[{"data":1,"prerenderedAt":590},["ShallowReactive",2],{"navigation":3,"\u002Fgetting-started":203,"\u002Fgetting-started-surround":587},[4,33,96,114,177],{"title":5,"path":6,"stem":7,"children":8,"icon":32},"Get started","\u002Fgetting-started","1.getting-started\u002F1.index",[9,12,17,22,27],{"title":10,"path":6,"stem":7,"icon":11},"Introduction","i-lucide-house",{"title":13,"path":14,"stem":15,"icon":16},"Install AuthEndpoints","\u002Fgetting-started\u002Finstallation","1.getting-started\u002F2.installation","i-lucide-download",{"title":18,"path":19,"stem":20,"icon":21},"Quick start","\u002Fgetting-started\u002Fquick-start","1.getting-started\u002F3.quick-start","i-lucide-play",{"title":23,"path":24,"stem":25,"icon":26},"Choose a sign-in stack","\u002Fgetting-started\u002Fchoose-a-sign-in-stack","1.getting-started\u002F4.choose-a-sign-in-stack","i-lucide-signpost",{"title":28,"path":29,"stem":30,"icon":31},"Use the AuthEndpoints skill with coding agents","\u002Fgetting-started\u002Fai-agents","1.getting-started\u002F5.ai-agents","i-lucide-bot","i-lucide-rocket",{"title":34,"path":35,"stem":36,"children":37,"icon":95},"Guides","\u002Fguides","2.guides\u002F01.index",[38,40,45,50,55,60,65,70,75,80,85,90],{"title":34,"path":35,"stem":36,"icon":39},"i-lucide-list-checks",{"title":41,"path":42,"stem":43,"icon":44},"Register users","\u002Fguides\u002Fregistration","2.guides\u002F02.registration","i-lucide-user-plus",{"title":46,"path":47,"stem":48,"icon":49},"Sign users in","\u002Fguides\u002Fsign-in","2.guides\u002F03.sign-in","i-lucide-log-in",{"title":51,"path":52,"stem":53,"icon":54},"Sign users out","\u002Fguides\u002Fsign-out","2.guides\u002F04.sign-out","i-lucide-log-out",{"title":56,"path":57,"stem":58,"icon":59},"Turn on two-factor authentication","\u002Fguides\u002Ftwo-factor","2.guides\u002F05.two-factor","i-lucide-smartphone",{"title":61,"path":62,"stem":63,"icon":64},"Reset a forgotten password","\u002Fguides\u002Freset-password","2.guides\u002F06.reset-password","i-lucide-key-round",{"title":66,"path":67,"stem":68,"icon":69},"Change a user's email or password","\u002Fguides\u002Fmanage-account","2.guides\u002F07.manage-account","i-lucide-user-cog",{"title":71,"path":72,"stem":73,"icon":74},"Add, rename, and remove passkeys","\u002Fguides\u002Fmanage-passkeys","2.guides\u002F08.manage-passkeys","i-lucide-scan-face",{"title":76,"path":77,"stem":78,"icon":79},"Link and unlink GitHub or Google accounts","\u002Fguides\u002Flink-external-accounts","2.guides\u002F09.link-external-accounts","i-lucide-link",{"title":81,"path":82,"stem":83,"icon":84},"Require step-up before sensitive actions","\u002Fguides\u002Fstep-up","2.guides\u002F10.step-up","i-lucide-shield-check",{"title":86,"path":87,"stem":88,"icon":89},"Call the API from a browser","\u002Fguides\u002Fbrowser-clients","2.guides\u002F11.browser-clients","i-lucide-globe",{"title":91,"path":92,"stem":93,"icon":94},"Prepare for production","\u002Fguides\u002Fproduction","2.guides\u002F12.production","i-lucide-factory","i-lucide-waypoints",{"title":97,"path":98,"stem":99,"children":100,"icon":113},"Composable endpoints","\u002Fcomposables","3.composables\u002F1.index",[101,104,108],{"title":102,"path":98,"stem":99,"icon":103},"How composition works","i-lucide-layout-grid",{"title":105,"path":106,"stem":107,"icon":39},"Composition