[{"data":1,"prerenderedAt":1898},["ShallowReactive",2],{"navigation":3,"changelog-versions":203},[4,33,96,114,177],{"title":5,"path":6,"stem":7,"children":8,"icon":32},"Get started","\u002Fgetting-started","1.getting-started\u002F1.index",[9,12,17,22,27],{"title":10,"path":6,"stem":7,"icon":11},"Introduction","i-lucide-house",{"title":13,"path":14,"stem":15,"icon":16},"Install AuthEndpoints","\u002Fgetting-started\u002Finstallation","1.getting-started\u002F2.installation","i-lucide-download",{"title":18,"path":19,"stem":20,"icon":21},"Quick start","\u002Fgetting-started\u002Fquick-start","1.getting-started\u002F3.quick-start","i-lucide-play",{"title":23,"path":24,"stem":25,"icon":26},"Choose a sign-in stack","\u002Fgetting-started\u002Fchoose-a-sign-in-stack","1.getting-started\u002F4.choose-a-sign-in-stack","i-lucide-signpost",{"title":28,"path":29,"stem":30,"icon":31},"Use the AuthEndpoints skill with coding agents","\u002Fgetting-started\u002Fai-agents","1.getting-started\u002F5.ai-agents","i-lucide-bot","i-lucide-rocket",{"title":34,"path":35,"stem":36,"children":37,"icon":95},"Guides","\u002Fguides","2.guides\u002F01.index",[38,40,45,50,55,60,65,70,75,80,85,90],{"title":34,"path":35,"stem":36,"icon":39},"i-lucide-list-checks",{"title":41,"path":42,"stem":43,"icon":44},"Register users","\u002Fguides\u002Fregistration","2.guides\u002F02.registration","i-lucide-user-plus",{"title":46,"path":47,"stem":48,"icon":49},"Sign users in","\u002Fguides\u002Fsign-in","2.guides\u002F03.sign-in","i-lucide-log-in",{"title":51,"path":52,"stem":53,"icon":54},"Sign users out","\u002Fguides\u002Fsign-out","2.guides\u002F04.sign-out","i-lucide-log-out",{"title":56,"path":57,"stem":58,"icon":59},"Turn on two-factor authentication","\u002Fguides\u002Ftwo-factor","2.guides\u002F05.two-factor","i-lucide-smartphone",{"title":61,"path":62,"stem":63,"icon":64},"Reset a forgotten password","\u002Fguides\u002Freset-password","2.guides\u002F06.reset-password","i-lucide-key-round",{"title":66,"path":67,"stem":68,"icon":69},"Change a user's email or password","\u002Fguides\u002Fmanage-account","2.guides\u002F07.manage-account","i-lucide-user-cog",{"title":71,"path":72,"stem":73,"icon":74},"Add, rename, and remove passkeys","\u002Fguides\u002Fmanage-passkeys","2.guides\u002F08.manage-passkeys","i-lucide-scan-face",{"title":76,"path":77,"stem":78,"icon":79},"Link and unlink GitHub or Google accounts","\u002Fguides\u002Flink-external-accounts","2.guides\u002F09.link-external-accounts","i-lucide-link",{"title":81,"path":82,"stem":83,"icon":84},"Require step-up before sensitive actions","\u002Fguides\u002Fstep-up","2.guides\u002F10.step-up","i-lucide-shield-check",{"title":86,"path":87,"stem":88,"icon":89},"Call the API from a browser","\u002Fguides\u002Fbrowser-clients","2.guides\u002F11.browser-clients","i-lucide-globe",{"title":91,"path":92,"stem":93,"icon":94},"Prepare for production","\u002Fguides\u002Fproduction","2.guides\u002F12.production","i-lucide-factory","i-lucide-waypoints",{"title":97,"path":98,"stem":99,"children":100,"icon":113},"Composable endpoints","\u002Fcomposables","3.composables\u002F1.index",[101,104,108],{"title":102,"path":98,"stem":99,"icon":103},"How composition works","i-lucide-layout-grid",{"title":105,"path":106,"stem":107,"icon":39},"Composition requirements","\u002Fcomposables\u002Frequirements","3.composables\u002F2.requirements",{"title":109,"path":110,"stem":111,"icon":112},"Compose a custom auth stack","\u002Fcomposables\u002Frecipes","3.composables\u002F3.recipes","i-lucide-book-marked","i-lucide-blocks",{"title":115,"icon":116,"path":117,"stem":118,"children":119,"page":176},"Reference","i-lucide-book-open","\u002Fmodules","4.modules",[120,125,129,134,139,144,148,153,157,162,166,171],{"title":121,"path":122,"stem":123,"icon":124},"Endpoint reference","\u002Fmodules\u002Fendpoints","4.modules\u002F01.endpoints","i-lucide-route",{"title":126,"path":127,"stem":128,"icon":69},"Identity management module","\u002Fmodules\u002Fidentity-management","4.modules\u002F02.identity-management",{"title":130,"path":131,"stem":132,"icon":133},"Cookie sign-in module","\u002Fmodules\u002Fcookie-auth","4.modules\u002F03.cookie-auth","i-lucide-cookie",{"title":135,"path":136,"stem":137,"icon":138},"Identity bearer sign-in module","\u002Fmodules\u002Fbearer-auth","4.modules\u002F04.bearer-auth","i-lucide-key",{"title":140,"path":141,"stem":142,"icon":143},"JWT module","\u002Fmodules\u002Fjwt","4.modules\u002F05.jwt","i-lucide-fingerprint",{"title":145,"path":146,"stem":147,"icon":74},"Passkeys module","\u002Fmodules\u002Fpasskeys","4.modules\u002F06.passkeys",{"title":149,"path":150,"stem":151,"icon":152},"ReAuth module","\u002Fmodules\u002Freauth","4.modules\u002F07.reauth","i-lucide-shield-alert",{"title":154,"path":155,"stem":156,"icon":49},"External OAuth packages","\u002Fmodules\u002Fexternal-oauth","4.modules\u002F08.external-oauth",{"title":158,"path":159,"stem":160,"icon":161},"Configuration options","\u002Fmodules\u002Fconfiguration","4.modules\u002F09.configuration","i-lucide-settings",{"title":163,"path":164,"stem":165,"icon":84},"Antiforgery (CSRF) rules","\u002Fmodules\u002Fcsrf","4.modules\u002F10.csrf",{"title":167,"path":168,"stem":169,"icon":170},"Responses and errors","\u002Fmodules\u002Ferrors","4.modules\u002F11.errors","i-lucide-circle-alert",{"title":172,"path":173,"stem":174,"icon":175},"Rate-limit policies","\u002Fmodules\u002Frate-limits","4.modules\u002F12.rate-limits","i-lucide-gauge",false,{"title":178,"icon":179,"path":180,"stem":181,"children":182,"page":176},"Concepts","i-lucide-lightbulb","\u002Fconcepts","5.concepts",[183,188,193,198],{"title":184,"path":185,"stem":186,"icon":187},"AuthEndpoints compared with other options","\u002Fconcepts\u002Fcompare","5.concepts\u002F1.compare","i-lucide-git-compare",{"title":189,"path":190,"stem":191,"icon":192},"Stock Identity endpoints vs