Skip to main content
ShipFree uses Better-Auth for a complete authentication solution with support for email/password, OAuth providers, email OTP, and organizations.

Architecture

The authentication system consists of three main components:
  1. Server-side Auth Configuration (src/lib/auth/auth.ts)
  2. Client-side Auth Client (src/lib/auth/auth-client.ts)
  3. API Routes (src/app/api/auth/[...all]/route.ts)

Features

Email & Password Authentication

Email and password authentication with optional email verification:

Email OTP (One-Time Password)

Passwordless authentication via email OTP:
Configuration (from src/lib/auth/auth.ts:130-188):
  • OTP Length: 6 digits
  • Expiration: 15 minutes
  • Types: sign-in, email-verification, forget-password
  • Email delivery: Configured via email service (Resend, Postmark, Plunk, or Nodemailer)

OAuth Providers

Supported OAuth providers (configured in src/lib/auth/auth.ts:45-78):

Google

Requires GOOGLE_CLIENT_ID and GOOGLE_CLIENT_SECRET

GitHub

Requires GITHUB_CLIENT_ID and GITHUB_CLIENT_SECRET

Microsoft

Requires MICROSOFT_CLIENT_ID and MICROSOFT_CLIENT_SECRET

Facebook

Requires FACEBOOK_CLIENT_ID and FACEBOOK_CLIENT_SECRET
Usage:

Session Management

Configuration from src/lib/auth/auth.ts:35-43:
Enable cookie-based session caching
Cache duration: 24 hours (in seconds)
number
default:2592000
Session lifetime: 30 days (in seconds)
number
default:86400
How often to refresh expiry: 24 hours (in seconds)
number
default:3600
Fresh session window: 1 hour (in seconds)
Get current session:

Organizations

Multi-tenant organization support via the organization plugin (src/lib/auth/auth.ts:190-211):

Database Schema

Better-Auth integrates with ShipFree’s PostgreSQL database via Drizzle ORM. See Database Schema for table structures. Key tables:
  • user - User accounts
  • session - Active sessions
  • account - OAuth accounts linked to users
  • verification - Email verification tokens and OTP codes

Email Verification

Email verification can be enabled/disabled via feature flag (src/config/feature-flags.ts). Configuration (src/lib/auth/auth.ts:80-126):

Password Reset

Password reset flow:

Sign Out

Custom Pages

Authentication pages are configured in src/lib/auth/auth.ts:214-219:

Next Steps

API Endpoints

Explore all available authentication endpoints

Database Schema

View authentication-related database tables