Skip to main content
Hookfish delegates application login and session management to your auth system. An application auth provider must verify both the user and the tenant they may currently act within.
Hookfish never accepts a tenant identifier from an unverified browser field. It does not fall back from a missing organization to the user ID.

Use Better Auth

Install the adapter alongside Better Auth:
Configure Better Auth with its organization plugin. Pass the server instance directly to Hookfish:
The adapter:
  • Reads the Better Auth session from the request headers.
  • Requires session.activeOrganizationId.
  • Uses the Better Auth organization API to verify current membership.
  • Returns session.user.id as the audit subject.
  • Returns the verified organization ID as the tenant.
  • Returns 401 for a missing session and 403 for a missing or unauthorized organization.
The adapter has no tenant presets. Your Better Auth organization is the Hookfish tenant. Represent a personal account as a single-member organization when your product supports personal workspaces.

Implement another provider

Clerk, WorkOS, and other integrations can implement the same contract:
The provider must verify current organization membership. Reading an unverified organization ID from a cookie, header, route parameter, or request body does not satisfy the contract.

Credential boundary

After authentication, Hookfish signs a capability that expires within one minute and is limited to the tenant’s internal resource subtree. The raw API verifies that signature and enforces its resource scope. The capability exists only between trusted server components. The browser may receive connection metadata, an authorization URL, or an operation status. It never receives the capability, root broker key, or stored provider credentials.