Changelog
Guides

Prepare for production

Checklist for running AuthEndpoints safely in Production.

Work through this checklist before you deploy. Startup validation catches some items. The rest are your responsibility.

Check the core settings

  • Serve the API over HTTPS.
  • Register a real IEmailSender<TUser>. When RequireEmailSenderInProduction is true (the default), startup fails in Production while Identity's no-op sender is registered.
  • Set Passkeys.ServerDomain when passkeys are on (the default). Startup fails in Production without it.
  • Leave RequireConfirmedAccount at true unless you have another way to verify email ownership.

Check the JWT settings

Skip this section if JWT is off.

  • Call modelBuilder.UseRefreshToken() on your DbContext and apply the migration.
  • Set an issuer and an audience. Startup fails in Production with the library defaults (Jwt and JwtAudience).
  • Use a symmetric key of at least 256 bits (32 UTF-8 bytes), or an asymmetric key.
  • If you upgrade from plaintext refresh-token storage, recreate the AuthEndpointsRefreshTokens table. AuthEndpoints now stores hashed tokens with reuse detection.

Check the external OAuth settings

Skip this section if you do not use GitHub or Google.

  • Map the OAuth routes yourself. MapAuthEndpoints does not map them.
  • Host a page at ErrorPath (default /auth/external/error).
  • Leave AutoLinkByEmail off unless a verified provider email should attach to an existing confirmed account.
  • Keep RequireVerifiedEmail on.

Check the browser setup

What the validators check

  • AuthEndpointsOptionsValidator checks IdentityPath, PasskeyPath, and Jwt.Path formats, and the Production passkey domain.
  • AuthEndpointsEmailSenderValidator checks the email sender in Production.
  • JWT options validation rejects the default issuer and audience in Production, and checks the key material against the signing algorithm.
  • AddGitHub and AddGoogle reject an empty ClientId or ClientSecret at startup.