AuthEndpoints","\u002Fconcepts\u002Fstock-identity-vs-authendpoints","5.concepts\u002F2.stock-identity-vs-authendpoints","i-lucide-columns-2",{"title":194,"path":195,"stem":196,"icon":197},"Security model","\u002Fconcepts\u002Fsecurity-model","5.concepts\u002F3.security-model","i-lucide-shield",{"title":199,"path":200,"stem":201,"icon":202},"FAQ","\u002Fconcepts\u002Ffaq","5.concepts\u002F4.faq","i-lucide-circle-help",[204,330,425,539,656,768,833,907,1003,1097,1165,1225,1334,1420,1500,1586,1657,1703,1758,1804,1841],{"id":205,"title":206,"badge":207,"body":208,"date":321,"description":322,"extension":323,"meta":324,"navigation":325,"path":326,"seo":327,"stem":328,"tag":206,"__hash__":329},"versions\u002Fversions\u002Fv3.1.1.md","v3.1.1","Latest",{"type":209,"value":210,"toc":312},"minimark",[211,216,244,257,261,287,291],[212,213,215],"h3",{"id":214},"authendpoints","AuthEndpoints",[217,218,219,220,224,225,228,229,232,233,232,236,239,240,243],"p",{},"On hosts without ",[221,222,223],"code",{},"o.Jwt.Enabled",", CSRF-protected endpoints returned 500 for callers without an application cookie. The CSRF check tried to authenticate against the JWT ",[221,226,227],{},"Bearer"," scheme, which those hosts never register. Anonymous passkey ",[221,230,231],{},"requestOptions",", ",[221,234,235],{},"register\u002Foptions",[221,237,238],{},"register",", and ",[221,241,242],{},"login"," failed on the default cookie facade and the Identity bearer facade. The check now skips unregistered schemes. Requests without a CSRF token return 400, and requests with a valid token succeed.",[245,246,247,251,254],"ul",{},[248,249,250],"li",{},"Anonymous passkey ceremonies work on the default cookie and Identity bearer facades without JWT",[248,252,253],{},"Missing or invalid CSRF tokens return 400 instead of 500",[248,255,256],{},"Hosts with JWT enabled behave as before",[212,258,260],{"id":259},"packages","Packages",[245,262,263,272],{},[248,264,265,268,269],{},[266,267,215],"strong",{}," ",[221,270,271],{},"3.1.1",[248,273,274,232,277,239,280,283,284],{},[266,275,276],{},"AuthEndpoints.External.OAuth",[266,278,279],{},"AuthEndpoints.OAuth.GitHub",[266,281,282],{},"AuthEndpoints.OAuth.Google"," unchanged at ",[221,285,286],{},"3.0.0-preview.4",[212,288,290],{"id":289},"links","Links",[245,292,293,300,306],{},[248,294,295],{},[296,297,299],"a",{"href":298},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Freleases\u002Ftag\u002Fv3.1.1","GitHub release",[248,301,302],{},[296,303,305],{"href":304},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Fcompare\u002Fv3.1.0...v3.1.1","Compare",[248,307,308],{},[296,309,311],{"href":310},"\u002Fgetting-started\u002Finstallation\u002F","Installation",{"title":313,"searchDepth":314,"depth":315,"links":316},"",1,2,[317,319,320],{"id":214,"depth":318,"text":215},3,{"id":259,"depth":318,"text":260},{"id":289,"depth":318,"text":290},"2026-10-04","Passkey and other CSRF-protected endpoints no longer return 500 when JWT is not enabled.","md",{},true,"\u002Fversions\u002Fv3.1.1",{"title":206,"description":322},"versions\u002Fv3.1.1","WmnRh0ydVF3mxrnnbHIrc33KLgZvsXfnWhxF7rIRr_A",{"id":331,"title":332,"badge":333,"body":334,"date":417,"description":418,"extension":323,"meta":419,"navigation":325,"path":420,"seo":421,"stem":422,"tag":423,"__hash__":424},"versions\u002Fversions\u002Fexternal-oauth-v3.0.0-preview.4.md","AuthEndpoints.External.OAuth 3.0.0-preview.4","Preview",{"type":209,"value":335,"toc":411},[336,339,369,372,381,384,396,398],[212,337,276],{"id":338},"authendpointsexternaloauth",[245,340,341,344,350,357,363,366],{},[248,342,343],{},"GitHub and Google handlers moved to their own packages. This nupkg no longer references either handler.",[248,345,346,349],{},[221,347,348],{},"AutoLinkByEmail"," defaults to false. When enabled, auto-link requires a verified provider email and a confirmed local email.",[248,351,352,353,356],{},"Login and link failures, including remote failure, clear the ",[221,354,355],{},"Identity.External"," cookie.",[248,358,359,362],{},[221,360,361],{},"returnUrl"," accepts rooted local paths and allowlists absolute origins the same way email-confirmation redirects do.",[248,364,365],{},"Unlink requires authorization, antiforgery, and ReAuth, and refuses the last sign-in method.",[248,367,368],{},"JWT completion writes only the refresh cookie.",[212,370,279],{"id":371},"authendpointsoauthgithub",[245,373,374],{},[248,375,376,377,380],{},"New package. ",[221,378,379],{},"AddGitHub"," loads a verified address from the GitHub emails API (verified primary, otherwise any verified address) and drops an unverified profile email.",[212,382,282],{"id":383},"authendpointsoauthgoogle",[245,385,386],{},[248,387,376,388,391,392,395],{},[221,389,390],{},"AddGoogle"," sets ",[221,393,394],{},"email_verified"," from the Google userinfo payload after host configuration.",[212,397,290],{"id":289},[245,399,400,405],{},[248,401,402],{},[296,403,305],{"href":404},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Fcompare\u002Fexternal-oauth-v3.0.0-preview.3...external-oauth-v3.0.0-preview.4",[248,406,407],{},[296,408,410],{"href":409},"\u002Fmodules\u002Fexternal-oauth\u002F","External OAuth docs",{"title":313,"searchDepth":314,"depth":315,"links":412},[413,414,415,416],{"id":338,"depth":318,"text":276},{"id":371,"depth":318,"text":279},{"id":383,"depth":318,"text":282},{"id":289,"depth":318,"text":290},"2026-09-30","Verified GitHub and Google email, safe auto-link, link and unlink hardening, and a package split.",{},"\u002Fversions\u002Fexternal-oauth-v3.0.0-preview.4",{"title":332,"description":418},"versions\u002Fexternal-oauth-v3.0.0-preview.4","external-oauth-v3.0.0-preview.4","SrSqQTJhOGA-ZaEsUc0K38k-cH6SEAP-_1kVSvM23vQ",{"id":426,"title":427,"badge":428,"body":429,"date":532,"description":533,"extension":323,"meta":534,"navigation":325,"path":535,"seo":536,"stem":537,"tag":427,"__hash__":538},"versions\u002Fversions\u002Fv3.1.0.md","v3.1.0",null,{"type":209,"value":430,"toc":527},[431,433,448,491,493,509,511],[212,432,215],{"id":214},[217,434,435,436,439,440,443,444,447],{},"Hosts