Guides
Guides
Task-based steps for registration, sign-in, account management, and production setup.
Each guide covers one task. The steps use the facade defaults: management and sign-in under /identity, passkeys under /account, JWT under /auth, and external OAuth under /auth/external.
Coming from MapIdentityApi? See Stock Identity endpoints vs AuthEndpoints.
| Guide | Use it when |
|---|---|
| Register users | You need sign-up with a password, a passkey, or GitHub or Google. |
| Sign users in | You need sign-in with a password, a passkey, or GitHub or Google, including 2FA codes. |
| Sign users out | You need logout for the cookie, Identity bearer, or JWT stack. |
| Turn on two-factor authentication | Users need authenticator codes and recovery codes. |
| Reset a forgotten password | A user cannot sign in and needs a reset email. |
| Change a user's email or password | A signed-in user changes their email or password. |
| Add, rename, and remove passkeys | A signed-in user manages their passkeys. |
| Link and unlink GitHub or Google accounts | A signed-in user connects or disconnects a provider login. |
| Require step-up before sensitive actions | An endpoint returns 401 or 403 until the user proves their identity again. |
| Call the API from a browser | You set up cookies, CSRF tokens, and CORS for a browser client. |
| Prepare for production | You are about to deploy. |
Route tables for every module are in the Endpoint reference.