ReAuth
ReAuth (step-up) confirms the user's identity before sensitive mutations. It is included when you map Identity management (with antiforgery in the management map).
Schemes and header
| Piece | Value |
|---|---|
| Cookie scheme | AuthEndpoints.ReAuth (default 5 minutes, ReAuth.Lifetime) |
| Bearer scheme | AuthEndpoints.ReAuth.Bearer |
| Header | X-AuthEndpoints-Reauth with reauthToken |
| Policy | ReAuthPolicy (claim Reauth=true) |
Routes
Mapped with management (facade under /identity):
| Method | Path | Notes |
|---|---|---|
GET | /manage/authMethods | Available step-up methods |
POST | /confirmIdentity | Exactly one proof; CSRF when mapped via management |
POST | /confirmIdentity/passkeyOptions | WebAuthn options for passkey step-up |
ConfirmIdentity proof
Provide exactly one of:
passwordtwoFactorCodetwoFactorRecoveryCodecredentialJson(passkey assertion)
On success: ReAuth cookie for browser clients; reauthToken for API clients using the header. Cookie and token share the same lifetime.
Lifetime
Default is 5 minutes, non-persistent, no sliding expiration. Set AuthEndpointsOptions.ReAuth.Lifetime (a TimeSpan) on the facade, or IOptions<AuthEndpointsReAuthOptions> on a composable host. One value drives confirm ExpiresUtc, cookie ExpireTimeSpan, and reauthToken expiry.
Valid range: 1 minute through 60 minutes. Startup rejects zero, negative, over 60 minutes, and InfiniteTimeSpan.
builder.Services.AddAuthEndpoints<AppUser, AppDbContext>(o =>
{
o.ReAuth.Lifetime = TimeSpan.FromMinutes(2);
});
Protecting host endpoints
builder.Services.AddCookieAuthEndpoints(); // or AddBearerAuthEndpoints — registers ReAuth schemes
app.MapPost("/billing/update", handler)
.RequireAuthorization()
.RequireReauth();
Typical client flow
GET /identity/manage/authMethods- Collect proof (password, 2FA, or passkey via
/confirmIdentity/passkeyOptions) POST /identity/confirmIdentity- Retry the sensitive action with ReAuth cookie and/or
X-AuthEndpoints-Reauth
Where ReAuth is required
- Manage 2FA / info mutations
- Passkey add, rename, delete, and creation options
- Any host endpoint with
.RequireReauth()