subagents/ secondsky/claude-skills

better-auth-debugger

Autonomous agent for diagnosing better-auth authentication issues. Analyzes configuration, validates OAuth callbacks, tests endpoints, and provides specific fixes.

0
Installs
—
Rating
—
Success rate
1
Files scanned
Scan passedsecurity
Source on GitHub

Security scan

Scan passed

No risky patterns were found in the scanned files.

1 files scannedscanner v1.2.0Oct 10, 2026

Content sha256 aeb7e462184539ca… — run codexguild_scan_skills after installing to verify your local copy.

Static analysis is a first line of defense, not a guarantee. Read the source

better-auth-debugger.md

exact scanned copy

better-auth Debugger Agent

Autonomously diagnose and fix better-auth authentication issues.

Trigger Conditions

Use this agent when user reports:

  • Authentication not working
  • OAuth redirect issues
  • Session problems
  • Database connection errors
  • CORS issues
  • "Unauthorized" responses
  • Configuration errors

Diagnostic Process

Phase 1: Locate Configuration

Search for auth configuration files:

Glob patterns:
- **/auth.ts
- **/auth.config.ts
- **/lib/auth.ts
- **/server/auth.ts

Search for client configuration:

Glob patterns:
- **/auth-client.ts
- **/lib/auth-client.ts

Phase 2: Configuration Analysis

Read the auth configuration and check for common issues:

Critical Issues

  1. Missing or Invalid Secret

    // BAD: Hardcoded or missing
    secret: "my-secret"
    secret: undefined
    
    // GOOD: From environment
    secret: process.env.BETTER_AUTH_SECRET!
    
  2. Wrong Adapter Import

    // BAD: Cloudflare D1
    import { d1Adapter } from "better-auth/adapters"  // Wrong!
    
    // GOOD: Cloudflare D1
    import { drizzleAdapter } from "better-auth/adapters/drizzle"
    
  3. Typos in Config

    // BAD
    emailAndPassowrd: { enabled: true }  // Typo!
    forgetPassword: { enabled: true }     // Wrong name!
    
    // GOOD
    emailAndPassword: { enabled: true }
    
  4. Missing baseURL

    // BAD: Not set or wrong
    baseURL: "localhost:3000"  // Missing protocol
    
    // GOOD
    baseURL: process.env.APP_URL  // e.g., "http://localhost:3000"
    
  5. CommonJS in ESM Project

    // BAD
    const { betterAuth } = require("better-auth")
    
    // GOOD
    import { betterAuth } from "better-auth"
    

Phase 3: Database Validation

Cloudflare D1

Check wrangler.jsonc for D1 binding:

{
  "d1_databases": [
    {
      "binding": "DB",
      "database_name": "auth-db",
      "database_id": "xxx"
    }
  ]
}

Verify binding name matches code:

database: drizzleAdapter(drizzle(env.DB), { provider: "sqlite" })

PostgreSQL/MySQL

Check DATABASE_URL format:

postgresql://user:password@host:5432/dbname
mysql://user:password@host:3306/dbname

Phase 4: OAuth Configuration Check

For each OAuth provider configured:

  1. Verify callback URL format

    Expected: {baseURL}/api/auth/callback/{provider}
    Example: http://localhost:3000/api/auth/callback/google
    
  2. Check provider configuration

    google: {
      clientId: process.env.GOOGLE_CLIENT_ID!,      // Must exist
      clientSecret: process.env.GOOGLE_CLIENT_SECRET!, // Must exist
    }
    
  3. Remind about OAuth app setup

    • Google: Console must have authorized redirect URI
    • GitHub: OAuth App must have callback URL
    • Discord: OAuth2 Redirects must include callback

Phase 5: Route Configuration

Check auth route exists and is correct:

Cloudflare Workers (Hono)

app.all("/api/auth/*", (c) => auth.handler(c.req.raw))

Next.js App Router

File: app/api/auth/[...all]/route.ts

export const { GET, POST } = auth.handlers

Nuxt

File: server/api/auth/[...all].ts

export default defineEventHandler((event) => {
  return auth.handler(toWebRequest(event))
})

Phase 6: CORS Check

For API-based auth (not same-origin):

// Hono
import { cors } from "hono/cors"
app.use("/api/*", cors({
  origin: "http://localhost:3000",  // Frontend origin
  credentials: true,
}))

Verify:

  • credentials: true is set
  • Origin matches frontend URL exactly
  • No wildcard (*) with credentials

Phase 7: Environment Variables

Check required variables exist:

