[{"data":1,"prerenderedAt":721},["ShallowReactive",2],{"navigation":3,"\u002Fguides\u002Fbrowser-clients":203,"\u002Fguides\u002Fbrowser-clients-surround":716},[4,33,96,114,177],{"title":5,"path":6,"stem":7,"children":8,"icon":32},"Get started","\u002Fgetting-started","1.getting-started\u002F1.index",[9,12,17,22,27],{"title":10,"path":6,"stem":7,"icon":11},"Introduction","i-lucide-house",{"title":13,"path":14,"stem":15,"icon":16},"Install AuthEndpoints","\u002Fgetting-started\u002Finstallation","1.getting-started\u002F2.installation","i-lucide-download",{"title":18,"path":19,"stem":20,"icon":21},"Quick start","\u002Fgetting-started\u002Fquick-start","1.getting-started\u002F3.quick-start","i-lucide-play",{"title":23,"path":24,"stem":25,"icon":26},"Choose a sign-in stack","\u002Fgetting-started\u002Fchoose-a-sign-in-stack","1.getting-started\u002F4.choose-a-sign-in-stack","i-lucide-signpost",{"title":28,"path":29,"stem":30,"icon":31},"Use the AuthEndpoints skill with coding agents","\u002Fgetting-started\u002Fai-agents","1.getting-started\u002F5.ai-agents","i-lucide-bot","i-lucide-rocket",{"title":34,"path":35,"stem":36,"children":37,"icon":95},"Guides","\u002Fguides","2.guides\u002F01.index",[38,40,45,50,55,60,65,70,75,80,85,90],{"title":34,"path":35,"stem":36,"icon":39},"i-lucide-list-checks",{"title":41,"path":42,"stem":43,"icon":44},"Register users","\u002Fguides\u002Fregistration","2.guides\u002F02.registration","i-lucide-user-plus",{"title":46,"path":47,"stem":48,"icon":49},"Sign users in","\u002Fguides\u002Fsign-in","2.guides\u002F03.sign-in","i-lucide-log-in",{"title":51,"path":52,"stem":53,"icon":54},"Sign users out","\u002Fguides\u002Fsign-out","2.guides\u002F04.sign-out","i-lucide-log-out",{"title":56,"path":57,"stem":58,"icon":59},"Turn on two-factor authentication","\u002Fguides\u002Ftwo-factor","2.guides\u002F05.two-factor","i-lucide-smartphone",{"title":61,"path":62,"stem":63,"icon":64},"Reset a forgotten password","\u002Fguides\u002Freset-password","2.guides\u002F06.reset-password","i-lucide-key-round",{"title":66,"path":67,"stem":68,"icon":69},"Change a user's email or password","\u002Fguides\u002Fmanage-account","2.guides\u002F07.manage-account","i-lucide-user-cog",{"title":71,"path":72,"stem":73,"icon":74},"Add, rename, and remove passkeys","\u002Fguides\u002Fmanage-passkeys","2.guides\u002F08.manage-passkeys","i-lucide-scan-face",{"title":76,"path":77,"stem":78,"icon":79},"Link and unlink GitHub or Google accounts","\u002Fguides\u002Flink-external-accounts","2.guides\u002F09.link-external-accounts","i-lucide-link",{"title":81,"path":82,"stem":83,"icon":84},"Require step-up before sensitive actions","\u002Fguides\u002Fstep-up","2.guides\u002F10.step-up","i-lucide-shield-check",{"title":86,"path":87,"stem":88,"icon":89},"Call the API from a browser","\u002Fguides\u002Fbrowser-clients","2.guides\u002F11.browser-clients","i-lucide-globe",{"title":91,"path":92,"stem":93,"icon":94},"Prepare for production","\u002Fguides\u002Fproduction","2.guides\u002F12.production","i-lucide-factory","i-lucide-waypoints",{"title":97,"path":98,"stem":99,"children":100,"icon":113},"Composable endpoints","\u002Fcomposables","3.composables\u002F1.index",[101,104,108],{"title":102,"path":98,"stem":99,"icon":103},"How composition works","i-lucide-layout-grid",{"title":105,"path":106,"stem":107,"icon":39},"Composition