Get started
Introduction
AuthEndpoints is an ASP.NET Core library of ready-made Identity auth endpoints for web and mobile clients.
AuthEndpoints maps ready-made auth API endpoints on top of ASP.NET Core Identity. It is for a first-party API: your own web and mobile clients (React, Next.js, Vue, Nuxt, Svelte, or native apps) signing in to your own backend. You keep Identity, your user type, and EF Core. AuthEndpoints adds the routes, the rate limits, the CSRF checks, and the step-up flow that you would otherwise write by hand.
What AuthEndpoints can do
| Capability | What it does | Guide |
|---|---|---|
| Email and password registration | Creates accounts and sends a confirmation email. | Register users |
| Passkey registration | Creates passwordless accounts with WebAuthn. | Register users |
| GitHub and Google | Adds social sign-up and sign-in in separate preview packages. | Register users |
| Cookie sessions | Signs browser users in with the Identity application cookie. | Sign users in |
| Identity bearer tokens | Issues access and refresh tokens for native and mobile apps. | Sign users in |
| JWT with a refresh cookie | Issues short-lived JWTs with rotating, hashed refresh tokens. | Sign users in |
| Passkey sign-in | Signs users in with a passkey. | Sign users in |
| Two-factor authentication | Turns on authenticator codes and 10 recovery codes. | Turn on two-factor authentication |
| Password reset | Sends reset codes and sets a new password. | Reset a forgotten password |
| Email and password change | Changes the email after the user confirms the new address. | Change a user's email or password |
| Passkey management | Adds, renames, and removes passkeys. | Add, rename, and remove passkeys |
| Account linking | Links and unlinks GitHub or Google logins. | Link and unlink GitHub or Google accounts |
| Step-up (ReAuth) | Asks for proof again before sensitive changes. | Require step-up before sensitive actions |
| Built-in protection | Adds CSRF checks, rate limits, lockout, and startup checks. | Security model |
| Composable modules | Maps only the routes you need, on your own prefixes. | Composable endpoints |
Facade or composition
Most hosts start with the facade: AddAuthEndpoints, UseAuthEndpoints, and MapAuthEndpoints. The facade maps Identity management, one password sign-in stack, and passkeys with secure defaults. JWT is opt-in. External OAuth is never part of the facade.
| Approach | Use it for |
|---|---|
| Cookie facade | Browser clients. This is the default. |
| Identity bearer facade | Native and mobile clients. Pass AuthEndpointsSignIn.IdentityBearer to AddAuthEndpoints. |
| Composition | A JWT-only API, custom prefixes, or a custom mix of modules. |
To pick a stack, see Choose a sign-in stack. To build one by hand, see Composable endpoints.
External OAuth (
AuthEndpoints.External.OAuth, AuthEndpoints.OAuth.GitHub, and AuthEndpoints.OAuth.Google) ships in preview packages. The core AuthEndpoints package does not include it.Requirements
- .NET 10
- ASP.NET Core Identity
- EF Core for the user store