can set how long a ReAuth step-up stays valid. ",[221,437,438],{},"AuthEndpointsOptions.ReAuth.Lifetime"," defaults to 5 minutes and applies to the ReAuth cookie, confirm ",[221,441,442],{},"ExpiresUtc",", and header ",[221,445,446],{},"reauthToken"," together. The cookie stays non-persistent with no sliding expiration. Values must be between 1 and 60 minutes.",[245,449,450,469,479,485],{},[248,451,452,455,456,459,460,463,464,239,466,468],{},[221,453,454],{},"ReAuth.Lifetime"," (",[221,457,458],{},"TimeSpan",", default 5 minutes) drives cookie ",[221,461,462],{},"ExpireTimeSpan",", confirm ",[221,465,442],{},[221,467,446],{}," expiry",[248,470,471,472,475,476],{},"Cookie remains non-persistent (",[221,473,474],{},"IsPersistent = false",") with ",[221,477,478],{},"SlidingExpiration = false",[248,480,481,482],{},"Startup validation rejects zero, negative, over 60 minutes, and ",[221,483,484],{},"InfiniteTimeSpan",[248,486,487,488],{},"Composable hosts use the same ",[221,489,490],{},"IOptions\u003CAuthEndpointsReAuthOptions>",[212,492,260],{"id":259},[245,494,495,502],{},[248,496,497,268,499],{},[266,498,215],{},[221,500,501],{},"3.1.0",[248,503,504,283,506],{},[266,505,276],{},[221,507,508],{},"3.0.0-preview.3",[212,510,290],{"id":289},[245,512,513,518,523],{},[248,514,515],{},[296,516,299],{"href":517},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Freleases\u002Ftag\u002Fv3.1.0",[248,519,520],{},[296,521,305],{"href":522},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Fcompare\u002Fv3.0.8...v3.1.0",[248,524,525],{},[296,526,311],{"href":310},{"title":313,"searchDepth":314,"depth":315,"links":528},[529,530,531],{"id":214,"depth":318,"text":215},{"id":259,"depth":318,"text":260},{"id":289,"depth":318,"text":290},"2026-09-20","ReAuth.Lifetime configures cookie and reauthToken expiry (default 5 minutes).",{},"\u002Fversions\u002Fv3.1.0",{"title":427,"description":533},"versions\u002Fv3.1.0","odhTHCAQ3qZ45EP-yO_nLmRLbSXV-MiQt4sGZszBDJ0",{"id":540,"title":541,"badge":428,"body":542,"date":649,"description":650,"extension":323,"meta":651,"navigation":325,"path":652,"seo":653,"stem":654,"tag":541,"__hash__":655},"versions\u002Fversions\u002Fv3.0.8.md","v3.0.8",{"type":209,"value":543,"toc":644},[544,546,564,579,609,611,626,628],[212,545,215],{"id":214},[217,547,548,549,551,552,555,556,559,560,563],{},"Passkey login ",[221,550,231],{}," takes JSON ",[221,553,554],{},"{ \"email\" }"," instead of ",[221,557,558],{},"?username=",". Unknown or empty email still returns 200 usernameless options. ",[221,561,562],{},"MapPasskeyEndpoints"," fails fast at map time if the user store lacks passkey or email support.",[217,565,566,567,570,571,574,575,578],{},"Signed-in passkey add rejects an attestation whose user id is not the current user and does not store it. Missing credentials on delete and rename return 404. Invalid credential ids and a ceremony that is not underway return validation problems. Add accepts optional ",[221,568,569],{},"name","; list and add include ",[221,572,573],{},"createdAt",". Register and login apply lockout and ",[221,576,577],{},"CanSignInAsync"," before completing sign-in: register that cannot sign in still returns the credential id with no session, and login returns 401.",[245,580,581,589,592,597,600,603],{},[248,582,548,583,551,585,555,587],{},[221,584,231],{},[221,586,554],{},[221,588,558],{},[248,590,591],{},"Unknown or empty email still returns 200 usernameless options",[248,593,594,596],{},[221,595,562],{}," fails fast at map time if the user store lacks passkey or email support",[248,598,599],{},"Signed-in add rejects a mismatched attestation user id and does not store it",[248,601,602],{},"Missing credentials on delete and rename return 404",[248,604,605,606,608],{},"Register and login apply lockout and ",[221,607,577],{}," before completing sign-in",[212,610,260],{"id":259},[245,612,613,620],{},[248,614,615,268,617],{},[266,616,215],{},[221,618,619],{},"3.0.8",[248,621,622,283,624],{},[266,623,276],{},[221,625,508],{},[212,627,290],{"id":289},[245,629,630,635,640],{},[248,631,632],{},[296,633,299],{"href":634},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Freleases\u002Ftag\u002Fv3.0.8",[248,636,637],{},[296,638,305],{"href":639},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Fcompare\u002Fv3.0.7...v3.0.8",[248,641,642],{},[296,643,311],{"href":310},{"title":313,"searchDepth":314,"depth":315,"links":645},[646,647,648],{"id":214,"depth":318,"text":215},{"id":259,"depth":318,"text":260},{"id":289,"depth":318,"text":290},"2026-09-19","Passkey login requestOptions takes JSON email; MapPasskeyEndpoints fails fast if the user store lacks passkey or email support.",{},"\u002Fversions\u002Fv3.0.8",{"title":541,"description":650},"versions\u002Fv3.0.8","UoWUHF_x5hWFkaOFoxg03vd5wPvOBhVne-419C9BvfA",{"id":657,"title":658,"badge":428,"body":659,"date":761,"description":762,"extension":323,"meta":763,"navigation":325,"path":764,"seo":765,"stem":766,"tag":658,"__hash__":767},"versions\u002Fversions\u002Fv3.0.7.md","v3.0.7",{"type":209,"value":660,"toc":756},[661,663,694,721,723,738,740],[212,662,215],{"id":214},[217,664,665,666,669,670,673,674,677,678,681,682,685,686,689,690,693],{},"Hosts can redirect browser email confirmation to an SPA route with status and flow query params. Set ",[221,667,668],{},"EmailConfirmation.ConfirmEmailRedirectUri"," to a rooted path or an absolute URI so browser ",[221,671,672],{},"GET"," confirm-email returns ",[221,675,676],{},"302"," with ",[221,679,680],{},"status"," and ",[221,683,684],{},"flow"," instead of the thank-you body or ",[221,687,688],{},"401",". Absolute URIs stay on ",[221,691,692],{},"AllowedRedirectOrigins",". Unset