Identity.Base Docs

Full Stack Integration

The recommended Identity Base architecture is a dedicated Identity Host that owns authentication and managed identities, a fleet of JWT-protected APIs, browser clients using the official SDKs, and workloads using short-lived client-credentials tokens.

Solution layout

bash
mkdir identity-full-stack
cd identity-full-stack
dotnet new sln -n IdentityFullStack
dotnet new web -n IdentityHost
mkdir Services
dotnet sln add IdentityHost/IdentityHost.csproj

Identity host responsibilities

  • Run Identity Base core services, OpenIddict, MFA, registration, and account flows.
  • Seed configuration-backed OpenIddict applications and scopes for browser or fixed service clients.
  • Own optional admin, organizations, roles, service-principal, and email modules.
  • Apply host-managed migrations for every enabled DbContext before seeders run.

Managed workload responsibilities

  • Keep each issued credential in an approved secret store and rotate it before expiry.
  • Use the standard /connect/token endpoint with grant_type=client_credentials.
  • Request only scopes granted to the managed application and depend on role-derived permissions for domain authorization.

Protected API responsibilities

  • Validate Identity Base-issued JWTs with `Identity.Base.AspNet`.
  • Require the correct scopes and any additional domain permissions.
  • Account for the offline-JWT revocation boundary; short token lifetimes limit the exposure window.
  • Stay separate from account creation, login, and token issuance concerns.

SPA responsibilities

  • Use the official React or Angular SDK for PKCE, account flows, and token refresh.
  • Match the registered client ID, redirect URI, and scope configuration from the host.
  • Call the identity host directly for auth flows and protected APIs with bearer tokens.