Reference
Responses and errors
Success and error response shapes for every AuthEndpoints module.
Most errors are problem details (application/problem+json). Validation errors are ValidationProblem responses: problem details with an errors object keyed by code. A few routes return other shapes. Each table below names the exact shape.
Shared responses
| Status | Body | Cause |
|---|---|---|
400 | Plain text Invalid or missing CSRF token. | The antiforgery filter rejected the request. |
401 or 403 | Empty | The route requires ReAuth and the request has no valid proof. |
429 | Empty | A rate-limit policy rejected the request. |
Identity management
| Route | Status | Shape |
|---|---|---|
POST /register | 200 | Empty. Also returned for a duplicate email. |
400 | ValidationProblem with Identity error codes, such as InvalidEmail or PasswordTooShort | |
GET /confirmEmail | 200 | Text Thank you for confirming your email. |
401 | Empty | |
302 | Only when ConfirmEmailRedirectUri is set. Query status=confirmed or status=failed, and flow=confirm or flow=change-email. | |
POST /resendConfirmationEmail | 200 | Empty |
POST /forgotPassword | 200 | Empty, always |
POST /resetPassword | 200 | Empty |
400 | ValidationProblem InvalidToken (bad code, unknown email, or unconfirmed email), or password-rule codes | |
GET /manage/2fa | 200 | { "isTwoFactorEnabled" } |
POST /manage/2fa | 200 | { "sharedKey", "recoveryCodesLeft", "recoveryCodes", "isTwoFactorEnabled", "isMachineRemembered" }. sharedKey is empty unless the key was just created, it was reset, or the request turned 2FA on. |
400 | ValidationProblem CannotResetSharedKeyAndEnable, RequiresTwoFactor, or InvalidTwoFactorCode | |
GET /manage/info, POST /manage/info | 200 | { "email", "isEmailConfirmed" } |
POST /manage/info | 400 | ValidationProblem OldPasswordRequired, InvalidEmail, PasswordMismatch, or password-rule codes |
ReAuth
| Route | Status | Shape |
|---|---|---|
GET /manage/authMethods | 200 | { "password", "authenticator", "recoveryCodes", "passkeys", "passkeyCount" } |
POST /confirmIdentity/passkeyOptions | 200 | WebAuthn request options JSON |
POST /confirmIdentity | 200 | { "reauthToken" } and the AuthEndpoints.ReAuth cookie |
400 | Plain JSON string Provide exactly one of Password, TwoFactorCode, TwoFactorRecoveryCode, or CredentialJson. | |
401 | Empty. The proof was wrong, or the passkey belongs to another user. |
Cookie and Identity bearer sign-in
| Route | Status | Shape |
|---|---|---|
POST /login | 200 | Empty with a cookie. Identity bearer without query flags returns { "tokenType", "accessToken", "expiresIn", "refreshToken" }. |
401 | Problem details, title RequiresTwoFactor, detail Two-factor authentication is required. | |
401 | Problem details, title Unauthorized, detail Invalid credentials. | |
POST /refresh (Identity bearer) | 200 | { "tokenType", "accessToken", "expiresIn", "refreshToken" } |
401 | Empty. The refresh token expired or the security stamp changed. | |
POST /logout | 200 | Empty |
GET /csrfToken | 200 | { "csrfToken" } |
JWT
| Route | Status | Shape |
|---|---|---|
POST /create | 200 | { "accessToken", "tokenType": "Bearer" } and the AuthEndpoints.Jwt.RefreshToken cookie |
400 | { "error": "invalid_request", "error_description" }. Not problem details. | |
401 | Problem details, detail Invalid credentials. | |
401 | Problem details, detail Two-factor authentication is required., extension requiresTwoFactor: true | |
401 | Problem details, detail Invalid two factor code., or the Identity error description for a bad recovery code | |
POST /refresh | 200 | { "accessToken" } with a rotated refresh cookie |
400 | { "errors": ["..."] }. Messages: Missing refresh token cookie., Invalid refresh token. Token may be expired or revoked by the server., Associated user no longer exists. | |
GET /verify | 204 | Empty |
POST /logout | 200 | Empty |
Passkeys
| Route | Status | Shape |
|---|---|---|
POST /passkeys/creationOptions, /requestOptions, /register/options | 200 | WebAuthn options JSON |
POST /passkeys/register/options | 400 | ValidationProblem Email |
POST /passkeys/register | 200 | { "credentialId" } when sign-in is not allowed. When it is allowed, the completer's response. |
400 | Problem details, detail Unable to complete registration. or The browser did not provide a passkey. | |
400 | ValidationProblem Email or InvalidPasskeyState | |
POST /passkeys/login | 200 | Empty with a cookie (useCookies or useSessionCookies), AccessTokenResponse (no flag), or the JWT shape (JWT completer) |
400 | Problem details, title Invalid Credential | |
400 | ValidationProblem InvalidPasskeyState | |
401 | Problem details, title Unauthorized, detail Invalid credentials. | |
POST /passkeys/ | 200 | { "credentialId", "displayName", "createdAt" } |
400 | ValidationProblem Name, UserMismatch, or InvalidPasskeyState. Problem details for a failed attestation or store error. | |
GET /passkeys/ | 200 | { "passkeys": [{ "credentialId", "displayName", "createdAt" }] } |
PATCH /passkeys/, DELETE /passkeys/{credentialIdUrl} | 200 | Empty |
400 | ValidationProblem InvalidCredentialId | |
404 | Empty |
External OAuth errors
The login and link callbacks redirect to ErrorPath?error=<code>&error_description=<text>. A request whose Accept header prefers application/json over text/html gets problem details instead, with title set to the code.
| Code | Status | Cause |
|---|---|---|
provider_mismatch | 400 | The provider login does not match the callback route. |
email_missing | 400 | The provider returned no email. |
email_unverified | 400 | The provider email is not verified, and the flow requires it. |
auto_link_disabled | 400 | A local account has this email, and AutoLinkByEmail is false. |
email_unconfirmed | 400 | Auto-link was refused because the local email is not confirmed. |
user_create_failed | 400 | Identity could not create the user. |
login_link_failed | 400 | Identity could not add the login. |
external_login_info_missing | 400 | No external login information was found for the callback. |
user_locked_out | 401 | The user is locked out. |
user_not_allowed | 401 | CanSignInAsync failed, for example because the email is not confirmed. |
A provider error (error in the callback query) is passed through with status 400.
| Route | Status | Shape |
|---|---|---|
GET /logins | 200 | [{ "loginProvider", "providerKey", "providerDisplayName" }] |
DELETE /logins/{loginProvider}/{providerKey} | 204 | Empty |
400 | Problem details, title last_signin_method | |
401 | Empty. No ReAuth proof. | |
404 | Empty |