[{"data":1,"prerenderedAt":338},["ShallowReactive",2],{"navigation":3,"\u002Fconcepts\u002Ffaq":203,"\u002Fconcepts\u002Ffaq-surround":335},[4,33,96,114,177],{"title":5,"path":6,"stem":7,"children":8,"icon":32},"Get started","\u002Fgetting-started","1.getting-started\u002F1.index",[9,12,17,22,27],{"title":10,"path":6,"stem":7,"icon":11},"Introduction","i-lucide-house",{"title":13,"path":14,"stem":15,"icon":16},"Install AuthEndpoints","\u002Fgetting-started\u002Finstallation","1.getting-started\u002F2.installation","i-lucide-download",{"title":18,"path":19,"stem":20,"icon":21},"Quick start","\u002Fgetting-started\u002Fquick-start","1.getting-started\u002F3.quick-start","i-lucide-play",{"title":23,"path":24,"stem":25,"icon":26},"Choose a sign-in stack","\u002Fgetting-started\u002Fchoose-a-sign-in-stack","1.getting-started\u002F4.choose-a-sign-in-stack","i-lucide-signpost",{"title":28,"path":29,"stem":30,"icon":31},"Use the AuthEndpoints skill with coding agents","\u002Fgetting-started\u002Fai-agents","1.getting-started\u002F5.ai-agents","i-lucide-bot","i-lucide-rocket",{"title":34,"path":35,"stem":36,"children":37,"icon":95},"Guides","\u002Fguides","2.guides\u002F01.index",[38,40,45,50,55,60,65,70,75,80,85,90],{"title":34,"path":35,"stem":36,"icon":39},"i-lucide-list-checks",{"title":41,"path":42,"stem":43,"icon":44},"Register users","\u002Fguides\u002Fregistration","2.guides\u002F02.registration","i-lucide-user-plus",{"title":46,"path":47,"stem":48,"icon":49},"Sign users in","\u002Fguides\u002Fsign-in","2.guides\u002F03.sign-in","i-lucide-log-in",{"title":51,"path":52,"stem":53,"icon":54},"Sign users out","\u002Fguides\u002Fsign-out","2.guides\u002F04.sign-out","i-lucide-log-out",{"title":56,"path":57,"stem":58,"icon":59},"Turn on two-factor authentication","\u002Fguides\u002Ftwo-factor","2.guides\u002F05.two-factor","i-lucide-smartphone",{"title":61,"path":62,"stem":63,"icon":64},"Reset a forgotten password","\u002Fguides\u002Freset-password","2.guides\u002F06.reset-password","i-lucide-key-round",{"title":66,"path":67,"stem":68,"icon":69},"Change a user's email or password","\u002Fguides\u002Fmanage-account","2.guides\u002F07.manage-account","i-lucide-user-cog",{"title":71,"path":72,"stem":73,"icon":74},"Add, rename, and remove passkeys","\u002Fguides\u002Fmanage-passkeys","2.guides\u002F08.manage-passkeys","i-lucide-scan-face",{"title":76,"path":77,"stem":78,"icon":79},"Link and unlink GitHub or Google accounts","\u002Fguides\u002Flink-external-accounts","2.guides\u002F09.link-external-accounts","i-lucide-link",{"title":81,"path":82,"stem":83,"icon":84},"Require step-up before sensitive actions","\u002Fguides\u002Fstep-up","2.guides\u002F10.step-up","i-lucide-shield-check",{"title":86,"path":87,"stem":88,"icon":89},"Call the API from a browser","\u002Fguides\u002Fbrowser-clients","2.guides\u002F11.browser-clients","i-lucide-globe",{"title":91,"path":92,"stem":93,"icon":94},"Prepare for production","\u002Fguides\u002Fproduction","2.guides\u002F12.production","i-lucide-factory","i-lucide-waypoints",{"title":97,"path":98,"stem":99,"children":100,"icon":113},"Composable endpoints","\u002Fcomposables","3.composables\u002F1.index",[101,104,108],{"title":102,"path":98,"stem":99,"icon":103},"How composition works","i-lucide-layout-grid",{"title":105,"path":106,"stem":107,"icon":39},"Composition