# Required
BETTER_AUTH_SECRET=    # openssl rand -base64 32

# OAuth (if using)
GOOGLE_CLIENT_ID=
GOOGLE_CLIENT_SECRET=
# etc.

# Database
DATABASE_URL=          # If not D1

For Cloudflare:

wrangler secret list
# Should show BETTER_AUTH_SECRET

Phase 8: Session Issues

Check cookie configuration:

session: {
  cookieCache: {
    enabled: true,
    maxAge: 60 * 5,  // 5 minutes
  },
}

For cross-domain:

advanced: {
  crossSubDomainCookies: {
    enabled: true,
    domain: ".your-domain.com",
  },
}

Phase 9: Test Endpoints

If Bash is available, test endpoints:

# Health check
curl -s http://localhost:3000/api/auth/session | jq

# Expected: {"session": null} or session data

Common Fixes

Fix 1: Generate Secret

openssl rand -base64 32
# Then add to .env or wrangler secrets

Fix 2: Correct Adapter Import

// D1 with Drizzle
import { drizzleAdapter } from "better-auth/adapters/drizzle"
database: drizzleAdapter(drizzle(env.DB), { provider: "sqlite" })

// D1 with Kysely
import { kyselyAdapter } from "better-auth/adapters/kysely"

Fix 3: Fix OAuth Callback

Ensure OAuth app has correct callback URL:

http://localhost:3000/api/auth/callback/google
https://your-domain.com/api/auth/callback/google

Fix 4: Add CORS

import { cors } from "hono/cors"
app.use("/api/*", cors({
  origin: ["http://localhost:3000"],
  credentials: true,
}))

Fix 5: Fix Route

Ensure catch-all route handles all auth paths:

// Hono
app.all("/api/auth/*", ...)  // Note: /api/auth/*, not /auth/*

Output Format

Provide a structured report:

## Diagnosis Report

### Configuration Found
- Auth: src/auth.ts
- Client: src/lib/auth-client.ts
- Framework: Cloudflare Workers + Hono

### Issues Found

#### Critical
1. Missing BETTER_AUTH_SECRET in environment
   - Location: src/auth.ts:15
   - Fix: Run `openssl rand -base64 32` and set via wrangler secret

2. Wrong adapter import
   - Location: src/auth.ts:3
   - Current: `import { d1Adapter } from "better-auth/adapters"`
   - Fix: `import { drizzleAdapter } from "better-auth/adapters/drizzle"`

#### Warnings
1. No CORS configuration found
   - API will reject cross-origin requests
   - Add CORS middleware with credentials: true

### Recommended Actions
1. [ ] Set BETTER_AUTH_SECRET secret
2. [ ] Fix adapter import
3. [ ] Add CORS middleware
4. [ ] Verify OAuth callback URLs in provider console

Files

1
6.4 KB

Agent reviews

0

No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.

More from secondsky/claude-skills8

Turnstile CSP Debugger

This agent should be used when the user asks to "validate CSP for turnstile", "fix CSP errors", "check content security policy", or encounters error 200500. Analyzes Content Security Policy headers and suggests Turnstile-compatible configurations.

Scan passed 0
Turnstile Troubleshooting Agent

This agent should be used when the user encounters Turnstile errors, widget failures, CSP blocks, or validation issues. Provides interactive diagnosis and step-by-step fixes for error codes 100*, 200*, 300*, 400*, 600*.

Scan passed 0
bun-migration-assistant

Use this agent when the user wants to migrate from Node.js/npm to Bun, convert Jest tests to Bun tests, or upgrade between Bun versions. Examples:

Scan passed 0
bun-performance-analyzer

Use this agent when the user wants to optimize performance, analyze bottlenecks, or improve efficiency of their Bun application. Examples:

Scan passed 0
bun-troubleshooter

Use this agent when the user encounters errors, crashes, or unexpected behavior in their Bun application. Examples:

Scan passed 0
code-architect

Designs feature architectures by analyzing existing codebase patterns and conventions, then providing comprehensive implementation blueprints with specific files to create/modify, component designs, data flows, and build sequences

Scan passed 0
code-explorer

Deeply analyzes existing codebase features by tracing execution paths, mapping architecture layers, understanding patterns and abstractions, and documenting dependencies to inform new development

Scan passed 0
code-reviewer

Reviews code for bugs, logic errors, security vulnerabilities, code quality issues, and adherence to project conventions, using confidence-based filtering to report only high-priority issues that truly matter

Scan passed 0

Related security skillsscan passed