requirements","\u002Fcomposables\u002Frequirements","3.composables\u002F2.requirements",{"title":109,"path":110,"stem":111,"icon":112},"Compose a custom auth stack","\u002Fcomposables\u002Frecipes","3.composables\u002F3.recipes","i-lucide-book-marked","i-lucide-blocks",{"title":115,"icon":116,"path":117,"stem":118,"children":119,"page":176},"Reference","i-lucide-book-open","\u002Fmodules","4.modules",[120,125,129,134,139,144,148,153,157,162,166,171],{"title":121,"path":122,"stem":123,"icon":124},"Endpoint reference","\u002Fmodules\u002Fendpoints","4.modules\u002F01.endpoints","i-lucide-route",{"title":126,"path":127,"stem":128,"icon":69},"Identity management module","\u002Fmodules\u002Fidentity-management","4.modules\u002F02.identity-management",{"title":130,"path":131,"stem":132,"icon":133},"Cookie sign-in module","\u002Fmodules\u002Fcookie-auth","4.modules\u002F03.cookie-auth","i-lucide-cookie",{"title":135,"path":136,"stem":137,"icon":138},"Identity bearer sign-in module","\u002Fmodules\u002Fbearer-auth","4.modules\u002F04.bearer-auth","i-lucide-key",{"title":140,"path":141,"stem":142,"icon":143},"JWT module","\u002Fmodules\u002Fjwt","4.modules\u002F05.jwt","i-lucide-fingerprint",{"title":145,"path":146,"stem":147,"icon":74},"Passkeys module","\u002Fmodules\u002Fpasskeys","4.modules\u002F06.passkeys",{"title":149,"path":150,"stem":151,"icon":152},"ReAuth module","\u002Fmodules\u002Freauth","4.modules\u002F07.reauth","i-lucide-shield-alert",{"title":154,"path":155,"stem":156,"icon":49},"External OAuth packages","\u002Fmodules\u002Fexternal-oauth","4.modules\u002F08.external-oauth",{"title":158,"path":159,"stem":160,"icon":161},"Configuration options","\u002Fmodules\u002Fconfiguration","4.modules\u002F09.configuration","i-lucide-settings",{"title":163,"path":164,"stem":165,"icon":84},"Antiforgery (CSRF) rules","\u002Fmodules\u002Fcsrf","4.modules\u002F10.csrf",{"title":167,"path":168,"stem":169,"icon":170},"Responses and errors","\u002Fmodules\u002Ferrors","4.modules\u002F11.errors","i-lucide-circle-alert",{"title":172,"path":173,"stem":174,"icon":175},"Rate-limit policies","\u002Fmodules\u002Frate-limits","4.modules\u002F12.rate-limits","i-lucide-gauge",false,{"title":178,"icon":179,"path":180,"stem":181,"children":182,"page":176},"Concepts","i-lucide-lightbulb","\u002Fconcepts","5.concepts",[183,188,193,198],{"title":184,"path":185,"stem":186,"icon":187},"AuthEndpoints compared with other options","\u002Fconcepts\u002Fcompare","5.concepts\u002F1.compare","i-lucide-git-compare",{"title":189,"path":190,"stem":191,"icon":192},"Stock Identity endpoints vs AuthEndpoints","\u002Fconcepts\u002Fstock-identity-vs-authendpoints","5.concepts\u002F2.stock-identity-vs-authendpoints","i-lucide-columns-2",{"title":194,"path":195,"stem":196,"icon":197},"Security model","\u002Fconcepts\u002Fsecurity-model","5.concepts\u002F3.security-model","i-lucide-shield",{"title":199,"path":200,"stem":201,"icon":202},"FAQ","\u002Fconcepts\u002Ffaq","5.concepts\u002F4.faq","i-lucide-circle-help",{"id":204,"title":86,"body":205,"description":709,"extension":710,"links":711,"meta":712,"navigation":713,"path":87,"seo":714,"stem":88,"__hash__":715},"docs\u002F2.guides\u002F11.browser-clients.md",{"type":206,"value":207,"toc":702},"minimark",[208,212,217,233,237,274,358,365,369,372,571,580,584,591,648,675,679,698],[209,210,211],"p",{},"Browser clients on the cookie stack and the JWT stack depend on