Skip to content

Introduction to Auth.js

Auth.js (formerly NextAuth.js) is the most popular authentication library for Next.js. It handles sessions, providers (Google, GitHub, email, credentials), CSRF protection, and database adapters — so you don’t have to build authentication from scratch.

Building authentication yourself is complex and error-prone. You need to handle:

  • Password hashing and verification
  • Session management (JWT or database)
  • OAuth flows (Google, GitHub)
  • CSRF protection
  • Secure cookie management

Auth.js handles all of this with a simple configuration.

FeatureDescription
Multiple providersGoogle, GitHub, credentials, email, and 80+ more
Session strategiesJWT (stateless) or database (stateful) sessions
Built-in securityCSRF tokens, secure cookies, HTTPS enforcement
Database adaptersPrisma, Drizzle, MongoDB, and more
TypeScript supportFully typed session and JWT callbacks