Signet


Certified authentication

A better-auth‑compatible auth server. Your data in your PostgreSQL — sealed, sovereign, certified.

Point any better-auth client at your own instance and own every credential end to end. Signet runs behind your walls, needs nothing from the public internet, and carries a recorded compatibility receipt so you can verify the seal before you trust it.

Integrate in three stepsRead the certification
Certification receipt
Compatibility profile
better-auth 1.6.23
recorded · 2026-07-22
Certification gap
0
recorded · 2026-07-22
End-to-end acceptance
14 / 14
recorded · 2026-07-22
Profile version
Signet compatibility profile v1
recorded · 2026-07-22
A recorded pointer to Signet's better-auth compatibility run, not an implied cryptographic attestation. Read the full receipt at /certification (JSON).

What you get

Own your auth. Users, sessions, and secrets live in your Postgres. No third party sits between you and the people who sign in.
Air‑gap capable. The docs, the generated config reference, and the machine on-ramp all travel inside the binary. A sealed network gets the identical experience, offline, at 2am.
Drop‑in for better-auth. Signet speaks the better-auth HTTP wire protocol. Existing better-auth client libraries integrate unchanged — no rewrite, gap 0.

Integrate in three steps

  1. Write signet.toml with this instance's public origin and a Postgres DSN.
  2. Provide the secret and database URL out-of-band, then boot. Migrations run on start.
  3. Point your better-auth client at /api/auth on this origin.

Full quickstart and the generated configuration reference live at /docs. Enlisting an AI agent to integrate for you? The machine on-ramp is /llms.txt.