requirements","\u002Fcomposables\u002Frequirements","3.composables\u002F2.requirements",{"title":109,"path":110,"stem":111,"icon":112},"Compose a custom auth stack","\u002Fcomposables\u002Frecipes","3.composables\u002F3.recipes","i-lucide-book-marked","i-lucide-blocks",{"title":115,"icon":116,"path":117,"stem":118,"children":119,"page":176},"Reference","i-lucide-book-open","\u002Fmodules","4.modules",[120,125,129,134,139,144,148,153,157,162,166,171],{"title":121,"path":122,"stem":123,"icon":124},"Endpoint reference","\u002Fmodules\u002Fendpoints","4.modules\u002F01.endpoints","i-lucide-route",{"title":126,"path":127,"stem":128,"icon":69},"Identity management module","\u002Fmodules\u002Fidentity-management","4.modules\u002F02.identity-management",{"title":130,"path":131,"stem":132,"icon":133},"Cookie sign-in module","\u002Fmodules\u002Fcookie-auth","4.modules\u002F03.cookie-auth","i-lucide-cookie",{"title":135,"path":136,"stem":137,"icon":138},"Identity bearer sign-in module","\u002Fmodules\u002Fbearer-auth","4.modules\u002F04.bearer-auth","i-lucide-key",{"title":140,"path":141,"stem":142,"icon":143},"JWT module","\u002Fmodules\u002Fjwt","4.modules\u002F05.jwt","i-lucide-fingerprint",{"title":145,"path":146,"stem":147,"icon":74},"Passkeys module","\u002Fmodules\u002Fpasskeys","4.modules\u002F06.passkeys",{"title":149,"path":150,"stem":151,"icon":152},"ReAuth module","\u002Fmodules\u002Freauth","4.modules\u002F07.reauth","i-lucide-shield-alert",{"title":154,"path":155,"stem":156,"icon":49},"External OAuth packages","\u002Fmodules\u002Fexternal-oauth","4.modules\u002F08.external-oauth",{"title":158,"path":159,"stem":160,"icon":161},"Configuration options","\u002Fmodules\u002Fconfiguration","4.modules\u002F09.configuration","i-lucide-settings",{"title":163,"path":164,"stem":165,"icon":84},"Antiforgery (CSRF) rules","\u002Fmodules\u002Fcsrf","4.modules\u002F10.csrf",{"title":167,"path":168,"stem":169,"icon":170},"Responses and errors","\u002Fmodules\u002Ferrors","4.modules\u002F11.errors","i-lucide-circle-alert",{"title":172,"path":173,"stem":174,"icon":175},"Rate-limit policies","\u002Fmodules\u002Frate-limits","4.modules\u002F12.rate-limits","i-lucide-gauge",false,{"title":178,"icon":179,"path":180,"stem":181,"children":182,"page":176},"Concepts","i-lucide-lightbulb","\u002Fconcepts","5.concepts",[183,188,193,198],{"title":184,"path":185,"stem":186,"icon":187},"AuthEndpoints compared with other options","\u002Fconcepts\u002Fcompare","5.concepts\u002F1.compare","i-lucide-git-compare",{"title":189,"path":190,"stem":191,"icon":192},"Stock Identity endpoints vs AuthEndpoints","\u002Fconcepts\u002Fstock-identity-vs-authendpoints","5.concepts\u002F2.stock-identity-vs-authendpoints","i-lucide-columns-2",{"title":194,"path":195,"stem":196,"icon":197},"Security model","\u002Fconcepts\u002Fsecurity-model","5.concepts\u002F3.security-model","i-lucide-shield",{"title":199,"path":200,"stem":201,"icon":202},"FAQ","\u002Fconcepts\u002Ffaq","5.concepts\u002F4.faq","i-lucide-circle-help",{"id":204,"title":10,"body":205,"description":580,"extension":581,"links":582,"meta":583,"navigation":584,"path":6,"seo":585,"stem":7,"__hash__":586},"docs\u002F1.getting-started\u002F1.index.md",{"type":206,"value":207,"toc":571},"minimark",[208,212,217,436,440,456,501,510,532,536,549,553],[209,210,211],"p",{},"AuthEndpoints maps ready-made auth API endpoints on top of ASP.NET Core Identity. It is for a first-party API: your own web and mobile