megachangelog
Better Auth logo

Better Auth Changelog

Better Auth — Auth, Developer Tools product updates and releases, tracked on megachangelog.


Fix1.7.2

v1.7.2

Bug fix release addressing user ban expiration handling, client type compatibility, session data validation, database migration issues, and URL validation improvements across multiple packages including core auth, OAuth provider, and database adapters.

authbug-fixesdatabaseoauthsecurity
Fix1.7.1

Bug fixes and dependency updates

Multiple bug fixes across core authentication, SCIM provisioning, SSO integration, CIMD caching, database adapters, and OAuth provider functionality. Bundled dependencies updated to latest compatible releases with no breaking changes to existing projects.

bug-fixesdatabasescimssooauth
Breaking1.7.0

v1.7.0 - Major Breaking Changes & OAuth/MCP Overhaul

Better Auth 1.7 introduces significant breaking changes including account scoping by issuer, restructured MCP as a separate package with OAuth foundation, OAuth provider back-channel logout support, and configuration changes for joins and identity handling. Account-related APIs require schema regeneration and manual migration of existing account identities before deployment.

breakingoauthmcpschemaaccount-identity
Fix1.6.30

Bug fixes and SSO domain verification improvements

Fixed concurrent cold-start requests that could lose authentication context due to async storage race conditions, and improved SSO domain verification to require verified provider domains and prevent unauthorized organization assignment via social sign-in.

authssobug-fixsecuritystorage
Fix1.7.0-rc.6

v1.7.0-rc.6 Release

Bug fix release addressing TypeScript compatibility issues, session handling, OAuth provider token validation, logout flows, and PostgreSQL schema exports across multiple packages in the Better Auth ecosystem.

authoauthtypescriptpostgresqlbugfix
Fix1.6.28

v1.6.28 Bug Fixes

Fixed duplicate session requests during React Suspense retries and restored client plugin declaration compatibility for downstream TypeScript consumers across better-auth, electron, and expo packages.

bug-fixesreacttypescriptsessionplugins
Announcement1.7.0-rc.5

v1.7.0-rc.5 release

Release candidate 5 for v1.7.0 includes breaking OAuth device grant refactoring, new username plugin options, bug fixes across OAuth provider and SCIM, and CLI package alignment improvements.

oauthbreaking-changedevice-grantbug-fixscim
Fix1.6.27

v1.6.27 Bug Fixes Release

This release fixes duplicate session requests during Suspense retries, corrects auth endpoint types in the SCIM package for better-call alignment, and resolves CLI version mismatches with installed packages.

bug-fixessessionsscimclistability
Fix1.7.0-rc.4

v1.7.0-rc.4 release with OAuth fixes and security improvements

This release includes numerous bug fixes across authentication flows including PKCE and Apple OAuth, session handling improvements, email OTP security enhancements, and a breaking change for Better Auth Expo that switches to async secure storage to prevent iOS Keychain crashes. Also introduces a placeholder email utility and fixes performance issues in Next.js integration.

oauthsessionsemail-otpsecuritybug-fixes
Fix1.6.26

v1.6.26 Release

This release includes multiple bug fixes across session management, OTP authentication, JWT handling, OAuth proxy, and database operations, along with performance improvements for Next.js applications and utilities for placeholder email generation.

sessionauthbug-fixesotpjwt
Breaking1.7.0-rc.3

v1.7.0-rc.3

Release candidate with breaking changes to Microsoft account identifiers, addition of RFC 8628 device authorization grant support, RP-initiated logout for OAuth providers, and database indexing improvements. Includes bug fixes for TypeScript composition, JWT session caching deadlocks, and SCIM/SSO enhancements.

breakingoauthdevice-flowscimsso
Fix1.6.25

v1.6.25

This release fixes Apple OAuth PKCE code challenge not being sent during authorization, Google One Tap incorrectly creating users when sign-up was disabled, Solid client missing $fetch and $store exposure, and internal adapter queries being routed to wrong tables when model names were remapped.

oauthbug-fixesauthsolid
Breaking1.7.0-rc.2

v1.7.0-rc.2

Release candidate with major refactoring of account identity scoping by issuer, database joins configuration migration, and SCIM decoupling from organizations. Multiple breaking changes require config updates and database migrations, along with numerous bug fixes and new features.

breakingauthdatabasessoscim
Improvement1.6.24

v1.6.24 Release

This release adds request context support to ID token verification, GDPR compliance options for login tracking, and fixes numerous bugs including session caching, type definitions, database migrations, and security issues across multiple packages.

authsecuritybug-fixesgdprapi
Feature1.7.0-rc.1

v1.7.0-rc.1 Release

This release adds Yandex as a supported OAuth social provider and fixes critical issues with auth migrations, row counting in database adapters, and string default value escaping in Drizzle schema generation.

oauthauthdatabasedrizzlemigration
Announcement1.6.23

v1.6.23 Release

Release includes Yandex OAuth provider support, fixes for row counting in D1 and postgres-js adapters, fixes for organization subscription actions in Stripe integration, and fixes for string default value escaping in Drizzle schema generation.

oauthdrizzlestripebillingbug-fixes
Breaking1.7.0-rc.0

v1.7.0-rc.0

Major breaking changes include refactored MCP package structure, OIDC back-channel logout support for session revocation across relying parties, explicit OAuth resource modeling with stricter scoping, and enhanced two-factor authentication with OTP method selection. Database schema changes require migration via npx auth migrate.

oauthbreakingoidcmcpauthentication
Announcement1.7.0-beta.10

v1.7.0-beta.10 Release

This beta release includes numerous bug fixes across authentication modules, dependency updates for jose, nanostores, and crypto packages, and new features including Drizzle Relations v2 support and refreshTokenReuseInterval options for better token handling in OAuth and MCP providers.

authoauthsecuritybug-fixesbeta

Sign up to see more

16 more changes from Better Auth. Sign up to read the whole changelog.

Sign up free

GitHub or email — no card needed.