Use Better Auth
Install the adapter alongside Better Auth:- Reads the Better Auth session from the request headers.
- Requires
session.activeOrganizationId. - Uses the Better Auth organization API to verify current membership.
- Returns
session.user.idas the audit subject. - Returns the verified organization ID as the tenant.
- Returns
401for a missing session and403for a missing or unauthorized organization.