Certification receipt · recorded 2026-07-25

What the receipt actually proves.

Two distinct runs support the claim: a differential conformance sweep of better-auth’s own suite, and an end-to-end acceptance run through better-auth’s unmodified client. They answer different questions, and the receipt keeps them separate.

Conformance sweep 280 / 280

Reference passes / Signet matches. Gap 0.

End-to-end acceptance 14 / 14

Real client-driven flows, passed in full.

Compatibility gap 0

Where the reference passes and Signet does not.

Scope. The sweep replays better-auth's own test suite — 29 files — against better-auth and against Signet, and compares the results. Gap 0 means every assertion that passes against better-auth also passes against Signet, byte for byte. It is not a claim that every better-auth route is implemented: the profile is scoped to what that suite exercises here, and anything it does not exercise sits outside it. Ask about a specific route and we will tell you plainly whether it is in the profile.

Differential conformance

How to read 280/280.

Better-auth’s own test suite is run twice — once against the better-auth reference implementation and once against Signet — and the results are diffed. The denominator is the reference ceiling: the tests the reference implementation passes. Signet matches the reference on every one of those tests, so the gap — the count where the reference passes and Signet does not — is 0.

End-to-end acceptance

What 14 / 14 means.

On top of the differential sweep, better-auth’s unmodified client drives real sign-up, session, organization, and two-factor flows against Signet. All 14 / 14 acceptance checks passed. Both runs were recorded 2026-07-25.

Receipt posture. These are recorded pointers to repeatable compatibility runs, not implied cryptographic attestations. A deployed Signet instance renders its own receipt at /certification from the same source as its machine-readable receipt.