Changelog

AuthEndpoints

Ready-made sign-up and sign-in endpoints for ASP.NET Core Identity: passwords, passkeys, GitHub and Google, two-factor codes, cookies, and tokens.

Program.cs
builder.Services.AddAuthEndpoints<AppUser, AppDbContext>(o =>
{
    o.Passkeys.ServerDomain = "example.com";
});
builder.Services.AddTransient<IEmailSender<AppUser>, MyEmailSender>();

var app = builder.Build();
app.UseAuthEndpoints();
app.MapAuthEndpoints<AppUser>();

What AuthEndpoints can do

Each capability links to the guide that shows you how to use it.

    Register with an email and password

    Create accounts and send confirmation email.

    Register with a passkey

    Create passwordless accounts with WebAuthn.

    GitHub and Google sign-in

    Add social sign-in in a separate preview package.

    Cookie sessions

    Sign browser users in with a secure app cookie.

    Identity bearer tokens

    Issue access and refresh tokens for mobile apps.

    JWT with a refresh cookie

    Issue short-lived JWTs with rotating refresh tokens.

    Passkey sign-in

    Sign users in with a passkey.

    Two-factor authentication

    Turn on authenticator codes and recovery codes.

    Password reset

    Send reset codes and set a new password.

    Email change

    Change the email after the user confirms it.

    Passkey management

    Add, rename, and remove passkeys.

    Account linking

    Link and unlink GitHub or Google accounts.

    Step-up (ReAuth)

    Ask for proof again before sensitive changes.

    Built-in protection

    CSRF, rate limits, lockout, and checks at startup.

    Composable modules

    Map only the routes you need, on your own prefixes.

Map auth in minutes

Start with the facade, then compose modules when you need custom paths or a JWT-only stack.