Identity.Base Docs

Package Reference

Identity Base is intentionally modular. The host starts with the core package, then layers RBAC, admin APIs, organizations, managed service principals, and email providers as needed. Frontend and API consumers use separate client packages.

Recommended adoption order

  1. 1. `Identity.Base` for the core identity server, OpenIddict, MFA, and account flows.
  2. 2. `Identity.Base.Roles` when you need role and permission claims.
  3. 3. `Identity.Base.Admin` when you need administrator-facing users and roles APIs.
  4. 4. `Identity.Base.Organizations` for memberships, invitations, and organization-scoped roles.
  5. 5. `Identity.Base.ServicePrincipals` for managed machine identities using RBAC and the client-credentials grant.
  6. 6. Client and email packages when you are ready to ship SPAs, downstream APIs, and account email flows.
Package Purpose
Identity.BaseCore OAuth2/OIDC, account flows, MFA, OpenIddict, and host integration
Identity.Base.RolesRole and permission catalog plus effective permission resolution
Identity.Base.AdminAdmin API endpoints for users, roles, and permissions
Identity.Base.OrganizationsMulti-organization memberships, invitations, and organization roles
Identity.Base.ServicePrincipalsManaged machine identities, revocable credentials, RBAC, and client-credentials tokens
Identity.Base.AspNetJWT validation helpers for downstream ASP.NET Core APIs
Identity.Base.Email.MailJetMailJet transactional email sender
Identity.Base.Email.SendGridSendGrid transactional email sender
@identity-base/react-clientReact 19 auth hooks and provider
@identity-base/react-organizationsReact organization state, membership, invitation, and context helpers
@identity-base/client-coreFramework-agnostic browser auth core
@identity-base/angular-clientAngular auth services, guards, and token attachment
@identity-base/angular-organizationsAngular organization services and active-organization header handling

Package families

  • Host packages live in your ASP.NET Core identity host and expose the auth, admin, roles, organizations, machine-identity, and email surfaces.
  • Resource-server package protects downstream APIs that consume Identity Base-issued JWTs.
  • Browser clients handle PKCE, account flows, token refresh, and optional organization context in SPAs.

Deep dives