[{"data":1,"prerenderedAt":1430},["ShallowReactive",2],{"navigation_docs":3,"-gotrue-endpoints":172,"-gotrue-endpoints-surround":1425},[4,26,67,98,124,140,161],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":25},"Getting Started","i-lucide-rocket","\u002Fgetting-started","1.getting-started",[10,15,20],{"title":11,"path":12,"stem":13,"icon":14},"Introduction","\u002Fgetting-started\u002Fintroduction","1.getting-started\u002F1.introduction","i-lucide-house",{"title":16,"path":17,"stem":18,"icon":19},"Installation","\u002Fgetting-started\u002Finstallation","1.getting-started\u002F2.installation","i-lucide-download",{"title":21,"path":22,"stem":23,"icon":24},"Quick Start","\u002Fgetting-started\u002Fquick-start","1.getting-started\u002F3.quick-start","i-lucide-play",false,{"title":27,"icon":28,"path":29,"stem":30,"children":31,"page":25},"Core","i-lucide-box","\u002Fcore","2.core",[32,37,42,47,52,57,62],{"title":33,"path":34,"stem":35,"icon":36},"Routing","\u002Fcore\u002Frouting","2.core\u002F1.routing","i-lucide-route",{"title":38,"path":39,"stem":40,"icon":41},"Handlers","\u002Fcore\u002Fhandlers","2.core\u002F2.handlers","i-lucide-braces",{"title":43,"path":44,"stem":45,"icon":46},"Request Binding","\u002Fcore\u002Frequest-binding","2.core\u002F3.request-binding","i-lucide-tags",{"title":48,"path":49,"stem":50,"icon":51},"Validation","\u002Fcore\u002Fvalidation","2.core\u002F4.validation","i-lucide-check-check",{"title":53,"path":54,"stem":55,"icon":56},"Context","\u002Fcore\u002Fcontext","2.core\u002F5.context","i-lucide-file-input",{"title":58,"path":59,"stem":60,"icon":61},"Errors","\u002Fcore\u002Ferrors","2.core\u002F6.errors","i-lucide-triangle-alert",{"title":63,"path":64,"stem":65,"icon":66},"Middleware","\u002Fcore\u002Fmiddleware","2.core\u002F7.middleware","i-lucide-layers",{"title":68,"icon":69,"path":70,"stem":71,"children":72,"page":25},"Auth","i-lucide-shield-check","\u002Fauth","3.auth",[73,78,83,88,93],{"title":74,"path":75,"stem":76,"icon":77},"Overview","\u002Fauth\u002Foverview","3.auth\u002F1.overview","i-lucide-shield",{"title":79,"path":80,"stem":81,"icon":82},"Auth Rules","\u002Fauth\u002Fauth-rules","3.auth\u002F2.auth-rules","i-lucide-lock",{"title":84,"path":85,"stem":86,"icon":87},"JWT Providers","\u002Fauth\u002Fjwt-providers","3.auth\u002F3.jwt-providers","i-lucide-key",{"title":89,"path":90,"stem":91,"icon":92},"Roles & Permissions","\u002Fauth\u002Froles-and-permissions","3.auth\u002F4.roles-and-permissions","i-lucide-users",{"title":94,"path":95,"stem":96,"icon":97},"Audit Logging","\u002Fauth\u002Faudit-logging","3.auth\u002F5.audit-logging","i-lucide-scroll-text",{"title":99,"icon":100,"path":101,"stem":102,"children":103,"page":25},"GoTrue","i-lucide-key-round","\u002Fgotrue","4.gotrue",[104,109,114,119],{"title":105,"path":106,"stem":107,"icon":108},"Proxy","\u002Fgotrue\u002Fproxy","4.gotrue\u002F1.proxy","i-lucide-shuffle",{"title":110,"path":111,"stem":112,"icon":113},"Endpoints","\u002Fgotrue\u002Fendpoints","4.gotrue\u002F2.endpoints","i-lucide-list",{"title":115,"path":116,"stem":117,"icon":118},"Client IP & Rate Limits","\u002Fgotrue\u002Fclient-ip-and-rate-limits","4.gotrue\u002F3.client-ip-and-rate-limits","i-lucide-network",{"title":120,"path":121,"stem":122,"icon":123},"Deployment","\u002Fgotrue\u002Fdeployment","4.gotrue\u002F4.deployment","i-lucide-server",{"title":125,"icon":126,"path":127,"stem":128,"children":129,"page":25},"API