Better Auth
Auth as a library inside the backend — no vendor, no second service.
Why Better Auth
Better Auth runs inside the Fastify process and stores users, sessions, and accounts in your Postgres through Drizzle.
The alternatives, and why they lost:
| Option | Why not |
|---|---|
| Auth.js | Same self-hosted shape, but no first-class Fastify integration |
| Keycloak, Authentik, Zitadel | A separate service to run and operate |
| Clerk, Auth0 | A vendor dependency with a usage-limited free tier |
| Firebase Auth | Pulls in Google's ecosystem and doesn't pair naturally with Postgres |
| Supabase Auth | Tied to Supabase's database, and free projects pause when idle |
What Bones uses from it
- Email and password, plus Google as a social provider.
- Email verification and password reset.
customSessionto add fields to every session —enabledFeatures,avatarUrl, and whether the user has accepted the terms.- The
bearerplugin, for the desktop app. - Its CLI, which generates
auth-schema.ts.