FAQ
Does this replace ASP.NET Core Identity?
No. AuthEndpoints maps endpoints on top of Identity. You keep Identity, your user type, and EF Core.
Cookie sessions or JWT?
Both are available, and so is Identity bearer. Cookies are the default for browser apps. See Choose a sign-in stack.
Are passkeys included?
Yes. The core package includes passkey registration, sign-in, and management, and the facade turns them on by default. Set Passkeys.ServerDomain in Production. Passkey sign-in skips two-factor authentication. See Security model.
How does 2FA work?
AuthEndpoints uses Identity's authenticator (TOTP) 2FA and 10 recovery codes. Changing 2FA settings requires step-up ReAuth. See Turn on two-factor authentication.
Can I map only some of the endpoints?
Yes. Start with a facade, then compose modules on your own prefixes when you need a custom path or a JWT-only API. See Composable endpoints.
Can users sign in with GitHub or Google?
Yes, with the preview packages AuthEndpoints.OAuth.GitHub and AuthEndpoints.OAuth.Google. You map their routes yourself. See Register users.
Can this be my Sign in with Google provider for other apps?
No. AuthEndpoints signs users in to your own app. If other apps need to treat you as their identity provider, use an OAuth and OpenID Connect server such as OpenIddict. See AuthEndpoints compared with other options.