Signet


Certified authentication

Auth you own. Your data in your PostgreSQL — sealed, sovereign, certified.

Every credential lives in your database. Signet runs behind your walls, needs nothing from the public internet, and carries a recorded compatibility receipt on every instance. Already on the stock better-auth client? Point baseURL here — no Signet SDK.

Integrate in three stepsRead the certification
Certification receipt
Compatibility profile
better-auth 1.6.23
recorded · 2026-07-22
Certification gap
0
recorded · 2026-07-22
End-to-end acceptance
14 / 14
recorded · 2026-07-22
Profile version
Signet compatibility profile v1
recorded · 2026-07-22
A recorded pointer to Signet's better-auth compatibility run, not an implied cryptographic attestation. Read the full receipt at /certification (JSON).

What you get

Own your auth. Users, sessions, and secrets live in your Postgres. No third party sits between you and the people who sign in.
Air‑gap capable. The docs, the generated config reference, and the machine on-ramp all travel inside the binary. A sealed network gets the identical experience, offline, at 2am.
Stock client drop‑in. Apps using the stock better-auth client integrate unchanged against this instance’s certified wire — no rewrite, gap 0.

Integrate in three steps

  1. Write signet.toml with this instance's public origin and a Postgres DSN.
  2. Provide the secret and database URL out-of-band, then boot. Migrations run on start.
  3. Point the stock better-auth client at /api/auth on this origin.

Full quickstart and the generated configuration reference live at /docs. Enlisting an AI agent to integrate for you? The machine on-ramp is /llms.txt.