Documentation
Guides and the REST API reference of ErtisAuth.
ErtisAuth is a self-hosted identity and access management (IAM) server built on ASP.NET Core and MongoDB. It signs users and applications in, issues tokens, and decides what each caller is allowed to do, for any number of applications that share the same users and permissions.
This documentation is the complete guide to ErtisAuth: how it works, how to run it, and every endpoint of its REST API with request and response examples. The interactive OpenAPI reference (/docs on a development instance) lists the same endpoints; this documentation adds the concepts, the flows that combine several endpoints, and the rules that a schema alone can't show.
Where to start#
| If you want to... | Read |
|---|---|
| Run ErtisAuth for the first time | Getting Started |
| Understand the building blocks | Core Concepts |
| Learn the conventions shared by all endpoints | API Conventions |
| Sign users in and work with tokens | Authentication |
| Control who can do what | Authorization |
| Protect your own .NET APIs with ErtisAuth | .NET SDK |
| Run ErtisAuth in production | Operations |
Guides#
- Getting Started: install, configure, set up and get your first token.
- Configuration: every setting of the server.
- Core Concepts: memberships, users, user types, roles, applications and more.
- API Conventions: routes, headers, pagination, queries and errors.
- Authentication: tokens, sign-in, refresh, verification and sign-out.
- Authorization: the RBAC and UBAC permission model.
- Account Recovery and Activation: activation mails, password reset and one-time passwords.
- Device Code Flow: sign in on devices without a keyboard.
- External Identity Providers: Google, Apple, Facebook and Microsoft sign-in.
- Events, Webhooks and Mail Hooks: react to what happens in a membership.
- .NET SDK: the client SDK and the ASP.NET Core integration.
- Operations: health checks, metrics, logging, indexes and a production checklist.
API reference#
| Resource | Page |
|---|---|
| Setup, health check | Getting Started, Operations |
| Tokens | Authentication |
| Active tokens, revoked tokens | Sessions |
| Memberships | Memberships |
| Users | Users |
| User types | User Types |
| Roles | Roles |
| Applications | Applications |
| Providers | External Identity Providers |
| Code policies, token codes | Device Code Flow |
| Events | Events |
| Webhooks | Webhooks |
| Mail hooks | Mail Hooks |
| Error codes | Error Codes |
License#
ErtisAuth is open source under the MIT License.
Found a mistake in the docs? Open an issue