CLI
Learn about the Better Auth CLI commands for generating and migrating database schemas, creating initial admins, initializing projects, generating secret keys, and gathering diagnostic info.
Better Auth comes with a built-in CLI to help you manage the database schemas, create initial admin users, initialize your project, generate a secret key for your application, and gather diagnostic information about your setup.
Generate
The generate command creates the schema required by Better Auth. If you're using a database adapter like Prisma or Drizzle, this command will generate the right schema for your ORM. If you're using the built-in Kysely adapter, it will generate an SQL file you can run directly on your database.
npx auth@latest generateOptions
--output- Where to save the generated schema. For Prisma, it will be saved in prisma/schema.prisma. For Drizzle, it goes to schema.ts in your project root. For Kysely, it's an SQL file saved as schema.sql in your project root.--config- The path to your Better Auth config file. By default, the CLI will search for an auth.ts file in ./, ./utils, ./lib, or any of these directories under thesrcdirectory.--yes- Skip the confirmation prompt and generate the schema directly.
Migrate
The migrate command applies the Better Auth schema directly to your database. This is available if you're using the built-in Kysely adapter. For other adapters, you'll need to apply the schema using your ORM's migration tool.
npx auth@latest migrateOptions
--config- The path to your Better Auth config file. By default, the CLI will search for an auth.ts file in ./, ./utils, ./lib, or any of these directories under thesrcdirectory.--yes- Skip the confirmation prompt and apply the schema directly.
Using PostgreSQL with a non-default schema?
The migrate command automatically detects your configured search_path and creates tables in the correct schema. See the PostgreSQL adapter documentation for configuration details.
Create Admin
The create-admin command creates an initial admin user through your configured Better Auth instance. It requires the Admin plugin and a persistent database, and it uses the same server-side auth.api.createUser path as the Admin plugin so passwords are hashed and database hooks still run.
npx auth@latest create-admin --email admin@example.com --name "Admin" --role adminIf users already exist, the command asks for confirmation. Use --force or --yes to skip that prompt.
Options
--email- The email address for the admin user.--password- The password for the admin user. If omitted, the CLI will prompt for it.--name- The name for the admin user. Defaults toAdmin.--role- The role to assign. Defaults toadmin.--data- Additional user fields as a JSON object.--no-email-verified- Create the admin user with an unverified email. By default, the CLI marks the admin email as verified.--config- The path to your Better Auth config file.--force- Create the admin user even when users already exist.--yes- Skip the existing-users confirmation prompt.
Init
The init command allows you to initialize Better Auth in your project.
npx auth@latest initOptions
--name- The name of your application. (defaults to thenameproperty in yourpackage.json).--framework- The framework your codebase is using. Currently, the only supported framework isNext.js.--plugins- The plugins you want to use. You can specify multiple plugins by separating them with a comma.--database- The database you want to use. Currently, the only supported database isSQLite.--package-manager- The package manager you want to use. Currently, the only supported package managers arenpm,pnpm,yarn,bun(defaults to the manager you used to initialize the CLI).
Upgrade
The upgrade command updates older better-auth dependencies and official @better-auth/* packages that participate in the synchronized release train to the version of the CLI being run. It compares the minimum version allowed by each package.json specifier; specifiers whose minimum is the same or newer are left unchanged. Independently versioned packages, such as @better-auth/utils, are not changed.
npx auth@latest upgradeOptions
--cwd- The project directory containing thepackage.jsonto update. Defaults to the current directory.--yes- Skip the confirmation prompt and install the updates directly.
Info
The info command provides diagnostic information about your Better Auth setup and environment. Useful for debugging and sharing when seeking support.
npx auth@latest infoOutput
The command displays:
- System: OS, CPU, memory, Node.js version
- Package Manager: Detected manager and version
- Better Auth: Version and configuration (sensitive data auto-redacted)
- Frameworks: Detected frameworks (Next.js, React, Vue, etc.)
- Databases: Database clients and ORMs (Prisma, Drizzle, etc.)
Options
--config- Path to your Better Auth config file--json- Output as JSON for sharing or programmatic use
Examples
# Basic usage
npx auth@latest info
# Custom config path
npx auth@latest info --config ./config/auth.ts
# JSON output
npx auth@latest info --json > auth-info.jsonSensitive data like secrets, API keys, and database URLs are automatically replaced with [REDACTED] for safe sharing.
Secret
The CLI also provides a way to generate a secret key for your Better Auth instance.
npx auth@latest secretCommon Issues
Error: Cannot find module X
The CLI resolves most imports for you: tsconfig.json path aliases (including SvelteKit's $lib) and stubbed framework virtual modules ($env/*, $app/*, cloudflare:workers, Vite assets like ?raw). For SvelteKit, run svelte-kit sync first so .svelte-kit/tsconfig.json exists.
A few module types can't load outside their bundler (e.g. .svelte components or import.meta.glob). Keep those out of your config file's import graph.