[{"data":1,"prerenderedAt":345},["ShallowReactive",2],{"navigation":3,"\u002Fgetting-started":94,"\u002Fgetting-started-surround":342},[4,33,52],{"title":5,"path":6,"stem":7,"children":8,"icon":32},"Getting Started","\u002Fgetting-started","1.getting-started\u002F1.index",[9,12,17,22,27],{"title":10,"path":6,"stem":7,"icon":11},"Introduction","i-lucide-house",{"title":13,"path":14,"stem":15,"icon":16},"Installation","\u002Fgetting-started\u002Finstallation","1.getting-started\u002F2.installation","i-lucide-download",{"title":18,"path":19,"stem":20,"icon":21},"Quick start","\u002Fgetting-started\u002Fquick-start","1.getting-started\u002F3.quick-start","i-lucide-play",{"title":23,"path":24,"stem":25,"icon":26},"Configuration","\u002Fgetting-started\u002Fconfiguration","1.getting-started\u002F4.configuration","i-lucide-settings",{"title":28,"path":29,"stem":30,"icon":31},"Production","\u002Fgetting-started\u002Fproduction","1.getting-started\u002F5.production","i-lucide-shield-check","i-lucide-rocket",{"title":34,"path":35,"stem":36,"children":37,"icon":51},"Composable Endpoints","\u002Fcomposables","2.composables\u002F1.index",[38,41,46],{"title":39,"path":35,"stem":36,"icon":40},"Overview","i-lucide-layout-grid",{"title":42,"path":43,"stem":44,"icon":45},"Requirements","\u002Fcomposables\u002Frequirements","2.composables\u002F2.requirements","i-lucide-list-checks",{"title":47,"path":48,"stem":49,"icon":50},"Recipes","\u002Fcomposables\u002Frecipes","2.composables\u002F3.recipes","i-lucide-book-marked","i-lucide-blocks",{"title":53,"icon":54,"path":55,"stem":56,"children":57,"page":93},"Modules","i-lucide-package","\u002Fmodules","3.modules",[58,63,68,73,78,83,88],{"title":59,"path":60,"stem":61,"icon":62},"Identity management","\u002Fmodules\u002Fidentity-management","3.modules\u002F1.identity-management","i-lucide-user-cog",{"title":64,"path":65,"stem":66,"icon":67},"Cookie auth","\u002Fmodules\u002Fcookie-auth","3.modules\u002F2.cookie-auth","i-lucide-cookie",{"title":69,"path":70,"stem":71,"icon":72},"Bearer auth","\u002Fmodules\u002Fbearer-auth","3.modules\u002F3.bearer-auth","i-lucide-key",{"title":74,"path":75,"stem":76,"icon":77},"JWT","\u002Fmodules\u002Fjwt","3.modules\u002F4.jwt","i-lucide-fingerprint",{"title":79,"path":80,"stem":81,"icon":82},"Passkeys","\u002Fmodules\u002Fpasskeys","3.modules\u002F5.passkeys","i-lucide-scan-face",{"title":84,"path":85,"stem":86,"icon":87},"ReAuth","\u002Fmodules\u002Freauth","3.modules\u002F6.reauth","i-lucide-shield-alert",{"title":89,"path":90,"stem":91,"icon":92},"External OAuth","\u002Fmodules\u002Fexternal-oauth","3.modules\u002F7.external-oauth","i-lucide-log-in",false,{"id":95,"title":10,"body":96,"description":335,"extension":336,"links":337,"meta":338,"navigation":339,"path":6,"seo":340,"stem":7,"__hash__":341},"docs\u002F1.getting-started\u002F1.index.md",{"type":97,"value":98,"toc":326},"minimark",[99,103,108,155,159,199,210,213,290,312,315],[100,101,102],"p",{},"AuthEndpoints gives you ready-made auth API endpoints on top of ASP.NET Core Identity. It fits a single-backend API serving a SPA or frontend with first-party email\u002Fpassword, cookies, JWT, and\u002For passkeys.",[104,105,107],"h2",{"id":106},"why-authendpoints","Why AuthEndpoints?",[109,110,111,119,137,143,149],"ul",{},[112,113,114,118],"li",{},[115,116,117],"strong",{},"Ready-made endpoints"," — map registration, login, password reset, 2FA, and session\u002Ftoken flows instead of wiring them yourself",[112,120,121,124,125,129,130,129,133,136],{},[115,122,123],{},"Opinionated quick