ErtisAuth

Documentation

Guides and the REST API reference of ErtisAuth.

ErtisAuth is a self-hosted identity and access management (IAM) server built on ASP.NET Core and MongoDB. It signs users and applications in, issues tokens, and decides what each caller is allowed to do, for any number of applications that share the same users and permissions.

This documentation is the complete guide to ErtisAuth: how it works, how to run it, and every endpoint of its REST API with request and response examples. The interactive OpenAPI reference (/docs on a development instance) lists the same endpoints; this documentation adds the concepts, the flows that combine several endpoints, and the rules that a schema alone can't show.

Where to start#

If you want to...Read
Run ErtisAuth for the first timeGetting Started
Understand the building blocksCore Concepts
Learn the conventions shared by all endpointsAPI Conventions
Sign users in and work with tokensAuthentication
Control who can do whatAuthorization
Protect your own .NET APIs with ErtisAuth.NET SDK
Run ErtisAuth in productionOperations

Guides#

API reference#

ResourcePage
Setup, health checkGetting Started, Operations
TokensAuthentication
Active tokens, revoked tokensSessions
MembershipsMemberships
UsersUsers
User typesUser Types
RolesRoles
ApplicationsApplications
ProvidersExternal Identity Providers
Code policies, token codesDevice Code Flow
EventsEvents
WebhooksWebhooks
Mail hooksMail Hooks
Error codesError Codes

License#

ErtisAuth is open source under the MIT License.

Found a mistake in the docs? Open an issue