Changelog
Guides

Guides

Task-based steps for registration, sign-in, account management, and production setup.

Each guide covers one task. The steps use the facade defaults: management and sign-in under /identity, passkeys under /account, JWT under /auth, and external OAuth under /auth/external.

Coming from MapIdentityApi? See Stock Identity endpoints vs AuthEndpoints.

GuideUse it when
Register usersYou need sign-up with a password, a passkey, or GitHub or Google.
Sign users inYou need sign-in with a password, a passkey, or GitHub or Google, including 2FA codes.
Sign users outYou need logout for the cookie, Identity bearer, or JWT stack.
Turn on two-factor authenticationUsers need authenticator codes and recovery codes.
Reset a forgotten passwordA user cannot sign in and needs a reset email.
Change a user's email or passwordA signed-in user changes their email or password.
Add, rename, and remove passkeysA signed-in user manages their passkeys.
Link and unlink GitHub or Google accountsA signed-in user connects or disconnects a provider login.
Require step-up before sensitive actionsAn endpoint returns 401 or 403 until the user proves their identity again.
Call the API from a browserYou set up cookies, CSRF tokens, and CORS for a browser client.
Prepare for productionYou are about to deploy.

Route tables for every module are in the Endpoint reference.