[{"data":1,"prerenderedAt":332},["ShallowReactive",2],{"navigation":3,"\u002Fexamples\u002Freauth":139,"\u002Fexamples\u002Freauth-surround":327},[4,48,79,98],{"title":5,"path":6,"stem":7,"children":8,"icon":47},"Getting Started","\u002Fgetting-started","1.getting-started\u002F1.index",[9,12,17,22,27,32,37,42],{"title":10,"path":6,"stem":7,"icon":11},"Introduction","i-lucide-house",{"title":13,"path":14,"stem":15,"icon":16},"Installation","\u002Fgetting-started\u002Finstallation","1.getting-started\u002F2.installation","i-lucide-download",{"title":18,"path":19,"stem":20,"icon":21},"AI agents","\u002Fgetting-started\u002Fai-agents","1.getting-started\u002F3.ai-agents","i-lucide-bot",{"title":23,"path":24,"stem":25,"icon":26},"Quick start","\u002Fgetting-started\u002Fquick-start","1.getting-started\u002F4.quick-start","i-lucide-play",{"title":28,"path":29,"stem":30,"icon":31},"Configuration","\u002Fgetting-started\u002Fconfiguration","1.getting-started\u002F5.configuration","i-lucide-settings",{"title":33,"path":34,"stem":35,"icon":36},"Production","\u002Fgetting-started\u002Fproduction","1.getting-started\u002F6.production","i-lucide-shield-check",{"title":38,"path":39,"stem":40,"icon":41},"Compare","\u002Fgetting-started\u002Fcompare","1.getting-started\u002F7.compare","i-lucide-git-compare",{"title":43,"path":44,"stem":45,"icon":46},"FAQ","\u002Fgetting-started\u002Ffaq","1.getting-started\u002F8.faq","i-lucide-circle-help","i-lucide-rocket",{"title":49,"path":50,"stem":51,"children":52,"icon":54},"Examples","\u002Fexamples","2.examples\u002F1.index",[53,55,60,65,70,74],{"title":49,"path":50,"stem":51,"icon":54},"i-lucide-waypoints",{"title":56,"path":57,"stem":58,"icon":59},"Register a confirmed account","\u002Fexamples\u002Fregister-confirmed-account","2.examples\u002F2.register-confirmed-account","i-lucide-mail-check",{"title":61,"path":62,"stem":63,"icon":64},"Reset a forgotten password","\u002Fexamples\u002Freset-forgotten-password","2.examples\u002F3.reset-forgotten-password","i-lucide-key-round",{"title":66,"path":67,"stem":68,"icon":69},"Enable and disable two-factor authentication","\u002Fexamples\u002Ftwo-factor","2.examples\u002F4.two-factor","i-lucide-smartphone",{"title":71,"path":72,"stem":73,"icon":36},"Complete step-up (ReAuth)","\u002Fexamples\u002Freauth","2.examples\u002F5.reauth",{"title":75,"path":76,"stem":77,"icon":78},"Sign in with a passkey","\u002Fexamples\u002Fpasskey-sign-in","2.examples\u002F6.passkey-sign-in","i-lucide-fingerprint",{"title":80,"path":81,"stem":82,"children":83,"icon":97},"Composable Endpoints","\u002Fcomposables","3.composables\u002F1.index",[84,87,92],{"title":85,"path":81,"stem":82,"icon":86},"Overview","i-lucide-layout-grid",{"title":88,"path":89,"stem":90,"icon":91},"Requirements","\u002Fcomposables\u002Frequirements","3.composables\u002F2.requirements","i-lucide-list-checks",{"title":93,"path":94,"stem":95,"icon":96},"Recipes","\u002Fcomposables\u002Frecipes","3.composables\u002F3.recipes","i-lucide-book-marked","i-lucide-blocks",{"title":99,"icon":100,"path":101,"stem":102,"children":103,"page":138},"Modules","i-lucide-package","\u002Fmodules","4.modules",[104,109,114,119,123,128,133],{"title":105,"path":106,"stem":107,"icon":108},"Identity management","\u002Fmodules\u002Fidentity-management","4.modules\u002F1.identity-management","i-lucide-user-cog",{"title":110,"path":111,"stem":112,"icon":113},"Cookie auth","\u002Fmodules\u002Fcookie-auth","4.modules\u002F2.cookie-auth","i-lucide-cookie",{"title":115,"path":116,"stem":117,"icon":118},"Bearer auth","\u002Fmodules\u002Fbearer-auth","4.modules\u002F3.bearer-auth","i-lucide-key",{"title":120,"path":121,"stem":122,"icon":78},"JWT","\u002Fmodules\u002Fjwt","4.modules\u002F4.jwt",{"title":124,"path":125,"stem":126,"icon":127},"Passkeys","\u002Fmodules\u002Fpasskeys","4.modules\u002F5.passkeys","i-lucide-scan-face",{"title":129,"path":130,"stem":131,"icon":132},"ReAuth","\u002Fmodules\u002Freauth","4.modules\u002F6.reauth","i-lucide-shield-alert",{"title":134,"path":135,"stem":136,"icon":137},"External