t3-code-android-nightly/.repos/alchemy-effect/examples/cloudflare-better-auth
Julius Marminge 6f9cea00ae
chore(refs): sync Effect and Alchemy references to 4.0.1 and beta.80 (#16170)
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-05 13:22:30 -07:00
..
public chore(refs): sync Effect and Alchemy references to 4.0.1 and beta.80 (#16170) 2026-10-05 13:22:30 -07:00
src chore(refs): sync Effect and Alchemy references to 4.0.1 and beta.80 (#16170) 2026-10-05 13:22:30 -07:00
test chore(refs): sync Effect and Alchemy references to 4.0.1 and beta.80 (#16170) 2026-10-05 13:22:30 -07:00
.env.example chore(refs): sync Effect and Alchemy references to 4.0.1 and beta.80 (#16170) 2026-10-05 13:22:30 -07:00
.gitignore chore(refs): sync Effect and Alchemy references to 4.0.1 and beta.80 (#16170) 2026-10-05 13:22:30 -07:00
alchemy.run.ts chore(refs): sync Effect and Alchemy references to 4.0.1 and beta.80 (#16170) 2026-10-05 13:22:30 -07:00
package.json chore(refs): sync Effect and Alchemy references to 4.0.1 and beta.80 (#16170) 2026-10-05 13:22:30 -07:00
README.md chore(refs): sync Effect and Alchemy references to 4.0.1 and beta.80 (#16170) 2026-10-05 13:22:30 -07:00
tsconfig.json chore(refs): sync Effect and Alchemy references to 4.0.1 and beta.80 (#16170) 2026-10-05 13:22:30 -07:00

Cloudflare Better Auth

Executable companion to the six-part Better Auth tutorial.

Run locally

From the repository root:

pnpm install
cd examples/cloudflare-better-auth
bun run dev

Use a configured Cloudflare profile. Alchemy chooses an available port and prints the URL; the local Worker and D1 run without provisioning cloud resources.

Open that URL, create an account, and sign out and back in. The page displays the current user and the protected API response without exposing session tokens.

Verify the HTTP flow

In another terminal in this example directory, paste the printed URL after read and press Enter:

read -r BETTER_AUTH_TEST_URL
export BETTER_AUTH_TEST_URL
timeout 60 bun test

The test creates a disposable account and checks cookies, sessions, public access, and sign-out rejection. Use a disposable database rather than production.

Enable GitHub

cp .env.example .env

Replace the dummy credentials with your GitHub OAuth application's values and enable the provider:

GITHUB_ENABLED=true
GITHUB_CLIENT_ID=your-oauth-client-id
GITHUB_CLIENT_SECRET=your-oauth-client-secret

Use the running application's origin to construct the registered callback:

printf '%s/api/auth/callback/github\n' "$BETTER_AUTH_TEST_URL"

Restart the dev command after configuration changes and check its printed URL. Update the registered callback if that URL changed; no fixed local port is required.

The page shows the GitHub button only when enabled. The public provider endpoint exposes that flag, never credentials.

Deploy

bun run deploy --stage production

Use separate production OAuth credentials and register the deployed callback URL. Optionally set AUTH_BASE_URL to your production origin; leave it unset locally to use the incoming request's origin.

Alchemy binds the database, migrates the schema, and preserves the generated signing secret through stack state. Keep that state for later deployments.

Remove the deployment

bun run destroy --stage production

Use the exact stage and profile of the deployment you intend to remove. The generated browser bundle in public/ui.js is ignored by Git.