clients (React, Next.js, Vue, Nuxt, Svelte, or native apps) signing in to your own backend. You keep Identity, your user type, and EF Core. AuthEndpoints adds the routes, the rate limits, the CSRF checks, and the step-up flow that you would otherwise write by hand.",[213,214,216],"h2",{"id":215},"what-authendpoints-can-do","What AuthEndpoints can do",[218,219,220,236],"table",{},[221,222,223],"thead",{},[224,225,226,230,233],"tr",{},[227,228,229],"th",{},"Capability",[227,231,232],{},"What it does",[227,234,235],{},"Guide",[237,238,239,254,267,280,293,306,319,332,345,358,371,384,397,410,423],"tbody",{},[224,240,241,245,248],{},[242,243,244],"td",{},"Email and password registration",[242,246,247],{},"Creates accounts and sends a confirmation email.",[242,249,250],{},[251,252,41],"a",{"href":253},"\u002Fguides\u002Fregistration\u002F",[224,255,256,259,262],{},[242,257,258],{},"Passkey registration",[242,260,261],{},"Creates passwordless accounts with WebAuthn.",[242,263,264],{},[251,265,41],{"href":266},"\u002Fguides\u002Fregistration\u002F#register-with-a-passkey",[224,268,269,272,275],{},[242,270,271],{},"GitHub and Google",[242,273,274],{},"Adds social sign-up and sign-in in separate preview packages.",[242,276,277],{},[251,278,41],{"href":279},"\u002Fguides\u002Fregistration\u002F#register-with-github-or-google",[224,281,282,285,288],{},[242,283,284],{},"Cookie sessions",[242,286,287],{},"Signs browser users in with the Identity application cookie.",[242,289,290],{},[251,291,46],{"href":292},"\u002Fguides\u002Fsign-in\u002F",[224,294,295,298,301],{},[242,296,297],{},"Identity bearer tokens",[242,299,300],{},"Issues access and refresh tokens for native and mobile apps.",[242,302,303],{},[251,304,46],{"href":305},"\u002Fguides\u002Fsign-in\u002F#sign-in-with-a-password-and-identity-bearer-tokens",[224,307,308,311,314],{},[242,309,310],{},"JWT with a refresh cookie",[242,312,313],{},"Issues short-lived JWTs with rotating, hashed refresh tokens.",[242,315,316],{},[251,317,46],{"href":318},"\u002Fguides\u002Fsign-in\u002F#sign-in-with-a-password-and-a-jwt",[224,320,321,324,327],{},[242,322,323],{},"Passkey sign-in",[242,325,326],{},"Signs users in with a passkey.",[242,328,329],{},[251,330,46],{"href":331},"\u002Fguides\u002Fsign-in\u002F#sign-in-with-a-passkey",[224,333,334,337,340],{},[242,335,336],{},"Two-factor authentication",[242,338,339],{},"Turns on authenticator codes and 10 recovery codes.",[242,341,342],{},[251,343,56],{"href":344},"\u002Fguides\u002Ftwo-factor\u002F",[224,346,347,350,353],{},[242,348,349],{},"Password reset",[242,351,352],{},"Sends reset codes and sets a new password.",[242,354,355],{},[251,356,61],{"href":357},"\u002Fguides\u002Freset-password\u002F",[224,359,360,363,366],{},[242,361,362],{},"Email and password change",[242,364,365],{},"Changes the email after the user confirms the new address.",[242,367,368],{},[251,369,66],{"href":370},"\u002Fguides\u002Fmanage-account\u002F",[224,372,373,376,379],{},[242,374,375],{},"Passkey management",[242,377,378],{},"Adds, renames, and removes passkeys.",[242,380,381],{},[251,382,71],{"href":383},"\u002Fguides\u002Fmanage-passkeys\u002F",[224,385,386,389,392],{},[242,387,388],{},"Account linking",[242,390,391],{},"Links and unlinks GitHub or Google logins.",[242,393,394],{},[251,395,76],{"href":396},"\u002Fguides\u002Flink-external-accounts\u002F",[224,398,399,402,405],{},[242,400,401],{},"Step-up (ReAuth)",[242,403,404],{},"Asks for proof again before sensitive changes.",[242,406,407],{},[251,408,81],{"href":409},"\u002Fguides\u002Fstep-up\u002F",[224,411,412,415,418],{},[242,413,414],{},"Built-in protection",[242,416,417],{},"Adds CSRF checks, rate limits, lockout, and startup checks.",[242,419,420],{},[251,421,194],{"href":422},"\u002Fconcepts\u002Fsecurity-model\u002F",[224,424,425,428,431],{},[242,426,427],{},"Composable modules",[242,429,430],{},"Maps only the routes you need, on your own prefixes.",[242,432,433],{},[251,434,97],{"href":435},"\u002Fcomposables\u002F",[213,437,439],{"id":438},"facade-or-composition","Facade or composition",[209,441,442,443,447,448,451,452,455],{},"Most hosts start with the facade: ",[444,445,446],"code",{},"AddAuthEndpoints",", ",[444,449,450],{},"UseAuthEndpoints",", and ",[444,453,454],{},"MapAuthEndpoints",". The facade maps Identity management, one password sign-in stack, and passkeys with secure defaults. JWT is opt-in. External OAuth is never part of the facade.",[218,457,458,468],{},[221,459,460],{},[224,461,462,465],{},[227,463,464],{},"Approach",[227,466,467],{},"Use it for",[237,469,470,478,493],{},[224,471,472,475],{},[242,473,474],{},"Cookie facade",[242,476,477],{},"Browser clients. This is the default.",[224,479,480,483],{},[242,481,482],{},"Identity bearer facade",[242,484,485,486,489,490,492],{},"Native and mobile clients. Pass ",[444,487,488],{},"AuthEndpointsSignIn.IdentityBearer"," to ",[444,491,446],{},".",[224,494,495,498],{},[242,496,497],{},"Composition",[242,499,500],{},"A JWT-only API, custom prefixes, or a custom mix of modules.",[209,502,503,504,507,508,492],{},"To pick a stack, see ",[251,505,23],{"href":506},"\u002Fgetting-started\u002Fchoose-a-sign-in-stack\u002F",". To build one by hand, see ",[251,509,97],{"href":435},[511,512,515],"callout",{"color":513,"icon":514},"warning","i-lucide-flask-conical",[209,516,517,518,447,521,451,524,527,528,531],{},"External OAuth (",[444,519,520],{},"AuthEndpoints.External.OAuth",[444,522,523],{},"AuthEndpoints.OAuth.GitHub",[444,525,526],{},"AuthEndpoints.OAuth.Google",") ships in preview packages. The core ",[444,529,530],{},"AuthEndpoints"," package does not include it.",[213,533,535],{"id":534},"requirements","Requirements",[537,538,539,543,546],"ul",{},[540,541,542],"li",{},".NET 10",[540,544,545],{},"ASP.NET Core Identity",[540,547,548],{},"EF Core for the user store",[213,550,552],{"id":551},"next","Next",[537,554,555,560,566],{},[540,556,557],{},[251,558,13],{"href":559},"\u002Fgetting-started\u002Finstallation\u002F",[540,561,562],{},[251,563,565],{"href":564},"\u002Fgetting-started\u002Fquick-start\u002F","Quick start: add cookie sign-in to an API",[540,567,568],{},[251,569,184],{"href":570},"\u002Fconcepts\u002Fcompare\u002F",{"title":572,"searchDepth":573,"depth":574,"links":575},"",1,2,[576,577,578,579],{"id":215,"depth":574,"text":216},{"id":438,"depth":574,"text":439},{"id":534,"depth":574,"text":535},{"id":551,"depth":574,"text":552},"AuthEndpoints is an ASP.NET Core library of ready-made Identity auth endpoints for web and mobile clients.","md",null,{},{"icon":11},{"title":10,"description":580},"Hh8fSvRL7sGt_v0wFl4toaSI3m08ZS-fgp5H4HcPh2Q",[582,588],{"title":13,"path":14,"stem":15,"description":589,"icon":16,"children":-1},"Add the AuthEndpoints NuGet package to your ASP.NET Core project.",1791123625686]