Docs","i-lucide-file-text","\u002Fapi-docs","5.api-docs",[130,135],{"title":131,"path":132,"stem":133,"icon":134},"OpenAPI","\u002Fapi-docs\u002Fopenapi","5.api-docs\u002F1.openapi","i-lucide-file-json",{"title":136,"path":137,"stem":138,"icon":139},"Scalar UI","\u002Fapi-docs\u002Fscalar","5.api-docs\u002F2.scalar","i-lucide-book-open-text",{"title":141,"icon":142,"path":143,"stem":144,"children":145,"page":25},"Guides","i-lucide-compass","\u002Fguides","6.guides",[146,151,156],{"title":147,"path":148,"stem":149,"icon":150},"Testing","\u002Fguides\u002Ftesting","6.guides\u002F1.testing","i-lucide-flask-conical",{"title":152,"path":153,"stem":154,"icon":155},"Performance","\u002Fguides\u002Fperformance","6.guides\u002F2.performance","i-lucide-gauge",{"title":157,"path":158,"stem":159,"icon":160},"Releasing","\u002Fguides\u002Freleasing","6.guides\u002F3.releasing","i-lucide-tag",{"title":162,"icon":163,"path":164,"stem":165,"children":166,"page":25},"Reference","i-lucide-code","\u002Freference","7.reference",[167],{"title":168,"path":169,"stem":170,"icon":171},"API Reference","\u002Freference\u002Fapi-reference","7.reference\u002F1.api-reference","i-lucide-list-tree",{"id":173,"title":110,"body":174,"description":1418,"extension":1419,"links":1420,"meta":1421,"navigation":1422,"path":111,"seo":1423,"stem":112,"__hash__":1424},"docs\u002F4.gotrue\u002F2.endpoints.md",{"type":175,"value":176,"toc":1406},"minimark",[177,188,193,196,434,439,549,600,604,611,685,786,817,821,824,911,915,918,971,987,990,1033,1040,1044,1047,1178,1190,1194,1197,1337,1348,1357,1361,1383,1387,1402],[178,179,180,184,185,187],"p",{},[181,182,183],"code",{},"gt.Mount(app, \"\u002Fauth\")"," registers three groups of routes. All paths below assume the ",[181,186,70],{}," prefix.",[189,190,192],"h2",{"id":191},"typed-json-endpoints","Typed JSON endpoints",[178,194,195],{},"These bind and validate a request struct, forward it, and pass GoTrue's body back unchanged. The response type is used to document the endpoint.",[197,198,199,218],"table",{},[200,201,202],"thead",{},[203,204,205,209,212,215],"tr",{},[206,207,208],"th",{},"Method and path",[206,210,211],{},"Request type",[206,213,214],{},"Response type",[206,216,217],{},"Rate limited",[219,220,221,240,256,276,294,313,331,349,367,382,398,416],"tbody",{},[203,222,223,229,232,237],{},[224,225,226],"td",{},[181,227,228],{},"GET \u002Fhealth",[224,230,231],{},"none",[224,233,234],{},[181,235,236],{},"HealthResponse",[224,238,239],{},"no",[203,241,242,247,249,254],{},[224,243,244],{},[181,245,246],{},"GET \u002Fsettings",[224,248,231],{},[224,250,251],{},[181,252,253],{},"SettingsResponse",[224,255,239],{},[203,257,258,263,268,273],{},[224,259,260],{},[181,261,262],{},"POST \u002Fsignup",[224,264,265],{},[181,266,267],{},"SignupRequest",[224,269,270],{},[181,271,272],{},"SessionResponse",[224,274,275],{},"yes",[203,277,278,283,288,292],{},[224,279,280],{},[181,281,282],{},"POST \u002Ftoken",[224,284,285],{},[181,286,287],{},"TokenRequest",[224,289,290],{},[181,291,272],{},[224,293,275],{},[203,295,296,301,306,311],{},[224,297,298],{},[181,299,300],{},"POST \u002Fotp",[224,302,303],{},[181,304,305],{},"OTPRequest",[224,307,308],{},[181,309,310],{},"MessageResponse",[224,312,275],{},[203,314,315,320,325,329],{},[224,316,317],{},[181,318,319],{},"POST \u002Fverify",[224,321,322],{},[181,323,324],{},"VerifyRequest",[224,326,327],{},[181,328,272],{},[224,330,239],{},[203,332,333,338,343,347],{},[224,334,335],{},[181,336,337],{},"POST \u002Frecover",[224,339,340],{},[181,341,342],{},"RecoverRequest",[224,344,345],{},[181,346,310],{},[224,348,275],{},[203,350,351,356,361,365],{},[224,352,353],{},[181,354,355],{},"POST \u002Fresend",[224,357,358],{},[181,359,360],{},"ResendRequest",[224,362,363],{},[181,364,310],{},[224,366,275],{},[203,368,369,374,376,380],{},[224,370,371],{},[181,372,373],{},"POST \u002Flogout",[224,375,231],{},[224,377,378],{},[181,379,310],{},[224,381,239],{},[203,383,384,389,391,396],{},[224,385,386],{},[181,387,388],{},"GET \u002Fuser",[224,390,231],{},[224,392,393],{},[181,394,395],{},"UserObject",[224,397,239],{},[203,399,400,405,410,414],{},[224,401,402],{},[181,403,404],{},"PUT \u002Fuser",[224,406,407],{},[181,408,409],{},"UpdateUserRequest",[224,411,412],{},[181,413,395],{},[224,415,239],{},[203,417,418,423,428,432],{},[224,419,420],{},[181,421,422],{},"POST \u002Freauthenticate",[224,424,425],{},[181,426,427],{},"ReauthenticateRequest",[224,429,430],{},[181,431,310],{},[224,433,239],{},[435,436,438],"h3",{"id":437},"sign-up","Sign up",[440,441,446],"pre",{"className":442,"code":443,"language":444,"meta":445,"style":445},"language-go shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","type SignupRequest struct {\n    Email    string         `json:\"email,omitempty\" validate:\"omitempty,email\"`\n    Phone    string         `json:\"phone,omitempty\"`\n    Password string         `json:\"password\" validate:\"required,min=6\"`\n    Data     map[string]any `json:\"data,omitempty\"`\n}\n","go","",[181,447,448,467,488,503,518,543],{"__ignoreMap":445},[449,450,453,457,461,464],"span",{"class":451,"line":452},"line",1,[449,454,456],{"class":455},"sMK4o","type",[449,458,460],{"class":459},"sBMFI"," SignupRequest",[449,462,463],{"class":455}," struct",[449,465,466],{"class":455}," {\n",[449,468,470,474,478,481,485],{"class":451,"line":469},2,[449,471,473],{"class":472},"sTEyZ","    Email    ",[449,475,477],{"class":476},"spNyl","string",[449,479,480],{"class":455},"         `",[449,482,484],{"class":483},"sfazB","json:\"email,omitempty\" validate:\"omitempty,email\"",[449,486,487],{"class":455},"`\n",[449,489,491,494,496,498,501],{"class":451,"line":490},3,[449,492,493],{"class":472},"    Phone    ",[449,495,477],{"class":476},[449,497,480],{"class":455},[449,499,500],{"class":483},"json:\"phone,omitempty\"",[449,502,487],{"class":455},[449,504,506,509,511,513,516],{"class":451,"line":505},4,[449,507,508],{"class":472},"    Password ",[449,510,477],{"class":476},[449,512,480],{"class":455},[449,514,515],{"class":483},"json:\"password\" validate:\"required,min=6\"",[449,517,487],{"class":455},[449,519,521,524,527,529,532,535,538,541],{"class":451,"line":520},5,[449,522,523],{"class":472},"    Data     ",[449,525,526],{"class":455},"map[",[449,528,477],{"class":476},[449,530,531],{"class":455},"]",[449,533,534],{"class":459},"any",[449,536,537],{"class":455}," `",[449,539,540],{"class":483},"json:\"data,omitempty\"",[449,542,487],{"class":455},[449,544,546],{"class":451,"line":545},6,[449,547,548],{"class":455},"}\n",[440,550,555],{"className":551,"code":552,"filename":553,"language":554,"meta":445,"style":445},"language-bash shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","curl -s localhost:8080\u002Fauth\u002Fsignup \\\n  -H 'Content-Type: