[{"data":1,"prerenderedAt":1129},["ShallowReactive",2],{"navigation":3,"\u002Fmodules\u002Fpasskeys":203,"\u002Fmodules\u002Fpasskeys-surround":1124},[4,33,96,114,177],{"title":5,"path":6,"stem":7,"children":8,"icon":32},"Get started","\u002Fgetting-started","1.getting-started\u002F1.index",[9,12,17,22,27],{"title":10,"path":6,"stem":7,"icon":11},"Introduction","i-lucide-house",{"title":13,"path":14,"stem":15,"icon":16},"Install AuthEndpoints","\u002Fgetting-started\u002Finstallation","1.getting-started\u002F2.installation","i-lucide-download",{"title":18,"path":19,"stem":20,"icon":21},"Quick start","\u002Fgetting-started\u002Fquick-start","1.getting-started\u002F3.quick-start","i-lucide-play",{"title":23,"path":24,"stem":25,"icon":26},"Choose a sign-in stack","\u002Fgetting-started\u002Fchoose-a-sign-in-stack","1.getting-started\u002F4.choose-a-sign-in-stack","i-lucide-signpost",{"title":28,"path":29,"stem":30,"icon":31},"Use the AuthEndpoints skill with coding agents","\u002Fgetting-started\u002Fai-agents","1.getting-started\u002F5.ai-agents","i-lucide-bot","i-lucide-rocket",{"title":34,"path":35,"stem":36,"children":37,"icon":95},"Guides","\u002Fguides","2.guides\u002F01.index",[38,40,45,50,55,60,65,70,75,80,85,90],{"title":34,"path":35,"stem":36,"icon":39},"i-lucide-list-checks",{"title":41,"path":42,"stem":43,"icon":44},"Register users","\u002Fguides\u002Fregistration","2.guides\u002F02.registration","i-lucide-user-plus",{"title":46,"path":47,"stem":48,"icon":49},"Sign users in","\u002Fguides\u002Fsign-in","2.guides\u002F03.sign-in","i-lucide-log-in",{"title":51,"path":52,"stem":53,"icon":54},"Sign users out","\u002Fguides\u002Fsign-out","2.guides\u002F04.sign-out","i-lucide-log-out",{"title":56,"path":57,"stem":58,"icon":59},"Turn on two-factor authentication","\u002Fguides\u002Ftwo-factor","2.guides\u002F05.two-factor","i-lucide-smartphone",{"title":61,"path":62,"stem":63,"icon":64},"Reset a forgotten password","\u002Fguides\u002Freset-password","2.guides\u002F06.reset-password","i-lucide-key-round",{"title":66,"path":67,"stem":68,"icon":69},"Change a user's email or password","\u002Fguides\u002Fmanage-account","2.guides\u002F07.manage-account","i-lucide-user-cog",{"title":71,"path":72,"stem":73,"icon":74},"Add, rename, and remove passkeys","\u002Fguides\u002Fmanage-passkeys","2.guides\u002F08.manage-passkeys","i-lucide-scan-face",{"title":76,"path":77,"stem":78,"icon":79},"Link and unlink GitHub or Google accounts","\u002Fguides\u002Flink-external-accounts","2.guides\u002F09.link-external-accounts","i-lucide-link",{"title":81,"path":82,"stem":83,"icon":84},"Require step-up before sensitive actions","\u002Fguides\u002Fstep-up","2.guides\u002F10.step-up","i-lucide-shield-check",{"title":86,"path":87,"stem":88,"icon":89},"Call the API from a browser","\u002Fguides\u002Fbrowser-clients","2.guides\u002F11.browser-clients","i-lucide-globe",{"title":91,"path":92,"stem":93,"icon":94},"Prepare for production","\u002Fguides\u002Fproduction","2.guides\u002F12.production","i-lucide-factory","i-lucide-waypoints",{"title":97,"path":98,"stem":99,"children":100,"icon":113},"Composable endpoints","\u002Fcomposables","3.composables\u002F1.index",[101,104,108],{"title":102,"path":98,"stem":99,"icon":103},"How composition works","i-lucide-layout-grid",{"title":105,"path":106,"stem":107,"icon":39},"Composition