Identity.Base Docs
@identity-base/client-core
`@identity-base/client-core` is the framework-agnostic browser auth engine underneath the React and Angular SDKs. Use it directly when you want to integrate Identity Base into a custom SPA runtime or another framework without adopting a higher-level package.
What it gives you
- Authorization code + PKCE helpers.
- Access token and refresh token management.
- Typed API calls for users, profiles, MFA, and admin endpoint families including service principals.
- Storage abstractions for memory, session storage, and local storage.
Use it directly when
- You are not using React or Angular.
- You want to wrap Identity Base in your own design-system-specific auth layer.
- You need imperative control over redirects, refresh timing, or token storage.
Basic setup
ts
import { IdentityAuthManager } from '@identity-base/client-core';
const auth = new IdentityAuthManager({
apiBase: 'https://identity.example.com',
clientId: 'spa-client',
redirectUri: 'https://app.example.com/auth/callback',
scope: 'openid profile email offline_access identity.api identity.admin',
tokenStorage: 'sessionStorage',
autoRefresh: true
});
await auth.startAuthorization(); | API | Purpose |
|---|---|
| IdentityAuthManager | Imperative entry point for login, logout, callback handling, refresh, and protected fetches. |
| TokenManager | Lower-level token persistence and refresh coordination. |
| ApiClient | Typed HTTP wrapper for Identity Base endpoint families. |
| generatePkce() | Creates verifier and challenge material for custom login flows. |
| createTokenStorage() | Lets you swap storage strategy cleanly. |
Integration advice
- Call `startAuthorization()` only in browser environments where redirect navigation is valid.
- Request `offline_access` if you expect refresh tokens and background refresh.
- Authorized calls attach a bearer token when available and otherwise retain same-origin cookie behavior.
- Problem Details and plain-text failures are normalized into `IdentityError`; empty `204` responses return `undefined`.
- Use the framework SDKs unless you specifically need custom lifecycle control.
- When organization flows return `requiresTokenRefresh`, refresh immediately so the latest claims reach the client.
Typed admin namespaces
Administrative operations are grouped under auth.admin.users, auth.admin.roles, auth.admin.permissions, and auth.admin.servicePrincipals.
ts
const principal = await auth.admin.servicePrincipals.create({
displayName: 'Invoice Worker',
})
const issued = await auth.admin.servicePrincipals.issueCredential(
principal.id,
{ name: 'production' },
)
// issued.secret is returned once. Store it immediately.