Better Auth Database Schema Diagram
Better Auth persists authentication in four core tables. The user table holds identity and profile fields; session rows point at users and carry the token, expiry, and device info; account rows link one authentication method (one provider) to a user with tokens and an optional password for credential logins; verification rows hold one-time values for email verification and password resets. The design detail that matters: account identity is the (issuer, accountId) pair with a unique compound index - the local id is only the row identifier you pass to account-management APIs, never the provider identity.
Last updated: 2026-09-27
Source: Better Auth core schema docs (better-auth.com/docs/concepts/database) · License: MIT
Tables in the Better Auth schema
| Column | Type | Nullable | Key |
|---|---|---|---|
| user | |||
| id | text | No | PK |
| name | text | No | - |
| text | No | - | |
| emailVerified | boolean | No | - |
| image | text | Yes | - |
| createdAt | timestamptz | No | - |
| updatedAt | timestamptz | No | - |
| session | |||
| id | text | No | PK |
| userId | text | No | - |
| token | text | No | - |
| expiresAt | timestamptz | No | - |
| ipAddress | text | Yes | - |
| userAgent | text | Yes | - |
| createdAt | timestamptz | No | - |
| updatedAt | timestamptz | No | - |
| account | |||
| id | text | No | PK |
| userId | text | No | - |
| issuer | text | No | - |
| accountId | text | No | - |
| providerId | text | No | - |
| accessToken | text | Yes | - |
| refreshToken | text | Yes | - |
| accessTokenExpiresAt | timestamptz | Yes | - |
| refreshTokenExpiresAt | timestamptz | Yes | - |
| scope | text | Yes | - |
| idToken | text | Yes | - |
| password | text | Yes | - |
| createdAt | timestamptz | No | - |
| updatedAt | timestamptz | No | - |
| verification | |||
| id | text | No | PK |
| identifier | text | No | - |
| value | text | No | - |
| expiresAt | timestamptz | No | - |
| createdAt | timestamptz | No | - |
| updatedAt | timestamptz | No | - |
Frequently asked questions
What tables does Better Auth use?
Better Auth's core schema is 4 tables: user, session, account, and verification. Plugins can add their own tables (for example, two-factor authentication adds columns to user).
How does Better Auth identify an OAuth account?
By the unique pair of issuer and accountId - the identity namespace plus the provider's stable identifier for that user. The account row's own id is a local identifier for API calls, not the provider identity.
How is Better Auth's schema different from NextAuth's?
The shapes are close cousins - both have users, sessions, accounts, and a verification table. Better Auth names the token table verification (NextAuth calls it verification_tokens), stores the provider identity as issuer plus accountId, and supports custom table and column names via modelName and fields config.
Explore more schemas
Visualize your own database
Paste your PostgreSQL connection string and get an interactive ER diagram of your own schema in under 10 seconds. No signup required.
Try it free →