[{"data":1,"prerenderedAt":530},["ShallowReactive",2],{"navigation":3,"\u002Fexamples\u002Fregister-confirmed-account":139,"\u002Fexamples\u002Fregister-confirmed-account-surround":525},[4,48,79,98],{"title":5,"path":6,"stem":7,"children":8,"icon":47},"Getting Started","\u002Fgetting-started","1.getting-started\u002F1.index",[9,12,17,22,27,32,37,42],{"title":10,"path":6,"stem":7,"icon":11},"Introduction","i-lucide-house",{"title":13,"path":14,"stem":15,"icon":16},"Installation","\u002Fgetting-started\u002Finstallation","1.getting-started\u002F2.installation","i-lucide-download",{"title":18,"path":19,"stem":20,"icon":21},"AI agents","\u002Fgetting-started\u002Fai-agents","1.getting-started\u002F3.ai-agents","i-lucide-bot",{"title":23,"path":24,"stem":25,"icon":26},"Quick start","\u002Fgetting-started\u002Fquick-start","1.getting-started\u002F4.quick-start","i-lucide-play",{"title":28,"path":29,"stem":30,"icon":31},"Configuration","\u002Fgetting-started\u002Fconfiguration","1.getting-started\u002F5.configuration","i-lucide-settings",{"title":33,"path":34,"stem":35,"icon":36},"Production","\u002Fgetting-started\u002Fproduction","1.getting-started\u002F6.production","i-lucide-shield-check",{"title":38,"path":39,"stem":40,"icon":41},"Compare","\u002Fgetting-started\u002Fcompare","1.getting-started\u002F7.compare","i-lucide-git-compare",{"title":43,"path":44,"stem":45,"icon":46},"FAQ","\u002Fgetting-started\u002Ffaq","1.getting-started\u002F8.faq","i-lucide-circle-help","i-lucide-rocket",{"title":49,"path":50,"stem":51,"children":52,"icon":54},"Examples","\u002Fexamples","2.examples\u002F1.index",[53,55,60,65,70,74],{"title":49,"path":50,"stem":51,"icon":54},"i-lucide-waypoints",{"title":56,"path":57,"stem":58,"icon":59},"Register a confirmed account","\u002Fexamples\u002Fregister-confirmed-account","2.examples\u002F2.register-confirmed-account","i-lucide-mail-check",{"title":61,"path":62,"stem":63,"icon":64},"Reset a forgotten password","\u002Fexamples\u002Freset-forgotten-password","2.examples\u002F3.reset-forgotten-password","i-lucide-key-round",{"title":66,"path":67,"stem":68,"icon":69},"Enable and disable two-factor authentication","\u002Fexamples\u002Ftwo-factor","2.examples\u002F4.two-factor","i-lucide-smartphone",{"title":71,"path":72,"stem":73,"icon":36},"Complete step-up (ReAuth)","\u002Fexamples\u002Freauth","2.examples\u002F5.reauth",{"title":75,"path":76,"stem":77,"icon":78},"Sign in with a passkey","\u002Fexamples\u002Fpasskey-sign-in","2.examples\u002F6.passkey-sign-in","i-lucide-fingerprint",{"title":80,"path":81,"stem":82,"children":83,"icon":97},"Composable Endpoints","\u002Fcomposables","3.composables\u002F1.index",[84,87,92],{"title":85,"path":81,"stem":82,"icon":86},"Overview","i-lucide-layout-grid",{"title":88,"path":89,"stem":90,"icon":91},"Requirements","\u002Fcomposables\u002Frequirements","3.composables\u002F2.requirements","i-lucide-list-checks",{"title":93,"path":94,"stem":95,"icon":96},"Recipes","\u002Fcomposables\u002Frecipes","3.composables\u002F3.recipes","i-lucide-book-marked","i-lucide-blocks",{"title":99,"icon":100,"path":101,"stem":102,"children":103,"page":138},"Modules","i-lucide-package","\u002Fmodules","4.modules",[104,109,114,119,123,128,133],{"title":105,"path":106,"stem":107,"icon":108},"Identity management","\u002Fmodules\u002Fidentity-management","4.modules\u002F1.identity-management","i-lucide-user-cog",{"title":110,"path":111,"stem":112,"icon":113},"Cookie auth","\u002Fmodules\u002Fcookie-auth","4.modules\u002F2.cookie-auth","i-lucide-cookie",{"title":115,"path":116,"stem":117,"icon":118},"Bearer auth","\u002Fmodules\u002Fbearer-auth","4.modules\u002F3.bearer-auth","i-lucide-key",{"title":120,"path":121,"stem":122,"icon":78},"JWT","\u002Fmodules\u002Fjwt","4.modules\u002F4.jwt",{"title":124,"path":125,"stem":126,"icon":127},"Passkeys","\u002Fmodules\u002Fpasskeys","4.modules\u002F5.passkeys","i-lucide-scan-face",{"title":129,"path":130,"stem":131,"icon":132},"ReAuth","\u002Fmodules\u002Freauth","4.modules\u002F6.reauth","i-lucide-shield-alert",{"title":134,"path":135,"stem":136,"icon":137},"External