Identity.Base Docs
Package Reference
Identity Base is intentionally modular. The host starts with the core package, then layers RBAC, admin APIs, organizations, managed service principals, and email providers as needed. Frontend and API consumers use separate client packages.
Recommended adoption order
- 1. `Identity.Base` for the core identity server, OpenIddict, MFA, and account flows.
- 2. `Identity.Base.Roles` when you need role and permission claims.
- 3. `Identity.Base.Admin` when you need administrator-facing users and roles APIs.
- 4. `Identity.Base.Organizations` for memberships, invitations, and organization-scoped roles.
- 5. `Identity.Base.ServicePrincipals` for managed machine identities using RBAC and the client-credentials grant.
- 6. Client and email packages when you are ready to ship SPAs, downstream APIs, and account email flows.
| Package | Purpose | Registry |
|---|---|---|
| Identity.Base | Core OAuth2/OIDC, account flows, MFA, OpenIddict, and host integration | NuGet |
| Identity.Base.Roles | Role and permission catalog plus effective permission resolution | NuGet |
| Identity.Base.Admin | Admin API endpoints for users, roles, and permissions | NuGet |
| Identity.Base.Organizations | Multi-organization memberships, invitations, and organization roles | NuGet |
| Identity.Base.ServicePrincipals | Managed machine identities, revocable credentials, RBAC, and client-credentials tokens | NuGet |
| Identity.Base.AspNet | JWT validation helpers for downstream ASP.NET Core APIs | NuGet |
| Identity.Base.Email.MailJet | MailJet transactional email sender | NuGet |
| Identity.Base.Email.SendGrid | SendGrid transactional email sender | NuGet |
| @identity-base/react-client | React 19 auth hooks and provider | npm |
| @identity-base/react-organizations | React organization state, membership, invitation, and context helpers | npm |
| @identity-base/client-core | Framework-agnostic browser auth core | npm |
| @identity-base/angular-client | Angular auth services, guards, and token attachment | npm |
| @identity-base/angular-organizations | Angular organization services and active-organization header handling | npm |
Package families
- Host packages live in your ASP.NET Core identity host and expose the auth, admin, roles, organizations, machine-identity, and email surfaces.
- Resource-server package protects downstream APIs that consume Identity Base-issued JWTs.
- Browser clients handle PKCE, account flows, token refresh, and optional organization context in SPAs.
Deep dives
Identity.Base core
Host wiring, endpoint families, seed callbacks, and extension points.
Identity.Base.Roles
Permission catalogs, role seeding, claim resolution, and user-role assignment.
Identity.Base.Admin
Admin endpoints, scope requirements, and operator-facing workflows.
Identity.Base.Organizations
Multi-org APIs, invitations, active organization scoping, and membership lifecycle.
Identity.Base.ServicePrincipals
Machine-identity lifecycle, RBAC roles, credential rotation, token issuance, and revocation boundaries.
@identity-base/client-core
Framework-agnostic PKCE, token lifecycle, and typed API access for custom SPAs.
Sample apps
Reference hosts and SPAs that demonstrate the supported deployment shapes.