Authentication
Choose the Better Convex Nuxt auth API for state, operations, users, routes, and backend policy.
Authentication is optional. When you turn it on, Better Auth stores the session and Better Convex Nuxt signs the Convex client in as the same user.
Choose the API
| Need | API |
|---|---|
| Current auth status and session user | useConvexAuth() |
| Sign in, sign up, sign out, plugins | useConvexAuth().client |
| Application profile data | useConvexQuery(query, args) |
| Signed-in user in a Nitro handler | getConvexUser(event) |
| Require a signed-in user in Nitro | requireConvexUser(event) |
| Signed-in user in a Convex function | auth.getUser(ctx), auth.requireUser(ctx) |
| Auth-state rendering | Vue conditionals |
| Navigation redirect | definePageMeta({ convexAuth: true }) |
| Query auth mode | auth: 'required' | 'optional' | 'none' |
| Access checks on your data | Your Convex functions |
| Additional Better Auth client plugins | defineConvexAuthClient() |
Enable or disable auth
Auth is enabled only by an options object with one exact public origin:
convex: {
auth: {
origin: process.env.SITE_URL ?? 'http://localhost:3000'
}
}Omit auth for a direct Convex-only application:
convex: {
}A no-auth build does not register Better Auth runtime plugins, proxy handlers, route middleware, auth auto-imports, or auth types. auth: false is reserved for a Nuxt configuration layer that must erase an inherited auth object.
Start here
- New setup: Better Auth setup
- Rendering state: Auth state and user
- Email and password: Sign in and sign out
- GitHub and Google: Social sign-in
- Navigation: Route protection
- Access checks: Backend authorization
- Plugins: Better Auth plugin support
- AI agents: Delegated OAuth and MCP