[{"data":1,"prerenderedAt":596},["ShallowReactive",2],{"navigation_docs":3,"-core-concepts-server-auth":208,"-core-concepts-server-auth-surround":591},[4,42,68,115,136,157],{"title":5,"path":6,"stem":7,"children":8,"icon":11},"Getting Started","\u002Fgetting-started","1.getting-started\u002F0.index",[9,12,17,22,27,32,37],{"title":10,"path":6,"stem":7,"icon":11},"Introduction","i-lucide-sparkles",{"title":13,"path":14,"stem":15,"icon":16},"Installation","\u002Fgetting-started\u002Finstallation","1.getting-started\u002F1.installation","i-lucide-download",{"title":18,"path":19,"stem":20,"icon":21},"Configuration","\u002Fgetting-started\u002Fconfiguration","1.getting-started\u002F2.configuration","i-lucide-settings",{"title":23,"path":24,"stem":25,"icon":26},"Client Setup","\u002Fgetting-started\u002Fclient-setup","1.getting-started\u002F3.client-setup","i-lucide-monitor",{"title":28,"path":29,"stem":30,"icon":31},"Type Augmentation","\u002Fgetting-started\u002Ftype-augmentation","1.getting-started\u002F4.type-augmentation","i-lucide-type",{"title":33,"path":34,"stem":35,"icon":36},"Schema Generation (NuxtHub)","\u002Fgetting-started\u002Fschema-generation","1.getting-started\u002F5.schema-generation","i-lucide-database",{"title":38,"path":39,"stem":40,"icon":41},"How It Works","\u002Fgetting-started\u002Fhow-it-works","1.getting-started\u002F6.how-it-works","i-lucide-workflow",{"title":43,"path":44,"stem":45,"children":46,"page":67},"Core Concepts","\u002Fcore-concepts","2.core-concepts",[47,51,55,59,63],{"title":48,"path":49,"stem":50},"serverAuth()","\u002Fcore-concepts\u002Fserver-auth","2.core-concepts\u002F1.server-auth",{"title":52,"path":53,"stem":54},"Sessions","\u002Fcore-concepts\u002Fsessions","2.core-concepts\u002F2.sessions",{"title":56,"path":57,"stem":58},"Route Protection","\u002Fcore-concepts\u002Froute-protection","2.core-concepts\u002F3.route-protection",{"title":60,"path":61,"stem":62},"Auto‑Imports and Aliases","\u002Fcore-concepts\u002Fauto-imports-aliases","2.core-concepts\u002F4.auto-imports-aliases",{"title":64,"path":65,"stem":66},"Security & Caveats","\u002Fcore-concepts\u002Fsecurity-caveats","2.core-concepts\u002F5.security-caveats",false,{"title":69,"path":70,"stem":71,"children":72,"page":67},"Guides","\u002Fguides","3.guides",[73,77,82,86,90,94,99,103,107,111],{"title":74,"path":75,"stem":76},"Role‑Based Access","\u002Fguides\u002Frole-based-access","3.guides\u002F1.role-based-access",{"title":78,"path":79,"stem":80,"icon":81},"Setup diagnostics","\u002Fguides\u002Fdiagnostics","3.guides\u002F10.diagnostics","i-lucide-circle-alert",{"title":83,"path":84,"stem":85},"OAuth Providers","\u002Fguides\u002Foauth-providers","3.guides\u002F2.oauth-providers",{"title":87,"path":88,"stem":89},"Custom Database","\u002Fguides\u002Fcustom-database","3.guides\u002F3.custom-database",{"title":91,"path":92,"stem":93},"Database-less Mode","\u002Fguides\u002Fdatabase-less-mode","3.guides\u002F4.database-less-mode",{"title":95,"path":96,"stem":97,"icon":98},"External Auth Backend","\u002Fguides\u002Fexternal-auth-backend","3.guides\u002F5.external-auth-backend","i-lucide-server",{"title":100,"path":101,"stem":102},"Migrating from nuxt-auth-utils","\u002Fguides\u002Fmigrate-from-nuxt-auth-utils","3.guides\u002F6.migrate-from-nuxt-auth-utils",{"title":104,"path":105,"stem":106},"Two-Factor Authentication (TOTP + Backup Codes)","\u002Fguides\u002Ftwo-factor-auth","3.guides\u002F7.two-factor-auth",{"title":108,"path":109,"stem":110},"Testing","\u002Fguides\u002Ftesting","3.guides\u002F8.testing",{"title":112,"path":113,"stem":114},"Production Deployment","\u002Fguides\u002Fproduction-deployment","3.guides\u002F9.production-deployment",{"title":116,"path":117,"stem":118,"children":119,"page":67},"Integrations","\u002Fintegrations","4.integrations",[120,124,128,132],{"title":121,"path":122,"stem":123},"NuxtHub","\u002Fintegrations\u002Fnuxthub","4.integrations\u002F1.nuxthub",{"title":125,"path":126,"stem":127},"DevTools","\u002Fintegrations\u002Fdevtools","4.integrations\u002F2.devtools",{"title":129,"path":130,"stem":131},"Convex","\u002Fintegrations\u002Fconvex","4.integrations\u002F3.convex",{"title":133,"path":134,"stem":135},"i18n","\u002Fintegrations\u002Fi18n","4.integrations\u002F4.i18n",{"title":137,"path":138,"stem":139,"children":140,"page":67},"API