Identity.Base Docs

Architecture

Identity Base composes in layers. A dedicated host runs OpenID Connect and account flows; optional RBAC, organization, admin, and service-principal packages extend it; browser clients and managed workloads obtain tokens; downstream APIs validate them.

Browser / SPA
Worker / Service
-->
Identity.Base Host
-->
PostgreSQL / SQL Server
JWT tokens
Microservices (Identity.Base.AspNet)

Package composition model

  • `Identity.Base` is the foundation: ASP.NET Identity, OpenIddict, MFA, and account flows.
  • `Identity.Base.Roles` adds the permission catalog and role-based claim resolution.
  • `Identity.Base.Organizations` adds memberships, invitations, and organization role management.
  • `Identity.Base.Admin` exposes administrator endpoints on top of the core and roles layers.
  • `Identity.Base.ServicePrincipals` adds managed machine identities, credentials, RBAC role assignments, and client-credentials integration.

Domain relationships

  • Users live in the core identity tables.
  • Organizations group users through memberships and optional organization-scoped roles.
  • Service principals represent workloads and receive permissions only through global RBAC roles.
  • Scopes gate access at the OAuth client level.
  • Permissions are RBAC claims such as `users.read` or `admin.organizations.manage` resolved from roles.