application\u002Fjson' \\\n  -d '{\"email\":\"ada@example.com\",\"password\":\"password123\",\"data\":{\"name\":\"Ada\"}}'\n","Terminal","bash",[181,556,557,571,587],{"__ignoreMap":445},[449,558,559,562,565,568],{"class":451,"line":452},[449,560,561],{"class":459},"curl",[449,563,564],{"class":483}," -s",[449,566,567],{"class":483}," localhost:8080\u002Fauth\u002Fsignup",[449,569,570],{"class":472}," \\\n",[449,572,573,576,579,582,585],{"class":451,"line":469},[449,574,575],{"class":483},"  -H",[449,577,578],{"class":455}," '",[449,580,581],{"class":483},"Content-Type: application\u002Fjson",[449,583,584],{"class":455},"'",[449,586,570],{"class":472},[449,588,589,592,594,597],{"class":451,"line":490},[449,590,591],{"class":483},"  -d",[449,593,578],{"class":455},[449,595,596],{"class":483},"{\"email\":\"ada@example.com\",\"password\":\"password123\",\"data\":{\"name\":\"Ada\"}}",[449,598,599],{"class":455},"'\n",[435,601,603],{"id":602},"get-a-token","Get a token",[178,605,606,607,610],{},"The grant is selected with the ",[181,608,609],{},"grant_type"," query parameter, which is forwarded to GoTrue along with the rest of the query string.",[440,612,614],{"className":442,"code":613,"language":444,"meta":445,"style":445},"type TokenRequest struct {\n    Email        string `json:\"email,omitempty\" validate:\"omitempty,email\"`\n    Phone        string `json:\"phone,omitempty\"`\n    Password     string `json:\"password,omitempty\"`\n    RefreshToken string `json:\"refresh_token,omitempty\"`\n}\n",[181,615,616,627,640,653,667,681],{"__ignoreMap":445},[449,617,618,620,623,625],{"class":451,"line":452},[449,619,456],{"class":455},[449,621,622],{"class":459}," TokenRequest",[449,624,463],{"class":455},[449,626,466],{"class":455},[449,628,629,632,634,636,638],{"class":451,"line":469},[449,630,631],{"class":472},"    Email        ",[449,633,477],{"class":476},[449,635,537],{"class":455},[449,637,484],{"class":483},[449,639,487],{"class":455},[449,641,642,645,647,649,651],{"class":451,"line":490},[449,643,644],{"class":472},"    Phone        ",[449,646,477],{"class":476},[449,648,537],{"class":455},[449,650,500],{"class":483},[449,652,487],{"class":455},[449,654,655,658,660,662,665],{"class":451,"line":505},[449,656,657],{"class":472},"    Password     ",[449,659,477],{"class":476},[449,661,537],{"class":455},[449,663,664],{"class":483},"json:\"password,omitempty\"",[449,666,487],{"class":455},[449,668,669,672,674,676,679],{"class":451,"line":520},[449,670,671],{"class":472},"    RefreshToken ",[449,673,477],{"class":476},[449,675,537],{"class":455},[449,677,678],{"class":483},"json:\"refresh_token,omitempty\"",[449,680,487],{"class":455},[449,682,683],{"class":451,"line":545},[449,684,548],{"class":455},[440,686,688],{"className":551,"code":687,"filename":553,"language":554,"meta":445,"style":445},"# password grant\ncurl -s 'localhost:8080\u002Fauth\u002Ftoken?grant_type=password' \\\n  -H 'Content-Type: application\u002Fjson' \\\n  -d '{\"email\":\"ada@example.com\",\"password\":\"password123\"}'\n\n# refresh grant\ncurl -s 'localhost:8080\u002Fauth\u002Ftoken?grant_type=refresh_token' \\\n  -H 'Content-Type: application\u002Fjson' \\\n  -d '{\"refresh_token\":\"...