Identity route reference
Generated reference: reviewed publication rules are not proof of runtime authorization or live availability. Use the guides for current behavior.
Paths are relative to AUTH_BASE_URL. These routes are individually reviewed for non-admin access. Credential recovery is not signup; new consumer provisioning is disabled.
The Identity guide describes request payloads, token grants, WebAuthn, and eligibility. This catalog lists routes, not generated HTTP body schemas.
Reviewed action routes
Section titled “Reviewed action routes”| Method | Path | Reviewed authentication | Documentation |
|---|---|---|---|
POST |
/account/reset-totp |
Existing account: username, password, and current TOTP or recovery code; security-profile gates apply. | Guide available — Usage guide |
POST |
/account/verify-totp |
Existing account with unverified authenticator: username and valid TOTP; security-profile/setup gates apply. | Guide available — Usage guide |
POST |
/client/pubkey |
Bearer token for the existing secret-authenticated machine client (token_kind=machine, exact secret AMR), with scopes covering current application grants; application eligibility and security-profile checks apply. No admin role is required. | Deprecated — one-way upgrade — Usage guide |
POST |
/connect/challenge |
Known client ID; the subsequent token exchange requires signed credential proof. | Guide available — Usage guide |
POST |
/connect/token |
Grant-specific client or user credential proof and current account/application checks. | Guide available — Usage guide |
POST |
/passkey/authenticate-complete |
Single-use options/session and valid WebAuthn assertion for an existing approved account; security-profile gates apply. | Guide available — Usage guide |
POST |
/passkey/authenticate-options |
WebAuthn ceremony options; options alone are not authentication. | Guide available — Usage guide |
POST |
/passkey/list |
Existing account: username, password, and TOTP or recovery code; security-profile gates apply. | Guide available — Usage guide |
POST |
/passkey/register-complete |
Existing approved account, single-use registration options, and valid WebAuthn attestation; security-profile gates apply. | Guide available — Usage guide |
POST |
/passkey/register-options |
Existing approved account: username, password, and TOTP or recovery code; security-profile gates apply. | Guide available — Usage guide |
POST |
/passkey/revoke |
Existing account: username, password, and TOTP or recovery code; security-profile gates apply. | Guide available — Usage guide |
POST /account/reset-totp
Section titled “POST /account/reset-totp”Credential-proof authenticator rotation, not account creation. Reverification is required after reset; a password alone is insufficient.
Reviewed authentication: Existing account: username, password, and current TOTP or recovery code; security-profile gates apply.
Guide available — Usage guide.
POST /account/verify-totp
Section titled “POST /account/verify-totp”Can reverify an existing account after rotation. Already-verified accounts are rejected, and setup linked to an approved consumer registration is rejected. This is not a consumer signup or approval path.
Reviewed authentication: Existing account with unverified authenticator: username and valid TOTP; security-profile/setup gates apply.
Guide available — Usage guide.
POST /client/pubkey
Section titled “POST /client/pubkey”Deprecated self-service for supported existing or legacy-compatible machine applications, not new client provisioning. On success the client secret is cleared and client_credentials is replaced by signed nonce-challenge authentication. There is no self-service rollback or replacement of an already-registered key here; retain the matching private key before upgrading.
Reviewed authentication: Bearer token for the existing secret-authenticated machine client (token_kind=machine, exact secret AMR), with scopes covering current application grants; application eligibility and security-profile checks apply. No admin role is required.
Deprecated — one-way upgrade — Usage guide.
POST /connect/challenge
Section titled “POST /connect/challenge”Nonce challenge for an already provisioned public-key client; receiving a challenge does not authorize access.
Reviewed authentication: Known client ID; the subsequent token exchange requires signed credential proof.
Guide available — Usage guide.
POST /connect/token
Section titled “POST /connect/token”Token exchange for existing approved identities. See the guide for supported grants and refresh restrictions; declaration inventory is not a grant specification.
Reviewed authentication: Grant-specific client or user credential proof and current account/application checks.
Guide available — Usage guide.
POST /passkey/authenticate-complete
Section titled “POST /passkey/authenticate-complete”Completes passkey authentication. It does not promise passkey refresh tokens.
Reviewed authentication: Single-use options/session and valid WebAuthn assertion for an existing approved account; security-profile gates apply.
Guide available — Usage guide.
POST /passkey/authenticate-options
Section titled “POST /passkey/authenticate-options”Starts authentication with an existing passkey; see the guide for the supported security profile.
Reviewed authentication: WebAuthn ceremony options; options alone are not authentication.
Guide available — Usage guide.
POST /passkey/list
Section titled “POST /passkey/list”Lists the account’s passkey metadata after credential proof.
Reviewed authentication: Existing account: username, password, and TOTP or recovery code; security-profile gates apply.
Guide available — Usage guide.
POST /passkey/register-complete
Section titled “POST /passkey/register-complete”Completes the credential-addition ceremony.
Reviewed authentication: Existing approved account, single-use registration options, and valid WebAuthn attestation; security-profile gates apply.
Guide available — Usage guide.
POST /passkey/register-options
Section titled “POST /passkey/register-options”Starts adding a passkey to an existing approved account, not registering a new consumer account.
Reviewed authentication: Existing approved account: username, password, and TOTP or recovery code; security-profile gates apply.
Guide available — Usage guide.
POST /passkey/revoke
Section titled “POST /passkey/revoke”Revokes a passkey owned by the proven account.
Reviewed authentication: Existing account: username, password, and TOTP or recovery code; security-profile gates apply.
Guide available — Usage guide.
Framework-owned contracts
Section titled “Framework-owned contracts”These endpoints are provided by OpenIddict. Use your deployment’s discovery metadata to confirm authority and endpoint locations.
| Method | Path | Reviewed authentication | Ownership / contract | Documentation |
|---|---|---|---|---|
GET |
/.well-known/openid-configuration |
Public authority metadata. | OpenID Connect discovery; framework-owned default. | Guide available — Usage guide |
GET |
/.well-known/oauth-authorization-server |
Public authority metadata. | OAuth authorization-server metadata; framework-owned default. | Guide available — Usage guide |
GET |
/.well-known/jwks |
Public verification keys, never private key material. | JSON Web Key Set; framework-owned default. Use discovery’s jwks_uri. | Guide available — Usage guide |
POST |
/connect/revocation |
OAuth client authentication and revocation validation handled by OpenIddict. | Framework-owned registered revocation endpoint, not an MVC action. | Guide available — Usage guide |