Identity.Base Docs

HTTP API and Scopes

When you integrate without a generated client, the scope configuration and OpenAPI document become the authoritative source for routes, payloads, and client-level access control.

Default scopes

  • `identity.api` is the conventional API scope used by protected resource servers.
  • `identity.admin` is the default admin-gating scope used by operator-facing surfaces.

Seed scopes and grant them explicitly

json
{
  "OpenIddict": {
    "Scopes": [
      {
        "Name": "identity.api",
        "Resources": ["identity.api"]
      }
    ],
    "Applications": [
      {
        "Permissions": [
          "scopes:identity.api",
          "endpoints:authorization",
          "grant_types:authorization_code",
          "requirements:pkce"
        ]
      }
    ]
  }
}

OpenAPI discovery

In Development, Identity Base maps OpenAPI JSON at /openapi/v1.json. The document reflects only the packages and endpoint mappings that your host actually enabled.

bash
curl -s https://localhost:5000/openapi/v1.json | jq -r '.paths | keys[]'

Managed client credentials

For managed service principals, Identity:ServicePrincipals:AllowedScopes determines the scopes granted when the managed OpenIddict application is created. Global RBAC roles determine the identity.permissions values in newly issued tokens.

bash
curl -sS https://identity.example.com/connect/token \
  -u "$CLIENT_ID:$CLIENT_SECRET" \
  -H 'Content-Type: application/x-www-form-urlencoded' \
  --data-urlencode 'grant_type=client_credentials' \
  --data-urlencode 'scope=identity.api'

When the optional package is mapped, OpenAPI also includes twelve routes beneath /admin/service-principals for lifecycle, roles, and credential operations.