Changelog
Get started

Introduction

AuthEndpoints is an ASP.NET Core library of ready-made Identity auth endpoints for web and mobile clients.

AuthEndpoints maps ready-made auth API endpoints on top of ASP.NET Core Identity. It is for a first-party API: your own web and mobile clients (React, Next.js, Vue, Nuxt, Svelte, or native apps) signing in to your own backend. You keep Identity, your user type, and EF Core. AuthEndpoints adds the routes, the rate limits, the CSRF checks, and the step-up flow that you would otherwise write by hand.

What AuthEndpoints can do

CapabilityWhat it doesGuide
Email and password registrationCreates accounts and sends a confirmation email.Register users
Passkey registrationCreates passwordless accounts with WebAuthn.Register users
GitHub and GoogleAdds social sign-up and sign-in in separate preview packages.Register users
Cookie sessionsSigns browser users in with the Identity application cookie.Sign users in
Identity bearer tokensIssues access and refresh tokens for native and mobile apps.Sign users in
JWT with a refresh cookieIssues short-lived JWTs with rotating, hashed refresh tokens.Sign users in
Passkey sign-inSigns users in with a passkey.Sign users in
Two-factor authenticationTurns on authenticator codes and 10 recovery codes.Turn on two-factor authentication
Password resetSends reset codes and sets a new password.Reset a forgotten password
Email and password changeChanges the email after the user confirms the new address.Change a user's email or password
Passkey managementAdds, renames, and removes passkeys.Add, rename, and remove passkeys
Account linkingLinks and unlinks GitHub or Google logins.Link and unlink GitHub or Google accounts
Step-up (ReAuth)Asks for proof again before sensitive changes.Require step-up before sensitive actions
Built-in protectionAdds CSRF checks, rate limits, lockout, and startup checks.Security model
Composable modulesMaps only the routes you need, on your own prefixes.Composable endpoints

Facade or composition

Most hosts start with the facade: AddAuthEndpoints, UseAuthEndpoints, and MapAuthEndpoints. The facade maps Identity management, one password sign-in stack, and passkeys with secure defaults. JWT is opt-in. External OAuth is never part of the facade.

ApproachUse it for
Cookie facadeBrowser clients. This is the default.
Identity bearer facadeNative and mobile clients. Pass AuthEndpointsSignIn.IdentityBearer to AddAuthEndpoints.
CompositionA JWT-only API, custom prefixes, or a custom mix of modules.

To pick a stack, see Choose a sign-in stack. To build one by hand, see Composable endpoints.

External OAuth (AuthEndpoints.External.OAuth, AuthEndpoints.OAuth.GitHub, and AuthEndpoints.OAuth.Google) ships in preview packages. The core AuthEndpoints package does not include it.

Requirements

  • .NET 10
  • ASP.NET Core Identity
  • EF Core for the user store

Next