[{"data":1,"prerenderedAt":725},["ShallowReactive",2],{"navigation":3,"\u002Fguides\u002Fbrowser-clients":203,"\u002Fguides\u002Fbrowser-clients-surround":720},[4,33,96,114,177],{"title":5,"path":6,"stem":7,"children":8,"icon":32},"Get started","\u002Fgetting-started","1.getting-started\u002F1.index",[9,12,17,22,27],{"title":10,"path":6,"stem":7,"icon":11},"Introduction","i-lucide-house",{"title":13,"path":14,"stem":15,"icon":16},"Install AuthEndpoints","\u002Fgetting-started\u002Finstallation","1.getting-started\u002F2.installation","i-lucide-download",{"title":18,"path":19,"stem":20,"icon":21},"Quick start","\u002Fgetting-started\u002Fquick-start","1.getting-started\u002F3.quick-start","i-lucide-play",{"title":23,"path":24,"stem":25,"icon":26},"Choose a sign-in stack","\u002Fgetting-started\u002Fchoose-a-sign-in-stack","1.getting-started\u002F4.choose-a-sign-in-stack","i-lucide-signpost",{"title":28,"path":29,"stem":30,"icon":31},"Use the AuthEndpoints skill with coding agents","\u002Fgetting-started\u002Fai-agents","1.getting-started\u002F5.ai-agents","i-lucide-bot","i-lucide-rocket",{"title":34,"path":35,"stem":36,"children":37,"icon":95},"Guides","\u002Fguides","2.guides\u002F01.index",[38,40,45,50,55,60,65,70,75,80,85,90],{"title":34,"path":35,"stem":36,"icon":39},"i-lucide-list-checks",{"title":41,"path":42,"stem":43,"icon":44},"Register users","\u002Fguides\u002Fregistration","2.guides\u002F02.registration","i-lucide-user-plus",{"title":46,"path":47,"stem":48,"icon":49},"Sign users in","\u002Fguides\u002Fsign-in","2.guides\u002F03.sign-in","i-lucide-log-in",{"title":51,"path":52,"stem":53,"icon":54},"Sign users out","\u002Fguides\u002Fsign-out","2.guides\u002F04.sign-out","i-lucide-log-out",{"title":56,"path":57,"stem":58,"icon":59},"Turn on two-factor authentication","\u002Fguides\u002Ftwo-factor","2.guides\u002F05.two-factor","i-lucide-smartphone",{"title":61,"path":62,"stem":63,"icon":64},"Reset a forgotten password","\u002Fguides\u002Freset-password","2.guides\u002F06.reset-password","i-lucide-key-round",{"title":66,"path":67,"stem":68,"icon":69},"Change a user's email or password","\u002Fguides\u002Fmanage-account","2.guides\u002F07.manage-account","i-lucide-user-cog",{"title":71,"path":72,"stem":73,"icon":74},"Add, rename, and remove passkeys","\u002Fguides\u002Fmanage-passkeys","2.guides\u002F08.manage-passkeys","i-lucide-scan-face",{"title":76,"path":77,"stem":78,"icon":79},"Link and unlink GitHub or Google accounts","\u002Fguides\u002Flink-external-accounts","2.guides\u002F09.link-external-accounts","i-lucide-link",{"title":81,"path":82,"stem":83,"icon":84},"Require step-up before sensitive actions","\u002Fguides\u002Fstep-up","2.guides\u002F10.step-up","i-lucide-shield-check",{"title":86,"path":87,"stem":88,"icon":89},"Call the API from a browser","\u002Fguides\u002Fbrowser-clients","2.guides\u002F11.browser-clients","i-lucide-globe",{"title":91,"path":92,"stem":93,"icon":94},"Prepare for production","\u002Fguides\u002Fproduction","2.guides\u002F12.production","i-lucide-factory","i-lucide-waypoints",{"title":97,"path":98,"stem":99,"children":100,"icon":113},"Composable endpoints","\u002Fcomposables","3.composables\u002F1.index",[101,104,108],{"title":102,"path":98,"stem":99,"icon":103},"How composition works","i-lucide-layout-grid",{"title":105,"path":106,"stem":107,"icon":39},"Composition