Identity.Base Docs
Architecture
Identity Base composes in layers. A dedicated host runs OpenID Connect and account flows; optional RBAC, organization, admin, and service-principal packages extend it; browser clients and managed workloads obtain tokens; downstream APIs validate them.
Browser / SPA
Worker / Service
--> Identity.Base Host
--> PostgreSQL / SQL Server
JWT tokens
Microservices (Identity.Base.AspNet)
Package composition model
- `Identity.Base` is the foundation: ASP.NET Identity, OpenIddict, MFA, and account flows.
- `Identity.Base.Roles` adds the permission catalog and role-based claim resolution.
- `Identity.Base.Organizations` adds memberships, invitations, and organization role management.
- `Identity.Base.Admin` exposes administrator endpoints on top of the core and roles layers.
- `Identity.Base.ServicePrincipals` adds managed machine identities, credentials, RBAC role assignments, and client-credentials integration.
Domain relationships
- Users live in the core identity tables.
- Organizations group users through memberships and optional organization-scoped roles.
- Service principals represent workloads and receive permissions only through global RBAC roles.
- Scopes gate access at the OAuth client level.
- Permissions are RBAC claims such as `users.read` or `admin.organizations.manage` resolved from roles.