Identity.Base Docs

Admin Operations

`Identity.Base.Admin` adds system-administrator endpoints on top of the core identity and RBAC packages. Optional packages extend the operator surface with organizations and managed service principals. Every admin route expects both the configured admin scope and its fine-grained permission.

Prerequisites

  • Identity host running with the admin package enabled and mapped.
  • Database schema current for the core and RBAC contexts.
  • For service principals, migrations applied for both `ServicePrincipalDbContext` and the updated `IdentityRolesDbContext`.
  • At least one administrator role and user seeded.
  • An OAuth client allowed to request `identity.admin`.

Key workflows

  • User management: list, search, create, update, lock, unlock, reset password, reset MFA, soft delete, and restore users.
  • Role management: create roles, assign permission sets, and inspect usage counts before deleting.
  • Permission catalog inspection: list the canonical permissions with paging and search support.
  • Machine identity management: create, update, disable or restore principals; assign roles; issue and revoke credentials.

Endpoint snapshot

  • GET /admin/users and GET /admin/users/{id}
  • POST /admin/users, PUT /admin/users/{id}, PUT /admin/users/{id}/roles
  • GET /admin/roles, POST /admin/roles, PUT /admin/roles/{id}
  • GET /admin/permissions
  • GET/POST /admin/service-principals, plus lifecycle, roles, and credential routes when the optional package is mapped

Service-principal operator permissions

Grant only the operations an administrator needs: service-principals.read, .create, .update, .disable, .manage-roles, and .manage-credentials.

Read the service-principal lifecycle and credential guide →