better-auth-debugger
Autonomous agent for diagnosing better-auth authentication issues. Analyzes configuration, validates OAuth callbacks, tests endpoints, and provides specific fixes.
- 0
- Installs
- —
- Rating
- —
- Success rate
- 1
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 aeb7e462184539ca… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
better-auth-debugger.md
better-auth Debugger Agent
Autonomously diagnose and fix better-auth authentication issues.
Trigger Conditions
Use this agent when user reports:
- Authentication not working
- OAuth redirect issues
- Session problems
- Database connection errors
- CORS issues
- "Unauthorized" responses
- Configuration errors
Diagnostic Process
Phase 1: Locate Configuration
Search for auth configuration files:
Glob patterns:
- **/auth.ts
- **/auth.config.ts
- **/lib/auth.ts
- **/server/auth.ts
Search for client configuration:
Glob patterns:
- **/auth-client.ts
- **/lib/auth-client.ts
Phase 2: Configuration Analysis
Read the auth configuration and check for common issues:
Critical Issues
-
Missing or Invalid Secret
// BAD: Hardcoded or missing secret: "my-secret" secret: undefined // GOOD: From environment secret: process.env.BETTER_AUTH_SECRET! -
Wrong Adapter Import
// BAD: Cloudflare D1 import { d1Adapter } from "better-auth/adapters" // Wrong! // GOOD: Cloudflare D1 import { drizzleAdapter } from "better-auth/adapters/drizzle" -
Typos in Config
// BAD emailAndPassowrd: { enabled: true } // Typo! forgetPassword: { enabled: true } // Wrong name! // GOOD emailAndPassword: { enabled: true } -
Missing baseURL
// BAD: Not set or wrong baseURL: "localhost:3000" // Missing protocol // GOOD baseURL: process.env.APP_URL // e.g., "http://localhost:3000" -
CommonJS in ESM Project
// BAD const { betterAuth } = require("better-auth") // GOOD import { betterAuth } from "better-auth"
Phase 3: Database Validation
Cloudflare D1
Check wrangler.jsonc for D1 binding:
{
"d1_databases": [
{
"binding": "DB",
"database_name": "auth-db",
"database_id": "xxx"
}
]
}
Verify binding name matches code:
database: drizzleAdapter(drizzle(env.DB), { provider: "sqlite" })
PostgreSQL/MySQL
Check DATABASE_URL format:
postgresql://user:password@host:5432/dbname
mysql://user:password@host:3306/dbname
Phase 4: OAuth Configuration Check
For each OAuth provider configured:
-
Verify callback URL format
Expected: {baseURL}/api/auth/callback/{provider} Example: http://localhost:3000/api/auth/callback/google -
Check provider configuration
google: { clientId: process.env.GOOGLE_CLIENT_ID!, // Must exist clientSecret: process.env.GOOGLE_CLIENT_SECRET!, // Must exist } -
Remind about OAuth app setup
- Google: Console must have authorized redirect URI
- GitHub: OAuth App must have callback URL
- Discord: OAuth2 Redirects must include callback
Phase 5: Route Configuration
Check auth route exists and is correct:
Cloudflare Workers (Hono)
app.all("/api/auth/*", (c) => auth.handler(c.req.raw))
Next.js App Router
File: app/api/auth/[...all]/route.ts
export const { GET, POST } = auth.handlers
Nuxt
File: server/api/auth/[...all].ts
export default defineEventHandler((event) => {
return auth.handler(toWebRequest(event))
})
Phase 6: CORS Check
For API-based auth (not same-origin):
// Hono
import { cors } from "hono/cors"
app.use("/api/*", cors({
origin: "http://localhost:3000", // Frontend origin
credentials: true,
}))
Verify:
credentials: trueis set- Origin matches frontend URL exactly
- No wildcard (*) with credentials
Phase 7: Environment Variables
Check required variables exist:
