Better Auth Basics
What Better Auth is and how a self run auth library differs from a hosted service like Clerk

Pixl presents
Clerk runs login on their servers. Better Auth runs it on yours. Pick based on who you want to blame.Clerk runs login on their servers. Better Auth runs it on yours. Pick based on who you want to blame.

In the last few lessons you met Clerk, a service that runs login for you on its own servers. Better Auth solves the same problem from the other direction. It's code you add to your own app, and it keeps your users in your OWN database.
What Is Better Auth?#
Better Auth describes itself as a "framework-agnostic, universal authentication and authorization framework for TypeScript." Big mouthful. Let's chew on it one piece at a time.
- Authentication and authorization. It handles sign up and log in (who you are), and it can also help with permissions (what you're allowed to do).
- Framework-agnostic. It isn't tied to one tool. The docs show setups for Next.js, Nuxt, SvelteKit, Express, Hono and more.
- For TypeScript. It's a JavaScript package written for TypeScript projects. You install it with npm, same as any other package.
The word that matters most in this lesson is library. You won't find a Better Auth website to sign up for, because it's a package of code that runs inside your app.
Library vs Hosted Service#
Think of it like cooking at home versus ordering takeout.
With a hosted service like Clerk, somebody else runs the kitchen. You connect your app to their servers, and they store your users, check passwords and manage sessions. You get a dashboard for changing settings.
With a library like Better Auth, YOU run the kitchen. The auth code lives in your project. When someone signs up, your own server checks their details and saves them to your own database.
Here's how they stack up side by side.
| Question | Better Auth | Clerk |
|---|---|---|
| What is it? | A library you install in your app | A hosted service you connect to |
| Where do user records live? | In your own database | On the service's servers |
| Who runs the auth code? | Your server | The service |
| Where do you change settings? | In your code, in a file called auth.ts | Mostly in a web dashboard |
Where Your User Data Lives#
This is the BIG difference between the two.
The Better Auth docs say it "connects to a database to store data" such as "users, sessions, and more." That database is yours. It could be PostgreSQL, MySQL or SQLite, or a database you reach through a tool like Prisma or Drizzle.
When you connect a database, Better Auth needs a few tables in it. The docs call this the core schema, and it's four tables.
userholds each person's accountsessionkeeps track of who's logged inaccountstores each way a user can log in, like a password or a GitHub accountverificationholds verification records
On its comparison page, Better Auth lists "Keep your data" as a reason to pick it over managed services, saying "Users stay in your database, not a third-party service."
I'll be honest, this is the part that gets me excited. My whole thing is own your tools, don't rent them. When the software you depend on belongs to somebody else, they can change the rules any Monday they feel like it... and you just find out.
Who Runs It and What It Costs#

With Better Auth, you run it. It runs as part of your app, on whatever server or host your app already uses. That same comparison page says you can "Run alongside your app or as a standalone self-hosted auth server" if you'd rather keep auth on its own.
So what does it cost? Here's what the official sources say.
- The GitHub page says Better Auth "is a free and open source project licensed under the MIT License."
- The comparison page lists "No per-user costs" as a reason to choose it over managed services.
Free library doesn't mean free auth though. You still pay for your own hosting and your own database, just like the rest of your app. For Clerk's prices, check the Clerk pricing page, since those move around.
What Features It Supports#
Out of the box, the docs say Better Auth has built-in support for two ways to sign in.
- Email and password
- Social providers, such as Google, GitHub, Apple and Discord
Everything else gets added through plugins. A plugin is an extra piece you switch on in your config. The docs mention plugins for stuff like this.
- Two factor authentication (2FA)
- Passkeys
- Username sign in
- Magic links
- Email one time codes (email OTP)
The docs also list bigger features like multi-tenancy, multi-session support, rate limiting and enterprise single sign-on (SSO).
When You Might Pick Each#
Both are solid picks. They just fit different situations.
Clerk might fit better when
- You want ready-made sign-in pages and a dashboard to manage users
- You'd rather not run or maintain auth code yourself
- You want login working with as little setup as possible
Better Auth might fit better when
- You want user data to stay in your own database
- You want to dodge per-user auth billing as your app grows
- You're comfortable setting up a database and editing config files
- You want to control every step of the login flow in your own code
Here's a simple way to think about it. Clerk trades some control for convenience. Better Auth trades some convenience for control.
TL;DR#
- Better Auth is a TypeScript library that runs inside your own app. Clerk is a hosted service that runs on its servers.
- With Better Auth, users, sessions and accounts are stored in your own database.
- Better Auth is free and open source under the MIT License, and its docs say there are no per-user costs. You still pay for your own hosting and database.
- Email and password plus social sign in are built in. Extras like 2FA, passkeys and magic links come from plugins.
- Pick Clerk for convenience, pick Better Auth for control over your data and code.
What's Next?#
Next up, you'll install Better Auth step by step. You'll set up the secret key, create the auth file, hook up a database and run the CLI that creates the tables...
This lesson ends with 2 short activities.
