Identity.Base Docs

@identity-base/client-core

`@identity-base/client-core` is the framework-agnostic browser auth engine underneath the React and Angular SDKs. Use it directly when you want to integrate Identity Base into a custom SPA runtime or another framework without adopting a higher-level package.

What it gives you

  • Authorization code + PKCE helpers.
  • Access token and refresh token management.
  • Typed API calls for users, profiles, MFA, and admin endpoint families including service principals.
  • Storage abstractions for memory, session storage, and local storage.

Use it directly when

  • You are not using React or Angular.
  • You want to wrap Identity Base in your own design-system-specific auth layer.
  • You need imperative control over redirects, refresh timing, or token storage.

Basic setup

ts
import { IdentityAuthManager } from '@identity-base/client-core';

const auth = new IdentityAuthManager({
  apiBase: 'https://identity.example.com',
  clientId: 'spa-client',
  redirectUri: 'https://app.example.com/auth/callback',
  scope: 'openid profile email offline_access identity.api identity.admin',
  tokenStorage: 'sessionStorage',
  autoRefresh: true
});

await auth.startAuthorization();
API Purpose
IdentityAuthManagerImperative entry point for login, logout, callback handling, refresh, and protected fetches.
TokenManagerLower-level token persistence and refresh coordination.
ApiClientTyped HTTP wrapper for Identity Base endpoint families.
generatePkce()Creates verifier and challenge material for custom login flows.
createTokenStorage()Lets you swap storage strategy cleanly.

Integration advice

  • Call `startAuthorization()` only in browser environments where redirect navigation is valid.
  • Request `offline_access` if you expect refresh tokens and background refresh.
  • Authorized calls attach a bearer token when available and otherwise retain same-origin cookie behavior.
  • Problem Details and plain-text failures are normalized into `IdentityError`; empty `204` responses return `undefined`.
  • Use the framework SDKs unless you specifically need custom lifecycle control.
  • When organization flows return `requiresTokenRefresh`, refresh immediately so the latest claims reach the client.

Typed admin namespaces

Administrative operations are grouped under auth.admin.users, auth.admin.roles, auth.admin.permissions, and auth.admin.servicePrincipals.

ts
const principal = await auth.admin.servicePrincipals.create({
  displayName: 'Invoice Worker',
})

const issued = await auth.admin.servicePrincipals.issueCredential(
  principal.id,
  { name: 'production' },
)

// issued.secret is returned once. Store it immediately.