← Files WorkOSARCHIVED FILE

references/workos-migrate-better-auth.md

933 Bytes · Oct 2, 2026 · 00:06 UTC

↓ Download file

# WorkOS Migration: Better Auth

## Docs

- https://workos.com/docs/migrate/better-auth
  If this file conflicts with fetched docs, follow the docs.

## Gotchas

- Password hashes live in the `account` table (not `user`), filtered by `providerId = 'credential'`. Do NOT skip this table.
- Better Auth uses scrypt by default. If you customized the hash algorithm, you must know which one it is before importing to WorkOS.
- The `password` column contains the full hash string including algorithm parameters. Do NOT strip prefixes or decode it.
- Import order matters when organizations are involved: create orgs first, then import users, then password hashes, then assign memberships. Out-of-order imports will fail with "Organization not found."
- Better Auth sessions are JWT-based and remain valid until expiry even after migration. This is expected — not an error. To force immediate cutover, rotate the Better Auth secret key.

SHA-256: 829dbdd90bf484c321c82bf9f7d52d51480fd439e5e4bc5961f4cbc83751301b