Back to Explore

better-auth/utils

GitHub
2 updates · last 90 days1 watchersOpen source

Last release:

@better-auth/utils is a simple TypeScript API that provides common authentication related cryptography utilities such as hashing, HMAC, RSA and ECDSA signing and verification, random string generation, OTP (HOTP/TOTP), and base64, hex, and binary encoding. It is built on top of Web Crypto APIs and supports both Node.js (using the Crypto module) and web environments via conditional exports.

Project status

  • Actively maintained: The source shows ongoing commits and package updates in 2026, with an upstream push on 2026-09-01, and multiple tagged updates in the following months.
  • Update cadence: After 2026-06-15, there were updates on 2026-07-25 (two versions) and at least one upstream push on 2026-09-01, suggesting a roughly 1 to 3 month pattern in this timeframe.

AI summary generated

AI-generated from public sources. May be inaccurate. Report

Recent updates

  • v0.5.0

    v0.5.0 focuses on handling of typed arrays for encoding utilities, specifically BigInt typed arrays. The diff narrows encoder input types to number-based TypedArrays and adds/adjusts runtime behavior and tests accordingly, plus includes a dev tooling change (lefthook) that is not described in the release notes.

    Breaking
  • v0.4.3

    v0.4.3 is primarily a set of bug fixes around encoding handling for HMAC and binary encoding. The code diff also includes a broader internal refactor of string and binary data normalization for crypto operations, plus a new hex-to-bytes helper and build toolchain changes.

    Features
  • v0.4.2

    v0.4.2 focuses on improving OTP verification security by avoiding early exits when checking TOTP codes. The core change modifies the TOTP verification loop to use constant-time equality, and adds a test to ensure all window candidates are evaluated. The release also updates GitHub release workflow behavior and small package.json metadata/scripts without mentioning them in the release notes.

    Security
  • v0.4.1

    Release v0.4.1 focuses on fixing the `password` entrypoint so it has the correct conditional export for the workerd runtime. In the same release, several repository and build workflow changes were made (Node version selection, pinned GitHub Actions, and workspace build settings), which are not described in the release notes.

  • v0.4.0

    v0.4.0 introduces a new password utility module that hashes and verifies passwords using scrypt with NFKC normalization. It includes both a node:crypto implementation (scrypt) and a default implementation based on @noble/hashes, wired up via conditional package exports.

    Features
  • v0.3.1

    v0.3.1 is a small update focused on a TypeScript 5.7 typing mismatch around Uint8Array (including Deno 2.2 behavior). The code changes introduce a compatibility type alias (Uint8Array_) and apply it to Base32/Base64 encode/decode signatures.

  • v0.3.0

    v0.3.0 removes the `uncrypto` dependency and switches the library to use the platform Web Crypto APIs directly. The code introduces a new helper `getWebcryptoSubtle()` and updates hashing, HMAC, RSA, and ECDSA implementations to call `crypto.subtle` via this helper.

  • v0.2.6

    v0.2.6 primarily updates the @better-auth/utils package metadata and dependency layout. The release notes state a single change: TypeScript was removed from runtime dependencies.

    Breaking
  • v0.2.5

    v0.2.5 includes bug fixes for the project. It corrects a README import path and updates the random string generator to fix modulo bias in character selection.

  • v0.2.4

    v0.2.4 is primarily a fix to random string generation so that when multiple alphabets are provided, they are combined rather than partially ignored. The code change also updates the TypeScript typing and introduces a test-side module mock adjustment.