# Authentication and authorization

Better Auth owns the shared `user`, `session`, `account`, and `verification` tables. Customers can create an email/password account at `/register` and sign in at `/login`. The Better Auth admin plugin adds role, ban, and impersonation support; storefront accounts receive the `user` role and only users with the `admin` role can access `/admin/*` pages or `/api/admin/*` endpoints.

The seed command creates the configured admin through Better Auth, or promotes an existing account with the same email. The old `admin_users` and `admin_sessions` tables remain in the database for a non-destructive transition but are no longer consulted by the application. Existing username-only administrators must use the configured `INITIAL_ADMIN_EMAIL` and rerun the seed once after applying migration `0001`.