Skip to main content

Better Auth plugin support

See which Better Auth plugins work with createBetterConvexAuth and what each one needs.

createBetterConvexAuth installs the Better Auth plugins itself. It does not accept a plugins option. You turn on a supported plugin with its own option. The browser client accepts only the matching client plugins in defineConvexAuthClient. Any other client plugin fails at startup.

Supported plugins

PluginServer optionClient pluginStatusNotes
OrganizationorganizationorganizationClient() from better-auth/client/pluginsSupportedNeeds a local auth component. Teams work with teams: { enabled: true }. Invitation email goes through the email hook.
Two-factortwoFactortwoFactorClient() from better-auth/client/pluginsSupportedNeeds a local auth component. One-time codes go through the email hook.
Email OTPemailOTPemailOTPClient() from better-auth/client/pluginsSupportedRequires the email hook. Adds no tables.
OAuth provideroauth.mcpoauthProviderClient() from @better-auth/oauth-provider/clientSupported for MCPOnly the MCP profile. A local auth component also needs it in the schema plugins. Dynamic client registration, UserInfo, and OpenID Connect discovery are off. See Delegated OAuth and MCP.
JWTNoneNoneBuilt inThe library always installs it. It stores the keys that sign Convex session tokens and OAuth access tokens. You cannot configure it.
Any other plugin, for example admin, API key, passkey, magic link, username, anonymous, OAuth popup, or phone numberRejectedRejectedNot supportedThe factory rejects plugins, and the client rejects unknown plugin IDs.

Email and password sign-in, email verification, and social providers are part of Better Auth itself, not plugins. Configure them with emailAndPassword, emailVerification, and socialProviders. See Social sign-in and Transactional auth email.

Options the library sets for you

Each supported plugin accepts the normal Better Auth options, except the email callbacks. The email hook sends every auth email, so these options fail with AUTH_CONFIG_INVALID:

  • organization.sendInvitationEmail
  • twoFactor.otpOptions.sendOTP
  • emailOTP.sendVerificationOTP

Turn on a plugin

  1. Add the server option to createBetterConvexAuth.
  2. For organization, two-factor, and the OAuth provider, add the plugin to convex/betterAuth/schemaPlugins.ts and regenerate the auth schema. For the OAuth provider, see step 1 of Add MCP to your application.
  3. Add the client plugin to defineConvexAuthClient.

Better Auth plugins shows each step with the organization plugin.

Why other plugins are rejected

Each plugin adds routes, tables, and cookies. The library checks those parts against its session and token rules before it supports a plugin. A plugin that is not in the table has no such check, so the factory rejects it instead of running it without one. To ask for a plugin, open an issue in the repository.