learn
packages/

Auth

Better Auth configuration, browser auth client, email delivery, and authentication helpers.

Signing in is email-based with verification links; Google OAuth is optional. Rooms never take a password or a session cookie over the socket: the HTTP server issues a short-lived presence ticket, and the WebSocket server verifies it during the upgrade before checking room access.

What it owns

  • Server-side auth configuration with email verification
  • The browser auth client the editor signs in through
  • Presence tickets the WebSocket server verifies on upgrade
  • Room invitation helpers with email delivery

Files

File list and purposes from the folder README.

FilePurpose
src/server.tsServer auth configuration and verification email.
src/client.tsBrowser auth client.
src/presenceTicket.tsPresence ticket issue and verify helpers.
src/roomInvitation.tsRoom invitation helpers.

Dependencies

LibraryVersion rangeWhy it is used here
bcrypt^6.0.0Hashes and verifies account passwords.
Better Auth1.7.7Email sign-in, verification mail, and Google OAuth.
dotenv^17.4.2Loads local environment files in development.
jsonwebtoken^9.0.3Signs presence tickets and room invitations.
Development and tooling (5)
LibraryVersion rangeWhy it is used here
@types/bcrypt^6.0.0Type declarations for bcrypt.
@types/jsonwebtoken^9.0.10Type declarations for jsonwebtoken.
@types/node26.4.1Type declarations for Node.js built-ins.
TypeScript7.0.2Compiles the workspace and type-checks every package.
Vitest^5.0.1Runs the unit and regression test suites.

Dependencies as of commit b0026d9.

Internal packages used

auth package
BrowserAPIRealtimeCacheDatabaseShareddurableephemeral

Talks to

Sources: packages/auth/README.md, packages/auth/src/README.md, packages/auth/src/server.ts, packages/auth/src/client.ts, packages/auth/src/presenceTicket.ts, packages/auth/src/roomInvitation.ts (documented at commit b0026d9)

On this page