Open Source · MIT License

Self-hosted identity
that scales with you

Identity.Base is a modular identity platform for .NET. OAuth2/OIDC, MFA, RBAC, multi-tenancy, and managed machine identities built on ASP.NET Core Identity and OpenIddict. No vendor lock-in.

Architecture Overview
React SPA
@identity-base/react-client
Angular App
@identity-base/angular-client
OAuth2 / PKCE
Identity.Base Host
OIDC
MFA
RBAC
Orgs
Admin
Machine IDs
Email
External
EF Core
JWT Tokens
PostgreSQL
or SQL Server
Microservices
Identity.Base.AspNet

Modular package architecture

Every capability is a separate NuGet or npm package. Compose your identity stack from independent modules.

NuGet

Identity.Base

Core OAuth2/OIDC provider with MFA support. ASP.NET Core Identity + OpenIddict.

NuGet

Identity.Base.Roles

RBAC primitives. Permission/role catalog with database-driven definitions.

NuGet

Identity.Base.Organizations

Multi-tenant organizations with memberships, org-scoped roles, and invitations.

NuGet

Identity.Base.Admin

Admin API endpoints for user, role, organization, and permission management.

NuGet

Identity.Base.ServicePrincipals

Managed machine identities with revocable credentials, RBAC roles, and short-lived client-credentials tokens.

NuGet

Identity.Base.AspNet

JWT validation middleware for downstream APIs and microservices.

NuGet

Email Add-ons

Identity.Base.Email.MailJet and Identity.Base.Email.SendGrid for transactional email.

npm

@identity-base/client-core

Framework-agnostic PKCE, token lifecycle, cookie fallback, and typed Identity admin APIs.

npm

@identity-base/react-client

React 19 hooks for authentication, user info, and token management.

npm

@identity-base/angular-client

Angular 16+ services for OIDC authentication and token lifecycle.

npm

Organization SDKs

React and Angular add-ons for memberships, invitations, roles, and active-organization context.

Built-in

External Auth Providers

Google, Microsoft, Apple, and GitHub social login. Configured via the core package.

Compose the identity host you need

Register each package explicitly, map only its endpoint family, and keep provider migrations in your host.

Program.cs

Program.cs
using Identity.Base.Admin.Configuration;
using Identity.Base.Admin.Endpoints;
using Identity.Base.Extensions;
using Identity.Base.Organizations.Extensions;
using Identity.Base.Roles.Endpoints;
using Identity.Base.ServicePrincipals.Extensions;
using Microsoft.EntityFrameworkCore;

var builder = WebApplication.CreateBuilder(args);

var configureDb =
    new Action<IServiceProvider, DbContextOptionsBuilder>((sp, options) =>
    {
        var connectionString = sp.GetRequiredService<IConfiguration>()
            .GetConnectionString("Primary")
            ?? throw new InvalidOperationException(
                "ConnectionStrings:Primary must be set.");

        options.UseNpgsql(connectionString);
    });

builder.Services.AddIdentityBase(
    builder.Configuration,
    builder.Environment,
    configureDbContext: configureDb);
builder.Services.AddIdentityAdmin(builder.Configuration, configureDb);
builder.Services.AddIdentityBaseOrganizations(configureDb);
builder.Services.AddIdentityBaseServicePrincipals(
    builder.Configuration,
    configureDb);

var app = builder.Build();
app.UseApiPipeline();
app.UseOrganizationContextFromHeader();
app.MapControllers();
app.MapApiEndpoints();
app.MapIdentityAdminEndpoints();
app.MapIdentityRolesUserEndpoints();
app.MapIdentityBaseOrganizationEndpoints();
app.MapIdentityBaseServicePrincipalEndpoints();

await app.RunAsync();

Install packages

bash
dotnet add package Identity.Base
dotnet add package Identity.Base.Admin
dotnet add package Identity.Base.Roles
dotnet add package Identity.Base.Organizations
dotnet add package Identity.Base.ServicePrincipals

React SDK

tsx
import { useAuth } from '@identity-base/react-client';

const {
  user,
  isAuthenticated,
  isLoading,
  error,
  logout,
} = useAuth();

Microservice JWT validation

csharp
builder.Services.AddIdentityBaseAuthentication(
    "https://id.myapp.com",
    "identity.api");

Why self-hosted identity?

The case for owning your authentication infrastructure.

$0

No per-user pricing

MIT licensed. No seat limits, no MAU caps, no surprise invoices at scale.

100%

Data sovereignty

Your user data stays in your infrastructure. No third-party access, full compliance control.

Modular

Use what you need

No monolith. Pick the packages that match your requirements and skip the rest.

Standards

Built on OpenIddict

RFC-compliant OAuth2 and OpenID Connect. Not a proprietary protocol.

.NET

Native ecosystem

First-class .NET integration. Works with your existing EF Core, DI, and middleware stack.

Open

No vendor lock-in

Fork it, extend it, contribute back. The code is yours to own and customize.

Ready to own your identity layer?

Start with the core package. Add modules as you grow. Always open source.