cookies and antiforgery tokens. Follow these steps for a single-page app (SPA) or any other browser client.",[213,214,216],"h2",{"id":215},"send-cookies-on-every-request","Send cookies on every request",[209,218,219,220,224,225,228,229,232],{},"Add ",[221,222,223],"code",{},"credentials: 'include'"," to every ",[221,226,227],{},"fetch"," call. With Axios, set ",[221,230,231],{},"withCredentials: true",". Without it, the browser does not send the application cookie, the antiforgery cookie, the ReAuth cookie, or the JWT refresh cookie.",[213,234,236],{"id":235},"send-a-csrf-token-on-protected-requests","Send a CSRF token on protected requests",[238,239,240,256,263],"ol",{},[241,242,243,244,247,248,251,252,255],"li",{},"Get a token. The cookie stack serves it at ",[221,245,246],{},"GET \u002Fidentity\u002FcsrfToken",". The JWT stack serves it at ",[221,249,250],{},"GET \u002Fauth\u002FcsrfToken",". Both return ",[221,253,254],{},"{ \"csrfToken\": \"...\" }"," and set the antiforgery cookie.",[241,257,258,259,262],{},"Send the token in the ",[221,260,261],{},"RequestVerificationToken"," header on every route that requires antiforgery.",[241,264,265,266,269,270,273],{},"If a request returns ",[221,267,268],{},"400"," with the body ",[221,271,272],{},"Invalid or missing CSRF token.",", get a new token and retry once.",[275,276,281],"pre",{"className":277,"code":278,"language":279,"meta":280,"style":280},"language-js shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","async function csrf() {\n  const r = await fetch('\u002Fidentity\u002FcsrfToken', { credentials: 'include' });\n  return (await r.json()).csrfToken;\n}\n\nconst csrfToken = await csrf();\nawait fetch('\u002Fidentity\u002Fmanage\u002Finfo', {\n  method: 'POST',\n  credentials: 'include',\n  headers: { 'Content-Type': 'application\u002Fjson', 'RequestVerificationToken': csrfToken },\n  body: JSON.stringify({ newEmail })\n});\n","js","",[221,282,283,291,297,303,309,316,322,328,334,340,346,352],{"__ignoreMap":280},[284,285,288],"span",{"class":286,"line":287},"line",1,[284,289,290],{},"async function csrf() {\n",[284,292,294],{"class":286,"line":293},2,[284,295,296],{},"  const r = await fetch('\u002Fidentity\u002FcsrfToken', { credentials: 'include' });\n",[284,298,300],{"class":286,"line":299},3,[284,301,302],{},"  return (await r.json()).csrfToken;\n",[284,304,306],{"class":286,"line":305},4,[284,307,308],{},"}\n",[284,310,312],{"class":286,"line":311},5,[284,313,315],{"emptyLinePlaceholder":314},true,"\n",[284,317,319],{"class":286,"line":318},6,[284,320,321],{},"const csrfToken = await csrf();\n",[284,323,325],{"class":286,"line":324},7,[284,326,327],{},"await fetch('\u002Fidentity\u002Fmanage\u002Finfo', {\n",[284,329,331],{"class":286,"line":330},8,[284,332,333],{},"  method: 'POST',\n",[284,335,337],{"class":286,"line":336},9,[284,338,339],{},"  credentials: 'include',\n",[284,341,343],{"class":286,"line":342},10,[284,344,345],{},"  headers: { 'Content-Type': 'application\u002Fjson', 'RequestVerificationToken': csrfToken },\n",[284,347,349],{"class":286,"line":348},11,[284,350,351],{},"  body: JSON.stringify({ newEmail })\n",[284,353,355],{"class":286,"line":354},12,[284,356,357],{},"});\n",[209,359,360,361,364],{},"The token is tied to the signed-in user. After sign-in or sign-out, get a new token. Login, register, forgot password, and reset password need no token. The