Identity.Base Docs
HTTP API and Scopes
When you integrate without a generated client, the scope configuration and OpenAPI document become the authoritative source for routes, payloads, and client-level access control.
Default scopes
- `identity.api` is the conventional API scope used by protected resource servers.
- `identity.admin` is the default admin-gating scope used by operator-facing surfaces.
Seed scopes and grant them explicitly
{
"OpenIddict": {
"Scopes": [
{
"Name": "identity.api",
"Resources": ["identity.api"]
}
],
"Applications": [
{
"Permissions": [
"scopes:identity.api",
"endpoints:authorization",
"grant_types:authorization_code",
"requirements:pkce"
]
}
]
}
} OpenAPI discovery
In Development, Identity Base maps OpenAPI JSON at /openapi/v1.json. The document reflects only the packages and endpoint mappings that your host actually enabled.
curl -s https://localhost:5000/openapi/v1.json | jq -r '.paths | keys[]' Managed client credentials
For managed service principals, Identity:ServicePrincipals:AllowedScopes determines the scopes granted when the managed OpenIddict application is created. Global RBAC roles determine the identity.permissions values in newly issued tokens.
curl -sS https://identity.example.com/connect/token \
-u "$CLIENT_ID:$CLIENT_SECRET" \
-H 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode 'grant_type=client_credentials' \
--data-urlencode 'scope=identity.api' When the optional package is mapped, OpenAPI also includes twelve routes beneath /admin/service-principals for lifecycle, roles, and credential operations.