Changelog
Reference

Endpoint reference

Every route that AuthEndpoints maps, with its auth, CSRF, ReAuth, and rate-limit requirements.

Paths use the facade defaults: IdentityPath is /identity, PasskeyPath is /account, and Jwt.Path is /auth. External OAuth routes have no default prefix. The table uses /auth/external, the prefix from the examples.

Column meanings:

Identity management

Mapped by MapIdentityManagementApi. The facade always maps it under IdentityPath. Management routes accept the application cookie, Identity bearer tokens, and JWT bearer tokens, when those schemes are registered.

MethodPathAuthCSRFReAuthRate limit
POST/identity/registerAccountAbuse
GET/identity/confirmEmail
POST/identity/resendConfirmationEmailYesYesAccountAbuse
POST/identity/forgotPasswordAccountAbuse
POST/identity/resetPasswordAccountAbuse
POST/identity/confirmIdentityYesYesConfirmIdentity
POST/identity/confirmIdentity/passkeyOptionsYesYesConfirmIdentity
GET/identity/manage/authMethodsYes
GET/identity/manage/2faYes
POST/identity/manage/2faYesYesYes
GET/identity/manage/infoYes
POST/identity/manage/infoYesYesYes

Details: Identity management module.

Mapped by MapCookieAuthEndpoints. The cookie facade maps it under IdentityPath.

MethodPathAuthCSRFReAuthRate limit
POST/identity/loginLogin
POST/identity/logoutYesYes
GET/identity/csrfToken

Details: Cookie sign-in module.

Identity bearer sign-in

Mapped by MapBearerAuthEndpoints. The bearer facade maps it under IdentityPath instead of cookie sign-in.

MethodPathAuthCSRFReAuthRate limit
POST/identity/loginLogin
POST/identity/refresh
POST/identity/logoutYes

Details: Identity bearer sign-in module.

Passkeys

Mapped by MapPasskeyEndpoints under {prefix}/passkeys. The facade maps it under PasskeyPath unless Passkeys.Enabled is false.

MethodPathAuthCSRFReAuthRate limit
POST/account/passkeys/creationOptionsYesYesYesPasskey.ObtainOptions
POST/account/passkeys/requestOptionsYesPasskey.ObtainOptions
POST/account/passkeys/register/optionsYesPasskey.ObtainOptions
POST/account/passkeys/registerYesPasskey.Register
POST/account/passkeys/loginYesLogin
POST/account/passkeys/YesYesYesPasskey.Register
GET/account/passkeys/Yes
PATCH/account/passkeys/YesYesYes
DELETE/account/passkeys/{credentialIdUrl}YesYesYes

Details: Passkeys module.

JWT

Mapped by MapJwtAuthEndpoints. The facade maps it under Jwt.Path when Jwt.Enabled is true.

MethodPathAuthCSRFReAuthRate limit
POST/auth/createLogin
POST/auth/refreshRefresh cookieYesLogin
GET/auth/verifyJWT bearer
POST/auth/logoutYes
GET/auth/csrfToken

Details: JWT module.

External OAuth

Mapped by MapGitHubAuthEndpoints, MapGoogleAuthEndpoints, MapExternalAuthEndpoints, MapExternalAuthProvider, and MapExternalAccountEndpoints. The facade never maps these routes. {provider} is github or google. {scheme} is GitHub or Google.

MethodPathAuthCSRFReAuthRate limit
GET/auth/external/login/{provider}Login
GET/auth/external/login/{provider}/callback
GET/auth/external/loginsYes
DELETE/auth/external/logins/{loginProvider}/{providerKey}YesYesYes
GET/auth/external/link/{scheme}YesLogin
GET/auth/external/link/{scheme}/callbackYes

The OAuth handlers also own /signin-github and /signin-google. Register those callback paths with each provider.

Details: External OAuth packages.