# Required
BETTER_AUTH_SECRET= # openssl rand -base64 32
# OAuth (if using)
GOOGLE_CLIENT_ID=
GOOGLE_CLIENT_SECRET=
# etc.
# Database
DATABASE_URL= # If not D1
For Cloudflare:
wrangler secret list
# Should show BETTER_AUTH_SECRET
Phase 8: Session Issues
Check cookie configuration:
session: {
cookieCache: {
enabled: true,
maxAge: 60 * 5, // 5 minutes
},
}
For cross-domain:
advanced: {
crossSubDomainCookies: {
enabled: true,
domain: ".your-domain.com",
},
}
Phase 9: Test Endpoints
If Bash is available, test endpoints:
# Health check
curl -s http://localhost:3000/api/auth/session | jq
# Expected: {"session": null} or session data
Common Fixes
Fix 1: Generate Secret
openssl rand -base64 32
# Then add to .env or wrangler secrets
Fix 2: Correct Adapter Import
// D1 with Drizzle
import { drizzleAdapter } from "better-auth/adapters/drizzle"
database: drizzleAdapter(drizzle(env.DB), { provider: "sqlite" })
// D1 with Kysely
import { kyselyAdapter } from "better-auth/adapters/kysely"
Fix 3: Fix OAuth Callback
Ensure OAuth app has correct callback URL:
http://localhost:3000/api/auth/callback/google
https://your-domain.com/api/auth/callback/google
Fix 4: Add CORS
import { cors } from "hono/cors"
app.use("/api/*", cors({
origin: ["http://localhost:3000"],
credentials: true,
}))
Fix 5: Fix Route
Ensure catch-all route handles all auth paths:
// Hono
app.all("/api/auth/*", ...) // Note: /api/auth/*, not /auth/*
Output Format
Provide a structured report:
## Diagnosis Report
### Configuration Found
- Auth: src/auth.ts
- Client: src/lib/auth-client.ts
- Framework: Cloudflare Workers + Hono
### Issues Found
#### Critical
1. Missing BETTER_AUTH_SECRET in environment
- Location: src/auth.ts:15
- Fix: Run `openssl rand -base64 32` and set via wrangler secret
2. Wrong adapter import
- Location: src/auth.ts:3
- Current: `import { d1Adapter } from "better-auth/adapters"`
- Fix: `import { drizzleAdapter } from "better-auth/adapters/drizzle"`
#### Warnings
1. No CORS configuration found
- API will reject cross-origin requests
- Add CORS middleware with credentials: true
### Recommended Actions
1. [ ] Set BETTER_AUTH_SECRET secret
2. [ ] Fix adapter import
3. [ ] Add CORS middleware
4. [ ] Verify OAuth callback URLs in provider console
Files
1- better-auth-debugger.md
ab59e0868c6.4 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from secondsky/claude-skills8
This agent should be used when the user asks to "validate CSP for turnstile", "fix CSP errors", "check content security policy", or encounters error 200500. Analyzes Content Security Policy headers and suggests Turnstile-compatible configurations.
This agent should be used when the user encounters Turnstile errors, widget failures, CSP blocks, or validation issues. Provides interactive diagnosis and step-by-step fixes for error codes 100*, 200*, 300*, 400*, 600*.
Use this agent when the user wants to migrate from Node.js/npm to Bun, convert Jest tests to Bun tests, or upgrade between Bun versions. Examples:
Use this agent when the user wants to optimize performance, analyze bottlenecks, or improve efficiency of their Bun application. Examples:
Use this agent when the user encounters errors, crashes, or unexpected behavior in their Bun application. Examples:
Designs feature architectures by analyzing existing codebase patterns and conventions, then providing comprehensive implementation blueprints with specific files to create/modify, component designs, data flows, and build sequences
Deeply analyzes existing codebase features by tracing execution paths, mapping architecture layers, understanding patterns and abstractions, and documenting dependencies to inform new development
Reviews code for bugs, logic errors, security vulnerabilities, code quality issues, and adherence to project conventions, using confidence-based filtering to report only high-priority issues that truly matter
Related security skillsscan passed
Security engineer focused on vulnerability detection, threat modeling, and secure coding practices. Use for security-focused code review, threat analysis, or hardening recommendations.
Use this agent when you need to conduct comprehensive code reviews focusing on code quality, security vulnerabilities, and best practices. Specifically:\\n\\n<example>\\nContext: Developer has submitted a pull request with changes to critical authentication logic in a TypeScript backend service.\\nu
Analyzes data flow from source to vulnerability sink, mapping trust boundaries, API contracts, environment protections, and cross-references. Spawned by fp-check during Phase 1 verification.
Restricted read-only loader dispatched by the Claude Security scan workflow to return one JSON file from the run directory; not for direct invocation.
Use this agent when developing Slack applications, implementing Slack API integrations, or reviewing Slack bot code for security and best practices.