[{"data":1,"prerenderedAt":496},["ShallowReactive",2],{"navigation":3,"\u002Fguides\u002Fsign-out":203,"\u002Fguides\u002Fsign-out-surround":491},[4,33,96,114,177],{"title":5,"path":6,"stem":7,"children":8,"icon":32},"Get started","\u002Fgetting-started","1.getting-started\u002F1.index",[9,12,17,22,27],{"title":10,"path":6,"stem":7,"icon":11},"Introduction","i-lucide-house",{"title":13,"path":14,"stem":15,"icon":16},"Install AuthEndpoints","\u002Fgetting-started\u002Finstallation","1.getting-started\u002F2.installation","i-lucide-download",{"title":18,"path":19,"stem":20,"icon":21},"Quick start","\u002Fgetting-started\u002Fquick-start","1.getting-started\u002F3.quick-start","i-lucide-play",{"title":23,"path":24,"stem":25,"icon":26},"Choose a sign-in stack","\u002Fgetting-started\u002Fchoose-a-sign-in-stack","1.getting-started\u002F4.choose-a-sign-in-stack","i-lucide-signpost",{"title":28,"path":29,"stem":30,"icon":31},"Use the AuthEndpoints skill with coding agents","\u002Fgetting-started\u002Fai-agents","1.getting-started\u002F5.ai-agents","i-lucide-bot","i-lucide-rocket",{"title":34,"path":35,"stem":36,"children":37,"icon":95},"Guides","\u002Fguides","2.guides\u002F01.index",[38,40,45,50,55,60,65,70,75,80,85,90],{"title":34,"path":35,"stem":36,"icon":39},"i-lucide-list-checks",{"title":41,"path":42,"stem":43,"icon":44},"Register users","\u002Fguides\u002Fregistration","2.guides\u002F02.registration","i-lucide-user-plus",{"title":46,"path":47,"stem":48,"icon":49},"Sign users in","\u002Fguides\u002Fsign-in","2.guides\u002F03.sign-in","i-lucide-log-in",{"title":51,"path":52,"stem":53,"icon":54},"Sign users out","\u002Fguides\u002Fsign-out","2.guides\u002F04.sign-out","i-lucide-log-out",{"title":56,"path":57,"stem":58,"icon":59},"Turn on two-factor authentication","\u002Fguides\u002Ftwo-factor","2.guides\u002F05.two-factor","i-lucide-smartphone",{"title":61,"path":62,"stem":63,"icon":64},"Reset a forgotten password","\u002Fguides\u002Freset-password","2.guides\u002F06.reset-password","i-lucide-key-round",{"title":66,"path":67,"stem":68,"icon":69},"Change a user's email or password","\u002Fguides\u002Fmanage-account","2.guides\u002F07.manage-account","i-lucide-user-cog",{"title":71,"path":72,"stem":73,"icon":74},"Add, rename, and remove passkeys","\u002Fguides\u002Fmanage-passkeys","2.guides\u002F08.manage-passkeys","i-lucide-scan-face",{"title":76,"path":77,"stem":78,"icon":79},"Link and unlink GitHub or Google accounts","\u002Fguides\u002Flink-external-accounts","2.guides\u002F09.link-external-accounts","i-lucide-link",{"title":81,"path":82,"stem":83,"icon":84},"Require step-up before sensitive actions","\u002Fguides\u002Fstep-up","2.guides\u002F10.step-up","i-lucide-shield-check",{"title":86,"path":87,"stem":88,"icon":89},"Call the API from a browser","\u002Fguides\u002Fbrowser-clients","2.guides\u002F11.browser-clients","i-lucide-globe",{"title":91,"path":92,"stem":93,"icon":94},"Prepare for production","\u002Fguides\u002Fproduction","2.guides\u002F12.production","i-lucide-factory","i-lucide-waypoints",{"title":97,"path":98,"stem":99,"children":100,"icon":113},"Composable endpoints","\u002Fcomposables","3.composables\u002F1.index",[101,104,108],{"title":102,"path":98,"stem":99,"icon":103},"How composition works","i-lucide-layout-grid",{"title":105,"path":106,"stem":107,"icon":39},"Composition requirements","\u002Fcomposables\u002Frequirements","3.composables\u002F2.requirements",{"title":109,"path":110,"stem":111,"icon":112},"Compose a custom auth stack","\u002Fcomposables\u002Frecipes","3.composables\u002F3.recipes","i-lucide-book-marked","i-lucide-blocks",{"title":115,"icon":116,"path":117,"stem":118,"children":119,"page":176},"Reference","i-lucide-book-open","\u002Fmodules","4.modules",[120,125,129,134,139,144,148,153,157,162,166,171],{"title":121,"path":122,"stem":123,"icon":124},"Endpoint reference","\u002Fmodules\u002Fendpoints","4.modules\u002F01.endpoints","i-lucide-route",{"title":126,"path":127,"stem":128,"icon":69},"Identity management