v1.7.1
megadose/holehev1.7.1Aug 18, 2026by better-release[bot]
AI Summary
This release focuses on bug fixes including native database transaction support for test instances, SCIM improvements for Microsoft Entra interoperability, and enhanced OAuth provider scope error responses for MCP clients.
Key Highlights
- Added native database transaction support to test instances for PostgreSQL and MySQL
- Fixed SCIM case-insensitive parsing for Microsoft Entra interoperability
- Fixed SAML assertion signature verification to validate raw assertions
- Improved OAuth scope error responses with proper WWW-Authenticate headers
- Fixed native adapter transactions for raw database instances
Full Release Notes
## `better-auth`
### Bug Fixes
- Added native database transaction support to test instances for PostgreSQL and MySQL.
- Updated bundled dependencies (`jose`, nanostores, noble crypto packages, SimpleWebAuthn) to their latest compatible releases, with no changes required to existing projects.
For detailed changes, see [`CHANGELOG`](https://github.com/better-auth/better-auth/blob/2344536054f9164ca5d1670c270d299049ee233e/packages/better-auth/CHANGELOG.md)
## `@better-auth/scim`
### Bug Fixes
- Fixed case-insensitive parsing of string Boolean values for SCIM User `active` and the `primary` sub-attribute of `emails`, `phoneNumbers`, `addresses`, `roles`, and `entitlements` at the HTTP ingress, improving Microsoft Entra interoperability.
- Added an optional SCIM-owned connection and credential catalog: configure `managedConnections` to allow trusted server code to create runtime tenant connections and issue, rotate, and revoke bearer credentials through server-only `auth.api` methods, without a code-defined connection or an application-owned verifier.
- Fixed an issue where trusted server code could not retain a terminal connection binding before a dynamic SCIM connection's first authenticated request when supplying a provisioning domain during decommissioning.
For detailed changes, see [`CHANGELOG`](https://github.com/better-auth/better-auth/blob/2344536054f9164ca5d1670c270d299049ee233e/packages/scim/CHANGELOG.md)
## `@better-auth/sso`
### Bug Fixes
- Fixed SSO provider registration to allow reusing a SCIM connection ID, as SCIM connections no longer participate in the authentication provider namespace.
- Fixed SAML assertion signature verification to validate signatures on the raw assertion instead of trusting an already-parsed response, and enforced signing policy and size limits on SP metadata. `wantAssertionsSigned` now correctly controls whether the SP requires signed assertions, matching real-world IdP signing behavior.
For detailed changes, see [`CHANGELOG`](https://github.com/better-auth/better-auth/blob/2344536054f9164ca5d1670c270d299049ee233e/packages/sso/CHANGELOG.md)
## `@better-auth/cimd`
### Bug Fixes
- Fixed Client ID Metadata Document caching to follow shared-cache freshness rules: the plugin now prefers `s-maxage` over `max-age` and `Expires`, honors `s-maxage=0`, conditionally revalidates with `ETag` or `Last-Modified`, and treats invalid or duplicate freshness directives as immediately stale. Concurrent refreshes now converge on a single client-resource link instead of failing on a unique constraint.
For detailed changes, see [`CHANGELOG`](https://github.com/better-auth/better-auth/blob/2344536054f9164ca5d1670c270d299049ee233e/packages/cimd/CHANGELOG.md)
## `@better-auth/kysely-adapter`
### Bug Fixes
- Fixed native adapter transactions for raw database instances (better-sqlite3, `node:sqlite`, `bun:sqlite`, `mysql2`, `pg`) passed directly as `database`, matching the behavior of the explicit `{ db }`/`{ dialect }` config shapes. Plugins requiring native transactions (such as `@better-auth/scim`) now work correctly when using the quickstart `database: new Database(...)` form.
For detailed changes, see [`CHANGELOG`](https://github.com/better-auth/better-auth/blob/2344536054f9164ca5d1670c270d299049ee233e/packages/kysely-adapter/CHANGELOG.md)
## `@better-auth/oauth-provider`
### Bug Fixes
- Fixed scope error responses so MCP clients now receive a `403` with an RFC 6750 `insufficient_scope` `WWW-Authenticate` challenge naming every missing scope, allowing clients to request all needed scopes in a single authorization request.
For detailed changes, see [`CHANGELOG`](https://github.com/better-auth/better-auth/blob/2344536054f9164ca5d1670c270d299049ee233e/packages/oauth-provider/CHANGELOG.md)
## `auth`
### Bug Fixes
- Fixed the CLI to refuse adding required columns without default values to already-populated tables ([#10863](https://github.com/better-auth/better-auth/pull/10863))
For detailed changes, see [`CHANGELOG`](https://github.com/better-auth/better-auth/blob/2344536054f9164ca5d1670c270d299049ee233e/packages/cli/CHANGELOG.md)
## Contributors
Thanks to everyone who contributed to this release:
@gustavovalverde
**Full changelog:** [`v1.7.0...v1.7.1`](https://github.com/better-auth/better-auth/compare/v1.7.0...v1.7.1)