hosts keep the existing text response.",[245,695,696,704,713],{},[248,697,698,699,681,701,703],{},"Hosts can redirect browser email confirmation to an SPA route with ",[221,700,680],{},[221,702,684],{}," query params",[248,705,706,707,710,711],{},"Absolute ",[221,708,709],{},"ConfirmEmailRedirectUri"," values stay on ",[221,712,692],{},[248,714,715,716,718,719],{},"Unset ",[221,717,709],{}," keeps the thank-you body or ",[221,720,688],{},[212,722,260],{"id":259},[245,724,725,732],{},[248,726,727,268,729],{},[266,728,215],{},[221,730,731],{},"3.0.7",[248,733,734,283,736],{},[266,735,276],{},[221,737,508],{},[212,739,290],{"id":289},[245,741,742,747,752],{},[248,743,744],{},[296,745,299],{"href":746},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Freleases\u002Ftag\u002Fv3.0.7",[248,748,749],{},[296,750,305],{"href":751},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Fcompare\u002Fv3.0.6...v3.0.7",[248,753,754],{},[296,755,311],{"href":310},{"title":313,"searchDepth":314,"depth":315,"links":757},[758,759,760],{"id":214,"depth":318,"text":215},{"id":259,"depth":318,"text":260},{"id":289,"depth":318,"text":290},"2026-09-08","Hosts can redirect browser email confirmation to an SPA route with status and flow query params.",{},"\u002Fversions\u002Fv3.0.7",{"title":658,"description":762},"versions\u002Fv3.0.7","vcPwtM_b3IjNVv73zhy5HbrgsGUiMsllXg5yC7pJTEY",{"id":769,"title":770,"badge":428,"body":771,"date":826,"description":827,"extension":323,"meta":828,"navigation":325,"path":829,"seo":830,"stem":831,"tag":770,"__hash__":832},"versions\u002Fversions\u002Fv3.0.6.md","v3.0.6",{"type":209,"value":772,"toc":821},[773,775,778,786,788,803,805],[212,774,215],{"id":214},[217,776,777],{},"Simple JWT refresh rotation is atomic under concurrent requests. Concurrent refresh calls against the same live refresh cookie complete with a single successor.",[245,779,780,783],{},[248,781,782],{},"Simple JWT refresh rotation is atomic under concurrent requests",[248,784,785],{},"Concurrent refresh of a live cookie does not issue a second live refresh cookie",[212,787,260],{"id":259},[245,789,790,797],{},[248,791,792,268,794],{},[266,793,215],{},[221,795,796],{},"3.0.6",[248,798,799,283,801],{},[266,800,276],{},[221,802,508],{},[212,804,290],{"id":289},[245,806,807,812,817],{},[248,808,809],{},[296,810,299],{"href":811},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Freleases\u002Ftag\u002Fv3.0.6",[248,813,814],{},[296,815,305],{"href":816},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Fcompare\u002Fv3.0.5...v3.0.6",[248,818,819],{},[296,820,311],{"href":310},{"title":313,"searchDepth":314,"depth":315,"links":822},[823,824,825],{"id":214,"depth":318,"text":215},{"id":259,"depth":318,"text":260},{"id":289,"depth":318,"text":290},"2026-09-07","Simple JWT refresh rotation is atomic under concurrent requests.",{},"\u002Fversions\u002Fv3.0.6",{"title":770,"description":827},"versions\u002Fv3.0.6","DSV9B4DEw_Tyt3N71cItJIPUVgpcu6Y8HPD99ypkWCw",{"id":834,"title":835,"badge":428,"body":836,"date":900,"description":901,"extension":323,"meta":902,"navigation":325,"path":903,"seo":904,"stem":905,"tag":835,"__hash__":906},"versions\u002Fversions\u002Fv3.0.5.md","v3.0.5",{"type":209,"value":837,"toc":895},[838,840,847,860,862,877,879],[212,839,215],{"id":214},[217,841,842,843,846],{},"Passwordless passkey register sends the same confirmation email as password register after a successful account create. Register only creates a new account: the attested user id must be new. Signed-in ",[221,844,845],{},"POST \u002Fpasskeys\u002F"," still adds passkeys to existing accounts.",[245,848,849,852,855],{},[248,850,851],{},"Confirmation email is sent after passwordless register creates a user",[248,853,854],{},"Passwordless register requires a new attested user id",[248,856,857,858],{},"Existing accounts still add passkeys via signed-in ",[221,859,845],{},[212,861,260],{"id":259},[245,863,864,871],{},[248,865,866,268,868],{},[266,867,215],{},[221,869,870],{},"3.0.5",[248,872,873,283,875],{},[266,874,276],{},[221,876,508],{},[212,878,290],{"id":289},[245,880,881,886,891],{},[248,882,883],{},[296,884,299],{"href":885},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Freleases\u002Ftag\u002Fv3.0.5",[248,887,888],{},[296,889,305],{"href":890},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Fcompare\u002Fv3.0.4...v3.0.5",[248,892,893],{},[296,894,311],{"href":310},{"title":313,"searchDepth":314,"depth":315,"links":896},[897,898,899],{"id":214,"depth":318,"text":215},{"id":259,"depth":318,"text":260},{"id":289,"depth":318,"text":290},"2026-09-06","Passwordless passkey register sends confirmation email; register creates only new accounts.",{},"\u002Fversions\u002Fv3.0.5",{"title":835,"description":901},"versions\u002Fv3.0.5","9WA48tBV3CQ7oSDRqQGdW_pOltUl0CcCPhQYKl4cNG8",{"id":908,"title":909,"badge":428,"body":910,"date":996,"description":997,"extension":323,"meta":998,"navigation":325,"path":999,"seo":1000,"stem":1001,"tag":909,"__hash__":1002},"versions\u002Fversions\u002Fv3.0.4.md","v3.0.4",{"type":209,"value":911,"toc":991},[912,914,937,956,958,973,975],[212,913,215],{"id":214},[217,915,916,917,920,921,924,925,928,929,932,933,936],{},"Passwordless passkey registration still mints ",[221,918,919],{},"Guid.NewGuid()"," (UUID v4) by default. Apps can register ",[221,922,923],{},"IPasskeyUserIdFactory"," (or ",[221,926,927],{},"AddPasskeyUserIdFactory",") to choose a different user id on ",[221,930,931],{},"RegisterOptions"," \u002F ",[221,934,935],{},"Register",". Cookie and Identity bearer facades are unchanged.",[245,938,939,946],{},[248,940,941,942,945],{},"Default remains ",[221,943,944],{},"Guid.NewGuid().ToString()"," when no factory is registered",[248,947,948,949,681,952,955],{},"Passwordless register still supports only ",[221,950,951],{},"string",[221,953,954],{},"Guid"," Identity