start"," — ",[126,127,128],"code",{},"AddAuthEndpoints"," \u002F ",[126,131,132],{},"UseAuthEndpoints",[126,134,135],{},"MapAuthEndpoints"," for cookie Identity + passkeys with secure defaults",[112,138,139,142],{},[115,140,141],{},"Sign-in stacks you choose"," — cookie sessions, Identity bearer tokens, or JWT",[112,144,145,148],{},[115,146,147],{},"Passkeys (WebAuthn)"," — passwordless register and login",[112,150,151,154],{},[115,152,153],{},"Built-in hardening"," — rate limiting, antiforgery for cookie flows, lockout-aware login, hashed JWT refresh tokens with reuse detection",[104,156,158],{"id":157},"facade-vs-compose","Facade vs compose",[160,161,162,175],"table",{},[163,164,165],"thead",{},[166,167,168,172],"tr",{},[169,170,171],"th",{},"Approach",[169,173,174],{},"When to use",[176,177,178,189],"tbody",{},[166,179,180,186],{},[181,182,183],"td",{},[115,184,185],{},"Facade",[181,187,188],{},"Cookie SPA + passkeys (and optional JWT). One DI call, one pipeline call, one map call.",[166,190,191,196],{},[181,192,193],{},[115,194,195],{},"Compose",[181,197,198],{},"Identity bearer, custom path prefixes, JWT-only, or a custom mix of modules.",[100,200,201,202,205,206,209],{},"See ",[203,204,18],"a",{"href":19}," for the facade, and ",[203,207,208],{"href":35},"Composable endpoints"," when you need to assemble modules yourself.",[104,211,53],{"id":212},"modules",[160,214,215,225],{},[163,216,217],{},[166,218,219,222],{},[169,220,221],{},"Module",[169,223,224],{},"Role",[176,226,227,236,245,254,263,272,281],{},[166,228,229,233],{},[181,230,231],{},[203,232,59],{"href":60},[181,234,235],{},"Register, confirm email, forgot\u002Freset password, manage info and 2FA",[166,237,238,242],{},[181,239,240],{},[203,241,64],{"href":65},[181,243,244],{},"Cookie login\u002Flogout + CSRF token",[166,246,247,251],{},[181,248,249],{},[203,250,69],{"href":70},[181,252,253],{},"Identity bearer login\u002Frefresh\u002Flogout",[166,255,256,260],{},[181,257,258],{},[203,259,74],{"href":75},[181,261,262],{},"JWT access tokens + HttpOnly refresh cookie",[166,264,265,269],{},[181,266,267],{},[203,268,79],{"href":80},[181,270,271],{},"WebAuthn passwordless + credential management",[166,273,274,278],{},[181,275,276],{},[203,277,84],{"href":85},[181,279,280],{},"Step-up confirmation for sensitive actions",[166,282,283,287],{},[181,284,285],{},[203,286,89],{"href":90},[181,288,289],{},"GitHub\u002FGoogle OAuth (separate preview package)",[291,292,295],"callout",{"color":293,"icon":294},"warning","i-lucide-flask-conical",[100,296,297,299,300,303,304,307,308,311],{},[203,298,89],{"href":90}," (",[126,301,302],{},"AuthEndpoints.External.OAuth",") is a ",[115,305,306],{},"preview"," package with its own version. It is not included in the core ",[126,309,310],{},"AuthEndpoints"," NuGet package.",[104,313,42],{"id":314},"requirements",[109,316,317,320,323],{},[112,318,319],{},".NET 10",[112,321,322],{},"ASP.NET Core Identity",[112,324,325],{},"EF Core for the user store",{"title":327,"searchDepth":328,"depth":329,"links":330},"",1,2,[331,332,333,334],{"id":106,"depth":329,"text":107},{"id":157,"depth":329,"text":158},{"id":212,"depth":329,"text":53},{"id":314,"depth":329,"text":42},"AuthEndpoints is an ASP.NET Core library of ready-made Identity auth endpoints for SPA backends.","md",null,{},{"icon":11},{"title":10,"description":335},"VC-vSPMat7M7PDfcKGa__285SZRgMQfyXh-asqyA5tg",[337,343],{"title":13,"path":14,"stem":15,"description":344,"icon":16,"children":-1},"Add the AuthEndpoints NuGet package to your ASP.NET Core project.",1785399439560]