Identity.Base is a modular identity platform for .NET. OAuth2/OIDC, MFA, RBAC, multi-tenancy, and managed machine identities built on ASP.NET Core Identity and OpenIddict. No vendor lock-in.
Every capability is a separate NuGet or npm package. Compose your identity stack from independent modules.
Core OAuth2/OIDC provider with MFA support. ASP.NET Core Identity + OpenIddict.
RBAC primitives. Permission/role catalog with database-driven definitions.
Multi-tenant organizations with memberships, org-scoped roles, and invitations.
Admin API endpoints for user, role, organization, and permission management.
Managed machine identities with revocable credentials, RBAC roles, and short-lived client-credentials tokens.
JWT validation middleware for downstream APIs and microservices.
Identity.Base.Email.MailJet and Identity.Base.Email.SendGrid for transactional email.
Framework-agnostic PKCE, token lifecycle, cookie fallback, and typed Identity admin APIs.
React 19 hooks for authentication, user info, and token management.
Angular 16+ services for OIDC authentication and token lifecycle.
React and Angular add-ons for memberships, invitations, roles, and active-organization context.
Google, Microsoft, Apple, and GitHub social login. Configured via the core package.
Register each package explicitly, map only its endpoint family, and keep provider migrations in your host.
Program.cs
using Identity.Base.Admin.Configuration;
using Identity.Base.Admin.Endpoints;
using Identity.Base.Extensions;
using Identity.Base.Organizations.Extensions;
using Identity.Base.Roles.Endpoints;
using Identity.Base.ServicePrincipals.Extensions;
using Microsoft.EntityFrameworkCore;
var builder = WebApplication.CreateBuilder(args);
var configureDb =
new Action<IServiceProvider, DbContextOptionsBuilder>((sp, options) =>
{
var connectionString = sp.GetRequiredService<IConfiguration>()
.GetConnectionString("Primary")
?? throw new InvalidOperationException(
"ConnectionStrings:Primary must be set.");
options.UseNpgsql(connectionString);
});
builder.Services.AddIdentityBase(
builder.Configuration,
builder.Environment,
configureDbContext: configureDb);
builder.Services.AddIdentityAdmin(builder.Configuration, configureDb);
builder.Services.AddIdentityBaseOrganizations(configureDb);
builder.Services.AddIdentityBaseServicePrincipals(
builder.Configuration,
configureDb);
var app = builder.Build();
app.UseApiPipeline();
app.UseOrganizationContextFromHeader();
app.MapControllers();
app.MapApiEndpoints();
app.MapIdentityAdminEndpoints();
app.MapIdentityRolesUserEndpoints();
app.MapIdentityBaseOrganizationEndpoints();
app.MapIdentityBaseServicePrincipalEndpoints();
await app.RunAsync(); Install packages
dotnet add package Identity.Base
dotnet add package Identity.Base.Admin
dotnet add package Identity.Base.Roles
dotnet add package Identity.Base.Organizations
dotnet add package Identity.Base.ServicePrincipals React SDK
import { useAuth } from '@identity-base/react-client';
const {
user,
isAuthenticated,
isLoading,
error,
logout,
} = useAuth(); Microservice JWT validation
builder.Services.AddIdentityBaseAuthentication(
"https://id.myapp.com",
"identity.api"); The case for owning your authentication infrastructure.
MIT licensed. No seat limits, no MAU caps, no surprise invoices at scale.
Your user data stays in your infrastructure. No third-party access, full compliance control.
No monolith. Pick the packages that match your requirements and skip the rest.
RFC-compliant OAuth2 and OpenID Connect. Not a proprietary protocol.
First-class .NET integration. Works with your existing EF Core, DI, and middleware stack.
Fork it, extend it, contribute back. The code is yours to own and customize.
Start with the core package. Add modules as you grow. Always open source.