requirements","\u002Fcomposables\u002Frequirements","3.composables\u002F2.requirements",{"title":109,"path":110,"stem":111,"icon":112},"Compose a custom auth stack","\u002Fcomposables\u002Frecipes","3.composables\u002F3.recipes","i-lucide-book-marked","i-lucide-blocks",{"title":115,"icon":116,"path":117,"stem":118,"children":119,"page":176},"Reference","i-lucide-book-open","\u002Fmodules","4.modules",[120,125,129,134,139,144,148,153,157,162,166,171],{"title":121,"path":122,"stem":123,"icon":124},"Endpoint reference","\u002Fmodules\u002Fendpoints","4.modules\u002F01.endpoints","i-lucide-route",{"title":126,"path":127,"stem":128,"icon":69},"Identity management module","\u002Fmodules\u002Fidentity-management","4.modules\u002F02.identity-management",{"title":130,"path":131,"stem":132,"icon":133},"Cookie sign-in module","\u002Fmodules\u002Fcookie-auth","4.modules\u002F03.cookie-auth","i-lucide-cookie",{"title":135,"path":136,"stem":137,"icon":138},"Identity bearer sign-in module","\u002Fmodules\u002Fbearer-auth","4.modules\u002F04.bearer-auth","i-lucide-key",{"title":140,"path":141,"stem":142,"icon":143},"JWT module","\u002Fmodules\u002Fjwt","4.modules\u002F05.jwt","i-lucide-fingerprint",{"title":145,"path":146,"stem":147,"icon":74},"Passkeys module","\u002Fmodules\u002Fpasskeys","4.modules\u002F06.passkeys",{"title":149,"path":150,"stem":151,"icon":152},"ReAuth module","\u002Fmodules\u002Freauth","4.modules\u002F07.reauth","i-lucide-shield-alert",{"title":154,"path":155,"stem":156,"icon":49},"External OAuth packages","\u002Fmodules\u002Fexternal-oauth","4.modules\u002F08.external-oauth",{"title":158,"path":159,"stem":160,"icon":161},"Configuration options","\u002Fmodules\u002Fconfiguration","4.modules\u002F09.configuration","i-lucide-settings",{"title":163,"path":164,"stem":165,"icon":84},"Antiforgery (CSRF) rules","\u002Fmodules\u002Fcsrf","4.modules\u002F10.csrf",{"title":167,"path":168,"stem":169,"icon":170},"Responses and errors","\u002Fmodules\u002Ferrors","4.modules\u002F11.errors","i-lucide-circle-alert",{"title":172,"path":173,"stem":174,"icon":175},"Rate-limit policies","\u002Fmodules\u002Frate-limits","4.modules\u002F12.rate-limits","i-lucide-gauge",false,{"title":178,"icon":179,"path":180,"stem":181,"children":182,"page":176},"Concepts","i-lucide-lightbulb","\u002Fconcepts","5.concepts",[183,188,193,198],{"title":184,"path":185,"stem":186,"icon":187},"AuthEndpoints compared with other options","\u002Fconcepts\u002Fcompare","5.concepts\u002F1.compare","i-lucide-git-compare",{"title":189,"path":190,"stem":191,"icon":192},"Stock Identity endpoints vs AuthEndpoints","\u002Fconcepts\u002Fstock-identity-vs-authendpoints","5.concepts\u002F2.stock-identity-vs-authendpoints","i-lucide-columns-2",{"title":194,"path":195,"stem":196,"icon":197},"Security model","\u002Fconcepts\u002Fsecurity-model","5.concepts\u002F3.security-model","i-lucide-shield",{"title":199,"path":200,"stem":201,"icon":202},"FAQ","\u002Fconcepts\u002Ffaq","5.concepts\u002F4.faq","i-lucide-circle-help",{"id":204,"title":145,"body":205,"description":1117,"extension":1118,"links":1119,"meta":1120,"navigation":1121,"path":146,"seo":1122,"stem":147,"__hash__":1123},"docs\u002F4.modules\u002F06.passkeys.md",{"type":206,"value":207,"toc":1105},"minimark",[208,212,217,259,269,272,313,324,336,340,379,389,393,557,575,579,605,631,638,642,651,671,676,689,711,743,765,781,784,821,825,834,1014,1021,1027,1031,1063,1067,1101],[209,210,211],"p",{},"Passkey (WebAuthn) endpoints for passwordless register\u002Flogin and managing credentials on an existing account.",[213,214,216],"h2",{"id":215},"di","DI",[218,219,224],"pre",{"className":220,"code":221,"language":222,"meta":223,"style":223},"language-cs shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","builder.Services.AddPasskeyEndpoints\u003CAppUser>();\n","cs","",[225,226,227],"code",{"__ignoreMap":223},[228,229,232,236,240,243,245,249,252,256],"span",{"class":230,"line":231},"line",1,[228,233,235],{"class":234},"sTEyZ","builder",[228,237,239],{"class":238},"sMK4o",".",[228,241,242],{"class":234},"Services",[228,244,239],{"class":238},[228,246,248],{"class":247},"s2Zo4","AddPasskeyEndpoints",[228,250,251],{"class":238},"\u003C",[228,253,255],{"class":254},"sBMFI","AppUser",[228,257,258],{"class":238},">();\n",[209,260,261,262,265,266,239],{},"This registers passkey rate limits\u002FReAuth and the default ",[225,263,264],{},"IdentityPasskeySignInCompleter\u003CAppUser>",". Prefer the generic overload for compose hosts so register\u002Flogin can resolve ",[225,267,268],{},"IPasskeySignInCompleter\u003CTUser>",[209,270,271],{},"To choose the user id minted during passwordless register:",[218,273,275],{"className":220,"code":274,"language":222,"meta":223,"style":223},"builder.Services.AddPasskeyUserIdFactory(() => Ulid.NewUlid().ToString());\n",[225,276,277],{"__ignoreMap":223},[228,278,279,281,283,285,287,290,293,296,299,301,304,307,310],{"class":230,"line":231},[228,280,235],{"class":234},[228,282,239],{"class":238},[228,284,242],{"class":234},[228,286,239],{"class":238},[228,288,289],{"class":247},"AddPasskeyUserIdFactory",[228,291,292],{"class":238},"(()",[228,294,295],{"class":238}," =>",[228,297,298],{"class":234}," Ulid",[228,300,239],{"class":238},[228,302,303],{"class":247},"NewUlid",[228,305,306],{"class":238},"().",[228,308,309],{"class":247},"ToString",[228,311,312],{"class":238},"());\n",[209,314,315,316,319,320,323],{},"Or register an ",[225,317,318],{},"IPasskeyUserIdFactory"," implementation. When no custom factory is registered, the id is ",[225,321,322],{},"Guid.NewGuid()"," (UUID v4).",[209,325,326,327,331,332,335],{},"Facade: passkeys are ",[328,329,330],"strong",{},"enabled by default","; set ",[225,333,334],{},"Passkeys.ServerDomain"," (required in Production).",[213,337,339],{"id":338},"map","Map",[218,341,343],{"className":220,"code":342,"language":222,"meta":223,"style":223},"app.MapGroup(\"\u002Faccount\").MapPasskeyEndpoints\u003CAppUser>();\n",[225,344,345],{"__ignoreMap":223},[228,346,347,350,352,355,358,361,365,367,370,373,375,377],{"class":230,"line":231},[228,348,349],{"class":234},"app",[228,351,239],{"class":238},[228,353,354],{"class":247},"MapGroup",[228,356,357],{"class":238},"(",[228,359,360],{"class":238},"\"",[228,362,364],{"class":363},"sfazB","\u002Faccount",[228,366,360],{"class":238},[228,368,369],{"class":238},").",[228,371,372],{"class":247},"MapPasskeyEndpoints",[228,374,251],{"class":238},[228,376,255],{"class":254},[228,378,258],{"class":238},[209,380,381,382,385,386,369],{},"Routes are mapped under ",[225,383,384],{},"{prefix}\u002Fpasskeys"," (facade default ",[225,387,388],{},"\u002Faccount\u002Fpasskeys",[213,390,392],{"id":391},"routes","Routes",[394,395,396,412],"table",{},[397,398,399],"thead",{},[400,401,402,406,409],"tr",{},[403,404,405],"th",{},"Method",[403,407,408],{},"Path",[403,410,411],{},"Auth \u002F extras",[413,414,415,431,448,464,478,500,514,528,542],"tbody",{},[400,416,417,423,428],{},[418,419,420],"td",{},[225,421,422],{},"POST",[418,424,425],{},[225,426,427],{},"\u002Fpasskeys\u002FcreationOptions",[418,429,430],{},"Auth + ReAuth + CSRF + rate limit",[400,432,433,437,442],{},[418,434,435],{},[225,436,422],{},[418,438,439],{},[225,440,441],{},"\u002Fpasskeys\u002FrequestOptions",[418,443,444,445],{},"CSRF + rate limit; optional body ",[225,446,447],{},"{ email }",[400,449,450,454,459],{},[418,451,452],{},[225,453,422],{},[418,455,456],{},[225,457,458],{},"\u002Fpasskeys\u002Fregister\u002Foptions",[418,460,461,462],{},"CSRF; body ",[225,463,447],{},[400,465,466,470,475],{},[418,467,468],{},[225,469,422],{},[418,471,472],{},[225,473,474],{},"\u002Fpasskeys\u002Fregister",[418,476,477],{},"CSRF; passwordless create + completer sign-in",[400,479,480,484,489],{},[418,481,482],{},[225,483,422],{},[418,485,486],{},[225,487,488],{},"\u002Fpasskeys\u002Flogin",[418,490,491,492,495,496,499],{},"CSRF; completer sign-in (",[225,493,494],{},"useCookies"," \u002F ",[225,497,498],{},"useSessionCookies"," for Identity completer)",[400,501,502,506,511],{},[418,503,504],{},[225,505,422],{},[418,507,508],{},[225,509,510],{},"\u002Fpasskeys\u002F",[418,512,513],{},"Add passkey (auth + ReAuth + CSRF)",[400,515,516,521,525],{},[418,517,518],{},[225,519,520],{},"GET",[418,522,523],{},[225,524,510],{},[418,526,527],{},"List passkeys (auth)",[400,529,530,535,539],{},[418,531,532],{},[225,533,534],{},"PATCH",[418,536,537],{},[225,538,510],{},[418,540,541],{},"Rename (auth + ReAuth + CSRF)",[400,543,544,549,554],{},[418,545,546],{},[225,547,548],{},"DELETE",[418,550,551],{},[225,552,553],{},"\u002Fpasskeys\u002F{credentialIdUrl}",[418,555,556],{},"Remove (auth + ReAuth + CSRF)",[209,558,559,560,563,564,567,568,571,572,574],{},"Identifier-first ",[225,561,562],{},"requestOptions"," with ",[225,565,566],{},"email"," may reveal passkey presence via ",[225,569,570],{},"allowCredentials",". Omit ",[225,573,566],{}," for usernameless\u002Fdiscoverable login.",[213,576,578],{"id":577},"passwordless-register-flow","Passwordless register flow",[580,581,582,591,597],"ol",{},[583,584,585,563,588],"li",{},[225,586,587],{},"POST \u002Faccount\u002Fpasskeys\u002Fregister\u002Foptions",[225,589,590],{},"{ \"email\": \"...\" }",[583,592,593,594],{},"Browser ",[225,595,596],{},"navigator.credentials.create(...)",[583,598,599,563,602],{},[225,600,601],{},"POST \u002Faccount\u002Fpasskeys\u002Fregister",[225,603,604],{},"{ \"email\": \"...\", \"credentialJson\": \"...