Identity.Base Docs

Host Configuration

Identity Base is explicit by design. The host owns database providers and migrations, OpenIddict clients and scopes, MFA, CORS, managed-client policy, external providers, email delivery, and key management.

Database providers

csharp
// PostgreSQL
options.UsePostgreSql("Host=localhost;Database=identity");

// SQL Server
options.UseSqlServer("Server=.;Database=identity");

Identity Base is provider-agnostic. The host chooses the provider and owns the migrations for every enabled DbContext.

OpenIddict clients, scopes, and PKCE permissions

json
{
  "OpenIddict": {
    "Scopes": [
      {
        "Name": "identity.api",
        "Resources": ["identity.api"]
      }
    ],
    "Applications": [
      {
        "ClientId": "spa-client",
        "Permissions": [
          "endpoints:authorization",
          "grant_types:authorization_code",
          "scopes:identity.api",
          "requirements:pkce"
        ]
      }
    ]
  }
}

Client seeding is strict. If you expect a scope, endpoint, refresh token, or PKCE requirement to exist, it must be listed explicitly in the client permissions.

External authentication providers

csharp
options.AddExternalProvider("Google", google => {
    google.ClientId = "...";
    google.ClientSecret = "...";
});

options.AddExternalProvider("Microsoft", ms => { /* ... */ });
options.AddExternalProvider("GitHub", gh => { /* ... */ });
options.AddExternalProvider("Apple", apple => { /* ... */ });

External providers are host-registered. You own the scheme registration, callback configuration, and the route keys that browser clients call.

Managed service-principal token policy

json
{
  "Identity": {
    "ServicePrincipals": {
      "AccessTokenLifetime": "00:15:00",
      "AllowedScopes": ["identity.api"]
    }
  }
}

Every allowed managed-client scope must also exist under OpenIddict:Scopes. Existing managed applications are not rewritten when this list changes.

Configuration sections that matter

  • `Registration` for confirmation and reset URL templates, plus dynamic profile fields.
  • `Cors` for browser origins that are allowed to call `/auth/*` and related endpoints.
  • `Mfa` for issuer name, email/SMS behavior, and transport settings.
  • `Identity:ServicePrincipals` for managed-client scopes and access-token lifetime.
  • `MailJet` / `SendGrid` only when the corresponding package is installed and enabled.
  • `IdentitySeed` to bootstrap the first administrator.