Generated

Generated Auth Runtime

Source-driven notes for the auth service, Better Auth modules, and the live auth flow diagrams generated from the app itself.

AuthGenerated
This file is generated from the live auth app. Do not edit it by hand; regenerate it from apps/docs-site/ with bun run generate.

Generated from: apps/core/auth/package.json, apps/core/auth/src/platform/better-auth/auth.ts, apps/core/auth/src/index.ts

Better Auth packages detected

PackageVersionTypeWhy it matters here
@better-auth/mcp1.7.0-rc.6Official addonAuth dependency discovered in the auth app manifest.
@better-auth/oauth-provider1.7.0-rc.6Official addonAuth dependency discovered in the auth app manifest.
@better-auth/passkey1.7.0-rc.6Official addonOfficial Better Auth passkey addon enabling WebAuthn / passkey ceremonies.
@better-auth/sso1.7.0-rc.6Official addonAuth dependency discovered in the auth app manifest.
@better-auth/stripe1.7.0-rc.6Official addonAuth dependency discovered in the auth app manifest.
@crown/better-auth-admin-accessworkspace:*Crown extensionCrown extension for platform-wide admin, GDPR, auditor, and support access flows.
@crown/better-auth-external-structureworkspace:*Crown extensionCrown extension for partner/external organization trees, invitations, and delegated access.
@crown/better-auth-organization-archiveworkspace:*Crown extensionCrown extension for organization archive, soft-delete, restore, and cascade handling.
@crown/better-auth-permissionsworkspace:*Crown extensionCrown extension for scoped roles, role templates, team grants, and permission checks.
@crown/better-auth-workspaceworkspace:*Crown extensionCrown extension for workspaces, workspace teams, invitations, and active workspace context.
better-auth1.7.0-rc.6CoreCore Better Auth runtime mounted by the auth service under /api/auth/**.

Plugin stack in configured order

#ModuleSourceTypeWhat it adds
1Bearer Reads../../features/session/bearer-readsOfficial addonBearer Reads is configured in the auth app.
2Email OTPbetter-auth/pluginsOfficial addonSends verification, reset-password, and security-code OTP emails through Better Auth.
3Two Factorbetter-auth/pluginsOfficial addonAdds TOTP / OTP-based second-factor challenges, backup codes, and trusted-device cookies.
4Two Factor Context../../features/two-factor/two-factor-contextOfficial addonTwo Factor Context is configured in the auth app.
5Expired Session Cookies../../features/session/expired-session-cookiesOfficial addonExpired Session Cookies is configured in the auth app.
6Adminbetter-auth/pluginsOfficial addonEnables Better Auth admin capabilities for platform owner/admin roles.
7Organizationbetter-auth/pluginsOfficial addonAdds organizations, teams, invitations, and membership roles to Better Auth.
8Workspace@crown/better-auth-workspaceCrown extensionAdds Crown workspaces, workspace teams, invitations, and active workspace tracking.
9Passkey@better-auth/passkeyOfficial addonEnables WebAuthn passkey registration and sign-in via @better-auth/passkey.
10Organization Archive@crown/better-auth-organization-archiveCrown extensionAdds archive, soft-delete, and restore lifecycle operations for organizations.
11JWTbetter-auth/pluginsOfficial addonSigns short-lived JWTs, manages JWKS keys, and defines the outbound token payload.
12External Structure@crown/better-auth-external-structureCrown extensionAdds hierarchical partner/external organization nodes, invitations, and delegated workspace access.
13Permissions@crown/better-auth-permissionsCrown extensionAdds scoped roles, role templates, effective-permission checks, and team-wide grants.
14Admin Access@crown/better-auth-admin-accessCrown extensionAdds platform-level admin access APIs for organizations, users, teams, workspaces, and GDPR actions.
15Sso@better-auth/ssoOfficial addonSso is configured in the auth app.
16Sso Policy../../features/sso/sso-policyOfficial addonSso Policy is configured in the auth app.
17Billing Plugins../../features/billing/billing-pluginsOfficial addonBilling Plugins is configured in the auth app.