Reference","\u002Fapi","5.api",[141,145,149,153],{"title":142,"path":143,"stem":144},"Composables","\u002Fapi\u002Fcomposables","5.api\u002F1.composables",{"title":146,"path":147,"stem":148},"Server Utilities","\u002Fapi\u002Fserver-utils","5.api\u002F2.server-utils",{"title":150,"path":151,"stem":152},"Components","\u002Fapi\u002Fcomponents","5.api\u002F3.components",{"title":154,"path":155,"stem":156},"Types","\u002Fapi\u002Ftypes","5.api\u002F4.types",{"title":158,"path":159,"stem":160,"children":161,"icon":81},"Errors","\u002Ferrors","6.errors\u002F0.index",[162,164,168,172,176,180,184,188,192,196,200,204],{"title":163,"path":159,"stem":160},"Overview",{"title":165,"path":166,"stem":167},"Auth configuration failed to load","\u002Ferrors\u002Fnuxt-auth-config-load-failed","6.errors\u002Fnuxt-auth-config-load-failed",{"title":169,"path":170,"stem":171},"Schema generator returned no code","\u002Ferrors\u002Fnuxt-auth-empty-schema","6.errors\u002Fnuxt-auth-empty-schema",{"title":173,"path":174,"stem":175},"Invalid server auth config export","\u002Ferrors\u002Fnuxt-auth-invalid-config-export","6.errors\u002Fnuxt-auth-invalid-config-export",{"title":177,"path":178,"stem":179},"Auth plugin path must be absolute","\u002Ferrors\u002Fnuxt-auth-invalid-plugin-source","6.errors\u002Fnuxt-auth-invalid-plugin-source",{"title":181,"path":182,"stem":183},"Missing auth configuration","\u002Ferrors\u002Fnuxt-auth-missing-config","6.errors\u002Fnuxt-auth-missing-config",{"title":185,"path":186,"stem":187},"NuxtHub database alias is missing","\u002Ferrors\u002Fnuxt-auth-missing-hub-db","6.errors\u002Fnuxt-auth-missing-hub-db",{"title":189,"path":190,"stem":191},"No database provider is enabled","\u002Ferrors\u002Fnuxt-auth-no-database-provider","6.errors\u002Fnuxt-auth-no-database-provider",{"title":193,"path":194,"stem":195},"Auth schema generation failed","\u002Ferrors\u002Fnuxt-auth-schema-generation-failed","6.errors\u002Fnuxt-auth-schema-generation-failed",{"title":197,"path":198,"stem":199},"Custom session storage is missing","\u002Ferrors\u002Fnuxt-auth-schema-storage-required","6.errors\u002Fnuxt-auth-schema-storage-required",{"title":201,"path":202,"stem":203},"Secondary storage in client-only mode","\u002Ferrors\u002Fnuxt-auth-storage-client-only","6.errors\u002Fnuxt-auth-storage-client-only",{"title":205,"path":206,"stem":207},"Unsupported database dialect","\u002Ferrors\u002Fnuxt-auth-unsupported-dialect","6.errors\u002Fnuxt-auth-unsupported-dialect",{"id":209,"title":48,"body":210,"description":585,"extension":586,"links":587,"meta":588,"navigation":240,"path":49,"seo":589,"stem":50,"__hash__":590},"docs\u002F2.core-concepts\u002F1.server-auth.md",{"type":211,"value":212,"toc":581},"minimark",[213,284,288,320,391,396,513,518,521,525,564,577],[214,215,216],"code-collapse",{},[217,218,224],"pre",{"className":219,"code":220,"filename":221,"language":222,"meta":223,"style":223},"language-txt shiki shiki-themes one-light synthwave-84 synthwave-84","Use server-side auth utilities in @nuxtjs\u002Fbetter-auth.\n\n- `serverAuth(event?)` — returns the Better Auth instance. Pass `event` in Nitro handlers for request-scoped database access and configuration context\n- `getUserSession(event)` — get current session (auto-imported in `server\u002F`)\n- `requireUserSession(event, options?)` — throws 401 if not authenticated, supports role matching\n- `getRequestSession(event)` — request-cached session, preferred over repeated `getUserSession` in same request\n- `setRequestSession(event, session)` — supply an authenticated session to downstream helpers for the current request\n- `refreshSessionCookieCache(event)` — refresh Better Auth's cached session cookie after server-side session data changes\n- All server utils are auto-imported, no import statements needed\n","Prompt","txt","",[225,226,227,235,242,248,254,260,266,272,278],"code",{"__ignoreMap":223},[228,229,232],"span",{"class":230,"line":231},"line",1,[228,233,234],{},"Use server-side auth utilities in @nuxtjs\u002Fbetter-auth.