\"}'\n",[181,689,690,696,711,723,734,740,745,761,774],{"__ignoreMap":445},[449,691,692],{"class":451,"line":452},[449,693,695],{"class":694},"sHwdD","# password grant\n",[449,697,698,700,702,704,707,709],{"class":451,"line":469},[449,699,561],{"class":459},[449,701,564],{"class":483},[449,703,578],{"class":455},[449,705,706],{"class":483},"localhost:8080\u002Fauth\u002Ftoken?grant_type=password",[449,708,584],{"class":455},[449,710,570],{"class":472},[449,712,713,715,717,719,721],{"class":451,"line":490},[449,714,575],{"class":483},[449,716,578],{"class":455},[449,718,581],{"class":483},[449,720,584],{"class":455},[449,722,570],{"class":472},[449,724,725,727,729,732],{"class":451,"line":505},[449,726,591],{"class":483},[449,728,578],{"class":455},[449,730,731],{"class":483},"{\"email\":\"ada@example.com\",\"password\":\"password123\"}",[449,733,599],{"class":455},[449,735,736],{"class":451,"line":520},[449,737,739],{"emptyLinePlaceholder":738},true,"\n",[449,741,742],{"class":451,"line":545},[449,743,744],{"class":694},"# refresh grant\n",[449,746,748,750,752,754,757,759],{"class":451,"line":747},7,[449,749,561],{"class":459},[449,751,564],{"class":483},[449,753,578],{"class":455},[449,755,756],{"class":483},"localhost:8080\u002Fauth\u002Ftoken?grant_type=refresh_token",[449,758,584],{"class":455},[449,760,570],{"class":472},[449,762,764,766,768,770,772],{"class":451,"line":763},8,[449,765,575],{"class":483},[449,767,578],{"class":455},[449,769,581],{"class":483},[449,771,584],{"class":455},[449,773,570],{"class":472},[449,775,777,779,781,784],{"class":451,"line":776},9,[449,778,591],{"class":483},[449,780,578],{"class":455},[449,782,783],{"class":483},"{\"refresh_token\":\"...\"}",[449,785,599],{"class":455},[178,787,788,789,791,792,795,796,795,799,795,802,795,805,808,809,812,813,816],{},"A successful response is a ",[181,790,272],{}," with ",[181,793,794],{},"access_token",", ",[181,797,798],{},"token_type",[181,800,801],{},"expires_in",[181,803,804],{},"expires_at",[181,806,807],{},"refresh_token",", the ",[181,810,811],{},"user"," object, and ",[181,814,815],{},"weak_password",".",[435,818,820],{"id":819},"read-and-update-the-current-user","Read and update the current user",[178,822,823],{},"Both require the caller's bearer token, which the proxy forwards as-is.",[440,825,827],{"className":551,"code":826,"filename":553,"language":554,"meta":445,"style":445},"curl -s localhost:8080\u002Fauth\u002Fuser -H \"Authorization: Bearer $TOKEN\"\n\ncurl -s -X PUT localhost:8080\u002Fauth\u002Fuser \\\n  -H \"Authorization: Bearer $TOKEN\" \\\n  -H 'Content-Type: application\u002Fjson' \\\n  -d '{\"data\":{\"name\":\"Ada Lovelace\"}}'\n",[181,828,829,853,857,873,888,900],{"__ignoreMap":445},[449,830,831,833,835,838,841,844,847,850],{"class":451,"line":452},[449,832,561],{"class":459},[449,834,564],{"class":483},[449,836,837],{"class":483}," localhost:8080\u002Fauth\u002Fuser",[449,839,840],{"class":483}," -H",[449,842,843],{"class":455}," \"",[449,845,846],{"class":483},"Authorization: Bearer ",[449,848,849],{"class":472},"$TOKEN",[449,851,852],{"class":455},"\"\n",[449,854,855],{"class":451,"line":469},[449,856,739],{"emptyLinePlaceholder":738},[449,858,859,861,863,866,869,871],{"class":451,"line":490},[449,860,561],{"class":459},[449,862,564],{"class":483},[449,864,865],{"class":483}," -X",[449,867,868],{"class":483}," PUT",[449,870,837],{"class":483},[449,872,570],{"class":472},[449,874,875,877,879,881,883,886],{"class":451,"line":505},[449,876,575],{"class":483},[449,878,843],{"class":455},[449,880,846],{"class":483},[449,882,849],{"class":472},[449,884,885],{"class":455},"\"",[449,887,570],{"class":472},[449,889,890,892,894,896,898],{"class":451,"line":520},[449,891,575],{"class":483},[449,893,578],{"class":455},[449,895,581],{"class":483},[449,897,584],{"class":455},[449,899,570],{"class":472},[449,901,902,904,906,909],{"class":451,"line":545},[449,903,591],{"class":483},[449,905,578],{"class":455},[449,907,908],{"class":483},"{\"data\":{\"name\":\"Ada