Identity.Base Docs

Roles and Permissions

The Identity.Base.Roles package adds a database-driven RBAC layer to the identity host. It resolves effective permissions into claims, powers the admin and organization endpoints, and keeps authorization separate from OAuth client scopes.

csharp
builder.Services
.AddIdentityBase(options => { /* ... */ })
.AddRoles();

Scopes vs permissions

  • Scopes such as `identity.api` and `identity.admin` are granted to OAuth clients and appear in tokens.
  • Permissions such as `users.read` and `roles.manage` are resolved from roles and emitted as `identity.permissions` claims.
  • Admin and organization endpoints commonly require both: the right scope and the right permission set.