Certified authentication
A better-auth‑compatible auth server. Your data in your PostgreSQL — sealed, sovereign, certified.
Point any better-auth client at your own instance and own every credential end to end. Signet runs behind your walls, needs nothing from the public internet, and carries a recorded compatibility receipt so you can verify the seal before you trust it.
✦ Certification receipt
Compatibility profile
better-auth 1.6.23
recorded · 2026-07-22
Certification gap
0
recorded · 2026-07-22
End-to-end acceptance
14 / 14
recorded · 2026-07-22
Profile version
Signet compatibility profile v1
recorded · 2026-07-22
A recorded pointer to Signet's better-auth compatibility run, not an implied cryptographic attestation. Read the full receipt at /certification (JSON).
What you get
Own your auth. Users, sessions, and secrets live in your Postgres. No third party sits between you and the people who sign in.
Air‑gap capable. The docs, the generated config reference, and the machine on-ramp all travel inside the binary. A sealed network gets the identical experience, offline, at 2am.
Drop‑in for better-auth. Signet speaks the better-auth HTTP wire protocol. Existing better-auth client libraries integrate unchanged — no rewrite, gap 0.
Integrate in three steps
- Write
signet.tomlwith this instance's public origin and a Postgres DSN. - Provide the secret and database URL out-of-band, then boot. Migrations run on start.
- Point your better-auth client at
/api/authon this origin.
Full quickstart and the generated configuration reference live at /docs. Enlisting an AI agent to integrate for you? The machine on-ramp is /llms.txt.