keys",[212,957,260],{"id":259},[245,959,960,967],{},[248,961,962,268,964],{},[266,963,215],{},[221,965,966],{},"3.0.4",[248,968,969,283,971],{},[266,970,276],{},[221,972,508],{},[212,974,290],{"id":289},[245,976,977,982,987],{},[248,978,979],{},[296,980,299],{"href":981},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Freleases\u002Ftag\u002Fv3.0.4",[248,983,984],{},[296,985,305],{"href":986},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Fcompare\u002Fv3.0.3...v3.0.4",[248,988,989],{},[296,990,311],{"href":310},{"title":313,"searchDepth":314,"depth":315,"links":992},[993,994,995],{"id":214,"depth":318,"text":215},{"id":259,"depth":318,"text":260},{"id":289,"depth":318,"text":290},"2026-09-04","Optional factory for the user id minted during passwordless passkey registration.",{},"\u002Fversions\u002Fv3.0.4",{"title":909,"description":997},"versions\u002Fv3.0.4","FQG780V5IWkmOtvWK4TT0uwnccfLHGvHs0Jfft77roY",{"id":1004,"title":1005,"badge":428,"body":1006,"date":1090,"description":1091,"extension":323,"meta":1092,"navigation":325,"path":1093,"seo":1094,"stem":1095,"tag":1005,"__hash__":1096},"versions\u002Fversions\u002Fv3.0.3.md","v3.0.3",{"type":209,"value":1007,"toc":1085},[1008,1010,1024,1050,1052,1067,1069],[212,1009,215],{"id":214},[217,1011,1012,1013,1016,1017,932,1020,1023],{},"Adds Identity bearer sign-in as a ",[221,1014,1015],{},"SignIn"," choice on the existing ",[221,1018,1019],{},"AddAuthEndpoints",[221,1021,1022],{},"MapAuthEndpoints"," facade, built from the existing management, bearer, passkey, and optional JWT modules.",[245,1025,1026,1039],{},[248,1027,1028,1031,1032,1035,1036],{},[221,1029,1030],{},"AuthEndpointsSignIn.IdentityBearer"," maps Identity ",[221,1033,1034],{},"Login"," (JSON access and refresh tokens) at ",[221,1037,1038],{},"IdentityPath",[248,1040,1041,1042,932,1044,677,1046,1049],{},"Cookie default (",[221,1043,1019],{},[221,1045,1022],{},[221,1047,1048],{},"SignIn = Cookie",") is unchanged",[212,1051,260],{"id":259},[245,1053,1054,1061],{},[248,1055,1056,268,1058],{},[266,1057,215],{},[221,1059,1060],{},"3.0.3",[248,1062,1063,283,1065],{},[266,1064,276],{},[221,1066,508],{},[212,1068,290],{"id":289},[245,1070,1071,1076,1081],{},[248,1072,1073],{},[296,1074,299],{"href":1075},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Freleases\u002Ftag\u002Fv3.0.3",[248,1077,1078],{},[296,1079,305],{"href":1080},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Fcompare\u002Fv3.0.2...v3.0.3",[248,1082,1083],{},[296,1084,311],{"href":310},{"title":313,"searchDepth":314,"depth":315,"links":1086},[1087,1088,1089],{"id":214,"depth":318,"text":215},{"id":259,"depth":318,"text":260},{"id":289,"depth":318,"text":290},"2026-09-02","Identity bearer facade for native and mobile clients.",{},"\u002Fversions\u002Fv3.0.3",{"title":1005,"description":1091},"versions\u002Fv3.0.3","pbdrDGx_q6ovUOjROngaomfhxw_nIjqxMUcR0ROAOPI",{"id":1098,"title":1099,"badge":428,"body":1100,"date":1158,"description":1159,"extension":323,"meta":1160,"navigation":325,"path":1161,"seo":1162,"stem":1163,"tag":1099,"__hash__":1164},"versions\u002Fversions\u002Fv3.0.1.md","v3.0.1",{"type":209,"value":1101,"toc":1153},[1102,1104,1110,1118,1120,1135,1137],[212,1103,215],{"id":214},[217,1105,1106,1107,1109],{},"Patch release on 3.0.0. Passkey register and login now call Identity ",[221,1108,577],{}," before establishing a session or issuing tokens, so confirmed-account (and other Identity sign-in) policy matches password and OAuth.",[245,1111,1112,1115],{},[248,1113,1114],{},"Unconfirmed register still returns the new credential without a session",[248,1116,1117],{},"Unconfirmed login returns 401, same shape as Identity login",[212,1119,260],{"id":259},[245,1121,1122,1129],{},[248,1123,1124,268,1126],{},[266,1125,215],{},[221,1127,1128],{},"3.0.1",[248,1130,1131,283,1133],{},[266,1132,276],{},[221,1134,508],{},[212,1136,290],{"id":289},[245,1138,1139,1144,1149],{},[248,1140,1141],{},[296,1142,299],{"href":1143},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Freleases\u002Ftag\u002Fv3.0.1",[248,1145,1146],{},[296,1147,305],{"href":1148},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Fcompare\u002Fv3.0.0...v3.0.1",[248,1150,1151],{},[296,1152,311],{"href":310},{"title":313,"searchDepth":314,"depth":315,"links":1154},[1155,1156,1157],{"id":214,"depth":318,"text":215},{"id":259,"depth":318,"text":260},{"id":289,"depth":318,"text":290},"2026-08-29","Passkey register and login honor CanSignInAsync \u002F confirmed-account policy.",{},"\u002Fversions\u002Fv3.0.1",{"title":1099,"description":1159},"versions\u002Fv3.0.1","zj3kieuCDujGQ_T15beZ028Cz-ToHSqepboxcfWBD5o",{"id":1166,"title":1167,"badge":333,"body":1168,"date":1217,"description":1218,"extension":323,"meta":1219,"navigation":325,"path":1220,"seo":1221,"stem":1222,"tag":1223,"__hash__":1224},"versions\u002Fversions\u002Fexternal-oauth-v3.0.0-preview.3.md","AuthEndpoints.External.OAuth 3.0.0-preview.3",{"type":209,"value":1169,"toc":1213},[1170,1172,1195,1197],[212,1171,276],{"id":338},[245,1173,1174,1192],{},[248,1175,1176,1177,1179,1180,1183,1184,1187,1188,1191],{},"Bump to ",[221,1178,508],{}," so the packed nupkg depends on ",[266,1181,1182],{},"AuthEndpoints 3.0.0"," (published ",[221,1185,1186],{},"3.0.0-preview.2"," still depends on ",[221,1189,1190],{},"3.0.0-rc.2",")",[248,1193,1194],{},"No OAuth feature changes; the package remains preview and is not part of the core 3.0 GA",[212,1196,290],{"id":289},[245,1198,1199,1204,1209],{},[248,1200,1201],{},[296,1202,299],{"href":1203},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Freleases\u002Ftag\u002Fexternal-oauth-v3.0.0-preview.3",[248,1205,1206],{},[296,1207,305],{"href":1208},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Fcompare\u002Fexternal-oauth-v3.0.0-preview.2...external-oauth-v3.0.0-preview.3",[248,1210,1211],{},[296,1212,410],{"href":409},{"title":313,"searchDepth":314,"depth":315,"links":1214},[1215,1216],{"id":338,"depth":318,"text":276},{"id":289,"depth":318,"text":290},"2026-08-27","Retarget