OAuth","\u002Fmodules\u002Fexternal-oauth","4.modules\u002F7.external-oauth","i-lucide-log-in",false,{"id":140,"title":71,"body":141,"description":320,"extension":321,"links":322,"meta":323,"navigation":324,"path":72,"seo":325,"stem":73,"__hash__":326},"docs\u002F2.examples\u002F5.reauth.md",{"type":142,"value":143,"toc":312},"minimark",[144,165,172,177,261,265,283,290,294],[145,146,147,148,152,153,156,157,160,161,164],"p",{},"Sensitive manage mutations and any host endpoint with ",[149,150,151],"code",{},".RequireReauth()"," need a fresh ReAuth proof. Browser clients get the ",[149,154,155],{},"AuthEndpoints.ReAuth"," cookie (5 minutes). API clients can send header ",[149,158,159],{},"X-AuthEndpoints-Reauth"," with the ",[149,162,163],{},"reauthToken"," from confirm.",[145,166,167,168,171],{},"Assume a signed-in cookie session and CSRF for ",[149,169,170],{},"POST \u002FconfirmIdentity"," when mapped with management.",[173,174,176],"h2",{"id":175},"steps","Steps",[178,179,180,196,202,233,247,252],"ol",{},[181,182,183,184,187,188,191,192,195],"li",{},"Call the protected action (for example ",[149,185,186],{},"POST \u002Fidentity\u002Fmanage\u002Finfo","). On missing ReAuth, expect ",[149,189,190],{},"401"," or ",[149,193,194],{},"403",".",[181,197,198,201],{},[149,199,200],{},"GET \u002Fidentity\u002Fmanage\u002FauthMethods"," to list available proofs.",[181,203,204,205,208,209],{},"Collect exactly one proof for ",[149,206,207],{},"POST \u002Fidentity\u002FconfirmIdentity",":\n",[210,211,212,217,222,227],"ul",{},[181,213,214],{},[149,215,216],{},"{ \"password\": \"…\" }",[181,218,219],{},[149,220,221],{},"{ \"twoFactorCode\": \"…\" }",[181,223,224],{},[149,225,226],{},"{ \"twoFactorRecoveryCode\": \"…\" }",[181,228,229,232],{},[149,230,231],{},"{ \"credentialJson\": \"…\" }"," after passkey options",[181,234,235,236,239,240,243,244,195],{},"For passkey step-up: ",[149,237,238],{},"POST \u002Fidentity\u002FconfirmIdentity\u002FpasskeyOptions",", run ",[149,241,242],{},"navigator.credentials.get(…)",", then send ",[149,245,246],{},"credentialJson",[181,248,249,251],{},[149,250,207],{}," with CSRF and one proof field.",[181,253,254,255,257,258,260],{},"On success, retry the protected action with the same session cookies. Send ",[149,256,159],{}," when the client stores ",[149,259,163],{}," instead of relying on the ReAuth cookie.",[173,262,264],{"id":263},"where-reauth-is-required","Where ReAuth is required",[210,266,267,275,278],{},[181,268,269,272,273],{},[149,270,271],{},"POST \u002Fidentity\u002Fmanage\u002F2fa"," and ",[149,274,186],{},[181,276,277],{},"Passkey add, rename, delete, and authenticated creation options",[181,279,280,281],{},"Host endpoints that call ",[149,282,151],{},[145,284,285,286,289],{},"See ",[287,288,129],"a",{"href":130}," for schemes, policy, and host wiring.",[173,291,293],{"id":292},"related","Related",[210,295,296,300,304,308],{},[181,297,298],{},[287,299,66],{"href":67},[181,301,302],{},[287,303,129],{"href":130},[181,305,306],{},[287,307,105],{"href":106},[181,309,310],{},[287,311,124],{"href":125},{"title":313,"searchDepth":314,"depth":315,"links":316},"",1,2,[317,318,319],{"id":175,"depth":315,"text":176},{"id":263,"depth":315,"text":264},{"id":292,"depth":315,"text":293},"Prove identity before a CSRF-protected manage or host action.","md",null,{},{"icon":36},{"title":71,"description":320},"u50OTTbd6jNZwo7RtOy7bZm1k5bWASQHBgO75G12TYk",[328,330],{"title":66,"path":67,"stem":68,"description":329,"icon":69,"children":-1},"Turn authenticator 2FA on or off with CSRF and ReAuth.",{"title":75,"path":76,"stem":77,"description":331,"icon":78,"children":-1},"Passwordless login for a confirmed account on the cookie facade.",1789052353241]