How Better Auth works in Crown

  • Better Auth is mounted inside the Hono auth service at /api/auth/**, so the browser talks to the service wrapper rather than to Better Auth directly.
  • The auth store uses surrealAdapter(...), so Better Auth state lives in SurrealDB alongside the Crown auth schema.
  • Primary sign-in modes detected: email + password, email OTP, passkey.
  • Email/password sign-in requires verified email before the normal session flow is considered complete.
  • OTP-related flows default to a 10-minute validity window unless overridden by environment variables.
  • A user creation hook bootstraps the first user as an owner, so initial platform setup happens inside the auth app rather than in separate seed logic.
  • A session creation hook normalizes Surreal record IDs and auto-activates organization, workspace, and team context whenever the user membership graph is unambiguous.
  • Trusted origins are configured explicitly, which keeps Better Auth, email links, passkeys, and cross-origin UI callbacks aligned with the deployed frontend origins.
  • Cookie defaults are centralized, so session, two-factor, and trusted-device cookies share the same secure / httpOnly / sameSite policy envelope.
  • The JWT plugin signs 15m tokens using EdDSA / Ed25519 and publishes JWKS for downstream verification.
  • The auth service layers a token-exchange route on top of Better Auth so an existing token can be reissued for an alternate SurrealDB access scope.
  • A passkey admin helper route lets privileged users inspect passkey records already persisted by Better Auth.
  • Crown-specific role template, custom role, and assignment APIs are hosted beside Better Auth so permission authoring stays anchored to the same authenticated session context.
  • Reference-numbering routes also live in the auth service, reusing the Better Auth session and resolved organization / workspace / team scope.

Session behavior detected

  • Session inactivity expiry: 60 * 30
  • Session refresh cadence: 60
  • Fresh-session window: 60 * 5
  • Cookie cache max age: 60

JWT claims detected

The Better Auth JWT payload currently includes: ac, activeOrganizationId, activeTeamId, activeWorkspaceId, db, email, emailVerified, false, id, ns, null, orgRole, role, sub, teamRole, twoFactorEnabled, twoFactorMethod, twoFactorMethods.

Auth-service endpoint groups detected

Route / prefixMethodsWhy it existsMatched paths
/api/auth/**GET, POSTMounted Better Auth handler for sign-in, sign-up, sessions, password reset, passkeys, and plugin endpoints./api/auth/**
/.well-known/jwks.jsonGETStable JWKS alias used by downstream APIs and SurrealDB to verify Better Auth JWTs./.well-known/jwks.json
/api/token/exchange-dbPOSTVerifies an existing Better Auth JWT and mints a database-scoped replacement token./api/token/exchange-db
/api/admin/user-passkeysGETAdmin helper route for inspecting passkey credentials already stored for a user./api/admin/user-passkeys
/api/reference-numbering/*GET, POSTCrown auth-service extensions that use the authenticated org/workspace/team context for reference numbering./api/reference-numbering/context<br/>/api/reference-numbering/organization<br/>/api/reference-numbering/team<br/>/api/reference-numbering/workspace
/api/role-templates*DELETE, GET, PATCH, POSTCrown role-template APIs layered next to Better Auth authorization metadata./api/role-templates<br/>/api/role-templates/:id<br/>/api/role-templates/:id/roles
/api/roles*DELETE, GET, PATCH, POSTCustom role CRUD, template-diff, and migration APIs layered on top of the Better Auth session./api/roles<br/>/api/roles/:id<br/>/api/roles/:id/migrate<br/>/api/roles/:id/template-diff
/api/role-assignments*DELETE, GET, POSTCrown role-assignment APIs that attach custom roles to members in org/workspace/team scopes./api/role-assignments<br/>/api/role-assignments/:id
/sessionGETMinimal authenticated echo of the Better Auth session and current user./session
/api/bootstrap/statusGETChecks whether the auth datastore already contains a privileged bootstrap user./api/bootstrap/status

Generation note

  • The auth flow diagram and this runtime summary are both derived from the auth app’s current Better Auth config and Hono routes.
  • If the plugin list, JWT payload, or auth-service routes change, the next docs generation run updates these artifacts automatically.