[{"data":1,"prerenderedAt":296},["ShallowReactive",2],{"navigation":3,"\u002Fconcepts\u002Fcompare":203,"\u002Fconcepts\u002Fcompare-surround":291},[4,33,96,114,177],{"title":5,"path":6,"stem":7,"children":8,"icon":32},"Get started","\u002Fgetting-started","1.getting-started\u002F1.index",[9,12,17,22,27],{"title":10,"path":6,"stem":7,"icon":11},"Introduction","i-lucide-house",{"title":13,"path":14,"stem":15,"icon":16},"Install AuthEndpoints","\u002Fgetting-started\u002Finstallation","1.getting-started\u002F2.installation","i-lucide-download",{"title":18,"path":19,"stem":20,"icon":21},"Quick start","\u002Fgetting-started\u002Fquick-start","1.getting-started\u002F3.quick-start","i-lucide-play",{"title":23,"path":24,"stem":25,"icon":26},"Choose a sign-in stack","\u002Fgetting-started\u002Fchoose-a-sign-in-stack","1.getting-started\u002F4.choose-a-sign-in-stack","i-lucide-signpost",{"title":28,"path":29,"stem":30,"icon":31},"Use the AuthEndpoints skill with coding agents","\u002Fgetting-started\u002Fai-agents","1.getting-started\u002F5.ai-agents","i-lucide-bot","i-lucide-rocket",{"title":34,"path":35,"stem":36,"children":37,"icon":95},"Guides","\u002Fguides","2.guides\u002F01.index",[38,40,45,50,55,60,65,70,75,80,85,90],{"title":34,"path":35,"stem":36,"icon":39},"i-lucide-list-checks",{"title":41,"path":42,"stem":43,"icon":44},"Register users","\u002Fguides\u002Fregistration","2.guides\u002F02.registration","i-lucide-user-plus",{"title":46,"path":47,"stem":48,"icon":49},"Sign users in","\u002Fguides\u002Fsign-in","2.guides\u002F03.sign-in","i-lucide-log-in",{"title":51,"path":52,"stem":53,"icon":54},"Sign users out","\u002Fguides\u002Fsign-out","2.guides\u002F04.sign-out","i-lucide-log-out",{"title":56,"path":57,"stem":58,"icon":59},"Turn on two-factor authentication","\u002Fguides\u002Ftwo-factor","2.guides\u002F05.two-factor","i-lucide-smartphone",{"title":61,"path":62,"stem":63,"icon":64},"Reset a forgotten password","\u002Fguides\u002Freset-password","2.guides\u002F06.reset-password","i-lucide-key-round",{"title":66,"path":67,"stem":68,"icon":69},"Change a user's email or password","\u002Fguides\u002Fmanage-account","2.guides\u002F07.manage-account","i-lucide-user-cog",{"title":71,"path":72,"stem":73,"icon":74},"Add, rename, and remove passkeys","\u002Fguides\u002Fmanage-passkeys","2.guides\u002F08.manage-passkeys","i-lucide-scan-face",{"title":76,"path":77,"stem":78,"icon":79},"Link and unlink GitHub or Google accounts","\u002Fguides\u002Flink-external-accounts","2.guides\u002F09.link-external-accounts","i-lucide-link",{"title":81,"path":82,"stem":83,"icon":84},"Require step-up before sensitive actions","\u002Fguides\u002Fstep-up","2.guides\u002F10.step-up","i-lucide-shield-check",{"title":86,"path":87,"stem":88,"icon":89},"Call the API from a browser","\u002Fguides\u002Fbrowser-clients","2.guides\u002F11.browser-clients","i-lucide-globe",{"title":91,"path":92,"stem":93,"icon":94},"Prepare for production","\u002Fguides\u002Fproduction","2.guides\u002F12.production","i-lucide-factory","i-lucide-waypoints",{"title":97,"path":98,"stem":99,"children":100,"icon":113},"Composable endpoints","\u002Fcomposables","3.composables\u002F1.index",[101,104,108],{"title":102,"path":98,"stem":99,"icon":103},"How composition works","i-lucide-layout-grid",{"title":105,"path":106,"stem":107,"icon":39},"Composition requirements","\u002Fcomposables\u002Frequirements","3.composables\u002F2.requirements",{"title":109,"path":110,"stem":111,"icon":112},"Compose a custom auth stack","\u002Fcomposables\u002Frecipes","3.composables\u002F3.recipes","i-lucide-book-marked","i-lucide-blocks",{"title":115,"icon":116,"path":117,"stem":118,"children":119,"page":176},"Reference","i-lucide-book-open","\u002Fmodules","4.modules",[120,125,129,134,139,144,148,153,157,162,166,171],{"title":121,"path":122,"stem":123,"icon":124},"Endpoint reference","\u002Fmodules\u002Fendpoints","4.modules\u002F01.endpoints","i-lucide-route",{"title":126,"path":127,"stem":128,"icon":69},"Identity management module","\u002Fmodules\u002Fidentity-management","4.modules\u002F02.identity-management",{"title":130,"path":131,"stem":132,"icon":133},"Cookie sign-in module","\u002Fmodules\u002Fcookie-auth","4.modules\u002F03.cookie-auth","i-lucide-cookie",{"title":135,"path":136,"stem":137,"icon":138},"Identity bearer sign-in module","\u002Fmodules\u002Fbearer-auth","4.modules\u002F04.bearer-auth","i-lucide-key",{"title":140,"path":141,"stem":142,"icon":143},"JWT module","\u002Fmodules\u002Fjwt","4.modules\u002F05.jwt","i-lucide-fingerprint",{"title":145,"path":146,"stem":147,"icon":74},"Passkeys module","\u002Fmodules\u002Fpasskeys","4.modules\u002F06.passkeys",{"title":149,"path":150,"stem":151,"icon":152},"ReAuth