OAuth","\u002Fmodules\u002Fexternal-oauth","4.modules\u002F7.external-oauth","i-lucide-log-in",false,{"id":140,"title":56,"body":141,"description":518,"extension":519,"links":520,"meta":521,"navigation":522,"path":57,"seo":523,"stem":58,"__hash__":524},"docs\u002F2.examples\u002F2.register-confirmed-account.md",{"type":142,"value":143,"toc":507},"minimark",[144,157,175,180,222,226,329,333,407,419,423,470,474,481,485],[145,146,147,148,152,153,156],"p",{},"Build a first-party SPA signup that stays logged out until the user confirms email, then signs in. Use this when ",[149,150,151],"code",{},"RequireConfirmedAccount"," is ",[149,154,155],{},"true"," (the facade default).",[145,158,159,160,163,164,167,168,171,172,174],{},"Assume the cookie facade: management and cookie login under ",[149,161,162],{},"\u002Fidentity",", passkeys under ",[149,165,166],{},"\u002Faccount",". See ",[169,170,23],"a",{"href":24}," and ",[169,173,93],{"href":94},".",[176,177,179],"h2",{"id":178},"shared-setup","Shared setup",[181,182,183,195,205,219],"ol",{},[184,185,186,187,171,191,194],"li",{},"Offer ",[188,189,190],"strong",{},"Password",[188,192,193],{},"Passkey"," on the same signup screen.",[184,196,197,198,201,202,174],{},"Call ",[149,199,200],{},"GET \u002Fidentity\u002FcsrfToken"," before unsafe POSTs that require antiforgery. Send the value as header ",[149,203,204],{},"RequestVerificationToken",[184,206,207,208,211,212,215,216,218],{},"After a successful register (",[149,209,210],{},"200","), show the same ",[188,213,214],{},"Check your email"," screen for both methods. Do not treat that ",[149,217,210],{}," as signed in.",[184,220,221],{},"Do not tell the user the email is already registered. Duplicate-email paths return generic success or a generic failure (see below).",[176,223,225],{"id":224},"password-register","Password register",[181,227,228,231,241,253,260,309,322],{},[184,229,230],{},"Collect email and password.",[184,232,233,236,237,240],{},[149,234,235],{},"POST \u002Fidentity\u002Fregister"," with body ",[149,238,239],{},"{ \"email\", \"password\" }"," and CSRF.",[184,242,243,244,246,247,249,250,252],{},"On ",[149,245,210],{},", show ",[188,248,214],{},". Stay logged out. Duplicate email also returns ",[149,251,210],{}," (anti-enumeration). Use the same copy.",[184,254,255,256,259],{},"On validation failure, show the ",[149,257,258],{},"400"," problem details.",[184,261,262,263,266,267],{},"The mail link calls ",[149,264,265],{},"GET \u002Fidentity\u002FconfirmEmail?userId=…&code=…",".\n",[268,269,270,283],"ul",{},[184,271,272,273,276,277,279,280,174],{},"With ",[149,274,275],{},"EmailConfirmation.ConfirmEmailRedirectUri"," unset: success is plain-text thank-you (",[149,278,210],{},"); failure is ",[149,281,282],{},"401",[184,284,285,286,289,290,171,293,296,297,300,301,304,305,174],{},"With the URI set: success and failure return ",[149,287,288],{},"302"," to that URI with ",[149,291,292],{},"status=confirmed|failed",[149,294,295],{},"flow=confirm"," (or ",[149,298,299],{},"flow=change-email"," when ",[149,302,303],{},"changedEmail"," is present). Configure the option under ",[169,306,308],{"href":307},"\u002Fgetting-started\u002Fconfiguration#email-confirmation","Email confirmation",[184,310,311,312,315,316,319,320,174],{},"After confirm, sign in: ",[149,313,314],{},"POST \u002Fidentity\u002Flogin"," with email and password. Use ",[149,317,318],{},"?useSessionCookies=false"," only when you need a persistent cookie. See ",[169,321,110],{"href":111},[184,323,324,325,328],{},"On login success, enter the app with the session cookie (",[149,326,327],{},"credentials: \"include\"",").",[176,330,332],{"id":331},"passkey-register","Passkey register",[181,334,335,338,348,355,363,379,389,396,401],{},[184,336,337],{},"Collect email only.",[184,339,340,343,344,347],{},[149,341,342],{},"POST \u002Faccount\u002Fpasskeys\u002Fregister\u002Foptions"," with ",[149,345,346],{},"{ \"email\" }"," and CSRF. Creation options are returned even when the email is already taken.",[184,349,350,351,354],{},"Run ",[149,352,353],{},"navigator.credentials.create(…)",". If the user cancels, show a soft UI error. Do not call register.",[184,356,357,343,360,240],{},[149,358,359],{},"POST \u002Faccount\u002Fpasskeys\u002Fregister?useCookies=true",[149,361,362],{},"{ \"email\", \"credentialJson\" }",[184,364,365,366,343,368,371,372,375,376,378],{},"New email success: ",[149,367,210],{},[149,369,370],{},"{ \"credentialId\" }"," (or equivalent ",[149,373,374],{},"PasskeyCredentialResponse","). No Identity application cookie while the account is unconfirmed. Show the same ",[188,377,214],{}," screen. You may add a short note that they registered with a passkey.",[184,380,381,382,384,385,388],{},"Email taken, bad ceremony, or an attempt to attach to an existing user id: generic ",[149,383,258],{}," ",[188,386,387],{},"\"Unable to complete registration.\""," Use that copy. Do not invent a more specific reason.",[184,390,391,392,395],{},"Confirm with the same mail link and ",[149,393,394],{},"GET \u002Fidentity\u002FconfirmEmail"," behavior as password register. The passkey is already stored on the unconfirmed user.",[184,397,398,399,174],{},"After confirm, sign in with a passkey. See ",[169,400,75],{"href":76},[184,402,403,404,406],{},"Login succeeds only after confirm. Unconfirmed login returns ",[149,405,282],{}," Invalid credentials.",[145,408,409,410,413,414,167,417,174],{},"Default passkey completer cookie flags follow Identity ",[149,411,412],{},"Login",", not facade ",[149,415,416],{},"LoginCookie",[169,418,124],{"href":125},[176,420,422],{"id":421},"host-checklist","Host checklist",[424,425,426,439],"table",{},[427,428,429],"thead",{},[430,431,432,436],"tr",{},[433,434,435],"th",{},"Do",[433,437,438],{},"Do not",[440,441,442,454,462],"tbody",{},[430,443,444,448],{},[445,446,447],"td",{},"Same check-email screen for password and passkey",[445,449,450,451,453],{},"Treat register ",[149,452,210],{}," as logged in",[430,455,456,459],{},[445,457,458],{},"Generic copy on duplicate email",[445,460,461],{},"Say \"email already registered\"",[430,463,464,467],{},[445,465,466],{},"Sign in only after confirm",[445,468,469],{},"Expect a session from unconfirmed passkey register",[176,471,473],{"id":472},"out-of-scope","Out of scope",[145,475,476,477,480],{},"This page does not cover sign-in inside ",[149,478,479],{},"confirmEmail",", public resend without a session, or OAuth.",[176,482,484],{"id":483},"related","Related",[268,486,487,491,495,499,503],{},[184,488,489],{},[169,490,75],{"href":76},[184,492,493],{},[169,494,105],{"href":106},[184,496,497],{},[169,498,124],{"href":125},[184,500,501],{},[169,502,110],{"href":111},[184,504,505],{},[169,506,28],{"href":307},{"title":508,"searchDepth":509,"depth":510,"links":511},"",1,2,[512,513,514,515,516,517],{"id":178,"depth":510,"text":179},{"id":224,"depth":510,"text":225},{"id":331,"depth":510,"text":332},{"id":421,"depth":510,"text":422},{"id":472,"depth":510,"text":473},{"id":483,"depth":510,"text":484},"SPA password and passkey signup when RequireConfirmedAccount is true.","md",null,{},{"icon":59},{"title":56,"description":518},"XRKVZcUvHS-0kwA1PlZxQQW0HjmeywzB7zF0T2rHhXY",[526,528],{"title":49,"path":50,"stem":51,"description":527,"icon":54,"children":-1},"Step-by-step request flows for AuthEndpoints facade defaults.",{"title":61,"path":62,"stem":63,"description":529,"icon":64,"children":-1},"Request a reset mail, set a new password, then sign in.",1789052353065]