\" }",[209,606,607,608,611,612,615,616,619,620,623,624,627,628,239],{},"A successful ",[328,609,610],{},"user create"," sends the same confirmation email as password ",[225,613,614],{},"POST \u002Fregister",". The account is not marked confirmed. Completers still skip a session when ",[225,617,618],{},"CanSignInAsync"," fails (for example ",[225,621,622],{},"RequireConfirmedAccount","). Duplicate-email and failed-attestation paths do not send that mail. Passwordless register never attaches a passkey to an existing user id; add a credential to an existing account with authenticated ",[225,625,626],{},"POST \u002Fpasskeys\u002FcreationOptions"," then ",[225,629,630],{},"POST \u002Fpasskeys\u002F",[209,632,633,634,239],{},"Client steps for passkey registration: ",[635,636,41],"a",{"href":637},"\u002Fguides\u002Fregistration\u002F#register-with-a-passkey",[213,639,641],{"id":640},"sign-in-completer","Sign-in completer",[209,643,644,645,647,648,650],{},"After a successful register\u002Flogin ceremony, the library runs lockout and ",[225,646,618],{},". It calls ",[225,649,268],{}," only when sign-in is allowed.",[652,653,656],"callout",{"icon":654,"color":655},"i-lucide-triangle-alert","warning",[209,657,658,659,662,663,666,667,670],{},"Passkey sign-in skips two-factor authentication. ",[225,660,661],{},"IdentityPasskeySignInCompleter"," calls ",[225,664,665],{},"SignInAsync"," directly, and ",[225,668,669],{},"JwtPasskeySignInCompleter"," issues tokens without a 2FA check. A user who turned on 2FA can still sign in with a passkey alone. A passkey is a phishing-resistant first factor. If your app needs a second factor after a passkey, register a completer that checks it.",[672,673,675],"h3",{"id":674},"default-identity","Default: Identity",[209,677,678,680,681,684,685,688],{},[225,679,661],{}," honors the same query flags as Identity bearer ",[225,682,683],{},"Login"," (",[225,686,687],{},"MapBearerAuthEndpoints","):",[690,691,692,698,704],"ul",{},[583,693,694,697],{},[225,695,696],{},"?useCookies=true"," → persistent application cookie",[583,699,700,703],{},[225,701,702],{},"?useSessionCookies=true"," → session application cookie",[583,705,706,707,710],{},"neither → Identity bearer token (",[225,708,709],{},"AccessTokenResponse",")",[652,712,714],{"icon":713},"i-lucide-info",[209,715,716,717,719,720,723,724,727,728,730,731,734,735,738,739,239],{},"The default completer follows bearer ",[225,718,683],{}," flags, ",[328,721,722],{},"not"," facade ",[225,725,726],{},"LoginCookie",". ",[225,729,696],{}," has no effect on ",[225,732,733],{},"POST \u002Fidentity\u002Flogin"," under ",[225,736,737],{},"MapAuthEndpoints",". See ",[635,740,742],{"href":741},"\u002Fmodules\u002Fcookie-auth\u002F","Cookie auth",[209,744,745,746,684,749,752,753,756,757,760,761,764],{},"Register also returns ",[225,747,748],{},"PasskeyCredentialResponse",[225,750,751],{},"credentialId","; ",[225,754,755],{},"displayName"," and ",[225,758,759],{},"createdAt"," when present). If sign-in is not allowed, register still returns that credential id with no session. Login returns ",[225,762,763],{},"401"," Invalid credentials. A custom completer cannot issue a cookie or token on those paths.",[209,766,767,768,770,771,774,775,778,779,239],{},"List and add return the same shape. ",[225,769,630],{}," accepts optional ",[225,772,773],{},"name"," (trimmed, max 200). Identity stores that as ",[225,776,777],{},"UserPasskeyInfo.Name",". JSON still uses ",[225,780,755],{},[209,782,783],{},"When the library gate denies sign-in (unconfirmed account, lockout):",[394,785,786,796],{},[397,787,788],{},[400,789,790,793],{},[403,791,792],{},"Kind",[403,794,795],{},"Response",[413,797,798,812],{},[400,799,800,803],{},[418,801,802],{},"Register",[418,804,805,807,808,811],{},[225,806,748],{}," (credential