Lovelace\"}}",[449,910,599],{"class":455},[189,912,914],{"id":913},"redirect-endpoints","Redirect endpoints",[178,916,917],{},"Some GoTrue endpoints answer with redirects or HTML rather than JSON, so they are proxied byte for byte through a reverse proxy instead of a typed handler.",[197,919,920,929],{},[200,921,922],{},[203,923,924,926],{},[206,925,208],{},[206,927,928],{},"Purpose",[219,930,931,941,951,961],{},[203,932,933,938],{},[224,934,935],{},[181,936,937],{},"GET \u002Fauthorize",[224,939,940],{},"Start an external OAuth flow",[203,942,943,948],{},[224,944,945],{},[181,946,947],{},"GET \u002Fcallback",[224,949,950],{},"External provider callback",[203,952,953,958],{},[224,954,955],{},[181,956,957],{},"GET \u002Fverify",[224,959,960],{},"Email link verification",[203,962,963,968],{},[224,964,965],{},[181,966,967],{},"GET \u002Foauth\u002Fauthorize",[224,969,970],{},"OAuth2 server authorization",[178,972,973,975,976,978,979,982,983,986],{},[181,974,957],{}," and ",[181,977,319],{}," are separate routes: the ",[181,980,981],{},"GET"," form is the link a user clicks in an email and redirects, while the ",[181,984,985],{},"POST"," form takes a JSON body and returns a session.",[178,988,989],{},"Point browsers at these directly:",[440,991,995],{"className":992,"code":993,"language":994,"meta":445,"style":445},"language-html shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","\u003Ca href=\"\u002Fauth\u002Fauthorize?provider=github\">Sign in with GitHub\u003C\u002Fa>\n","html",[181,996,997],{"__ignoreMap":445},[449,998,999,1002,1006,1009,1012,1014,1017,1019,1022,1025,1028,1030],{"class":451,"line":452},[449,1000,1001],{"class":455},"\u003C",[449,1003,1005],{"class":1004},"swJcz","a",[449,1007,1008],{"class":476}," href",[449,1010,1011],{"class":455},"=",[449,1013,885],{"class":455},[449,1015,1016],{"class":483},"\u002Fauth\u002Fauthorize?provider=github",[449,1018,885],{"class":455},[449,1020,1021],{"class":455},">",[449,1023,1024],{"class":472},"Sign in with GitHub",[449,1026,1027],{"class":455},"\u003C\u002F",[449,1029,1005],{"class":1004},[449,1031,1032],{"class":455},">\n",[178,1034,1035,1036,1039],{},"If the proxy cannot reach GoTrue, these routes return ",[181,1037,1038],{},"502"," with the standard JSON error body.",[189,1041,1043],{"id":1042},"oauth2-server","OAuth2 server",[178,1045,1046],{},"Mounted unconditionally. GoTrue decides whether the feature is on, and returns its own error when it is not.",[197,1048,1049,1061],{},[200,1050,1051],{},[203,1052,1053,1055,1057,1059],{},[206,1054,208],{},[206,1056,211],{},[206,1058,214],{},[206,1060,217],{},[219,1062,1063,1079,1094,1110,1124,1143,1162],{},[203,1064,1065,1070,1072,1077],{},[224,1066,1067],{},[181,1068,1069],{},"GET \u002F.well-known\u002Foauth-authorization-server",[224,1071,231],{},[224,1073,1074],{},[181,1075,1076],{},"OAuthServerMetadata",[224,1078,239],{},[203,1080,1081,1086,1088,1092],{},[224,1082,1083],{},[181,1084,1085],{},"GET \u002F.well-known\u002Fopenid-configuration",[224,1087,231],{},[224,1089,1090],{},[181,1091,1076],{},[224,1093,239],{},[203,1095,1096,1101,1103,1108],{},[224,1097,1098],{},[181,1099,1100],{},"GET \u002F.well-known\u002Fjwks.json",[224,1102,231],{},[224,1104,1105],{},[181,1106,1107],{},"JWKSResponse",[224,1109,239],{},[203,1111,1112,1116,1119,1122],{},[224,1113,1114],{},[181,1115,967],{},[224,1117,1118],{},"redirect passthrough",[224,1120,1121],{},"—",[224,1123,239],{},[203,1125,1126,1131,1136,1141],{},[224,1127,1128],{},[181,1129,1130],{},"POST \u002Foauth\u002Ftoken",[224,1132,1133],{},[181,1134,1135],{},"OAuthTokenRequest",[224,1137,1138],{},[181,1139,1140],{},"OAuthTokenResponse",[224,1142,275],{},[203,1144,1145,1150,1155,1160],{},[224,1146,1147],{},[181,1148,1149],{},"POST \u002Foauth\u002Fclients\u002Fregister",[224,1151,1152],{},[181,1153,1154],{},"ClientRegistrationRequest",[224,1156,1157],{},[181,1158,1159],{},"ClientRegistrationResponse",[224,1161,275],{},[203,1163,1164,1169,1171,1176],{},[224,1165,1166],{},[181,1167,1168],{},"GET \u002Foauth\u002Fuserinfo",[224,1170,231],{},[224,1172,1173],{},[181,1174,1175],{},"OAuthUserInfo",[224,1177,239],{},[1179,1180,1181,1182,1185,1186,1189],"caution",{},"With ",[181,1183,1184],{},"GOTRUE_OAUTH_SERVER_ALLOW_DYNAMIC_REGISTRATION=true",", anyone who can reach ",[181,1187,1188],{},"\u002Fauth\u002Foauth\u002Fclients\u002Fregister"," can create an OAuth client. ezz rate limits the route, but if you do not need public registration, turn the setting off in GoTrue.",[189,1191,1193],{"id":1192},"passkeys-and-webauthn","Passkeys and WebAuthn",[178,1195,1196],{},"Also mounted unconditionally.",[197,1198,1199,1211],{},[200,1200,1201],{},[203,1202,1203,1205,1207,1209],{},[206,1204,208],{},[206,1206,211],{},[206,1208,214],{},[206,1210,217],{},[219,1212,1213,1229,1248,1267,1286,1304,1322],{},[203,1214,1215,1220,1222,1227],{},[224,1216,1217],{},[181,1218,1219],{},"GET \u002Fpasskeys",[224,1221,231],{},[224,1223,1224],{},[181,1225,1226],{},"PasskeyListResponse",[224,1228,239],{},[203,1230,1231,1236,1241,1246],{},[224,1232,1233],{},[181,1234,1235],{},"POST \u002Fpasskeys\u002Fregistration\u002Foptions",[224,1237,1238],{},[181,1239,1240],{},"PasskeyRegistrationOptionsRequest",[224,1242,1243],{},[181,1244,1245],{},"PasskeyRegistrationOptionsResponse",[224,1247,239],{},[203,1249,1250,1255,1260,1265],{},[224,1251,1252],{},[181,1253,1254],{},"POST \u002Fpasskeys\u002Fregistration\u002Fverify",[224,1256,1257],{},[181,1258,1259],{},"PasskeyRegistrationVerifyRequest",[224,1261,1262],{},[181,1263,1264],{},"PasskeyRegistrationVerifyResponse",[224,1266,239],{},[203,1268,1269,1274,1279,1284],{},[224,1270,1271],{},[181,1272,1273],{},"POST \u002Fpasskeys\u002Fauthentication\u002Foptions",[224,1275,1276],{},[181,1277,1278],{},"PasskeyAuthenticationOptionsRequest",[224,1280,1281],{},[181,1282,1283],{},"PasskeyAuthenticationOptionsResponse",[224,1285,275],{},[203,1287,1288,1293,1298,1302],{},[224,1289,1290],{},[181,1291,1292],{},"POST \u002Fpasskeys\u002Fauthentication\u002Fverify",[224,1294,1295],{},[181,1296,1297],{},"PasskeyAuthenticationVerifyRequest",[224,1299,1300],{},[181,1301,272],{},[224,1303,275],{},[203,1305,1306,1311,1316,1320],{},[224,1307,1308],{},[181,1309,1310],{},"PATCH \u002Fpasskeys\u002F{id}",[224,1312,1313],{},[181,1314,1315],{},"PasskeyUpdateRequest",[224,1317,1318],{},[181,1319,1264],{},[224,1321,239],{},[203,1323,1324,1329,1331,1335],{},[224,1325,1326],{},[181,1327,1328],{},"DELETE \u002Fpasskeys\u002F{id}",[224,1330,231],{},[224,1332,1333],{},[181,1334,310],{},[224,1336,239],{},[178,1338,1339,1340,1343,1344,1347],{},"The two ",[181,1341,1342],{},"{id}"," routes forward the inbound path rather than a fixed one, so the identifier is validated first. It must be a single non-empty segment with no slashes and no dot-dot components; anything else is rejected with ",[181,1345,1346],{},"400"," before the request leaves your process. Both share one rate-limit bucket per client, keyed by the route template rather than the concrete ID.",[178,1349,1350,1351,1354,1355,816],{},"Browsers must perform WebAuthn against the public origin, which means ",[181,1352,1353],{},"GOTRUE_WEBAUTHN_RP_ORIGINS"," has to include your ezz origin. See ",[1005,1356,120],{"href":121},[189,1358,1360],{"id":1359},"route-metadata","Route metadata",[178,1362,1363,1364,1366,1367,1370,1371,1374,1375,1378,1379,1382],{},"Mounted routes carry tags so the docs group them sensibly: ",[181,1365,68],{}," for the core endpoints, ",[181,1368,1369],{},"OAuth"," for the OAuth2 server, and ",[181,1372,1373],{},"Passkey"," for WebAuthn. They are all registered ",[181,1376,1377],{},"Public()"," at the ezz layer, since GoTrue performs its own bearer-token checks. They appear in ",[181,1380,1381],{},"\u002Fopenapi.json"," and the Scalar UI next to your own routes.",[189,1384,1386],{"id":1385},"next-steps","Next steps",[1388,1389,1390,1397],"ul",{},[1391,1392,1393,1396],"li",{},[1005,1394,1395],{"href":116},"Client IP and rate limits"," for which requests get throttled and how the key is derived.",[1391,1398,1399,1401],{},[1005,1400,120],{"href":121}," for the GoTrue configuration this expects.",[1403,1404,1405],"style",{},"html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html pre.shiki code .sTEyZ, html code.shiki .sTEyZ{--shiki-light:#90A4AE;--shiki-default:#EEFFFF;--shiki-dark:#BABED8}html pre.shiki code .spNyl, html code.shiki .spNyl{--shiki-light:#9C3EDA;--shiki-default:#C792EA;--shiki-dark:#C792EA}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sHwdD, html code.shiki .sHwdD{--shiki-light:#90A4AE;--shiki-light-font-style:italic;--shiki-default:#546E7A;--shiki-default-font-style:italic;--shiki-dark:#676E95;--shiki-dark-font-style:italic}html pre.shiki code .swJcz, html code.shiki .swJcz{--shiki-light:#E53935;--shiki-default:#F07178;--shiki-dark:#F07178}",{"title":445,"searchDepth":469,"depth":469,"links":1407},[1408,1413,1414,1415,1416,1417],{"id":191,"depth":469,"text":192,"children":1409},[1410,1411,1412],{"id":437,"depth":490,"text":438},{"id":602,"depth":490,"text":603},{"id":819,"depth":490,"text":820},{"id":913,"depth":469,"text":914},{"id":1042,"depth":469,"text":1043},{"id":1192,"depth":469,"text":1193},{"id":1359,"depth":469,"text":1360},{"id":1385,"depth":469,"text":1386},"Every route gt.Mount registers, with its request and response types.","md",null,{},{"icon":113},{"title":110,"description":1418},"zPrHNQF261wd2WOijF4AzXT3uM9m2OFRhKmPtguYc8E",[1426,1428],{"title":105,"path":106,"stem":107,"description":1427,"icon":108,"children":-1},"Keep GoTrue on a private network and expose typed, documented \u002Fauth\u002F* routes through your own service.",{"title":115,"path":116,"stem":117,"description":1429,"icon":118,"children":-1},"Recover the real client IP behind a load balancer and throttle sensitive auth endpoints with Redis.",1784970048275]