Skip to main content
In development. 86d is being built in the open. Every capability is Experimental until it earns evidence, so check maturity levels before you rely on anything here.
A Store handles two kinds of sign-in: Shoppers reaching their Customer account, and you reaching Store Admin. Both run on Better Auth. Get this configured before the Store is reachable by anyone other than you.

Set the secret first

BETTER_AUTH_SECRET signs every session token and auth cookie. Without a real one, nothing authenticates.
.env
Production refuses to start when this value is missing, under 32 characters, a known default, or too predictable to pass an entropy check. Development and test fall back to a local-only value, and production rejects that fallback by name.
Point BETTER_AUTH_URL at your public URL so OAuth callbacks resolve:
.env

Endpoints

Better Auth owns everything under /api/auth/[...all]. These routes are wired for you.

Shoppers do not need an account

A Guest can buy without registering. Guest Carts are tracked with a guestId cookie set on first visit. The target behavior is that a Shopper who registers later inherits their earlier Guest Orders. That continuity is built but not yet proven in production, so do not promise automatic Order claiming to your Shoppers until the release notes mark it Stable.

Social login does not work yet

.env.example lists Google, X, Slack, Shopify, Apple, and Facebook credentials. The current auth package does not read them. Setting them enables nothing, and there is no error to tell you so. Do not advertise those sign-in methods to your Shoppers until the auth package implements and tests them.

Store Admin access

Admin users hold the admin role. Only they can reach /admin, manage Products and Orders, or upload files.

The seeded account

86d init and docker compose up create a Store Admin account. The defaults are admin@example.com and password123.
Change that password before the Store is reachable from the internet. It is published in these docs, so treat the default as already compromised.
Store Admin currently has no screen for adding more admin users. For a Store you host yourself, use the seeded account with a replaced password. Managed deployments can use 86d.app sign-in instead. Do not build a workflow that depends on inviting a second admin until that Feature ships.

86d.app single sign-on

Set both OAuth client values to let people sign in to Store Admin with their 86d Account. 86D_API_URL supplies the OpenID discovery origin.
.env
The provider asks for the openid, profile, email, and store:admin scopes. The Store grants a local admin role only when the returned profile carries the admin role or the store:admin scope. Leave either client value unset and the provider stays off.
This is a separate OAuth client from anything a machine uses. 86D_WORKLOAD_CREDENTIAL cannot authenticate a person, and this client secret cannot authenticate a workload. Keep it out of browser code, logs, agent output, Templates, and merchant-readable settings.

Email and password

Email and password sign-in is on by default. Customers and admins register and sign in with an address and a password, hashed by Better Auth’s configured hasher. The pinned version uses scrypt.
The current configuration registers no password-reset or verification-email callbacks. RESEND_API_KEY alone does not create those flows. A Shopper who forgets their password today has no way back in. Use email and password only where you have tested a recovery path, or use 86d.app sign-in.