Skip to content

Identity route reference

Generated reference: reviewed publication rules are not proof of runtime authorization or live availability. Use the guides for current behavior.

Paths are relative to AUTH_BASE_URL. These routes are individually reviewed for non-admin access. Credential recovery is not signup; new consumer provisioning is disabled.

The Identity guide describes request payloads, token grants, WebAuthn, and eligibility. This catalog lists routes, not generated HTTP body schemas.

Method Path Reviewed authentication Documentation
POST /account/reset-totp Existing account: username, password, and current TOTP or recovery code; security-profile gates apply. Guide available — Usage guide
POST /account/verify-totp Existing account with unverified authenticator: username and valid TOTP; security-profile/setup gates apply. Guide available — Usage guide
POST /client/pubkey Bearer token for the existing secret-authenticated machine client (token_kind=machine, exact secret AMR), with scopes covering current application grants; application eligibility and security-profile checks apply. No admin role is required. Deprecated — one-way upgrade — Usage guide
POST /connect/challenge Known client ID; the subsequent token exchange requires signed credential proof. Guide available — Usage guide
POST /connect/token Grant-specific client or user credential proof and current account/application checks. Guide available — Usage guide
POST /passkey/authenticate-complete Single-use options/session and valid WebAuthn assertion for an existing approved account; security-profile gates apply. Guide available — Usage guide
POST /passkey/authenticate-options WebAuthn ceremony options; options alone are not authentication. Guide available — Usage guide
POST /passkey/list Existing account: username, password, and TOTP or recovery code; security-profile gates apply. Guide available — Usage guide
POST /passkey/register-complete Existing approved account, single-use registration options, and valid WebAuthn attestation; security-profile gates apply. Guide available — Usage guide
POST /passkey/register-options Existing approved account: username, password, and TOTP or recovery code; security-profile gates apply. Guide available — Usage guide
POST /passkey/revoke Existing account: username, password, and TOTP or recovery code; security-profile gates apply. Guide available — Usage guide

Credential-proof authenticator rotation, not account creation. Reverification is required after reset; a password alone is insufficient.

Reviewed authentication: Existing account: username, password, and current TOTP or recovery code; security-profile gates apply.

Guide available — Usage guide.

Can reverify an existing account after rotation. Already-verified accounts are rejected, and setup linked to an approved consumer registration is rejected. This is not a consumer signup or approval path.

Reviewed authentication: Existing account with unverified authenticator: username and valid TOTP; security-profile/setup gates apply.

Guide available — Usage guide.

Deprecated self-service for supported existing or legacy-compatible machine applications, not new client provisioning. On success the client secret is cleared and client_credentials is replaced by signed nonce-challenge authentication. There is no self-service rollback or replacement of an already-registered key here; retain the matching private key before upgrading.

Reviewed authentication: Bearer token for the existing secret-authenticated machine client (token_kind=machine, exact secret AMR), with scopes covering current application grants; application eligibility and security-profile checks apply. No admin role is required.

Deprecated — one-way upgrade — Usage guide.

Nonce challenge for an already provisioned public-key client; receiving a challenge does not authorize access.

Reviewed authentication: Known client ID; the subsequent token exchange requires signed credential proof.

Guide available — Usage guide.

Token exchange for existing approved identities. See the guide for supported grants and refresh restrictions; declaration inventory is not a grant specification.

Reviewed authentication: Grant-specific client or user credential proof and current account/application checks.

Guide available — Usage guide.

Completes passkey authentication. It does not promise passkey refresh tokens.

Reviewed authentication: Single-use options/session and valid WebAuthn assertion for an existing approved account; security-profile gates apply.

Guide available — Usage guide.

Starts authentication with an existing passkey; see the guide for the supported security profile.

Reviewed authentication: WebAuthn ceremony options; options alone are not authentication.

Guide available — Usage guide.

Lists the account’s passkey metadata after credential proof.

Reviewed authentication: Existing account: username, password, and TOTP or recovery code; security-profile gates apply.

Guide available — Usage guide.

Completes the credential-addition ceremony.

Reviewed authentication: Existing approved account, single-use registration options, and valid WebAuthn attestation; security-profile gates apply.

Guide available — Usage guide.

Starts adding a passkey to an existing approved account, not registering a new consumer account.

Reviewed authentication: Existing approved account: username, password, and TOTP or recovery code; security-profile gates apply.

Guide available — Usage guide.

Revokes a passkey owned by the proven account.

Reviewed authentication: Existing account: username, password, and TOTP or recovery code; security-profile gates apply.

Guide available — Usage guide.

These endpoints are provided by OpenIddict. Use your deployment’s discovery metadata to confirm authority and endpoint locations.

Method Path Reviewed authentication Ownership / contract Documentation
GET /.well-known/openid-configuration Public authority metadata. OpenID Connect discovery; framework-owned default. Guide available — Usage guide
GET /.well-known/oauth-authorization-server Public authority metadata. OAuth authorization-server metadata; framework-owned default. Guide available — Usage guide
GET /.well-known/jwks Public verification keys, never private key material. JSON Web Key Set; framework-owned default. Use discovery’s jwks_uri. Guide available — Usage guide
POST /connect/revocation OAuth client authentication and revocation validation handled by OpenIddict. Framework-owned registered revocation endpoint, not an MVC action. Guide available — Usage guide