\n",[228,236,238],{"class":230,"line":237},2,[228,239,241],{"emptyLinePlaceholder":240},true,"\n",[228,243,245],{"class":230,"line":244},3,[228,246,247],{},"- `serverAuth(event?)` — returns the Better Auth instance. Pass `event` in Nitro handlers for request-scoped database access and configuration context\n",[228,249,251],{"class":230,"line":250},4,[228,252,253],{},"- `getUserSession(event)` — get current session (auto-imported in `server\u002F`)\n",[228,255,257],{"class":230,"line":256},5,[228,258,259],{},"- `requireUserSession(event, options?)` — throws 401 if not authenticated, supports role matching\n",[228,261,263],{"class":230,"line":262},6,[228,264,265],{},"- `getRequestSession(event)` — request-cached session, preferred over repeated `getUserSession` in same request\n",[228,267,269],{"class":230,"line":268},7,[228,270,271],{},"- `setRequestSession(event, session)` — supply an authenticated session to downstream helpers for the current request\n",[228,273,275],{"class":230,"line":274},8,[228,276,277],{},"- `refreshSessionCookieCache(event)` — refresh Better Auth's cached session cookie after server-side session data changes\n",[228,279,281],{"class":230,"line":280},9,[228,282,283],{},"- All server utils are auto-imported, no import statements needed\n",[285,286,287],"p",{},"Use this page when you need authentication state or Better Auth APIs inside Nitro handlers, middleware, plugins, or other server-side code.",[285,289,290,293,294,297,298,301,302,305,306,308,309,312,313,316,317,319],{},[225,291,292],{},"serverAuth(event?)"," returns the Better Auth instance. Pass ",[225,295,296],{},"event"," in Nitro handlers for request-scoped database access and ",[225,299,300],{},"ctx.requestOrigin",". In production, the canonical auth URL comes from ",[225,303,304],{},"runtimeConfig.public.siteUrl"," or platform environment variables. Development can infer it from the request. Outside request contexts, such as seed scripts and tasks, call ",[225,307,48],{}," without an event. On Nuxt 4.6+, when the auth secret is derived from ",[225,310,311],{},"NUXT_APP_SECRET",", it is resolved asynchronously: the module starts it when the server starts and awaits it in its handlers, middleware, and session utilities. Code that runs at server startup, such as a Nitro plugin, should use ",[225,314,315],{},"await ensureServerAuth()",", which waits for the secret and then returns the same instance as ",[225,318,48],{},".",[217,321,326],{"className":322,"code":323,"filename":324,"language":325,"meta":223,"style":223},"language-ts shiki shiki-themes one-light synthwave-84 synthwave-84","export default defineNitroPlugin(async () => {\n  const auth = await ensureServerAuth()\n  \u002F\u002F ...\n})\n","server\u002Fplugins\u002Fseed.ts","ts",[225,327,328,358,380,386],{"__ignoreMap":223},[228,329,330,334,338,342,346,349,352,355],{"class":230,"line":231},[228,331,333],{"class":332},"sqe1H","export",[228,335,337],{"class":336},"sKg8T"," default",[228,339,341],{"class":340},"sfT9l"," defineNitroPlugin",[228,343,345],{"class":344},"s17Py","(",[228,347,348],{"class":332},"async",[228,350,351],{"class":344}," () ",[228,353,354],{"class":332},"=>",[228,356,357],{"class":344}," {\n",[228,359,360,363,367,371,374,377],{"class":230,"line":237},[228,361,362],{"class":332},"  const",[228,364,366],{"class":365},"s6Rhl"," auth",[228,368,370],{"class":369},"sQBpM"," =",[228,372,373],{"class":332}," await",[228,375,376],{"class":340}," ensureServerAuth",[228,378,379],{"class":344},"()\n",[228,381,382],{"class":230,"line":244},[228,383,385],{"class":384},"st7cf","  \u002F\u002F ...