Skip to main content

Authentication Feature

Enable user authentication in your web-app template using Better Auth.
Authentication is only available for the web-app template and requires the database feature.

How it works

Sessions are managed by Better Auth and stored in a separate SQLite database (/data/auth.db).

Enabling Authentication

Add to your runtm.yaml:

Setup

1. Generate Secret

2. Deploy

Frontend Usage

Auth Hooks

Protected Routes

Use AuthGuard to protect pages:
AuthGuard redirects unauthenticated users to the login page.

Login Form

The template includes a ready-to-use login form:

Auth Components

The template includes these components:

Backend Integration

Getting Current User

Protected Endpoints

Session Storage

Sessions are stored in a separate SQLite database at /data/auth.db. This keeps auth data isolated from your application data.

OAuth Providers (Optional)

To add social login (Google, GitHub, etc.), configure providers:
Add to manifest:

Customization

Custom Login Page

Redirect After Login

Best Practices

Use at least 32 characters:
Keep it in .env.local and never commit to git.
Runtime provides HTTPS by default. Never disable it for auth.
Consider adding rate limiting to auth endpoints to prevent brute force.

Troubleshooting

Set the secret:
Enable database in manifest:
Check that cookies are being set. Ensure you’re accessing via HTTPS.
Authentication only works with the web-app template, not backend-service or static-site.