Identity.Base Docs
Identity.Base.Organizations
`Identity.Base.Organizations` is the multi-tenant layer for Identity Base. It adds organizations, memberships, organization-scoped roles, invitation acceptance, and the middleware needed to flow an active organization through non-admin requests.
Core concepts
- Organizations are first-class aggregates with status, metadata, members, and roles.
- Memberships map users to organizations and drive organization-aware claims.
- Organization roles can extend or override permission sets for that organization.
- Invitations are stored by the package, but the host is responsible for sending email.
Critical runtime rule
For non-admin routes, the active organization is client-selected by sending the X-Organization-Id header. The package middleware reads that header and makes the organization context available to the services and claims pipeline.
| Surface | Examples | Who uses it |
|---|---|---|
| Admin org routes | /admin/organizations, /members, /roles, /invitations | Platform admins with `admin.organizations.*` permissions. |
| User org routes | /users/me/organizations, /members, /roles, /invitations | Authenticated users managing their own organization context. |
| Invitation flow | GET /invitations/{code}, POST /invitations/claim | Invite preview for anonymous users, claim for authenticated invitees. |
Invitation flow
- Create an invitation under the target organization.
- Email the returned code with your own host-side delivery mechanism.
- Let the invitee preview the invitation anonymously.
- After sign-in, call `POST /invitations/claim` and refresh tokens when the response says `requiresTokenRefresh`.
Extension points
- Override organization scope resolution with a custom resolver if tenant-wide admins need special access.
- Replace the invitation store if you want different persistence semantics.
- Use lifecycle listeners for create/update/archive/invite/member events.
- Hook post-seed provisioning for billing, provisioning, or tenant bootstrap.