Endpoint reference
Paths use the facade defaults: IdentityPath is /identity, PasskeyPath is /account, and Jwt.Path is /auth. External OAuth routes have no default prefix. The table uses /auth/external, the prefix from the examples.
Column meanings:
- Auth: the route requires a signed-in user.
- CSRF: the route runs the antiforgery filter. See Antiforgery (CSRF) rules.
- ReAuth: the route requires a fresh step-up proof. See ReAuth module.
- Rate limit: the policy name without the
AuthEndpoints.prefix. See Rate-limit policies.
Identity management
Mapped by MapIdentityManagementApi. The facade always maps it under IdentityPath. Management routes accept the application cookie, Identity bearer tokens, and JWT bearer tokens, when those schemes are registered.
| Method | Path | Auth | CSRF | ReAuth | Rate limit |
|---|---|---|---|---|---|
POST | /identity/register | AccountAbuse | |||
GET | /identity/confirmEmail | ||||
POST | /identity/resendConfirmationEmail | Yes | Yes | AccountAbuse | |
POST | /identity/forgotPassword | AccountAbuse | |||
POST | /identity/resetPassword | AccountAbuse | |||
POST | /identity/confirmIdentity | Yes | Yes | ConfirmIdentity | |
POST | /identity/confirmIdentity/passkeyOptions | Yes | Yes | ConfirmIdentity | |
GET | /identity/manage/authMethods | Yes | |||
GET | /identity/manage/2fa | Yes | |||
POST | /identity/manage/2fa | Yes | Yes | Yes | |
GET | /identity/manage/info | Yes | |||
POST | /identity/manage/info | Yes | Yes | Yes |
Details: Identity management module.
Cookie sign-in
Mapped by MapCookieAuthEndpoints. The cookie facade maps it under IdentityPath.
| Method | Path | Auth | CSRF | ReAuth | Rate limit |
|---|---|---|---|---|---|
POST | /identity/login | Login | |||
POST | /identity/logout | Yes | Yes | ||
GET | /identity/csrfToken |
Details: Cookie sign-in module.
Identity bearer sign-in
Mapped by MapBearerAuthEndpoints. The bearer facade maps it under IdentityPath instead of cookie sign-in.
| Method | Path | Auth | CSRF | ReAuth | Rate limit |
|---|---|---|---|---|---|
POST | /identity/login | Login | |||
POST | /identity/refresh | ||||
POST | /identity/logout | Yes |
Details: Identity bearer sign-in module.
Passkeys
Mapped by MapPasskeyEndpoints under {prefix}/passkeys. The facade maps it under PasskeyPath unless Passkeys.Enabled is false.
| Method | Path | Auth | CSRF | ReAuth | Rate limit |
|---|---|---|---|---|---|
POST | /account/passkeys/creationOptions | Yes | Yes | Yes | Passkey.ObtainOptions |
POST | /account/passkeys/requestOptions | Yes | Passkey.ObtainOptions | ||
POST | /account/passkeys/register/options | Yes | Passkey.ObtainOptions | ||
POST | /account/passkeys/register | Yes | Passkey.Register | ||
POST | /account/passkeys/login | Yes | Login | ||
POST | /account/passkeys/ | Yes | Yes | Yes | Passkey.Register |
GET | /account/passkeys/ | Yes | |||
PATCH | /account/passkeys/ | Yes | Yes | Yes | |
DELETE | /account/passkeys/{credentialIdUrl} | Yes | Yes | Yes |
Details: Passkeys module.
JWT
Mapped by MapJwtAuthEndpoints. The facade maps it under Jwt.Path when Jwt.Enabled is true.
| Method | Path | Auth | CSRF | ReAuth | Rate limit |
|---|---|---|---|---|---|
POST | /auth/create | Login | |||
POST | /auth/refresh | Refresh cookie | Yes | Login | |
GET | /auth/verify | JWT bearer | |||
POST | /auth/logout | Yes | |||
GET | /auth/csrfToken |
Details: JWT module.
External OAuth
Mapped by MapGitHubAuthEndpoints, MapGoogleAuthEndpoints, MapExternalAuthEndpoints, MapExternalAuthProvider, and MapExternalAccountEndpoints. The facade never maps these routes. {provider} is github or google. {scheme} is GitHub or Google.
| Method | Path | Auth | CSRF | ReAuth | Rate limit |
|---|---|---|---|---|---|
GET | /auth/external/login/{provider} | Login | |||
GET | /auth/external/login/{provider}/callback | ||||
GET | /auth/external/logins | Yes | |||
DELETE | /auth/external/logins/{loginProvider}/{providerKey} | Yes | Yes | Yes | |
GET | /auth/external/link/{scheme} | Yes | Login | ||
GET | /auth/external/link/{scheme}/callback | Yes |
The OAuth handlers also own /signin-github and /signin-google. Register those callback paths with each provider.
Details: External OAuth packages.