requirements","\u002Fcomposables\u002Frequirements","3.composables\u002F2.requirements",{"title":109,"path":110,"stem":111,"icon":112},"Compose a custom auth stack","\u002Fcomposables\u002Frecipes","3.composables\u002F3.recipes","i-lucide-book-marked","i-lucide-blocks",{"title":115,"icon":116,"path":117,"stem":118,"children":119,"page":176},"Reference","i-lucide-book-open","\u002Fmodules","4.modules",[120,125,129,134,139,144,148,153,157,162,166,171],{"title":121,"path":122,"stem":123,"icon":124},"Endpoint reference","\u002Fmodules\u002Fendpoints","4.modules\u002F01.endpoints","i-lucide-route",{"title":126,"path":127,"stem":128,"icon":69},"Identity management module","\u002Fmodules\u002Fidentity-management","4.modules\u002F02.identity-management",{"title":130,"path":131,"stem":132,"icon":133},"Cookie sign-in module","\u002Fmodules\u002Fcookie-auth","4.modules\u002F03.cookie-auth","i-lucide-cookie",{"title":135,"path":136,"stem":137,"icon":138},"Identity bearer sign-in module","\u002Fmodules\u002Fbearer-auth","4.modules\u002F04.bearer-auth","i-lucide-key",{"title":140,"path":141,"stem":142,"icon":143},"JWT module","\u002Fmodules\u002Fjwt","4.modules\u002F05.jwt","i-lucide-fingerprint",{"title":145,"path":146,"stem":147,"icon":74},"Passkeys module","\u002Fmodules\u002Fpasskeys","4.modules\u002F06.passkeys",{"title":149,"path":150,"stem":151,"icon":152},"ReAuth module","\u002Fmodules\u002Freauth","4.modules\u002F07.reauth","i-lucide-shield-alert",{"title":154,"path":155,"stem":156,"icon":49},"External OAuth packages","\u002Fmodules\u002Fexternal-oauth","4.modules\u002F08.external-oauth",{"title":158,"path":159,"stem":160,"icon":161},"Configuration options","\u002Fmodules\u002Fconfiguration","4.modules\u002F09.configuration","i-lucide-settings",{"title":163,"path":164,"stem":165,"icon":84},"Antiforgery (CSRF) rules","\u002Fmodules\u002Fcsrf","4.modules\u002F10.csrf",{"title":167,"path":168,"stem":169,"icon":170},"Responses and errors","\u002Fmodules\u002Ferrors","4.modules\u002F11.errors","i-lucide-circle-alert",{"title":172,"path":173,"stem":174,"icon":175},"Rate-limit policies","\u002Fmodules\u002Frate-limits","4.modules\u002F12.rate-limits","i-lucide-gauge",false,{"title":178,"icon":179,"path":180,"stem":181,"children":182,"page":176},"Concepts","i-lucide-lightbulb","\u002Fconcepts","5.concepts",[183,188,193,198],{"title":184,"path":185,"stem":186,"icon":187},"AuthEndpoints compared with other options","\u002Fconcepts\u002Fcompare","5.concepts\u002F1.compare","i-lucide-git-compare",{"title":189,"path":190,"stem":191,"icon":192},"Stock Identity endpoints vs AuthEndpoints","\u002Fconcepts\u002Fstock-identity-vs-authendpoints","5.concepts\u002F2.stock-identity-vs-authendpoints","i-lucide-columns-2",{"title":194,"path":195,"stem":196,"icon":197},"Security model","\u002Fconcepts\u002Fsecurity-model","5.concepts\u002F3.security-model","i-lucide-shield",{"title":199,"path":200,"stem":201,"icon":202},"FAQ","\u002Fconcepts\u002Ffaq","5.concepts\u002F4.faq","i-lucide-circle-help",{"id":204,"title":199,"body":205,"description":328,"extension":329,"links":330,"meta":331,"navigation":332,"path":200,"seo":333,"stem":201,"__hash__":334},"docs\u002F5.concepts\u002F4.faq.md",{"type":206,"value":207,"toc":315},"minimark",[208,213,217,221,229,233,244,248,254,258,264,268,282,286,292,296],[209,210,212],"h2",{"id":211},"does-this-replace-aspnet-core-identity","Does this replace ASP.NET Core Identity?",[214,215,216],"p",{},"No. AuthEndpoints