Guides
Prepare for production
Checklist for running AuthEndpoints safely in Production.
Work through this checklist before you deploy. Startup validation catches some items. The rest are your responsibility.
Check the core settings
- Serve the API over HTTPS.
- Register a real
IEmailSender<TUser>. WhenRequireEmailSenderInProductionistrue(the default), startup fails in Production while Identity's no-op sender is registered. - Set
Passkeys.ServerDomainwhen passkeys are on (the default). Startup fails in Production without it. - Leave
RequireConfirmedAccountattrueunless you have another way to verify email ownership.
Check the JWT settings
Skip this section if JWT is off.
- Call
modelBuilder.UseRefreshToken()on yourDbContextand apply the migration. - Set an issuer and an audience. Startup fails in Production with the library defaults (
JwtandJwtAudience). - Use a symmetric key of at least 256 bits (32 UTF-8 bytes), or an asymmetric key.
- If you upgrade from plaintext refresh-token storage, recreate the
AuthEndpointsRefreshTokenstable. AuthEndpoints now stores hashed tokens with reuse detection.
Check the external OAuth settings
Skip this section if you do not use GitHub or Google.
- Map the OAuth routes yourself.
MapAuthEndpointsdoes not map them. - Host a page at
ErrorPath(default/auth/external/error). - Leave
AutoLinkByEmailoff unless a verified provider email should attach to an existing confirmed account. - Keep
RequireVerifiedEmailon.
Check the browser setup
- If the client runs on another origin, add a CORS policy with credentials. See Call the API from a browser.
- Decide whether passkey and OAuth sign-in skipping 2FA fits your threat model. See Security model.
What the validators check
AuthEndpointsOptionsValidatorchecksIdentityPath,PasskeyPath, andJwt.Pathformats, and the Production passkey domain.AuthEndpointsEmailSenderValidatorchecks the email sender in Production.- JWT options validation rejects the default issuer and audience in Production, and checks the key material against the signing algorithm.
AddGitHubandAddGooglereject an emptyClientIdorClientSecretat startup.