Back to Explore

better-auth/better-call

GitHub
4 updates · last 90 days1 watchersOpen source

Last release:

Better Call is a tiny TypeScript web framework for defining typed endpoints and invoking them either as normal functions or by mounting them to a router served by standard-compatible servers like Bun, Node, Next.js, or SvelteKit. It also includes a typed RPC client for type-safe client-side calls to those endpoints, with validation support via standard schema libraries like Zod.

Project status

  • Actively maintained: The repo shows an upstream push today (2026-10-02) and a very recent update (v1.4.1 on 2026-10-01), with additional updates earlier in 2026 (June and August).
  • Cadence: Updates appear to be on a fairly steady rhythm in 2026, with at least a couple of substantial changes between spring/summer and another change just after (v1.3.x in June, v1.4.0 in August, v1.4.1 in October).

AI summary generated

AI-generated from public sources. May be inaccurate. Report

Recent updates

  • v1.4.1

    Release v1.4.1 primarily focuses on cookie security behavior. The code change refactors cookie serialization to ensure required browser attributes are applied, and it adds tests for prefix and attribute handling.

    Security
  • v1.4.0

    v1.4.0 primarily refactors TypeScript types to align route parameter inference with rou3 and tightens the typing around middleware and endpoint contexts. The code also bumps the rou3 dependency to a newer version, and introduces new type-level constructs (MiddlewareHandler, updated EndpointContext generics) that affect how developers type their handlers.

    Breaking
  • v1.3.8

    Release v1.3.8 release notes only mention a packaging fix to include the README in the published npm package. However, the actual diff contains several substantive runtime and typing changes, including router basePath routing behavior, response header handling and Set-Cookie merging rules, JSON parse error handling, and serialization behavior.

    Features
  • v2.0.6

    Release v2.0.6’s release notes only mention a packaging fix (including the README in the published package). The actual code diff shows a much larger v2.0.x refactor with changes to public exports, router basePath routing semantics, client typing behavior, and multiple type system adjustments that are not described in the release notes.

    Breaking
  • v1.3.7

    v1.3.7 tightens how `createRouter` handles the `basePath` configuration. Instead of stripping `basePath` wherever it appears in the pathname, it now only strips when the request path starts with `basePath` as a proper leading path segment prefix.

  • v2.0.5

    v2.0.5 is described as a small router bug fix: it now strips basePath only when it is a leading prefix. The code diff shows this, but it also contains several additional behavior and API surface changes that are not mentioned in the release notes.

  • v1.3.6

    v1.3.6 adds `responseHeaders` to `EndpointContext`, letting handlers inspect the live response header accumulator while other middleware/handler steps run. The release also includes fixes around streaming responses, JSON body parsing for empty input, and preserving multiple `Set-Cookie` headers when merging headers.

    Features
  • v2.0.4

    v2.0.4 primarily focuses on developer ergonomics and response handling. It exposes a live responseHeaders accumulator on EndpointContext, improves error behavior for empty JSON bodies, fixes streaming response truncation, and ensures Set-Cookie headers are preserved correctly when merging headers.

    Features
  • v1.3.5

    Release v1.3.5 has release notes that state there are no significant changes, however the code diff shows multiple functional and build-time modifications. The most impactful change is in response generation, where request-only and hop-by-hop headers are now stripped from Headers provided via the response init (including when converting APIError to a Response).

    BreakingSecurity
  • v2.0.3

    v2.0.3 focuses on bug fixes. It updates toResponse() to strip request-only headers from response headers to avoid protocol issues like Content-Length mismatches, and it makes Endpoint properties readonly while improving OpenAPI schema typing.

    Breaking