Set the secret first
BETTER_AUTH_SECRET signs every session token and auth cookie. Without a real one, nothing authenticates.
.env
BETTER_AUTH_URL at your public URL so OAuth callbacks resolve:
.env
Endpoints
Better Auth owns everything under/api/auth/[...all]. These routes are wired for you.
Shoppers do not need an account
A Guest can buy without registering. Guest Carts are tracked with aguestId cookie set on first visit.
The target behavior is that a Shopper who registers later inherits their earlier Guest Orders. That continuity is built but not yet proven in production, so do not promise automatic Order claiming to your Shoppers until the release notes mark it Stable.
Social login does not work yet
.env.example lists Google, X, Slack, Shopify, Apple, and Facebook credentials. The current auth package does not read them. Setting them enables nothing, and there is no error to tell you so.
Do not advertise those sign-in methods to your Shoppers until the auth package implements and tests them.
Store Admin access
Admin users hold theadmin role. Only they can reach /admin, manage Products and Orders, or upload files.
The seeded account
86d init and docker compose up create a Store Admin account. The defaults are admin@example.com and password123.
Store Admin currently has no screen for adding more admin users. For a Store you host yourself, use the seeded account with a replaced password. Managed deployments can use 86d.app sign-in instead. Do not build a workflow that depends on inviting a second admin until that Feature ships.
86d.app single sign-on
Set both OAuth client values to let people sign in to Store Admin with their 86d Account.86D_API_URL supplies the OpenID discovery origin.
.env
openid, profile, email, and store:admin scopes. The Store grants a local admin role only when the returned profile carries the admin role or the store:admin scope. Leave either client value unset and the provider stays off.
This is a separate OAuth client from anything a machine uses.
86D_WORKLOAD_CREDENTIAL cannot authenticate a person, and this client secret cannot authenticate a workload. Keep it out of browser code, logs, agent output, Templates, and merchant-readable settings.