Standalone demo for AuthEndpoints: an ASP.NET Core API plus a Nuxt UI playground and a cookie SPA app flow.
AuthEndpointsDemo/
Demo/ # ASP.NET Core API (.NET 10)
web/ # Nuxt 4 + Nuxt UI playground + /app shell
- .NET 10 SDK
- Node.js 20+ and pnpm
- Optional: GitHub / Google OAuth app credentials for external login
cd Demo
cp .env.example .env # if you do not already have .env
dotnet restore
dotnet run --launch-profile httpAPI listens on http://localhost:5041.
| Variable | Purpose |
|---|---|
FRONTEND_ORIGIN |
CORS origin for the Nuxt app (default http://localhost:3000) |
DB_CONNECTION_STRING |
SQLite connection string |
JWT_SYMMETRIC_KEY |
JWT signing key (32+ chars) |
GITHUB_CLIENT_ID / GITHUB_CLIENT_SECRET |
Optional GitHub OAuth |
GOOGLE_CLIENT_ID / GOOGLE_CLIENT_SECRET |
Optional Google OAuth |
Packages: AuthEndpoints 3.1.0, AuthEndpoints.External.OAuth 3.0.0-preview.3.
OpenAPI / Scalar: http://localhost:5041/scalar
Emails (confirmation, password reset) are written to the API console via ConsoleEmailSender.
RequireConfirmedAccount is true. After GET /auth/cookie/confirmEmail, the API redirects to /app/confirm-email?status=confirmed|failed&flow=confirm (or flow=change-email). The Demo host forwards that rooted path to the Nuxt origin so the browser lands on the SPA.
Passkeys are enabled (Passkeys.Enabled = true, Passkeys.ServerDomain = localhost). ReAuth step-up uses the library default lifetime of 5 minutes.
Cookie identity stays under /auth/cookie (not /account). CSRF header is RequestVerificationToken.
| Area | Prefix |
|---|---|
| Cookie + account management | /auth/cookie |
| JWT | /auth/jwt |
| Passkeys | /auth/passkey |
| External OAuth | /auth/external |
cd web
cp .env.example .env # NUXT_PUBLIC_API_BASE=http://localhost:5041
pnpm install
pnpm devUI listens on http://localhost:3000.
Cookie-only product path (JWT stays on the playground):
- Open http://localhost:3000/app/register (or Overview → Try the app flow)
- Register with password or passkey — a
200is not a signed-in session - Check email: copy the confirmation link from the API console
- Confirm:
- Click the console link (browser follows confirm →
/app/confirm-email?status=&flow=), or - On
/app/check-email, expand Local dev: paste confirmation link (same parse →GET /auth/cookie/confirmEmailpath as the playground Account panel)
- Click the console link (browser follows confirm →
- Sign in with password or passkey. Password sign-in opens a two-factor modal when the account requires it. Forgot / reset password is
/app/forgot-passwordand/app/reset-password(reset codes are in the API console). - Dummy home shows account info from
/auth/cookie/manage/info, with links to Security (/app/security) and Passkeys (/app/passkeys). Logout returns to/app/login
Sensitive security and passkey mutations try the action first, then prompt for identity (password, authenticator, recovery code, or passkey when GET /auth/cookie/manage/authMethods reports one). The ReAuth token is kept in memory only.
Playground paste-link path remains on Register / Confirm (/account). Playground Security / Passkeys panels remain raw API explorers; the product UI is under /app.
Use the header Cookie / JWT toggle, walk each nav panel, and watch the response inspector.
Suggested playground flow:
- Diagnostics → Create default user (already confirmed) or Register a new account
- For a new registration, confirm email using the link logged in the API console (Account → Paste link, or the app check-email paste)
- Cookie Auth or JWT Auth → sign in
- Account Info / Security / Passkeys / External as needed
- Cookie and JWT refresh flows need
credentials: includeand CSRF (RequestVerificationTokenfrom/auth/cookie/csrfTokenor/auth/jwt/csrfToken). - Sensitive manage / passkey mutations require ReAuth (
confirmIdentity, thenX-AuthEndpoints-Reauthor the ReAuth cookie). - Passkeys use
Passkeys.ServerDomain = localhost.