requirements","\u002Fcomposables\u002Frequirements","3.composables\u002F2.requirements",{"title":109,"path":110,"stem":111,"icon":112},"Compose a custom auth stack","\u002Fcomposables\u002Frecipes","3.composables\u002F3.recipes","i-lucide-book-marked","i-lucide-blocks",{"title":115,"icon":116,"path":117,"stem":118,"children":119,"page":176},"Reference","i-lucide-book-open","\u002Fmodules","4.modules",[120,125,129,134,139,144,148,153,157,162,166,171],{"title":121,"path":122,"stem":123,"icon":124},"Endpoint reference","\u002Fmodules\u002Fendpoints","4.modules\u002F01.endpoints","i-lucide-route",{"title":126,"path":127,"stem":128,"icon":69},"Identity management module","\u002Fmodules\u002Fidentity-management","4.modules\u002F02.identity-management",{"title":130,"path":131,"stem":132,"icon":133},"Cookie sign-in module","\u002Fmodules\u002Fcookie-auth","4.modules\u002F03.cookie-auth","i-lucide-cookie",{"title":135,"path":136,"stem":137,"icon":138},"Identity bearer sign-in module","\u002Fmodules\u002Fbearer-auth","4.modules\u002F04.bearer-auth","i-lucide-key",{"title":140,"path":141,"stem":142,"icon":143},"JWT module","\u002Fmodules\u002Fjwt","4.modules\u002F05.jwt","i-lucide-fingerprint",{"title":145,"path":146,"stem":147,"icon":74},"Passkeys module","\u002Fmodules\u002Fpasskeys","4.modules\u002F06.passkeys",{"title":149,"path":150,"stem":151,"icon":152},"ReAuth module","\u002Fmodules\u002Freauth","4.modules\u002F07.reauth","i-lucide-shield-alert",{"title":154,"path":155,"stem":156,"icon":49},"External OAuth packages","\u002Fmodules\u002Fexternal-oauth","4.modules\u002F08.external-oauth",{"title":158,"path":159,"stem":160,"icon":161},"Configuration options","\u002Fmodules\u002Fconfiguration","4.modules\u002F09.configuration","i-lucide-settings",{"title":163,"path":164,"stem":165,"icon":84},"Antiforgery (CSRF) rules","\u002Fmodules\u002Fcsrf","4.modules\u002F10.csrf",{"title":167,"path":168,"stem":169,"icon":170},"Responses and errors","\u002Fmodules\u002Ferrors","4.modules\u002F11.errors","i-lucide-circle-alert",{"title":172,"path":173,"stem":174,"icon":175},"Rate-limit policies","\u002Fmodules\u002Frate-limits","4.modules\u002F12.rate-limits","i-lucide-gauge",false,{"title":178,"icon":179,"path":180,"stem":181,"children":182,"page":176},"Concepts","i-lucide-lightbulb","\u002Fconcepts","5.concepts",[183,188,193,198],{"title":184,"path":185,"stem":186,"icon":187},"AuthEndpoints compared with other options","\u002Fconcepts\u002Fcompare","5.concepts\u002F1.compare","i-lucide-git-compare",{"title":189,"path":190,"stem":191,"icon":192},"Stock Identity endpoints vs AuthEndpoints","\u002Fconcepts\u002Fstock-identity-vs-authendpoints","5.concepts\u002F2.stock-identity-vs-authendpoints","i-lucide-columns-2",{"title":194,"path":195,"stem":196,"icon":197},"Security model","\u002Fconcepts\u002Fsecurity-model","5.concepts\u002F3.security-model","i-lucide-shield",{"title":199,"path":200,"stem":201,"icon":202},"FAQ","\u002Fconcepts\u002Ffaq","5.concepts\u002F4.faq","i-lucide-circle-help",{"id":204,"title":86,"body":205,"description":713,"extension":714,"links":715,"meta":716,"navigation":717,"path":87,"seo":718,"stem":88,"__hash__":719},"docs\u002F2.guides\u002F11.browser-clients.md",{"type":206,"value":207,"toc":706},"minimark",[208,212,217,233,237,274,358,366,370,373,572,581,585,592,649,676,680,702],[209,210,211],"p",{},"Browser clients on the cookie stack and the JWT stack depend on cookies and antiforgery tokens. Follow these steps for