the preview OAuth package to depend on stable AuthEndpoints 3.0.0.",{},"\u002Fversions\u002Fexternal-oauth-v3.0.0-preview.3",{"title":1167,"description":1218},"versions\u002Fexternal-oauth-v3.0.0-preview.3","external-oauth-v3.0.0-preview.3","V9Rc2t9JIbfd5d5sRGc-BXa3WnBYHj7-pxbJ9NuX_zE",{"id":1226,"title":1227,"badge":428,"body":1228,"date":1217,"description":1328,"extension":323,"meta":1329,"navigation":325,"path":1330,"seo":1331,"stem":1332,"tag":1227,"__hash__":1333},"versions\u002Fversions\u002Fv3.0.0.md","v3.0.0",{"type":209,"value":1229,"toc":1323},[1230,1232,1235,1286,1288,1305,1307],[212,1231,215],{"id":214},[217,1233,1234],{},"3.0 is the first stable release of the rewritten Identity auth stack. Last feature work was rc.4 (pluggable passkey sign-in); this cut is version and docs only.",[245,1236,1237,1248,1251,1263,1266,1269,1280],{},[248,1238,1239,1240,932,1242,932,1245,1247],{},"Opinionated facade: ",[221,1241,1019],{},[221,1243,1244],{},"UseAuthEndpoints",[221,1246,1022],{}," (cookie Identity + passkeys by default; JWT opt-in)",[248,1249,1250],{},"Sign-in stacks you choose: cookie sessions, Identity bearer tokens, or Simple JWT (hashed refresh tokens, production issuer\u002Faudience\u002Fkey validation)",[248,1252,1253,1254,455,1257,681,1260,1191],{},"Passkeys (WebAuthn) for passwordless register and login, including pluggable ",[221,1255,1256],{},"IPasskeySignInCompleter\u003CTUser>",[221,1258,1259],{},"IdentityPasskeySignInCompleter",[221,1261,1262],{},"JwtPasskeySignInCompleter",[248,1264,1265],{},"Account lifecycle: register, confirm email, forgot\u002Freset password, manage info and 2FA",[248,1267,1268],{},"Step-up ReAuth for sensitive manage and passkey mutations",[248,1270,1271,1272,1275,1276,1279],{},"Roles-aware ",[221,1273,1274],{},"AddAuthEndpoints\u003CTUser, TRole, TContext>"," so Identity ",[221,1277,1278],{},"IRoleStore"," registers correctly",[248,1281,1282,1283,1191],{},".NET 10 (",[221,1284,1285],{},"net10.0",[212,1287,260],{"id":259},[245,1289,1290,1297],{},[248,1291,1292,268,1294],{},[266,1293,215],{},[221,1295,1296],{},"3.0.0",[248,1298,1299,1301,1302,1304],{},[266,1300,276],{}," remains a separate preview package (",[221,1303,508],{},", retargeted at this core)",[212,1306,290],{"id":289},[245,1308,1309,1314,1319],{},[248,1310,1311],{},[296,1312,299],{"href":1313},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Freleases\u002Ftag\u002Fv3.0.0",[248,1315,1316],{},[296,1317,305],{"href":1318},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Fcompare\u002Fv3.0.0-rc.4...v3.0.0",[248,1320,1321],{},[296,1322,311],{"href":310},{"title":313,"searchDepth":314,"depth":315,"links":1324},[1325,1326,1327],{"id":214,"depth":318,"text":215},{"id":259,"depth":318,"text":260},{"id":289,"depth":318,"text":290},"First stable 3.0 release — opinionated facade, cookie \u002F bearer \u002F JWT, passkeys, 2FA, and ReAuth on .NET 10.",{},"\u002Fversions\u002Fv3.0.0",{"title":1227,"description":1328},"versions\u002Fv3.0.0","qnyqFec6a7xCAaBTGD1EaUJwc4qDJb5RMkShcpggJWU",{"id":1335,"title":1336,"badge":1337,"body":1338,"date":1412,"description":1413,"extension":323,"meta":1414,"navigation":325,"path":1415,"seo":1416,"stem":1417,"tag":1418,"__hash__":1419},"versions\u002Fversions\u002Fv3.0.0-rc.4.md","v3.0.0-rc.4","RC",{"type":209,"value":1339,"toc":1407},[1340,1342,1376,1378,1392,1394],[212,1341,215],{"id":214},[245,1343,1344,1350,1362,1367],{},[248,1345,1346,1347,1349],{},"Added ",[221,1348,1256],{}," so passkey register\u002Flogin completion is pluggable (same idea as External.OAuth completers)",[248,1351,1352,1353,1355,1356,932,1359],{},"Default ",[221,1354,1259],{}," preserves cookie \u002F Identity bearer scheme selection via ",[221,1357,1358],{},"useCookies",[221,1360,1361],{},"useSessionCookies",[248,1363,1346,1364,1366],{},[221,1365,1262],{}," for Simple JWT access token + refresh cookie after passwordless register\u002Flogin",[248,1368,1346,1369,681,1372,1375],{},[221,1370,1371],{},"AddPasskeyEndpoints\u003CTUser>()",[221,1373,1374],{},"AddPasskeySignInCompleter\u003CTUser, TCompleter>()","; facade registers the generic passkey DI overload",[212,1377,260],{"id":259},[245,1379,1380,1387],{},[248,1381,1382,268,1384],{},[266,1383,215],{},[221,1385,1386],{},"3.0.0-rc.4",[248,1388,1389,1391],{},[266,1390,276],{}," (unchanged)",[212,1393,290],{"id":289},[245,1395,1396,1401],{},[248,1397,1398],{},[296,1399,299],{"href":1400},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Freleases\u002Ftag\u002Fv3-2026.08.02",[248,1402,1403],{},[296,1404,1406],{"href":1405},"\u002Fmodules\u002Fpasskeys\u002F","Passkeys",{"title":313,"searchDepth":314,"depth":315,"links":1408},[1409,1410,1411],{"id":214,"depth":318,"text":215},{"id":259,"depth":318,"text":260},{"id":289,"depth":318,"text":290},"2026-08-02","Pluggable passkey sign-in completer with Simple JWT support.",{},"\u002Fversions\u002Fv3.0.0-rc.4",{"title":1336,"description":1413},"versions\u002Fv3.0.0-rc.4","v3-2026.08.02","bEQah-HAv_HHMAnz7YQ78sLzZrIY_PdM294nWlDAFrg",{"id":1421,"title":1422,"badge":333,"body":1423,"date":1492,"description":1493,"extension":323,"meta":1494,"navigation":325,"path":1495,"seo":1496,"stem":1497,"tag":1498,"__hash__":1499},"versions\u002Fversions\u002Fexternal-oauth-v3.0.0-preview.2.md","AuthEndpoints.External.OAuth 3.0.0-preview.2",{"type":209,"value":1424,"toc":1488},[1425,1427,1475,1477],[212,1426,276],{"id":338},[245,1428,1429,1432,1438,1444,1447,1454,1463,1469],{},[248,1430,1431],{},"Require verified email by default; auto-link by email only when verified",[248,1433,1434,1435,1437],{},"Clear ",[221,1436,355],{}," cookie after successful sign-in \u002F link",[248,1439,1440,1441,1443],{},"Stricter ",[221,1442,361],{}," (relative-only by default; optional origin allowlist)",[248,1445,1446],{},"Options