next-safe-action Better Auth Adapter
Install
Import
Quick Start
1. Set up Better Auth
Create your Better Auth server instance. Add the nextCookies() plugin if your actions need to set cookies (e.g. signInEmail, signUpEmail):
2. Enable auth interrupts in Next.js
The default behavior uses unauthorized() from next/navigation, which requires this flag:
3. Create an authenticated action client
4. Use it in your actions
How It Works
betterAuth() creates a pre-validation middleware for the safe action client's .use() chain:
- Fetches the session by calling
auth.api.getSession({ headers: await headers() })using the request headers fromnext/headers - Blocks unauthenticated requests by calling
unauthorized()fromnext/navigationwhen no session exists - Injects typed context by passing
{ auth: { user, session } }tonext(), merging it into the action context
The context is namespaced under auth to avoid collisions with other middleware context properties.
Type Inference
The middleware infers the exact user and session types from your Better Auth instance, including any fields added by plugins. For example, if you use the organization plugin, ctx.auth.session will include activeOrganizationId. No manual type annotations are needed.
Entry Points
Exported Types
vs. Manual Auth Middleware
If you are using Better Auth, prefer betterAuth(auth) over writing manual auth middleware. The adapter handles session fetching, cookie integration, typing, and unauthorized rejection automatically.
Supporting Docs
- Custom authorize patterns (role checks, redirects, org access)


