Identity.Base Docs

Identity.Base Documentation

Identity.Base is a modular, self-hosted identity platform for .NET teams. These docs cover host setup, local development, package composition, frontend SDKs, admin and organization workflows, managed machine identities, and HTTP/API integration.

Open Source · MIT License ·

Why Identity.Base?

Self-hosted
Keep identity infrastructure and data under your control.
Modular
Add roles, organizations, admin APIs, machine identities, and email providers incrementally.
Standards-based
Built on ASP.NET Core Identity and OpenIddict with OAuth2/OIDC flows.

Recommended setup path

  1. 1
    Start with the Quick Start
    Create a real package-based host, wire the services explicitly, and verify OIDC discovery and health.
  2. 2
    Get local development working early
    Run the Docker stack with PostgreSQL and MailHog so account and email flows work before you wire your product.
  3. 3
    Configure the host before frontend integration
    Database provider, OpenIddict clients and scopes, MFA, CORS, and external providers belong in the host first.
  4. 4
    Add only the modules you need
    Roles, organizations, admin APIs, service principals, and email senders are layered packages, not mandatory defaults.
  5. 5
    Wire SPAs and downstream APIs last
    Once the host and scopes are stable, add the React or Angular SDK and JWT validation in your .NET APIs.

Documentation sections

Quick Start

Create a host from packages, own the migrations, and verify OIDC plus health endpoints.

Local Development

Run the Docker stack locally with PostgreSQL, MailHog, and the sample clients.

Full Stack Integration

Follow the recommended architecture for a dedicated identity host, protected APIs, and browser clients.

Host Configuration

Wire database providers, OpenIddict clients and scopes, MFA, CORS, external providers, and email transport.

HTTP API and Scopes

Understand `identity.api`, `identity.admin`, OpenAPI discovery, and how client permissions actually seed.

ASP.NET APIs

Protect downstream .NET APIs with `Identity.Base.AspNet`, request logging, and scope-based authorization.

Admin Operations

Operate `/admin/users`, `/admin/roles`, and `/admin/permissions` with the right scopes and RBAC.

Email Delivery

Configure MailJet or SendGrid for confirmation, reset-password, and email MFA challenge flows.

Packages and Architecture

Choose the right NuGet and npm packages and understand how the layers compose.

Package Deep Dives

Drill into the core, roles, admin, organizations, and client-core packages with the host and runtime details that matter in production.

Organizations

Implement memberships, invitations, active-organization scoping, and organization-specific roles.

Service Principals

Provision machine identities with revocable credentials, role-derived permissions, and short-lived client-credentials tokens.

React and Angular SDKs

Use the official browser SDKs for PKCE, account flows, profile updates, permissions, and route protection.

Samples and Playbooks

Follow the sample apps and operational playbooks that the upstream repository uses to validate real integrations.

Canonical source material

These site docs are grounded in the upstream Identity repository: the package docs hub, detailed guides, playbooks, HTTP API references, and sample apps. Use the repo for implementation detail and this site as the navigable integration guide.