validation for External settings and provider ClientId\u002FSecret",[248,1448,1449,1450,1453],{},"Browser error redirects to ",[221,1451,1452],{},"ErrorPath"," (JSON Problem when client prefers JSON)",[248,1455,1456,1459,1460],{},[221,1457,1458],{},"AddLoginRateLimiting"," registered from ",[221,1461,1462],{},"AddExternalAuthEndpoints",[248,1464,1465,1468],{},[221,1466,1467],{},"JwtExternalLoginCompleter"," for JWT refresh-cookie completion",[248,1470,1471,1474],{},[221,1472,1473],{},"MapExternalAccountEndpoints"," for list \u002F link \u002F unlink while signed in",[212,1476,290],{"id":289},[245,1478,1479,1484],{},[248,1480,1481],{},[296,1482,299],{"href":1483},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Freleases\u002Ftag\u002Fexternal-oauth-v3.0.0-preview.2",[248,1485,1486],{},[296,1487,410],{"href":409},{"title":313,"searchDepth":314,"depth":315,"links":1489},[1490,1491],{"id":338,"depth":318,"text":276},{"id":289,"depth":318,"text":290},"2026-07-30","Production hardening — verified email, safer linking, error redirects, JWT completer, account link\u002Funlink.",{},"\u002Fversions\u002Fexternal-oauth-v3.0.0-preview.2",{"title":1422,"description":1493},"versions\u002Fexternal-oauth-v3.0.0-preview.2","external-oauth-v3.0.0-preview.2","kMLkTZ2uXzLdT87E4sPP6DGWI1AGHUM8MvJAZNNxyhs",{"id":1501,"title":1502,"badge":1337,"body":1503,"date":1492,"description":1579,"extension":323,"meta":1580,"navigation":325,"path":1581,"seo":1582,"stem":1583,"tag":1584,"__hash__":1585},"versions\u002Fversions\u002Fv3.0.0-rc.3.md","v3.0.0-rc.3",{"type":209,"value":1504,"toc":1574},[1505,1507,1535,1537,1560,1562],[212,1506,215],{"id":214},[245,1508,1509,1524],{},[248,1510,1346,1511,1513,1514,1516,1517,1520,1521,1191],{},[221,1512,1274],{}," so Identity roles register ",[221,1515,1278],{}," correctly (no second ",[221,1518,1519],{},"AddEntityFrameworkStores"," after ",[221,1522,1523],{},"AddRoles",[248,1525,1526,1527,932,1529,1532,1533,1191],{},"Made ",[221,1528,1458],{},[221,1530,1531],{},"AddIdentityEndpointRateLimiting"," public for compose scenarios (e.g. ",[221,1534,276],{},[212,1536,260],{"id":259},[245,1538,1539,1546],{},[248,1540,1541,268,1543],{},[266,1542,215],{},[221,1544,1545],{},"3.0.0-rc.3",[248,1547,1548,1550,1551,1553,1554,1557,1558],{},[266,1549,276],{}," (unchanged) ",[221,1552,1186],{}," — requires AuthEndpoints ",[266,1555,1556],{},"rc.3+"," for ",[221,1559,1458],{},[212,1561,290],{"id":289},[245,1563,1564,1569],{},[248,1565,1566],{},[296,1567,299],{"href":1568},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Freleases\u002Ftag\u002Fv3-2026.07.30.2",[248,1570,1571],{},[296,1572,305],{"href":1573},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Fcompare\u002Fv3.0.0-rc.2...v3-2026.07.30.2",{"title":313,"searchDepth":314,"depth":315,"links":1575},[1576,1577,1578],{"id":214,"depth":318,"text":215},{"id":259,"depth":318,"text":260},{"id":289,"depth":318,"text":290},"Roles-aware AddAuthEndpoints overload and public login rate-limiting API.",{},"\u002Fversions\u002Fv3.0.0-rc.3",{"title":1502,"description":1579},"versions\u002Fv3.0.0-rc.3","v3-2026.07.30.2","sPZShrjW-zrUE8qaeXwukdnYaQCloWOv-c0p66hItf8",{"id":1587,"title":1588,"badge":333,"body":1589,"date":1649,"description":1650,"extension":323,"meta":1651,"navigation":325,"path":1652,"seo":1653,"stem":1654,"tag":1655,"__hash__":1656},"versions\u002Fversions\u002Fexternal-oauth-v3.0.0-preview.1.md","AuthEndpoints.External.OAuth 3.0.0-preview.1",{"type":209,"value":1590,"toc":1645},[1591,1593,1632,1634],[212,1592,276],{"id":338},[245,1594,1595,1600,1606,1619,1626],{},[248,1596,1346,1597,1599],{},[221,1598,276],{}," as a separate preview NuGet package",[248,1601,1602,1603,1605],{},"Shared Core: ",[221,1604,1462],{},", provisioning service, pluggable cookie completer, shared login\u002Fcallback handlers",[248,1607,1608,1609,932,1611,232,1614,932,1616,1191],{},"GitHub and Google provider modules (",[221,1610,379],{},[221,1612,1613],{},"MapGitHubAuthEndpoints",[221,1615,390],{},[221,1617,1618],{},"MapGoogleAuthEndpoints",[248,1620,1621,1622,1625],{},"Default completion issues an Identity application cookie; ",[221,1623,1624],{},"AddCompleter\u003CT>"," for future JWT (or other) modes",[248,1627,1628,1629,1631],{},"Compose-only — not wired into the ",[221,1630,1019],{}," facade",[212,1633,290],{"id":289},[245,1635,1636,1641],{},[248,1637,1638],{},[296,1639,299],{"href":1640},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Freleases\u002Ftag\u002Fexternal-oauth-v3.0.0-preview.1",[248,1642,1643],{},[296,1644,410],{"href":409},{"title":313,"searchDepth":314,"depth":315,"links":1646},[1647,1648],{"id":338,"depth":318,"text":276},{"id":289,"depth":318,"text":290},"2026-07-29","First preview of modular GitHub\u002FGoogle OAuth endpoints.",{},"\u002Fversions\u002Fexternal-oauth-v3.0.0-preview.1",{"title":1588,"description":1650},"versions\u002Fexternal-oauth-v3.0.0-preview.1","external-oauth-v3.0.0-preview.1","gehxt_Oky74PZQYksabD_16xllJV0ySVHoJOYpJB9-I",{"id":1658,"title":1659,"badge":1337,"body":1660,"date":1696,"description":1697,"extension":323,"meta":1698,"navigation":325,"path":1699,"seo":1700,"stem":1701,"tag":1659,"__hash__":1702},"versions\u002Fversions\u002Fv3.0.0-rc.2.md","v3.0.0-rc.2",{"type":209,"value":1661,"toc":1692},[1662,1666,1678,1680],[212,1663,1665],{"id":1664},"changed","Changed",[245,1667,1668,1675],{},[248,1669,1670,1671,1674],{},"Split Identity ",[266,1672,1673],{},"management"," from sign-in so hosts can compose cookie, bearer, or JWT stacks independently",[248,1676,1677],{},"Hardened JWT defaults (hashed refresh tokens, production issuer\u002Faudience\u002Fkey validation)",[212,1679,290],{"id":289},[245,1681,1682,1687],{},[248,1683,1684],{},[296,1685,299],{"href":1686},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Freleases\u002Ftag\u002Fv3.0.0-rc.2",[248,1688,1689],{},[296,1690,305],{"href":1691},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Fcompare\u002Fv3.0.0-rc.1...v3.0.0-rc.2",{"title":313,"searchDepth":314,"depth":315,"links":1693},[1694,1695],{"id":1664,"depth":318,"text":1665},{"id":289,"depth":318,"text":290},"2026-07-26","Split