\n",[228,387,388],{"class":230,"line":250},[228,389,390],{"class":344},"})\n",[392,393,395],"h2",{"id":394},"when-to-use-what","When to Use What",[397,398,399,415],"table",{},[400,401,402],"thead",{},[403,404,405,409,412],"tr",{},[406,407,408],"th",{},"Task",[406,410,411],{},"Use",[406,413,414],{},"Example",[416,417,418,432,445,458,471,484,500],"tbody",{},[403,419,420,424,429],{},[421,422,423],"td",{},"Get request-cached session context",[421,425,426],{},[225,427,428],{},"getRequestSession(event)",[421,430,431],{},"Cache once per request with context-backed storage when available",[403,433,434,437,442],{},[421,435,436],{},"Supply a request session",[421,438,439],{},[225,440,441],{},"setRequestSession(event, session)",[421,443,444],{},"Reuse a session resolved by trusted server authentication",[403,446,447,450,455],{},[421,448,449],{},"Get current session",[421,451,452],{},[225,453,454],{},"getUserSession(event)",[421,456,457],{},"Check if user is logged in",[403,459,460,463,468],{},[421,461,462],{},"Refresh cached session cookie",[421,464,465],{},[225,466,467],{},"refreshSessionCookieCache(event)",[421,469,470],{},"Use after updating data returned by Better Auth session helpers",[403,472,473,476,481],{},[421,474,475],{},"Require authentication",[421,477,478],{},[225,479,480],{},"requireUserSession(event)",[421,482,483],{},"Protect an API route",[403,485,486,489,494],{},[421,487,488],{},"Access Better Auth API",[421,490,491],{},[225,492,493],{},"serverAuth(event)",[421,495,496,497],{},"Call ",[225,498,499],{},"auth.api.listSessions()",[403,501,502,505,510],{},[421,503,504],{},"Get session with options",[421,506,507],{},[225,508,509],{},"requireUserSession(event, { user: { role: 'admin' } })",[421,511,512],{},"Role-based protection",[285,514,515,517],{},[225,516,467],{}," refreshes the cached session cookie. It does not update the session or user record; perform that update first.",[519,520],"read-more",{"to":147},[392,522,524],{"id":523},"server-endpoint-path","Server endpoint path",[285,526,527,528,531,532,535,536,539,540,543,544,547,548,550,551,554,555,557,558,560,561,563],{},"The module registers Better Auth at ",[225,529,530],{},"\u002Fapi\u002Fauth"," within the Nuxt app. If ",[225,533,534],{},"app.baseURL"," is ",[225,537,538],{},"\u002Fapp\u002F",", the public endpoints and generated callback URLs use ",[225,541,542],{},"\u002Fapp\u002Fapi\u002Fauth",". ",[225,545,546],{},"defineServerAuth"," accepts only ",[225,549,530],{}," as ",[225,552,553],{},"basePath"," and rejects other values when resolving the config. Remove a custom server ",[225,556,553],{}," or set it to ",[225,559,530],{},"; the module includes ",[225,562,534],{}," automatically.",[285,565,566,567,570,571,573,574,319],{},"External backends configured with ",[225,568,569],{},"auth.clientOnly: true"," can still use a custom ",[225,572,553],{}," in ",[225,575,576],{},"defineClientAuth",[578,579,580],"style",{},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sqe1H, html code.shiki .sqe1H{--shiki-light:#A626A4;--shiki-default:#FEDE5D;--shiki-dark:#FEDE5D}html pre.shiki code .sKg8T, html code.shiki .sKg8T{--shiki-light:#E45649;--shiki-default:#FEDE5D;--shiki-dark:#FEDE5D}html pre.shiki code .sfT9l, html code.shiki .sfT9l{--shiki-light:#4078F2;--shiki-default:#36F9F6;--shiki-dark:#36F9F6}html pre.shiki code .s17Py, html code.shiki .s17Py{--shiki-light:#383A42;--shiki-default:#BBBBBB;--shiki-dark:#BBBBBB}html pre.shiki code .s6Rhl, html code.shiki .s6Rhl{--shiki-light:#986801;--shiki-default:#FF7EDB;--shiki-dark:#FF7EDB}html pre.shiki code .sQBpM, html code.shiki .sQBpM{--shiki-light:#0184BC;--shiki-default:#FFFFFFEE;--shiki-dark:#FFFFFFEE}html pre.shiki code .st7cf, html code.shiki .st7cf{--shiki-light:#A0A1A7;--shiki-light-font-style:italic;--shiki-default:#848BBD;--shiki-default-font-style:italic;--shiki-dark:#848BBD;--shiki-dark-font-style:italic}",{"title":223,"searchDepth":237,"depth":237,"links":582},[583,584],{"id":394,"depth":237,"text":395},{"id":523,"depth":237,"text":524},"When to reach for the full Better Auth server instance.","md",null,{},{"title":48,"description":585},"OG3cMivIiR0raRbf-x6iwz1oQA5NMp0SIE2IVtyF35U",[592,594],{"title":38,"path":39,"stem":40,"description":593,"icon":41,"children":-1},"Understand the architecture after completing setup.",{"title":52,"path":53,"stem":54,"description":595,"children":-1},"Access reactive session state with SSR support using `useUserSession()`.",1791297060640]