Identity.Base Docs
Host Configuration
Identity Base is explicit by design. The host owns database providers and migrations, OpenIddict clients and scopes, MFA, CORS, managed-client policy, external providers, email delivery, and key management.
Database providers
// PostgreSQL
options.UsePostgreSql("Host=localhost;Database=identity");
// SQL Server
options.UseSqlServer("Server=.;Database=identity"); Identity Base is provider-agnostic. The host chooses the provider and owns the migrations for every enabled DbContext.
OpenIddict clients, scopes, and PKCE permissions
{
"OpenIddict": {
"Scopes": [
{
"Name": "identity.api",
"Resources": ["identity.api"]
}
],
"Applications": [
{
"ClientId": "spa-client",
"Permissions": [
"endpoints:authorization",
"grant_types:authorization_code",
"scopes:identity.api",
"requirements:pkce"
]
}
]
}
} Client seeding is strict. If you expect a scope, endpoint, refresh token, or PKCE requirement to exist, it must be listed explicitly in the client permissions.
External authentication providers
options.AddExternalProvider("Google", google => {
google.ClientId = "...";
google.ClientSecret = "...";
});
options.AddExternalProvider("Microsoft", ms => { /* ... */ });
options.AddExternalProvider("GitHub", gh => { /* ... */ });
options.AddExternalProvider("Apple", apple => { /* ... */ }); External providers are host-registered. You own the scheme registration, callback configuration, and the route keys that browser clients call.
Managed service-principal token policy
{
"Identity": {
"ServicePrincipals": {
"AccessTokenLifetime": "00:15:00",
"AllowedScopes": ["identity.api"]
}
}
} Every allowed managed-client scope must also exist under OpenIddict:Scopes. Existing managed applications are not rewritten when this list changes.
Configuration sections that matter
- `Registration` for confirmation and reset URL templates, plus dynamic profile fields.
- `Cors` for browser origins that are allowed to call `/auth/*` and related endpoints.
- `Mfa` for issuer name, email/SMS behavior, and transport settings.
- `Identity:ServicePrincipals` for managed-client scopes and access-token lifetime.
- `MailJet` / `SendGrid` only when the corresponding package is installed and enabled.
- `IdentitySeed` to bootstrap the first administrator.