full list is in ",[362,363,163],"a",{"href":164},".",[213,366,368],{"id":367},"set-up-cors-when-the-client-runs-on-another-origin","Set up CORS when the client runs on another origin",[209,370,371],{},"AuthEndpoints does not configure CORS. If the browser client and the API have different origins, add a CORS policy in the host that allows credentials and the AuthEndpoints headers:",[275,373,377],{"className":374,"code":375,"language":376,"meta":280,"style":280},"language-cs shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","builder.Services.AddCors(o => o.AddPolicy(\"spa\", policy => policy\n    .WithOrigins(\"https:\u002F\u002Fapp.example.com\")\n    .AllowCredentials()\n    .AllowAnyMethod()\n    .WithHeaders(\"Content-Type\", \"RequestVerificationToken\", \"X-AuthEndpoints-Reauth\")));\n\nvar app = builder.Build();\napp.UseCors(\"spa\");\napp.UseAuthEndpoints();\n","cs",[221,378,379,437,457,467,476,513,517,539,560],{"__ignoreMap":280},[284,380,381,385,388,391,393,397,400,404,407,410,412,415,417,420,424,426,429,432,434],{"class":286,"line":287},[284,382,384],{"class":383},"sTEyZ","builder",[284,386,364],{"class":387},"sMK4o",[284,389,390],{"class":383},"Services",[284,392,364],{"class":387},[284,394,396],{"class":395},"s2Zo4","AddCors",[284,398,399],{"class":387},"(",[284,401,403],{"class":402},"sBMFI","o",[284,405,406],{"class":387}," =>",[284,408,409],{"class":383}," o",[284,411,364],{"class":387},[284,413,414],{"class":395},"AddPolicy",[284,416,399],{"class":387},[284,418,419],{"class":387},"\"",[284,421,423],{"class":422},"sfazB","spa",[284,425,419],{"class":387},[284,427,428],{"class":387},",",[284,430,431],{"class":402}," policy",[284,433,406],{"class":387},[284,435,436],{"class":383}," policy\n",[284,438,439,442,445,447,449,452,454],{"class":286,"line":293},[284,440,441],{"class":387},"    .",[284,443,444],{"class":395},"WithOrigins",[284,446,399],{"class":387},[284,448,419],{"class":387},[284,450,451],{"class":422},"https:\u002F\u002Fapp.example.com",[284,453,419],{"class":387},[284,455,456],{"class":387},")\n",[284,458,459,461,464],{"class":286,"line":299},[284,460,441],{"class":387},[284,462,463],{"class":395},"AllowCredentials",[284,465,466],{"class":387},"()\n",[284,468,469,471,474],{"class":286,"line":305},[284,470,441],{"class":387},[284,472,473],{"class":395},"AllowAnyMethod",[284,475,466],{"class":387},[284,477,478,480,483,485,487,490,492,494,497,499,501,503,505,508,510],{"class":286,"line":311},[284,479,441],{"class":387},[284,481,482],{"class":395},"WithHeaders",[284,484,399],{"class":387},[284,486,419],{"class":387},[284,488,489],{"class":422},"Content-Type",[284,491,419],{"class":387},[284,493,428],{"class":387},[284,495,496],{"class":387}," \"",[284,498,261],{"class":422},[284,500,419],{"class":387},[284,502,428],{"class":387},[284,504,496],{"class":387},[284,506,507],{"class":422},"X-AuthEndpoints-Reauth",[284,509,419],{"class":387},[284,511,512],{"class":387},")));\n",[284,514,515],{"class":286,"line":318},[284,516,315],{"emptyLinePlaceholder":314},[284,518,519,522,525,528,531,533,536],{"class":286,"line":324},[284,520,521],{"class":402},"var",[284,523,524],{"class":402}," app",[284,526,527],{"class":387}," =",[284,529,530],{"class":383}," builder",[284,532,364],{"class":387},[284,534,535],{"class":395},"Build",[284,537,538],{"class":387},"();\n",[284,540,541,544,546,549,551,553,555,557],{"class":286,"line":330},[284,542,543],{"class":383},"app",[284,545,364],{"class":387},[284,547,548],{"class":395},"UseCors",[284,550,399],{"class":387},[284,552,419],{"class":387},[284,554,423],{"class":422},[284,556,419],{"class":387},[284,558,559],{"class":387},");\n",[284,561,562,564,566,569],{"class":286,"line":336},[284,563,543],{"class":383},[284,565,364],{"class":387},[284,567,568],{"class":395},"UseAuthEndpoints",[284,570,538],{"class":387},[209,572,573,575,576,579],{},[221,574,463],{}," does