better-auth-tenancy
v1.6.16
Published
Multi-tenant authentication plugin for Better Auth
Downloads
8
Readme
better-auth-tenancy
Multi-tenant authentication plugin for Better Auth.
Add tenant-scoped users, per-tenant OAuth, and management APIs to your Better Auth setup.
Features
- Tenant-scoped users — the same email can exist under different tenants as separate users
- Per-tenant OAuth — store OAuth client credentials per tenant, with fallback to global providers
- Management APIs — create, update, list, and delete tenants and OAuth configs
- Better Auth native — extends schema, endpoints, and the client plugin alongside Better Auth adapters and sessions
Requirements
- Node.js 20+
- Better Auth
^1.6.16 - A supported database adapter (Drizzle, Prisma, etc.)
Installation
pnpm add better-auth-tenancy better-authPeer dependencies (@better-auth/core, better-call) are typically installed automatically with better-auth.
Usage
Server
import { tenantAuth } from "better-auth-tenancy";
import { betterAuth } from "better-auth";
export const auth = betterAuth({
database: /* your adapter */,
secret: process.env.BETTER_AUTH_SECRET,
emailAndPassword: { enabled: true },
plugins: [tenantAuth()],
});Client
import { tenantAuthClient } from "better-auth-tenancy/client";
import { createAuthClient } from "better-auth/react";
export const authClient = createAuthClient({
baseURL: process.env.NEXT_PUBLIC_APP_URL,
plugins: [tenantAuthClient()],
});Database schema
The plugin adds:
tenant— tenant recordstenantOauthConfig— per-tenant OAuth credentialstenantIdonuser,session,account, andverification
Generate and apply the schema with the Better Auth CLI:
npx @better-auth/cli generate
# then push or migrate with your ORMBy default, the global unique constraint on user.email is removed so the same address can exist under different tenants. Set keepEmailGloballyUnique: true on the plugin if you want one email to map to a single tenant globally.
Quick example
// Create a tenant
await auth.api.createTenant({
body: { name: "Acme", slug: "acme" },
});
// Sign up under that tenant
await authClient.signUpEmailTenant({
tenantId: tenant.id,
email: "[email protected]",
password: "secure-password",
name: "Jane Doe",
});Documentation
Full guides and API reference live in the repo under docs/. A complete Next.js example with PostgreSQL and Drizzle is in examples/nextjs-demo/.
License
MIT