id); ",[328,809,810],{},"no"," session or tokens",[400,813,814,816],{},[418,815,683],{},[418,817,818,820],{},[225,819,763],{}," Invalid credentials",[672,822,824],{"id":823},"simple-jwt","Simple JWT",[209,826,827,828,830,831,688],{},"Register ",[225,829,669],{}," instead (requires ",[225,832,833],{},"AddJwtEndpoints",[218,835,837],{"className":220,"code":836,"language":222,"meta":223,"style":223},"builder.Services.AddPasskeyEndpoints\u003CAppUser>();\nbuilder.Services.AddJwtEndpoints\u003CAppUser, AppDbContext>(o =>\n{\n    o.Issuer = \"https:\u002F\u002Fexample.com\";\n    o.Audience = \"https:\u002F\u002Fexample.com\";\n    o.SigningOptions.SymmetricKey = builder.Configuration[\"Jwt:SymmetricKey\"];\n});\nbuilder.Services.AddPasskeySignInCompleter\u003CAppUser, JwtPasskeySignInCompleter\u003CAppUser>>();\n",[225,838,839,857,889,895,920,940,978,984],{"__ignoreMap":223},[228,840,841,843,845,847,849,851,853,855],{"class":230,"line":231},[228,842,235],{"class":234},[228,844,239],{"class":238},[228,846,242],{"class":234},[228,848,239],{"class":238},[228,850,248],{"class":247},[228,852,251],{"class":238},[228,854,255],{"class":254},[228,856,258],{"class":238},[228,858,860,862,864,866,868,870,872,874,877,880,883,886],{"class":230,"line":859},2,[228,861,235],{"class":234},[228,863,239],{"class":238},[228,865,242],{"class":234},[228,867,239],{"class":238},[228,869,833],{"class":247},[228,871,251],{"class":238},[228,873,255],{"class":254},[228,875,876],{"class":238},",",[228,878,879],{"class":254}," AppDbContext",[228,881,882],{"class":238},">(",[228,884,885],{"class":254},"o",[228,887,888],{"class":238}," =>\n",[228,890,892],{"class":230,"line":891},3,[228,893,894],{"class":238},"{\n",[228,896,898,901,903,906,909,912,915,917],{"class":230,"line":897},4,[228,899,900],{"class":234},"    o",[228,902,239],{"class":238},[228,904,905],{"class":234},"Issuer ",[228,907,908],{"class":238},"=",[228,910,911],{"class":238}," \"",[228,913,914],{"class":363},"https:\u002F\u002Fexample.com",[228,916,360],{"class":238},[228,918,919],{"class":238},";\n",[228,921,923,925,927,930,932,934,936,938],{"class":230,"line":922},5,[228,924,900],{"class":234},[228,926,239],{"class":238},[228,928,929],{"class":234},"Audience ",[228,931,908],{"class":238},[228,933,911],{"class":238},[228,935,914],{"class":363},[228,937,360],{"class":238},[228,939,919],{"class":238},[228,941,943,945,947,950,952,955,957,960,962,965,968,970,973,975],{"class":230,"line":942},6,[228,944,900],{"class":234},[228,946,239],{"class":238},[228,948,949],{"class":234},"SigningOptions",[228,951,239],{"class":238},[228,953,954],{"class":234},"SymmetricKey ",[228,956,908],{"class":238},[228,958,959],{"class":234}," builder",[228,961,239],{"class":238},[228,963,964],{"class":234},"Configuration",[228,966,967],{"class":238},"[",[228,969,360],{"class":238},[228,971,972],{"class":363},"Jwt:SymmetricKey",[228,974,360],{"class":238},[228,976,977],{"class":238},"];\n",[228,979,981],{"class":230,"line":980},7,[228,982,983],{"class":238},"});\n",[228,985,987,989,991,993,995,998,1000,1002,1004,1007,1009,1011],{"class":230,"line":986},8,[228,988,235],{"class":234},[228,990,239],{"class":238},[228,992,242],{"class":234},[228,994,239],{"class":238},[228,996,997],{"class":247},"AddPasskeySignInCompleter",[228,999,251],{"class":238},[228,1001,255],{"class":254},[228,1003,876],{"class":238},[228,1005,1006],{"class":254}," JwtPasskeySignInCompleter",[228,1008,251],{"class":238},[228,1010,255],{"class":254},[228,1012,1013],{"class":238},">>();\n",[209,1015,1016,1017,1020],{},"Successful