introspection, userinfo, registration, and device-authorization responses now send `Cache-Control: no-store` so proxies and browsers do not cache them.

Client-side sign out in Better Auth

To sign out a user on the client side, call authClient.signOut(). Example: `const { data, error } = await authClient.signOut();`

Get session on client side with Better Auth

To retrieve the current session on the client side, use the useSession hook from authClient. This returns an object with data (session data), error, refetch, isPending, and isRefetching properties. Example: `const { data, error, refetch, isPending, isRefetching } = authClient.useSession();`

Server-side sign out in Better Auth

To sign out a user on the server side, call auth.api.signOut() with headers from Next.js. Example: `const { success } = await auth.api.signOut({ headers: await headers() });`

Get session on server side with Better Auth

To retrieve the current session on the server side, use auth.api.getSession() with headers from Next.js. Example: `const session = await auth.api.getSession({ headers: await headers() });`

Better Auth supports stateless session management without database

Better Auth supports stateless session management using JWT without requiring a database. This is different from Auth.js which primarily uses database adapters for session storage.

Give your agent this brain