module","\u002Fmodules\u002Fidentity-management","4.modules\u002F02.identity-management",{"title":130,"path":131,"stem":132,"icon":133},"Cookie sign-in module","\u002Fmodules\u002Fcookie-auth","4.modules\u002F03.cookie-auth","i-lucide-cookie",{"title":135,"path":136,"stem":137,"icon":138},"Identity bearer sign-in module","\u002Fmodules\u002Fbearer-auth","4.modules\u002F04.bearer-auth","i-lucide-key",{"title":140,"path":141,"stem":142,"icon":143},"JWT module","\u002Fmodules\u002Fjwt","4.modules\u002F05.jwt","i-lucide-fingerprint",{"title":145,"path":146,"stem":147,"icon":74},"Passkeys module","\u002Fmodules\u002Fpasskeys","4.modules\u002F06.passkeys",{"title":149,"path":150,"stem":151,"icon":152},"ReAuth module","\u002Fmodules\u002Freauth","4.modules\u002F07.reauth","i-lucide-shield-alert",{"title":154,"path":155,"stem":156,"icon":49},"External OAuth packages","\u002Fmodules\u002Fexternal-oauth","4.modules\u002F08.external-oauth",{"title":158,"path":159,"stem":160,"icon":161},"Configuration options","\u002Fmodules\u002Fconfiguration","4.modules\u002F09.configuration","i-lucide-settings",{"title":163,"path":164,"stem":165,"icon":84},"Antiforgery (CSRF) rules","\u002Fmodules\u002Fcsrf","4.modules\u002F10.csrf",{"title":167,"path":168,"stem":169,"icon":170},"Responses and errors","\u002Fmodules\u002Ferrors","4.modules\u002F11.errors","i-lucide-circle-alert",{"title":172,"path":173,"stem":174,"icon":175},"Rate-limit policies","\u002Fmodules\u002Frate-limits","4.modules\u002F12.rate-limits","i-lucide-gauge",false,{"title":178,"icon":179,"path":180,"stem":181,"children":182,"page":176},"Concepts","i-lucide-lightbulb","\u002Fconcepts","5.concepts",[183,188,193,198],{"title":184,"path":185,"stem":186,"icon":187},"AuthEndpoints compared with other options","\u002Fconcepts\u002Fcompare","5.concepts\u002F1.compare","i-lucide-git-compare",{"title":189,"path":190,"stem":191,"icon":192},"Stock Identity endpoints vs AuthEndpoints","\u002Fconcepts\u002Fstock-identity-vs-authendpoints","5.concepts\u002F2.stock-identity-vs-authendpoints","i-lucide-columns-2",{"title":194,"path":195,"stem":196,"icon":197},"Security model","\u002Fconcepts\u002Fsecurity-model","5.concepts\u002F3.security-model","i-lucide-shield",{"title":199,"path":200,"stem":201,"icon":202},"FAQ","\u002Fconcepts\u002Ffaq","5.concepts\u002F4.faq","i-lucide-circle-help",{"id":204,"title":51,"body":205,"description":484,"extension":485,"links":486,"meta":487,"navigation":488,"path":52,"seo":489,"stem":53,"__hash__":490},"docs\u002F2.guides\u002F04.sign-out.md",{"type":206,"value":207,"toc":478},"minimark",[208,212,294,299,371,392,396,405,408,412,430,441,445,474],[209,210,211],"p",{},"Each sign-in stack has its own logout route, and each one behaves differently. Use the section for your stack.",[213,214,215,237],"table",{},[216,217,218],"thead",{},[219,220,221,225,228,231,234],"tr",{},[222,223,224],"th",{},"Stack",[222,226,227],{},"Endpoint",[222,229,230],{},"Needs a signed-in user",[222,232,233],{},"CSRF",[222,235,236],{},"What it ends",[238,239,240,260,277],"tbody",{},[219,241,242,246,252,255,257],{},[243,244,245],"td",{},"Cookie",[243,247,248],{},[249,250,251],"code",{},"POST \u002Fidentity\u002Flogout",[243,253,254],{},"Yes",[243,256,254],{},[243,258,259],{},"The application, external, two-factor, remember-client, and ReAuth cookies",[219,261,262,265,269,271,274],{},[243,263,264],{},"Identity bearer",[243,266,267],{},[249,268,251],{},[243,270,254],{},[243,272,273],{},"No",[243,275,276],{},"Cookies only. Bearer tokens stay valid until they expire.",[219,278,279,282,287,289,291],{},[243,280,281],{},"JWT",[243,283,284],{},[249,285,286],{},"POST \u002Fauth\u002Flogout",[243,288,273],{},[243,290,254],{},[243,292,293],{},"The refresh-token family and the refresh cookie",[295,296,298],"h2",{"id":297},"sign-out-of-the-cookie-stack","Sign out of the cookie stack",[300,301,302,310],"ol",{},[303,304,305,306,309],"li",{},"Get a CSRF token from ",[249,307,308],{},"GET \u002Fidentity\u002FcsrfToken",".",[303,311,312,313,315,316,319,320,323,324],{},"Send ",[249,314,251],{}," with ",[249,317,318],{},"credentials: 'include'"," and the ",[249,321,322],{},"RequestVerificationToken"," header.",[325,326,331],"pre",{"className":327,"code":328,"language":329,"meta":330,"style":330},"language-js shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","const { csrfToken } = await fetch('\u002Fidentity\u002FcsrfToken', { credentials: 'include' }).then(r => r.json());\nawait fetch('\u002Fidentity\u002Flogout', {\n  method: 'POST',\n  credentials: 'include',\n  headers: { 'RequestVerificationToken': csrfToken }\n});\n","js","",[249,332,333,341,347,353,359,365],{"__ignoreMap":330},[334,335,338],"span",{"class":336,"line":337},"line",1,[334,339,340],{},"const { csrfToken } = await fetch('\u002Fidentity\u002FcsrfToken', { credentials: 'include' }).then(r => r.json());\n",[334,342,344],{"class":336,"line":343},2,[334,345,346],{},"await fetch('\u002Fidentity\u002Flogout', {\n",[334,348,350],{"class":336,"line":349},3,[334,351,352],{},"  method: 'POST',\n",[334,354,356],{"class":336,"line":355},4,[334,357,358],{},"  credentials: 'include',\n",[334,360,362],{"class":336,"line":361},5,[334,363,364],{},"  headers: { 'RequestVerificationToken': csrfToken }\n",[334,366,368],{"class":336,"line":367},6,[334,369,370],{},"});\n",[209,372,373,374,377,378,377,381,377,384,387,388,391],{},"Logout signs out of the ",[249,375,376],{},"Identity.Application",", ",[249,379,380],{},"Identity.External",[249,382,383],{},"Identity.TwoFactorUserId",[249,385,386],{},"Identity.TwoFactorRememberMe",", and ",[249,389,390],{},"AuthEndpoints.ReAuth"," schemes. Because it clears the remember-client cookie, the next password login from that browser asks for a 2FA code again.",[295,393,395],{"id":394},"sign-out-of-the-identity-bearer-stack","Sign out of the Identity bearer stack",[209,397,312,398,400,401,404],{},[249,399,251],{}," with the ",[249,402,403],{},"Authorization: Bearer \u003CaccessToken>"," header. No CSRF token is needed.",[209,406,407],{},"This call clears cookies only. It does not revoke the access token or the refresh token. To end the session on the client, delete both tokens from storage. The tokens stay valid on the server until they expire.",[295,409,411],{"id":410},"sign-out-of-the-jwt-stack","Sign out of the JWT stack",[300,413,414,419,427],{},[303,415,305,416,309],{},[249,417,418],{},"GET \u002Fauth\u002FcsrfToken",[303,420,312,421,315,423,319,425,323],{},[249,422,286],{},[249,424,318],{},[249,426,322],{},[303,428,429],{},"Delete the access token from client memory.",[209,431,432,433,436,437,440],{},"The endpoint does not require a signed-in user. It revokes the whole refresh-token family of the cookie it receives, deletes the cookie, and returns ",[249,434,435],{},"200",". The access token stays valid until it expires (15 minutes by default, ",[249,438,439],{},"AccessTokenLifetime",").",[295,442,444],{"id":443},"related","Related",[446,447,448,454,459,464,469],"ul",{},[303,449,450],{},[451,452,46],"a",{"href":453},"\u002Fguides\u002Fsign-in\u002F",[303,455,456],{},[451,457,163],{"href":458},"\u002Fmodules\u002Fcsrf\u002F",[303,460,461],{},[451,462,130],{"href":463},"\u002Fmodules\u002Fcookie-auth\u002F",[303,465,466],{},[451,467,135],{"href":468},"\u002Fmodules\u002Fbearer-auth\u002F",[303,470,471],{},[451,472,140],{"href":473},"\u002Fmodules\u002Fjwt\u002F",[475,476,477],"style",{},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":330,"searchDepth":337,"depth":343,"links":479},[480,481,482,483],{"id":297,"depth":343,"text":298},{"id":394,"depth":343,"text":395},{"id":410,"depth":343,"text":411},{"id":443,"depth":343,"text":444},"Sign users out of the cookie, Identity bearer, and JWT stacks.","md",null,{},{"icon":54},{"title":51,"description":484},"Rf4WhgAia2JDSMygeiyTrirUV7E2RxW_UOg8aKRBeZ4",[492,494],{"title":46,"path":47,"stem":48,"description":493,"icon":49,"children":-1},"Sign users in with a password, a passkey, or GitHub or Google, and handle two-factor codes and recovery codes.",{"title":56,"path":57,"stem":58,"description":495,"icon":59,"children":-1},"Turn authenticator two-factor authentication on and off, and issue recovery codes.",1791123626236]