> **better-auth-security-best-practices** — skill 6 of 6 in [better-auth/skills](https://skillsdocs.com/better-auth/skills).
>
> Book (all skills, one file): https://skillsdocs.com/better-auth/skills.md
> Machine manifest: https://skillsdocs.com/better-auth/skills/.well-known/agent-skills/index.json
> Install the book: `npx skills add better-auth/skills`
> Upstream: https://github.com/better-auth/skills/blob/main/security/SKILL.md @ `main`
> Raw bytes, no header: https://raw.githubusercontent.com/better-auth/skills/main/security/SKILL.md
> Base for relative paths: https://raw.githubusercontent.com/better-auth/skills/main/security/
> Licence: No licence detected — all rights reserved by its authors
>
> Content © its authors. This skill's body is not served here; the links above are. Takedown: https://github.com/DreambaseAI/skillsdocs/issues/new?labels=takedown&title=Takedown+request

# better-auth-security-best-practices

Configure rate limiting, manage auth secrets, set up CSRF protection, define trusted origins, secure sessions and cookies, encrypt OAuth tokens, track IP addresses, and implement audit logging for Better Auth. Use when users need to secure their auth setup, prevent brute force attacks, or harden a Better Auth deployment.

No licence could be detected for this skill at either the repository or the skill level, so its body is not reproduced here. Read it upstream:

https://raw.githubusercontent.com/better-auth/skills/main/security/SKILL.md