maps endpoints on top of Identity. You keep Identity, your user type, and EF Core.",[209,218,220],{"id":219},"cookie-sessions-or-jwt","Cookie sessions or JWT?",[214,222,223,224,228],{},"Both are available, and so is Identity bearer. Cookies are the default for browser apps. See ",[225,226,23],"a",{"href":227},"\u002Fgetting-started\u002Fchoose-a-sign-in-stack\u002F",".",[209,230,232],{"id":231},"are-passkeys-included","Are passkeys included?",[214,234,235,236,240,241,228],{},"Yes. The core package includes passkey registration, sign-in, and management, and the facade turns them on by default. Set ",[237,238,239],"code",{},"Passkeys.ServerDomain"," in Production. Passkey sign-in skips two-factor authentication. See ",[225,242,194],{"href":243},"\u002Fconcepts\u002Fsecurity-model\u002F#two-factor-is-a-password-add-on",[209,245,247],{"id":246},"how-does-2fa-work","How does 2FA work?",[214,249,250,251,228],{},"AuthEndpoints uses Identity's authenticator (TOTP) 2FA and 10 recovery codes. Changing 2FA settings requires step-up ReAuth. See ",[225,252,56],{"href":253},"\u002Fguides\u002Ftwo-factor\u002F",[209,255,257],{"id":256},"can-i-map-only-some-of-the-endpoints","Can I map only some of the endpoints?",[214,259,260,261,228],{},"Yes. Start with a facade, then compose modules on your own prefixes when you need a custom path or a JWT-only API. See ",[225,262,97],{"href":263},"\u002Fcomposables\u002F",[209,265,267],{"id":266},"can-users-sign-in-with-github-or-google","Can users sign in with GitHub or Google?",[214,269,270,271,274,275,278,279,228],{},"Yes, with the preview packages ",[237,272,273],{},"AuthEndpoints.OAuth.GitHub"," and ",[237,276,277],{},"AuthEndpoints.OAuth.Google",". You map their routes yourself. See ",[225,280,41],{"href":281},"\u002Fguides\u002Fregistration\u002F#register-with-github-or-google",[209,283,285],{"id":284},"can-this-be-my-sign-in-with-google-provider-for-other-apps","Can this be my Sign in with Google provider for other apps?",[214,287,288,289,228],{},"No. AuthEndpoints signs users in to your own app. If other apps need to treat you as their identity provider, use an OAuth and OpenID Connect server such as OpenIddict. See ",[225,290,184],{"href":291},"\u002Fconcepts\u002Fcompare\u002F",[209,293,295],{"id":294},"related","Related",[297,298,299,304,310],"ul",{},[300,301,302],"li",{},[225,303,184],{"href":291},[300,305,306],{},[225,307,309],{"href":308},"\u002Fgetting-started\u002Fquick-start\u002F","Quick start: add cookie sign-in to an API",[300,311,312],{},[225,313,91],{"href":314},"\u002Fguides\u002Fproduction\u002F",{"title":316,"searchDepth":317,"depth":318,"links":319},"",1,2,[320,321,322,323,324,325,326,327],{"id":211,"depth":318,"text":212},{"id":219,"depth":318,"text":220},{"id":231,"depth":318,"text":232},{"id":246,"depth":318,"text":247},{"id":256,"depth":318,"text":257},{"id":266,"depth":318,"text":267},{"id":284,"depth":318,"text":285},{"id":294,"depth":318,"text":295},"Does AuthEndpoints replace Identity? Cookie or JWT? Passkeys, 2FA, composing routes, and Sign in with Google as a provider.","md",null,{},{"icon":202},{"title":199,"description":328},"7skhIOHfcBWycWDARcTpjdSuD90W2pD-yhfrbODhK70",[336,330],{"title":194,"path":195,"stem":196,"description":337,"icon":197,"children":-1},"How AuthEndpoints protects sign-in and account changes, and which trade-offs it leaves to the host.",1791123629827]