module","\u002Fmodules\u002Freauth","4.modules\u002F07.reauth","i-lucide-shield-alert",{"title":154,"path":155,"stem":156,"icon":49},"External OAuth packages","\u002Fmodules\u002Fexternal-oauth","4.modules\u002F08.external-oauth",{"title":158,"path":159,"stem":160,"icon":161},"Configuration options","\u002Fmodules\u002Fconfiguration","4.modules\u002F09.configuration","i-lucide-settings",{"title":163,"path":164,"stem":165,"icon":84},"Antiforgery (CSRF) rules","\u002Fmodules\u002Fcsrf","4.modules\u002F10.csrf",{"title":167,"path":168,"stem":169,"icon":170},"Responses and errors","\u002Fmodules\u002Ferrors","4.modules\u002F11.errors","i-lucide-circle-alert",{"title":172,"path":173,"stem":174,"icon":175},"Rate-limit policies","\u002Fmodules\u002Frate-limits","4.modules\u002F12.rate-limits","i-lucide-gauge",false,{"title":178,"icon":179,"path":180,"stem":181,"children":182,"page":176},"Concepts","i-lucide-lightbulb","\u002Fconcepts","5.concepts",[183,188,193,198],{"title":184,"path":185,"stem":186,"icon":187},"AuthEndpoints compared with other options","\u002Fconcepts\u002Fcompare","5.concepts\u002F1.compare","i-lucide-git-compare",{"title":189,"path":190,"stem":191,"icon":192},"Stock Identity endpoints vs AuthEndpoints","\u002Fconcepts\u002Fstock-identity-vs-authendpoints","5.concepts\u002F2.stock-identity-vs-authendpoints","i-lucide-columns-2",{"title":194,"path":195,"stem":196,"icon":197},"Security model","\u002Fconcepts\u002Fsecurity-model","5.concepts\u002F3.security-model","i-lucide-shield",{"title":199,"path":200,"stem":201,"icon":202},"FAQ","\u002Fconcepts\u002Ffaq","5.concepts\u002F4.faq","i-lucide-circle-help",{"id":204,"title":184,"body":205,"description":284,"extension":285,"links":286,"meta":287,"navigation":288,"path":185,"seo":289,"stem":186,"__hash__":290},"docs\u002F5.concepts\u002F1.compare.md",{"type":206,"value":207,"toc":274},"minimark",[208,212,217,220,224,227,236,242,250,254],[209,210,211],"p",{},"AuthEndpoints is a first-party auth API on top of ASP.NET Core Identity. Use it when you own the users. Use something else when you need an OAuth or OpenID Connect server, or when Microsoft's Identity API endpoints already cover the whole job.",[213,214,216],"h2",{"id":215},"vs-wiring-identity-yourself","vs wiring Identity yourself",[209,218,219],{},"You still use Identity, EF Core, and your user type. AuthEndpoints maps the endpoints you would otherwise write: register, login, 2FA, password reset, passkeys, and GitHub or Google sign-in. You also get the hardening that hand-written endpoints often miss: rate limits, CSRF checks, and generic responses that do not reveal which emails exist.",[213,221,223],{"id":222},"vs-openiddict","vs OpenIddict",[209,225,226],{},"OpenIddict is an OAuth 2 and OpenID Connect server. Use it when other apps sign in to you as a provider. AuthEndpoints is for your own web and mobile clients that call your own API. It issues first-party cookies or tokens. It is not a federation server.",[213,228,230,231,235],{"id":229},"vs-identity-api-endpoints-mapidentityapi","vs Identity API endpoints (",[232,233,234],"code",{},"MapIdentityApi",")",[209,237,238,239,241],{},"Identity API endpoints give you a bearer-token first-party API. AuthEndpoints covers that job and the cookie-app job. It adds passkeys, step-up ReAuth, composable modules, and hardening defaults: rate limits, antiforgery, lockout, and refresh-token reuse detection. Use ",[232,240,234],{}," if the framework sample is enough. Use AuthEndpoints if you need cookies, passkeys, or to compose only the routes you need.",[209,243,244,245,249],{},"Side-by-side register, login, reset, and 2FA: ",[246,247,248],"a",{"href":190},"Stock Identity vs AuthEndpoints",".",[213,251,253],{"id":252},"related","Related",[255,256,257,262,266,270],"ul",{},[258,259,260],"li",{},[246,261,189],{"href":190},[258,263,264],{},[246,265,18],{"href":19},[258,267,268],{},[246,269,97],{"href":98},[258,271,272],{},[246,273,199],{"href":200},{"title":275,"searchDepth":276,"depth":277,"links":278},"",1,2,[279,280,281,283],{"id":215,"depth":277,"text":216},{"id":222,"depth":277,"text":223},{"id":229,"depth":277,"text":282},"vs Identity API endpoints (MapIdentityApi)",{"id":252,"depth":277,"text":253},"How AuthEndpoints differs from wiring ASP.NET Core Identity yourself, from OpenIddict, and from Identity API endpoints.","md",null,{},{"icon":187},{"title":184,"description":284},"XAHJ2ozs1YRwZYNuLh8mEC536EqcYndXdzawEHe23Qc",[292,294],{"title":172,"path":173,"stem":174,"description":293,"icon":175,"children":-1},"The rate-limit policies AuthEndpoints registers, their limits, and the routes that use them.",{"title":189,"path":190,"stem":191,"description":295,"icon":192,"children":-1},"Side-by-side register, login, password reset, and 2FA for MapIdentityApi and the AuthEndpoints facade.",1791096173198]