passkey register\u002Flogin then returns the same shape as JWT ",[225,1018,1019],{},"\u002Fcreate",": access token in JSON + HttpOnly refresh cookie. Cookie query flags are ignored for this completer.",[209,1022,1023,1024,1026],{},"Facade JWT opt-in does ",[328,1025,722],{}," auto-select the JWT completer — register it explicitly when you want Simple JWT after passkeys.",[213,1028,1030],{"id":1029},"constraints","Constraints",[690,1032,1033,1052,1057,1060],{},[583,1034,1035,1036,563,1039,1042,1043,1046,1047,1049,1050,239],{},"Passwordless register needs ",[225,1037,1038],{},"IdentityUser",[225,1040,1041],{},"string"," or ",[225,1044,1045],{},"Guid"," key. The default user id is ",[225,1048,322],{}," (UUID v4). Apps can override the minted id by registering ",[225,1051,318],{},[583,1053,1054,1056],{},[225,1055,372],{}," throws at map time if the user store lacks passkey or email support. The module is email-keyed.",[583,1058,1059],{},"CSRF is required for WebAuthn ceremonies.",[583,1061,1062],{},"Sensitive credential mutations require ReAuth.",[213,1064,1066],{"id":1065},"related","Related",[690,1068,1069,1075,1081,1086,1091,1096],{},[583,1070,1071],{},[635,1072,1074],{"href":1073},"\u002Fmodules\u002Fjwt\u002F","JWT",[583,1076,1077],{},[635,1078,1080],{"href":1079},"\u002Fmodules\u002Freauth\u002F","ReAuth",[583,1082,1083],{},[635,1084,158],{"href":1085},"\u002Fmodules\u002Fconfiguration\u002F#passkeys",[583,1087,1088],{},[635,1089,41],{"href":1090},"\u002Fguides\u002Fregistration\u002F",[583,1092,1093],{},[635,1094,46],{"href":1095},"\u002Fguides\u002Fsign-in\u002F#sign-in-with-a-passkey",[583,1097,1098],{},[635,1099,71],{"href":1100},"\u002Fguides\u002Fmanage-passkeys\u002F",[1102,1103,1104],"style",{},"html pre.shiki code .sTEyZ, html code.shiki .sTEyZ{--shiki-light:#90A4AE;--shiki-default:#EEFFFF;--shiki-dark:#BABED8}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .s2Zo4, html code.shiki .s2Zo4{--shiki-light:#6182B8;--shiki-default:#82AAFF;--shiki-dark:#82AAFF}html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}",{"title":223,"searchDepth":231,"depth":859,"links":1106},[1107,1108,1109,1110,1111,1115,1116],{"id":215,"depth":859,"text":216},{"id":338,"depth":859,"text":339},{"id":391,"depth":859,"text":392},{"id":577,"depth":859,"text":578},{"id":640,"depth":859,"text":641,"children":1112},[1113,1114],{"id":674,"depth":891,"text":675},{"id":823,"depth":891,"text":824},{"id":1029,"depth":859,"text":1030},{"id":1065,"depth":859,"text":1066},"WebAuthn passwordless register\u002Flogin and credential management endpoints.","md",null,{},{"icon":74},{"title":145,"description":1117},"rwkjbKg4d0yytLAXDtZy6Q8RZI0l18AgvfZXHlIC-Aw",[1125,1127],{"title":140,"path":141,"stem":142,"description":1126,"icon":143,"children":-1},"JWT access tokens with an HttpOnly refresh cookie, hashed storage, and reuse detection.",{"title":149,"path":150,"stem":151,"description":1128,"icon":152,"children":-1},"Step-up reauthentication for sensitive manage and passkey actions.",1791123628396]