What Bones

Better Auth

Auth as a library inside the backend — no vendor, no second service.

Why Better Auth

Better Auth runs inside the Fastify process and stores users, sessions, and accounts in your Postgres through Drizzle.

The alternatives, and why they lost:

OptionWhy not
Auth.jsSame self-hosted shape, but no first-class Fastify integration
Keycloak, Authentik, ZitadelA separate service to run and operate
Clerk, Auth0A vendor dependency with a usage-limited free tier
Firebase AuthPulls in Google's ecosystem and doesn't pair naturally with Postgres
Supabase AuthTied to Supabase's database, and free projects pause when idle

What Bones uses from it

  • Email and password, plus Google as a social provider.
  • Email verification and password reset.
  • customSession to add fields to every session — enabledFeatures, avatarUrl, and whether the user has accepted the terms.
  • The bearer plugin, for the desktop app.
  • Its CLI, which generates auth-schema.ts.

Used in