a single-page app (SPA) or any other browser client.",[213,214,216],"h2",{"id":215},"send-cookies-on-every-request","Send cookies on every request",[209,218,219,220,224,225,228,229,232],{},"Add ",[221,222,223],"code",{},"credentials: 'include'"," to every ",[221,226,227],{},"fetch"," call. With Axios, set ",[221,230,231],{},"withCredentials: true",". Without it, the browser does not send the application cookie, the antiforgery cookie, the ReAuth cookie, or the JWT refresh cookie.",[213,234,236],{"id":235},"send-a-csrf-token-on-protected-requests","Send a CSRF token on protected requests",[238,239,240,256,263],"ol",{},[241,242,243,244,247,248,251,252,255],"li",{},"Get a token. The cookie stack serves it at ",[221,245,246],{},"GET \u002Fidentity\u002FcsrfToken",". The JWT stack serves it at ",[221,249,250],{},"GET \u002Fauth\u002FcsrfToken",". Both return ",[221,253,254],{},"{ \"csrfToken\": \"...\" }"," and set the antiforgery cookie.",[241,257,258,259,262],{},"Send the token in the ",[221,260,261],{},"RequestVerificationToken"," header on every route that requires antiforgery.",[241,264,265,266,269,270,273],{},"If a request returns ",[221,267,268],{},"400"," with the body ",[221,271,272],{},"Invalid or missing CSRF token.",", get a new token and retry once.",[275,276,281],"pre",{"className":277,"code":278,"language":279,"meta":280,"style":280},"language-js shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","async function csrf() {\n  const r = await fetch('\u002Fidentity\u002FcsrfToken', { credentials: 'include' });\n  return (await r.json()).csrfToken;\n}\n\nconst csrfToken = await csrf();\nawait fetch('\u002Fidentity\u002Fmanage\u002Finfo', {\n  method: 'POST',\n  credentials: 'include',\n  headers: { 'Content-Type': 'application\u002Fjson', 'RequestVerificationToken': csrfToken },\n  body: JSON.stringify({ newEmail })\n});\n","js","",[221,282,283,291,297,303,309,316,322,328,334,340,346,352],{"__ignoreMap":280},[284,285,288],"span",{"class":286,"line":287},"line",1,[284,289,290],{},"async function csrf() {\n",[284,292,294],{"class":286,"line":293},2,[284,295,296],{},"  const r = await fetch('\u002Fidentity\u002FcsrfToken', { credentials: 'include' });\n",[284,298,300],{"class":286,"line":299},3,[284,301,302],{},"  return (await r.json()).csrfToken;\n",[284,304,306],{"class":286,"line":305},4,[284,307,308],{},"}\n",[284,310,312],{"class":286,"line":311},5,[284,313,315],{"emptyLinePlaceholder":314},true,"\n",[284,317,319],{"class":286,"line":318},6,[284,320,321],{},"const csrfToken = await csrf();\n",[284,323,325],{"class":286,"line":324},7,[284,326,327],{},"await fetch('\u002Fidentity\u002Fmanage\u002Finfo', {\n",[284,329,331],{"class":286,"line":330},8,[284,332,333],{},"  method: 'POST',\n",[284,335,337],{"class":286,"line":336},9,[284,338,339],{},"  credentials: 'include',\n",[284,341,343],{"class":286,"line":342},10,[284,344,345],{},"  headers: { 'Content-Type': 'application\u002Fjson', 'RequestVerificationToken': csrfToken },\n",[284,347,349],{"class":286,"line":348},11,[284,350,351],{},"  body: JSON.stringify({ newEmail })\n",[284,353,355],{"class":286,"line":354},12,[284,356,357],{},"});\n",[209,359,360,361,365],{},"The token is tied to the signed-in user. After sign-in or sign-out, get a new token. Login, register, forgot password, and reset password need no token. The full list is in ",[362,363,163],"a",{"href":364},"\u002Fmodules\u002Fcsrf\u002F",".",[213,367,369],{"id":368},"set-up-cors-when-the-client-runs-on-another-origin","Set up CORS when the client runs on another origin",[209,371,372],{},"AuthEndpoints does not configure CORS. If the browser client and the API have different origins, add a CORS policy in the host that allows credentials and the AuthEndpoints headers:",[275,374,378],{"className":375,"code":376,"language":377,"meta":280,"style":280},"language-cs shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","builder.Services.AddCors(o => o.AddPolicy(\"spa\", policy => policy\n    .WithOrigins(\"https:\u002F\u002Fapp.example.com\")\n    .AllowCredentials()\n    .AllowAnyMethod()\n    .WithHeaders(\"Content-Type\", \"RequestVerificationToken\", \"X-AuthEndpoints-Reauth\")));\n\nvar app = builder.Build();\napp.UseCors(\"spa\");\napp.UseAuthEndpoints();\n","cs",[221,379,380,438,458,468,477,514,518,540,561],{"__ignoreMap":280},[284,381,382,386,389,392,394,398,401,405,408,411,413,416,418,421,425,427,430,433,435],{"class":286,"line":287},[284,383,385],{"class":384},"sTEyZ","builder",[284,387,365],{"class":388},"sMK4o",[284,390,391],{"class":384},"Services",[284,393,365],{"class":388},[284,395,397],{"class":396},"s2Zo4","AddCors",[284,399,400],{"class":388},"(",[284,402,404],{"class":403},"sBMFI","o",[284,406,407],{"class":388}," =>",[284,409,410],{"class":384}," o",[284,412,365],{"class":388},[284,414,415],{"class":396},"AddPolicy",[284,417,400],{"class":388},[284,419,420],{"class":388},"\"",[284,422,424],{"class":423},"sfazB","spa",[284,426,420],{"class":388},[284,428,429],{"class":388},",",[284,431,432],{"class":403}," policy",[284,434,407],{"class":388},[284,436,437],{"class":384}," policy\n",[284,439,440,443,446,448,450,453,455],{"class":286,"line":293},[284,441,442],{"class":388},"    .",[284,444,445],{"class":396},"WithOrigins",[284,447,400],{"class":388},[284,449,420],{"class":388},[284,451,452],{"class":423},"https:\u002F\u002Fapp.example.com",[284,454,420],{"class":388},[284,456,457],{"class":388},")\n",[284,459,460,462,465],{"class":286,"line":299},[284,461,442],{"class":388},[284,463,464],{"class":396},"AllowCredentials",[284,466,467],{"class":388},"()\n",[284,469,470,472,475],{"class":286,"line":305},[284,471,442],{"class":388},[284,473,474],{"class":396},"AllowAnyMethod",[284,476,467],{"class":388},[284,478,479,481,484,486,488,491,493,495,498,500,502,504,506,509,511],{"class":286,"line":311},[284,480,442],{"class":388},[284,482,483],{"class":396},"WithHeaders",[284,485,400],{"class":388},[284,487,420],{"class":388},[284,489,490],{"class":423},"Content-Type",[284,492,420],{"class":388},[284,494,429],{"class":388},[284,496,497],{"class":388}," \"",[284,499,261],{"class":423},[284,501,420],{"class":388},[284,503,429],{"class":388},[284,505,497],{"class":388},[284,507,508],{"class":423},"X-AuthEndpoints-Reauth",[284,510,420],{"class":388},[284,512,513],{"class":388},")));\n",[284,515,516],{"class":286,"line":318},[284,517,315],{"emptyLinePlaceholder":314},[284,519,520,523,526,529,532,534,537],{"class":286,"line":324},[284,521,522],{"class":403},"var",[284,524,525],{"class":403}," app",[284,527,528],{"class":388}," =",[284,530,531],{"class":384}," builder",[284,533,365],{"class":388},[284,535,536],{"class":396},"Build",[284,538,539],{"class":388},"();\n",[284,541,542,545,547,550,552,554,556,558],{"class":286,"line":330},[284,543,544],{"class":384},"app",[284,546,365],{"class":388},[284,548,549],{"class":396},"UseCors",[284,551,400],{"class":388},[284,553,420],{"class":388},[284,555,424],{"class":423},[284,557,420],{"class":388},[284,559,560],{"class":388},");\n",[284,562,563,565,567,570],{"class":286,"line":336},[284,564,544],{"class":384},[284,566,365],{"class":388},[284,568,569],{"class":396},"UseAuthEndpoints",[284,571,539],{"class":388},[209,573,574,576,577,580],{},[221,575,464],{}," does