Identity management from sign-in and harden JWT defaults.",{},"\u002Fversions\u002Fv3.0.0-rc.2",{"title":1659,"description":1697},"versions\u002Fv3.0.0-rc.2","kTxFRcs7xTRa2WqxXT2AFHlnAvQflBEOuEhoLNGYcB4",{"id":1704,"title":1705,"badge":1337,"body":1706,"date":1751,"description":1752,"extension":323,"meta":1753,"navigation":325,"path":1754,"seo":1755,"stem":1756,"tag":1705,"__hash__":1757},"versions\u002Fversions\u002Fv3.0.0-rc.1.md","v3.0.0-rc.1",{"type":209,"value":1707,"toc":1746},[1708,1712,1725,1727,1732,1734],[212,1709,1711],{"id":1710},"added","Added",[245,1713,1714,1722],{},[248,1715,1239,1716,932,1718,932,1720],{},[221,1717,1019],{},[221,1719,1244],{},[221,1721,1022],{},[248,1723,1724],{},"Identity cookie and bearer endpoint integration tests",[212,1726,1665],{"id":1664},[245,1728,1729],{},[248,1730,1731],{},"Hardened Identity and Passkey flows for the 3.0 release candidate",[212,1733,290],{"id":289},[245,1735,1736,1741],{},[248,1737,1738],{},[296,1739,299],{"href":1740},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Freleases\u002Ftag\u002Fv3.0.0-rc.1",[248,1742,1743],{},[296,1744,305],{"href":1745},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Fcompare\u002F3.0.0-alpha.11...v3.0.0-rc.1",{"title":313,"searchDepth":314,"depth":315,"links":1747},[1748,1749,1750],{"id":1710,"depth":318,"text":1711},{"id":1664,"depth":318,"text":1665},{"id":289,"depth":318,"text":290},"2026-07-25","Identity\u002FPasskey hardening and the opinionated AddAuthEndpoints facade.",{},"\u002Fversions\u002Fv3.0.0-rc.1",{"title":1705,"description":1752},"versions\u002Fv3.0.0-rc.1","5Wco5wraEHKpzZqS_Q_BevONNQyLiG97Cpfe0bvqCjs",{"id":1759,"title":1760,"badge":1761,"body":1762,"date":1797,"description":1798,"extension":323,"meta":1799,"navigation":325,"path":1800,"seo":1801,"stem":1802,"tag":1760,"__hash__":1803},"versions\u002Fversions\u002Fv3.0.0-alpha.11.md","3.0.0-alpha.11","Alpha",{"type":209,"value":1763,"toc":1792},[1764,1766,1771,1773,1778,1780],[212,1765,1711],{"id":1710},[245,1767,1768],{},[248,1769,1770],{},"Passwordless PasskeyEndpoints (register \u002F login \u002F manage credentials)",[212,1772,1665],{"id":1664},[245,1774,1775],{},[248,1776,1777],{},"Hardened JWT authentication and refresh-token handling",[212,1779,290],{"id":289},[245,1781,1782,1787],{},[248,1783,1784],{},[296,1785,299],{"href":1786},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Freleases\u002Ftag\u002F3.0.0-alpha.11",[248,1788,1789],{},[296,1790,305],{"href":1791},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Fcompare\u002Fv3.0.0-alpha.8...3.0.0-alpha.11",{"title":313,"searchDepth":314,"depth":315,"links":1793},[1794,1795,1796],{"id":1710,"depth":318,"text":1711},{"id":1664,"depth":318,"text":1665},{"id":289,"depth":318,"text":290},"2026-07-24","Hardened JWT auth and finished passwordless PasskeyEndpoints.",{},"\u002Fversions\u002Fv3.0.0-alpha.11",{"title":1760,"description":1798},"versions\u002Fv3.0.0-alpha.11","a2oXkTdIWqPDaeThsqq2MRgT3izTr_Ebz8VlbrXNcNc",{"id":1805,"title":1806,"badge":1761,"body":1807,"date":1834,"description":1835,"extension":323,"meta":1836,"navigation":325,"path":1837,"seo":1838,"stem":1839,"tag":1806,"__hash__":1840},"versions\u002Fversions\u002Fv3.0.0-alpha.8.md","v3.0.0-alpha.8",{"type":209,"value":1808,"toc":1830},[1809,1811,1816,1818],[212,1810,1665],{"id":1664},[245,1812,1813],{},[248,1814,1815],{},"Updated the ReAuth cookie authentication scheme",[212,1817,290],{"id":289},[245,1819,1820,1825],{},[248,1821,1822],{},[296,1823,299],{"href":1824},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Freleases\u002Ftag\u002Fv3.0.0-alpha.8",[248,1826,1827],{},[296,1828,305],{"href":1829},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Fcompare\u002Fv3.0.0-alpha.7...v3.0.0-alpha.8",{"title":313,"searchDepth":314,"depth":315,"links":1831},[1832,1833],{"id":1664,"depth":318,"text":1665},{"id":289,"depth":318,"text":290},"2025-12-20","Updated ReAuth cookie scheme.",{},"\u002Fversions\u002Fv3.0.0-alpha.8",{"title":1806,"description":1835},"versions\u002Fv3.0.0-alpha.8","bRIRaI5WTsDuXZeSs1b5BJzgg5i1opZVTdHUmSSAQ_U",{"id":1842,"title":1843,"badge":1761,"body":1844,"date":1891,"description":1892,"extension":323,"meta":1893,"navigation":325,"path":1894,"seo":1895,"stem":1896,"tag":1843,"__hash__":1897},"versions\u002Fversions\u002Fv3.0.0-alpha.1.md","v3.0.0-alpha.1",{"type":209,"value":1845,"toc":1886},[1846,1848,1862,1864,1872,1874],[212,1847,1711],{"id":1710},[245,1849,1850,1853,1856],{},[248,1851,1852],{},"Cookie authentication endpoints",[248,1854,1855],{},"Leverage official ASP.NET Core Identity API endpoints",[248,1857,1858,1859],{},"Step-up reauthentication via ",[221,1860,1861],{},"\u002FconfirmIdentity",[212,1863,1665],{"id":1664},[245,1865,1866,1869],{},[248,1867,1868],{},"Reorganized and simplified project structure",[248,1870,1871],{},"Breaking changes expected along the 3.0 alpha path",[212,1873,290],{"id":289},[245,1875,1876,1881],{},[248,1877,1878],{},[296,1879,299],{"href":1880},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Freleases\u002Ftag\u002Fv3.0.0-alpha.1",[248,1882,1883],{},[296,1884,305],{"href":1885},"https:\u002F\u002Fgithub.com\u002Fmadeyoga\u002FAuthEndpoints\u002Fcompare\u002Fv2.2.0...v3.0.0-alpha.1",{"title":313,"searchDepth":314,"depth":315,"links":1887},[1888,1889,1890],{"id":1710,"depth":318,"text":1711},{"id":1664,"depth":318,"text":1665},{"id":289,"depth":318,"text":290},"2025-10-16","Cookie auth, Identity API endpoints, and step-up ReAuth — start of the 3.0 line.",{},"\u002Fversions\u002Fv3.0.0-alpha.1",{"title":1843,"description":1892},"versions\u002Fv3.0.0-alpha.1","nQL1QH04T46ibFvd91ysJtL7gEBJW_uuFhcT62DFiVU",1791123625477]