Identity.Base Docs
Full Stack Integration
The recommended Identity Base architecture is a dedicated Identity Host that owns authentication and managed identities, a fleet of JWT-protected APIs, browser clients using the official SDKs, and workloads using short-lived client-credentials tokens.
Solution layout
bash
mkdir identity-full-stack
cd identity-full-stack
dotnet new sln -n IdentityFullStack
dotnet new web -n IdentityHost
mkdir Services
dotnet sln add IdentityHost/IdentityHost.csproj Identity host responsibilities
- Run Identity Base core services, OpenIddict, MFA, registration, and account flows.
- Seed configuration-backed OpenIddict applications and scopes for browser or fixed service clients.
- Own optional admin, organizations, roles, service-principal, and email modules.
- Apply host-managed migrations for every enabled DbContext before seeders run.
Managed workload responsibilities
- Keep each issued credential in an approved secret store and rotate it before expiry.
- Use the standard
/connect/tokenendpoint withgrant_type=client_credentials. - Request only scopes granted to the managed application and depend on role-derived permissions for domain authorization.
Protected API responsibilities
- Validate Identity Base-issued JWTs with `Identity.Base.AspNet`.
- Require the correct scopes and any additional domain permissions.
- Account for the offline-JWT revocation boundary; short token lifetimes limit the exposure window.
- Stay separate from account creation, login, and token issuance concerns.
SPA responsibilities
- Use the official React or Angular SDK for PKCE, account flows, and token refresh.
- Match the registered client ID, redirect URI, and scope configuration from the host.
- Call the identity host directly for auth flows and protected APIs with bearer tokens.