Authentication Feature
Enable user authentication in yourweb-app template using Better Auth.
Authentication is only available for the
web-app template and requires the database feature.How it works
Sessions are managed by Better Auth and stored in a separate SQLite database (/data/auth.db).
Enabling Authentication
Add to yourruntm.yaml:
Setup
1. Generate Secret
2. Deploy
Frontend Usage
Auth Hooks
Protected Routes
UseAuthGuard to protect pages:
AuthGuard redirects unauthenticated users to the login page.
Login Form
The template includes a ready-to-use login form:Auth Components
The template includes these components:Backend Integration
Getting Current User
Protected Endpoints
Session Storage
Sessions are stored in a separate SQLite database at/data/auth.db. This keeps auth data isolated from your application data.
OAuth Providers (Optional)
To add social login (Google, GitHub, etc.), configure providers:Customization
Custom Login Page
Redirect After Login
Best Practices
Generate a strong secret
Generate a strong secret
Use at least 32 characters:
Never expose AUTH_SECRET
Never expose AUTH_SECRET
Keep it in
.env.local and never commit to git.Use HTTPS
Use HTTPS
Runtime provides HTTPS by default. Never disable it for auth.
Add rate limiting
Add rate limiting
Consider adding rate limiting to auth endpoints to prevent brute force.
Troubleshooting
'AUTH_SECRET not set' error
'AUTH_SECRET not set' error
Set the secret:
'features.auth requires database'
'features.auth requires database'
Enable database in manifest:
Session not persisting
Session not persisting
Check that cookies are being set. Ensure you’re accessing via HTTPS.
'auth is only supported for web-app'
'auth is only supported for web-app'
Authentication only works with the
web-app template, not backend-service or static-site.