not work with ",[221,578,579],{},"AllowAnyOrigin",". List the exact origins.",[213,582,584],{"id":583},"keep-the-client-and-the-api-on-the-same-site","Keep the client and the API on the same site",[209,586,587,588,591],{},"CORS lets the request through, but cookie ",[221,589,590],{},"SameSite"," rules decide which cookies the browser sends:",[593,594,595,609],"table",{},[596,597,598],"thead",{},[599,600,601,605],"tr",{},[602,603,604],"th",{},"Cookie",[602,606,607],{},[221,608,590],{},[610,611,612,626,638],"tbody",{},[599,613,614,620],{},[615,616,617],"td",{},[221,618,619],{},".AspNetCore.Identity.Application",[615,621,622,625],{},[221,623,624],{},"Lax"," (Identity default)",[599,627,628,633],{},[615,629,630],{},[221,631,632],{},"AuthEndpoints.ReAuth",[615,634,635],{},[221,636,637],{},"Strict",[599,639,640,645],{},[615,641,642],{},[221,643,644],{},"AuthEndpoints.Jwt.RefreshToken",[615,646,647],{},[221,648,637],{},[209,650,651,654,655,658,659,662,663,666,667,669,670,672,673,675],{},[221,652,653],{},"app.example.com"," and ",[221,656,657],{},"api.example.com"," are the same site, so these cookies work. A client on a different registrable domain, such as ",[221,660,661],{},"example-app.com"," calling ",[221,664,665],{},"example.com",", is cross-site. The browser does not send ",[221,668,624],{}," or ",[221,671,637],{}," cookies on cross-site ",[221,674,227],{}," calls. Serve the API under the same site as the client, or put a reverse proxy in front of it.",[213,677,679],{"id":678},"related","Related",[681,682,683,687,692,697],"ul",{},[241,684,685],{},[362,686,163],{"href":364},[241,688,689],{},[362,690,46],{"href":691},"\u002Fguides\u002Fsign-in\u002F",[241,693,694],{},[362,695,130],{"href":696},"\u002Fmodules\u002Fcookie-auth\u002F",[241,698,699],{},[362,700,140],{"href":701},"\u002Fmodules\u002Fjwt\u002F",[703,704,705],"style",{},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sTEyZ, html code.shiki .sTEyZ{--shiki-light:#90A4AE;--shiki-default:#EEFFFF;--shiki-dark:#BABED8}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .s2Zo4, html code.shiki .s2Zo4{--shiki-light:#6182B8;--shiki-default:#82AAFF;--shiki-dark:#82AAFF}html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}",{"title":280,"searchDepth":287,"depth":293,"links":707},[708,709,710,711,712],{"id":215,"depth":293,"text":216},{"id":235,"depth":293,"text":236},{"id":368,"depth":293,"text":369},{"id":583,"depth":293,"text":584},{"id":678,"depth":293,"text":679},"Send cookies and CSRF tokens from a browser client, and set up CORS when the client runs on another origin.","md",null,{},{"icon":89},{"title":86,"description":713},"sGNJxz0_xqVjvOLPRRPOn2w05O14rNtsKe1XoNbM1ug",[721,723],{"title":81,"path":82,"stem":83,"description":722,"icon":84,"children":-1},"Ask a signed-in user to prove their identity again before a sensitive change, then retry the change.",{"title":91,"path":92,"stem":93,"description":724,"icon":94,"children":-1},"Checklist for running AuthEndpoints safely in Production.",1791123627330]