What is Better Auth?
Authentication with managed Google sign-in or email/password flows provisioned for generated apps. Auth pages (callbacks, sign-in) are private surfaces and stay noindexed like any other.
Example
A client portal ships with Google sign-in managed by BYOB; the developer never touches OAuth client secrets or session tables.
Related terms
Magic Link / OTP
Passwordless sign-in: the user receives an email link or one-time code instead of inventing a password. Fewer credentials to phish, fewer reset flows to build, higher conversion than passwords.
BYOB-Managed Google Auth
Google sign-in provisioned by the platform so generated apps authenticate without the developer registering OAuth clients. Project-owned OAuth remains available for teams bringing their own brand and keys.
Row-Level Security (RLS)
Per-user table policies enforced by the database itself: users can only read or write their own rows. RLS is what makes the anon key safe to ship in client code.
Cloudflare Worker
Serverless code running on Cloudflare’s edge network, close to visitors worldwide. BYOB deploys generated apps as Workers: no servers to provision, scale, or patch.
Dispatcher Worker
The SaaS router that maps each request — by publish slug or custom domain — to the right per-project Worker. One edge entry point, thousands of isolated apps behind it.
Dispatch Namespace
The isolate group containing a fleet of per-project Workers. Namespaces let one platform deploy, version, and route user projects independently.