Certified authentication
Auth you own. Your data in your PostgreSQL — sealed, sovereign, certified.
Every credential lives in your database. Signet runs behind your walls, needs nothing from the public internet, and carries a recorded compatibility receipt on every instance. Already on the stock better-auth client? Point baseURL here — no Signet SDK.
✦ Certification receipt
Compatibility profile
better-auth 1.6.23
recorded · 2026-07-22
Certification gap
0
recorded · 2026-07-22
End-to-end acceptance
14 / 14
recorded · 2026-07-22
Profile version
Signet compatibility profile v1
recorded · 2026-07-22
A recorded pointer to Signet's better-auth compatibility run, not an implied cryptographic attestation. Read the full receipt at /certification (JSON).
What you get
Own your auth. Users, sessions, and secrets live in your Postgres. No third party sits between you and the people who sign in.
Air‑gap capable. The docs, the generated config reference, and the machine on-ramp all travel inside the binary. A sealed network gets the identical experience, offline, at 2am.
Stock client drop‑in. Apps using the stock better-auth client integrate unchanged against this instance’s certified wire — no rewrite, gap 0.
Integrate in three steps
- Write
signet.tomlwith this instance's public origin and a Postgres DSN. - Provide the secret and database URL out-of-band, then boot. Migrations run on start.
- Point the stock better-auth client at
/api/authon this origin.
Full quickstart and the generated configuration reference live at /docs. Enlisting an AI agent to integrate for you? The machine on-ramp is /llms.txt.