Account and sign-in security

By Daniel Ensminger
Account and sign-in security
Social uses Better Auth with Convex-backed persistence. New users can create an email-and-password account or continue with GitHub when that provider is configured.
Optional protections
After signing in, account controls can add a passkey for WebAuthn-capable devices and enable two-factor authentication. Email verification, password reset, session management, and compromised-password checks are also wired into the authentication service.
What passkeys change
A passkey uses a public-key credential associated with the Social domain. The device or password manager handles the local unlock step. Social stores the server-side credential data needed to verify the sign-in; it does not receive the device biometric used to unlock a passkey.
Available sign-in methods depend on the account, browser, device, and production provider configuration. Social does not claim that every account is passwordless by default.

