Changelog
Reference

Rate-limit policies

The rate-limit policies AuthEndpoints registers, their limits, and the routes that use them.

All policies partition by client IP address. A rejected request returns 429. Policies take effect only when the pipeline calls UseRateLimiter(). UseAuthEndpoints calls it.

Policies

Policy constantLimiterLimit
AuthEndpoints.LoginToken bucket10 tokens. 2 tokens are added every 10 seconds.
AuthEndpoints.AccountAbuseFixed window10 requests per minute
AuthEndpoints.ConfirmIdentityFixed window20 requests per minute
AuthEndpoints.Passkey.ObtainOptionsFixed window5 requests per minute
AuthEndpoints.Passkey.RegisterFixed window3 requests per minute

No policy queues requests. The QueueLimit is 0.

Routes per policy

PolicyRoutes
AuthEndpoints.LoginCookie and Identity bearer POST /login, JWT POST /create and POST /refresh, passkey POST /passkeys/login, external GET /login/{provider} and GET /link/{scheme}
AuthEndpoints.AccountAbusePOST /register, POST /resendConfirmationEmail, POST /forgotPassword, POST /resetPassword
AuthEndpoints.ConfirmIdentityPOST /confirmIdentity, POST /confirmIdentity/passkeyOptions
AuthEndpoints.Passkey.ObtainOptionsPOST /passkeys/creationOptions, POST /passkeys/requestOptions, POST /passkeys/register/options
AuthEndpoints.Passkey.RegisterPOST /passkeys/register, POST /passkeys/

Identity bearer POST /refresh has no rate limit.

Registration

DI callPolicies it registers
AddCookieAuthEndpointsLogin, AccountAbuse, ConfirmIdentity
AddBearerAuthEndpointsLogin, AccountAbuse, ConfirmIdentity
AddJwtEndpointsLogin, AccountAbuse, ConfirmIdentity
AddPasskeyEndpointsLogin, AccountAbuse, ConfirmIdentity, Passkey.ObtainOptions, Passkey.Register
AddExternalAuthEndpointsLogin

Each policy is registered once, even when several calls add it. The facade makes the matching calls for you.