Stratara.Identity.Core
4.0.3
Prefix Reserved
dotnet add package Stratara.Identity.Core --version 4.0.3
NuGet\Install-Package Stratara.Identity.Core -Version 4.0.3
<PackageReference Include="Stratara.Identity.Core" Version="4.0.3" />
<PackageVersion Include="Stratara.Identity.Core" Version="4.0.3" />
<PackageReference Include="Stratara.Identity.Core" />
paket add Stratara.Identity.Core --version 4.0.3
#r "nuget: Stratara.Identity.Core, 4.0.3"
#:package Stratara.Identity.Core@4.0.3
#addin nuget:?package=Stratara.Identity.Core&version=4.0.3
#tool nuget:?package=Stratara.Identity.Core&version=4.0.3
Stratara.Identity.Core
Derived. The behaviour described here is specified under
openspec/specs/. Those specifications are the source; this page explains and illustrates them.
License: MIT.
Channel-agnostic identity primitives for the Stratara stack. Ships the shared model records, interfaces, and the typed HttpClient wrapper consumed by host-specific packages (e.g. Stratara.Identity.AspNetCore for server-side Blazor, with consumer-supplied implementations for non-web hosts such as mobile or desktop).
What's in the box
| Folder | Contents |
|---|---|
Models/ |
AccessTokenInfo (persisted token + expiry), LoginRequest / LoginResponse (HTTP payload shape), ClaimsResponse / ClaimDto (identity-endpoint claims), StrataraSignInResult (standalone, channel-agnostic sign-in outcome with localized failure message, token info, resolved user id, two-factor / lockout flags — no inheritance from Microsoft.AspNetCore.Identity.SignInResult) |
Abstractions/ |
IStrataraSignInManager (per-channel sign-in dispatch), IStrataraAuthenticationStateProvider (auth-state surface), ITokenStorage (secure-storage abstraction), IStrataraRedirectManager (host-native post-auth redirect) |
HttpClientHelper.cs |
IHttpClientHelper + default impl — typed wrapper so identity services can depend on the right configured HttpClient (auth handler + base address) without coupling to specific names |
Quick start
Reference this package from any host or library that needs to consume the Stratara identity surface (model records or the abstractions). Host-specific concrete implementations live in Stratara.Identity.AspNetCore for server-side Blazor; non-web host implementations are supplied by the consumer app.
Dependencies
Stratara.Shared— diagnostics, multitenancy types, session-context helpers used by the host-specific implementations downstream.
No ASP.NET Core / Microsoft.AspNetCore.Identity dependency by design — this package is consumable from MAUI, console, and unit-test contexts without dragging the ASP.NET runtime in transitively.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Stratara.Shared (>= 4.0.3)
NuGet packages (1)
Showing the top 1 NuGet packages that depend on Stratara.Identity.Core:
| Package | Downloads |
|---|---|
|
Stratara.Identity.AspNetCore
Channel-agnostic ASP.NET Core identity wiring for the Stratara stack — AddAspNetIdentity and AddAspNetIdentityWithSignInManager extensions, IStrataraSignInManager wrapper, EF stores, i18n'd failure messages, optional passkey support, external-login OpenID Connect + JWT-bearer helpers, and hardened JIT external-login provisioning. Consumers wire their own AuthenticationStateProvider (Blazor Server, MAUI, etc.). |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 4.0.3 | 56 | 9/3/2026 |
| 4.0.2 | 154 | 9/3/2026 |
| 4.0.1 | 98 | 9/2/2026 |
| 4.0.0 | 273 | 8/31/2026 |
| 4.0.0-preview.1 | 49 | 8/31/2026 |
| 3.4.0 | 127 | 8/28/2026 |
| 3.3.0 | 324 | 8/25/2026 |
| 3.2.3 | 107 | 8/22/2026 |
| 3.2.2 | 742 | 8/14/2026 |
| 3.2.1 | 706 | 8/2/2026 |
| 3.2.0 | 118 | 7/18/2026 |
| 3.1.7 | 126 | 7/1/2026 |
| 3.1.6 | 549 | 6/22/2026 |
| 3.1.5 | 126 | 6/22/2026 |
| 3.1.4 | 138 | 6/15/2026 |
| 3.1.3 | 126 | 6/10/2026 |
| 3.1.2 | 142 | 6/5/2026 |
| 3.1.1 | 220 | 6/1/2026 |
| 3.1.0 | 137 | 5/30/2026 |
| 3.0.23 | 127 | 5/28/2026 |
Three fixes to the same complaint: a host composed exactly as the documentation describes did not
start. Each one was a registration the composites assumed somebody else had made — a tracer, a unit
of work, a Redis connection — and each is now made by the registration that needs it. Nothing that
already worked changes: every fix defers to a registration the host makes itself, in either order,
so the lines a working host added to get past these gaps can simply be deleted. Additive on every
published surface.
### Fixed
- **A host without Redis starts and dispatches.** Every composite that carries a dispatcher
registered the projection-replay state, and its only implementation took a Redis connection that
no composite registers, so a host composed as documented failed at its first dispatch unless it
also ran Redis and called `AddCaching()`. `AddProjectionReplayState()` now chooses at first
resolution: with a registered `IConnectionMultiplexer` the Redis-backed state as before, without
one an in-process state with the same lease semantics — and a warning, once at start-up
(`104_012`), that replay coordination is confined to that process, so a replay requested there
suppresses publication there only. A deployment whose replay must reach several hosts registers
the shared connection, in either order. Redis-backed hosts observe no change.
- **Registering a store context now registers its unit of work.**
`AddNpgsqlWriteDbContextFactory<T>()` registered the context factory, the context and the default
connection resolver but not the `IWriteUnitOfWork` that the event source, the outbox dispatcher and
the command worker take from the container — and nothing else in the published packages did, so a
host composed exactly as documented failed at its first command with a dependency-injection error.
The write registration now try-adds a scoped `IWriteUnitOfWork` over its context, and
`AddNpgsqlReadDbContextFactory<T>()` try-adds `IProjectionsUnitOfWork` and `IReadUnitOfWork`
likewise. A unit of work the host registers itself, before or after, is still the one used; a
hand-written registration can simply be deleted.
- **`AddMediator()` no longer requires the host to register an OpenTelemetry `Tracer`.** The
mediator traces every dispatch and obtained its tracer from the host, but nothing registered one,
so a host that called `AddMediator()` and nothing else failed at the first resolve of `IMediator`.
`AddMediator()` now registers a fallback that emits the dispatch spans from the framework's
`Stratara.Application` activity source — a host that subscribes to framework telemetry sees them,
a host that subscribes to nothing pays for nothing. A `Tracer` the host registers, before or after
`AddMediator()`, is still the one used, so no existing host changes behaviour; the registration
line can simply be deleted. The samples, the README and the package README no longer carry it.