Identity.Base Docs

Identity.Base.Organizations

`Identity.Base.Organizations` is the multi-tenant layer for Identity Base. It adds organizations, memberships, organization-scoped roles, invitation acceptance, and the middleware needed to flow an active organization through non-admin requests.

Core concepts

  • Organizations are first-class aggregates with status, metadata, members, and roles.
  • Memberships map users to organizations and drive organization-aware claims.
  • Organization roles can extend or override permission sets for that organization.
  • Invitations are stored by the package, but the host is responsible for sending email.

Critical runtime rule

For non-admin routes, the active organization is client-selected by sending the X-Organization-Id header. The package middleware reads that header and makes the organization context available to the services and claims pipeline.

Surface Examples
Admin org routes/admin/organizations, /members, /roles, /invitations
User org routes/users/me/organizations, /members, /roles, /invitations
Invitation flowGET /invitations/{code}, POST /invitations/claim

Invitation flow

  1. Create an invitation under the target organization.
  2. Email the returned code with your own host-side delivery mechanism.
  3. Let the invitee preview the invitation anonymously.
  4. After sign-in, call `POST /invitations/claim` and refresh tokens when the response says `requiresTokenRefresh`.

Extension points

  • Override organization scope resolution with a custom resolver if tenant-wide admins need special access.
  • Replace the invitation store if you want different persistence semantics.
  • Use lifecycle listeners for create/update/archive/invite/member events.
  • Hook post-seed provisioning for billing, provisioning, or tenant bootstrap.