Better Auth plugin support
See which Better Auth plugins work with createBetterConvexAuth and what each one needs.
createBetterConvexAuth installs the Better Auth plugins itself. It does not
accept a plugins option. You turn on a supported plugin with its own option.
The browser client accepts only the matching client plugins in
defineConvexAuthClient. Any other client plugin fails at startup.
Supported plugins
| Plugin | Server option | Client plugin | Status | Notes |
|---|---|---|---|---|
| Organization | organization | organizationClient() from better-auth/client/plugins | Supported | Needs a local auth component. Teams work with teams: { enabled: true }. Invitation email goes through the email hook. |
| Two-factor | twoFactor | twoFactorClient() from better-auth/client/plugins | Supported | Needs a local auth component. One-time codes go through the email hook. |
| Email OTP | emailOTP | emailOTPClient() from better-auth/client/plugins | Supported | Requires the email hook. Adds no tables. |
| OAuth provider | oauth.mcp | oauthProviderClient() from @better-auth/oauth-provider/client | Supported for MCP | Only the MCP profile. A local auth component also needs it in the schema plugins. Dynamic client registration, UserInfo, and OpenID Connect discovery are off. See Delegated OAuth and MCP. |
| JWT | None | None | Built in | The library always installs it. It stores the keys that sign Convex session tokens and OAuth access tokens. You cannot configure it. |
| Any other plugin, for example admin, API key, passkey, magic link, username, anonymous, OAuth popup, or phone number | Rejected | Rejected | Not supported | The factory rejects plugins, and the client rejects unknown plugin IDs. |
Email and password sign-in, email verification, and social providers are part
of Better Auth itself, not plugins. Configure them with emailAndPassword,
emailVerification, and socialProviders. See
Social sign-in and
Transactional auth email.
Options the library sets for you
Each supported plugin accepts the normal Better Auth options, except the email
callbacks. The email hook sends every auth email, so these options fail with
AUTH_CONFIG_INVALID:
organization.sendInvitationEmailtwoFactor.otpOptions.sendOTPemailOTP.sendVerificationOTP
Turn on a plugin
- Add the server option to
createBetterConvexAuth. - For organization, two-factor, and the OAuth provider, add the plugin to
convex/betterAuth/schemaPlugins.tsand regenerate the auth schema. For the OAuth provider, see step 1 of Add MCP to your application. - Add the client plugin to
defineConvexAuthClient.
Better Auth plugins shows each step with the organization plugin.
Why other plugins are rejected
Each plugin adds routes, tables, and cookies. The library checks those parts against its session and token rules before it supports a plugin. A plugin that is not in the table has no such check, so the factory rejects it instead of running it without one. To ask for a plugin, open an issue in the repository.