not work with ",[221,577,578],{},"AllowAnyOrigin",". List the exact origins.",[213,581,583],{"id":582},"keep-the-client-and-the-api-on-the-same-site","Keep the client and the API on the same site",[209,585,586,587,590],{},"CORS lets the request through, but cookie ",[221,588,589],{},"SameSite"," rules decide which cookies the browser sends:",[592,593,594,608],"table",{},[595,596,597],"thead",{},[598,599,600,604],"tr",{},[601,602,603],"th",{},"Cookie",[601,605,606],{},[221,607,589],{},[609,610,611,625,637],"tbody",{},[598,612,613,619],{},[614,615,616],"td",{},[221,617,618],{},".AspNetCore.Identity.Application",[614,620,621,624],{},[221,622,623],{},"Lax"," (Identity default)",[598,626,627,632],{},[614,628,629],{},[221,630,631],{},"AuthEndpoints.ReAuth",[614,633,634],{},[221,635,636],{},"Strict",[598,638,639,644],{},[614,640,641],{},[221,642,643],{},"AuthEndpoints.Jwt.RefreshToken",[614,645,646],{},[221,647,636],{},[209,649,650,653,654,657,658,661,662,665,666,668,669,671,672,674],{},[221,651,652],{},"app.example.com"," and ",[221,655,656],{},"api.example.com"," are the same site, so these cookies work. A client on a different registrable domain, such as ",[221,659,660],{},"example-app.com"," calling ",[221,663,664],{},"example.com",", is cross-site. The browser does not send ",[221,667,623],{}," or ",[221,670,636],{}," cookies on cross-site ",[221,673,227],{}," calls. Serve the API under the same site as the client, or put a reverse proxy in front of it.",[213,676,678],{"id":677},"related","Related",[680,681,682,686,690,694],"ul",{},[241,683,684],{},[362,685,163],{"href":164},[241,687,688],{},[362,689,46],{"href":47},[241,691,692],{},[362,693,130],{"href":131},[241,695,696],{},[362,697,140],{"href":141},[699,700,701],"style",{},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sTEyZ, html code.shiki .sTEyZ{--shiki-light:#90A4AE;--shiki-default:#EEFFFF;--shiki-dark:#BABED8}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .s2Zo4, html code.shiki .s2Zo4{--shiki-light:#6182B8;--shiki-default:#82AAFF;--shiki-dark:#82AAFF}html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}",{"title":280,"searchDepth":287,"depth":293,"links":703},[704,705,706,707,708],{"id":215,"depth":293,"text":216},{"id":235,"depth":293,"text":236},{"id":367,"depth":293,"text":368},{"id":582,"depth":293,"text":583},{"id":677,"depth":293,"text":678},"Send cookies and CSRF tokens from a browser client, and set up CORS when the client runs on another origin.","md",null,{},{"icon":89},{"title":86,"description":709},"bxHRXOu8KHPUPZPfFyt7sCylhjzlWZW4r8Fy1oJy7EY",[717,719],{"title":81,"path":82,"stem":83,"description":718,"icon":84,"children":-1},"Ask a signed-in user to prove their identity again before a sensitive change, then retry the change.",{"title":91,"path":92,"stem":93,"description":720,"icon":94,"children":-1},"Checklist for running AuthEndpoints safely in Production.",1791096171084]