Get Current Session
Returns the active session and its user, based on the request's session cookie. Returns `null` rather than an error when no valid session cookie is present. This endpoint returns Better Auth's payload, not the `{ success, message, data }` envelope.
Internal session cookie for local development.
In: cookie
Response Body
application/json
curl -X GET "https://example.com/api/v1/auth/get-session"{ "session": {}, "user": {}}Sign In With Email OTPPOST
Exchanges a valid OTP for a session. On success the session cookie is set via `Set-Cookie` and the session token plus the user record are returned. A user is created automatically on first sign-in. Codes expire after 5 minutes and allow 3 attempts by default. This endpoint returns Better Auth's payload, not the `{ success, message, data }` envelope. Rate limited to 20 requests per minute per IP — the default for `/api/v1/auth/*`. (A tighter 5/minute rule exists in configuration but targets `/email-otp/verify-otp`, a path this Better Auth version does not expose, so it never applies.)
Sign OutPOST
Revokes the current session and clears the session cookie. Also flushes the server-side session cache for that cookie. This endpoint returns Better Auth's payload, not the `{ success, message, data }` envelope.