← ClaudeAtlas

email-and-password-best-practiceslisted

Configure email verification, implement password reset flows, set password policies, and customise hashing algorithms for Better Auth email/password authentication. Use when users need to set up login, sign-in, sign-up, credential authentication, or password security with Better Auth.
arthjean/skills · ★ 3 · AI & Automation · score 66
Install: claude install-skill arthjean/skills
## Quick Start 1. Enable email/password: `emailAndPassword: { enabled: true }` 2. Configure `emailVerification.sendVerificationEmail` 3. Add `sendResetPassword` for password reset flows 4. Run `npx @better-auth/cli@latest migrate` 5. Verify: attempt sign-up and confirm verification email triggers --- ## Email Verification Setup Configure `emailVerification.sendVerificationEmail` to verify user email addresses. ```ts import { betterAuth } from "better-auth"; import { sendEmail } from "./email"; // your email sending function export const auth = betterAuth({ emailVerification: { sendVerificationEmail: async ({ user, url, token }, request) => { await sendEmail({ to: user.email, subject: "Verify your email address", text: `Click the link to verify your email: ${url}`, }); }, }, }); ``` **Note**: The `url` parameter contains the full verification link. The `token` is available if you need to build a custom verification URL. ### Requiring Email Verification For stricter security, enable `emailAndPassword.requireEmailVerification` to block sign-in until the user verifies their email. When enabled, unverified users will receive a new verification email on each sign-in attempt. ```ts export const auth = betterAuth({ emailAndPassword: { requireEmailVerification: true, }, }); ``` **Note**: This requires `sendVerificationEmail` to be configured and only applies to email/password sign-ins. ## Client Side Validation Imple