v1.7.1

Leonxlnx/taste-skillv1.7.1Aug 18, 2026by better-release[bot]

AI Summary

Primarily a bug fix release that introduces native database transaction support for test instances and improves Microsoft Entra interoperability within the SCIM plugin. It also fixes OAuth provider scope error responses and native adapter transactions for raw database instances.

Key Highlights

  • Added native database transaction support to test instances for PostgreSQL and MySQL
  • Fixed SCIM case-insensitive parsing for Microsoft Entra interoperability
  • Fixed MCP OAuth scope error responses to return 403 with insufficient_scope challenges
  • Fixed native adapter transactions for raw database instances

New Features

  • Added optional SCIM-owned connection and credential catalog for trusted server code

Full Release Notes

## `better-auth`

### Bug Fixes

- Added native database transaction support to test instances for PostgreSQL and MySQL.
- Updated bundled dependencies (`jose`, nanostores, noble crypto packages, SimpleWebAuthn) to their latest compatible releases, with no changes required to existing projects.

For detailed changes, see [`CHANGELOG`](https://github.com/better-auth/better-auth/blob/2344536054f9164ca5d1670c270d299049ee233e/packages/better-auth/CHANGELOG.md)

## `@better-auth/scim`

### Bug Fixes

- Fixed case-insensitive parsing of string Boolean values for SCIM User `active` and the `primary` sub-attribute of `emails`, `phoneNumbers`, `addresses`, `roles`, and `entitlements` at the HTTP ingress, improving Microsoft Entra interoperability.
- Added an optional SCIM-owned connection and credential catalog: configure `managedConnections` to allow trusted server code to create runtime tenant connections and issue, rotate, and revoke bearer credentials through server-only `auth.api` methods, without a code-defined connection or an application-owned verifier.
- Fixed an issue where trusted server code could not retain a terminal connection binding before a dynamic SCIM connection's first authenticated request when supplying a provisioning domain during decommissioning.

For detailed changes, see [`CHANGELOG`](https://github.com/better-auth/better-auth/blob/2344536054f9164ca5d1670c270d299049ee233e/packages/scim/CHANGELOG.md)

## `@better-auth/sso`

### Bug Fixes

- Fixed SSO provider registration to allow reusing a SCIM connection ID, as SCIM connections no longer participate in the authentication provider namespace.
- Fixed SAML assertion signature verification to validate signatures on the raw assertion instead of trusting an already-parsed response, and enforced signing policy and size limits on SP metadata. `wantAssertionsSigned` now correctly controls whether the SP requires signed assertions, matching real-world IdP signing behavior.

For detailed changes, see [`CHANGELOG`](https://github.com/better-auth/better-auth/blob/2344536054f9164ca5d1670c270d299049ee233e/packages/sso/CHANGELOG.md)

## `@better-auth/cimd`

### Bug Fixes

- Fixed Client ID Metadata Document caching to follow shared-cache freshness rules: the plugin now prefers `s-maxage` over `max-age` and `Expires`, honors `s-maxage=0`, conditionally revalidates with `ETag` or `Last-Modified`, and treats invalid or duplicate freshness directives as immediately stale. Concurrent refreshes now converge on a single client-resource link instead of failing on a unique constraint.

For detailed changes, see [`CHANGELOG`](https://github.com/better-auth/better-auth/blob/2344536054f9164ca5d1670c270d299049ee233e/packages/cimd/CHANGELOG.md)

## `@better-auth/kysely-adapter`

### Bug Fixes

- Fixed native adapter transactions for raw database instances (better-sqlite3, `node:sqlite`, `bun:sqlite`, `mysql2`, `pg`) passed directly as `database`, matching the behavior of the explicit `{ db }`/`{ dialect }` config shapes. Plugins requiring native transactions (such as `@better-auth/scim`) now work correctly when using the quickstart `database: new Database(...)` form.

For detailed changes, see [`CHANGELOG`](https://github.com/better-auth/better-auth/blob/2344536054f9164ca5d1670c270d299049ee233e/packages/kysely-adapter/CHANGELOG.md)

## `@better-auth/oauth-provider`

### Bug Fixes

- Fixed scope error responses so MCP clients now receive a `403` with an RFC 6750 `insufficient_scope` `WWW-Authenticate` challenge naming every missing scope, allowing clients to request all needed scopes in a single authorization request.

For detailed changes, see [`CHANGELOG`](https://github.com/better-auth/better-auth/blob/2344536054f9164ca5d1670c270d299049ee233e/packages/oauth-provider/CHANGELOG.md)

## `auth`

### Bug Fixes

- Fixed the CLI to refuse adding required columns without default values to already-populated tables ([#10863](https://github.com/better-auth/better-auth/pull/10863))

For detailed changes, see [`CHANGELOG`](https://github.com/better-auth/better-auth/blob/2344536054f9164ca5d1670c270d299049ee233e/packages/cli/CHANGELOG.md)

## Contributors

Thanks to everyone who contributed to this release:

@gustavovalverde

**Full changelog:** [`v1.7.0...v1.7.1`](https://github.com/better-auth/better-auth/compare/v1.7.0...v1.7.1)