Skip to main content

Types

Version: 2.22.0

ApiResource​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/Resource-1 ➔ System.Identity-2.22.0/ApiResource-1 No description available currently.

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System.Identity-2/RequireResourceIndicatorFalse
System.Identity-2/SecretsFalse
System.Identity-2/ScopesFalse
System.Identity-2/AllowedAccessTokenSigningAlgorithmsFalse

ApiScope​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/Resource-1 ➔ System.Identity-2.22.0/ApiScope-1 No description available currently.

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System.Identity-2/IsEmphasizedFalse
System.Identity-2/IsRequiredFalse

AzureEntraIdIdentityProvider​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/IdentityProvider-1 ➔ System.Identity-2.22.0/AzureEntraIdIdentityProvider-1 No description available currently.

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System-2/TenantIdFalse
System.Identity-2/AuthorityTrue
System.Identity-2/ClientIdFalse
System.Identity-2/ClientSecretFalse

Client​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/Client-1 No description available currently.

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System-2/EnabledFalse
System.Identity-2/ClientIdFalse
System.Identity-2/ProtocolTypeFalse
System.Identity-2/SecretsFalse
System.Identity-2/RequireClientSecretFalse
System-2/NameTrue
System-2/DescriptionTrue
System.Identity-2/ClientUriTrue
System.Identity-2/LogoUriTrue
System.Identity-2/RequireConsentTrue
System.Identity-2/AllowRememberConsentFalse
System.Identity-2/AllowedGrantTypesFalse
System.Identity-2/RequirePkceFalse
System.Identity-2/AllowPlainTextPkceFalse
System.Identity-2/RequireRequestObjectFalse
System.Identity-2/AllowAccessTokensViaBrowserFalse
System.Identity-2/RequireDPoPFalse
System.Identity-2/DPoPValidationModeFalse
System.Identity-2/DPoPClockSkewFalse
System.Identity-2/RedirectUrisFalse
System.Identity-2/PostLogoutRedirectUrisFalse
System.Identity-2/FrontChannelLogoutUriTrue
System.Identity-2/FrontChannelLogoutSessionRequiredFalse
System.Identity-2/BackChannelLogoutUriTrue
System.Identity-2/BackChannelLogoutSessionRequiredFalse
System.Identity-2/AllowOfflineAccessFalse
System.Identity-2/AllowedScopesFalse
System.Identity-2/AlwaysIncludeUserClaimsInIdTokenFalse
System.Identity-2/IdentityTokenLifetimeFalse
System.Identity-2/AllowedIdentityTokenSigningAlgorithmsFalse
System.Identity-2/AccessTokenLifetimeFalse
System.Identity-2/AuthorizationCodeLifetimeFalse
System.Identity-2/AbsoluteRefreshTokenLifetimeFalse
System.Identity-2/SlidingRefreshTokenLifetimeFalse
System.Identity-2/ConsentLifetimeTrue
System.Identity-2/UpdateAccessTokenClaimsOnRefreshFalse
System.Identity-2/RefreshTokenExpirationFalse
System.Identity-2/AccessTokenTypeFalse
System.Identity-2/EnableLocalLoginFalse
System.Identity-2/IdentityProviderRestrictionsFalse
System.Identity-2/IncludeJwtIdFalse
System.Identity-2/ClientClaimsFalse
System.Identity-2/AlwaysSendClientClaimsFalse
System.Identity-2/ClientClaimsPrefixTrue
System.Identity-2/PairWiseSubjectSaltTrue
System.Identity-2/UserSsoLifetimeTrue
System.Identity-2/UserCodeTypeTrue
System.Identity-2/DeviceCodeLifetimeFalse
System.Identity-2/CibaLifetimeTrue
System.Identity-2/PollingIntervalTrue
System.Identity-2/CoordinateLifetimeWithUserSessionTrue
System.Identity-2/AllowedCorsOriginsFalse
System.Identity-2/InitiateLoginUriTrue
System.Identity-2/AutoProvisionInChildTenantsFalse
System.Identity-2/ProvisionedByParentTenantIdTrue
System.Identity-2/DynamicRegistrationFalse
System.Identity-2/DynamicRegistrationExpiresAtTrue

Outbound Associations​

Outbound NameOutbound MultiplicityCkRoleIdTargetCKTypeIdTarget Attributes
AssignedRolesNSystem.Identity-2/AssignedRoleSystem.Identity-2/Role

Inbound Associations​

Inbound NameInbound MultiplicityCkRoleIdTargetCKTypeIdTarget Attributes
ImpersonatorsNSystem.Identity-2/MayActAsSystem.Identity-2/Client

ClientMirror​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/ClientMirror-1

Tracks a ClientCredentials client that the parent tenant has auto-provisioned into a child tenant. Lives in the parent tenant's database. One row per (parentClientId × childTenantId) pair.

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System.Identity-2/ClientIdFalse
System.Identity-2/ParentTenantIdFalse
System.Identity-2/ChildTenantIdFalse
System.Identity-2/ProvisionedAtFalse
System.Identity-2/SecretHashVersionFalse

DataPermission​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/DataPermission-1

Named data permission (dot-namespaced), granted to roles via GrantsPermission; DataPolicies bind it to CK types (AB#4972).

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System.Identity-2/PermissionIdFalse
System-2/DescriptionTrue

DataPolicy​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/DataPolicy-1

Binds a DataPermission to CK types with actions, scope and enforcement mode. A CK type is protected as soon as any policy targets it (AB#4972).

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System.Identity-2/TargetCkTypeIdsFalse
System.Identity-2/PolicyActionsFalse
System.Identity-2/PolicyScopeFalse
System.Identity-2/PolicyEnforcementModeFalse

Outbound Associations​

Outbound NameOutbound MultiplicityCkRoleIdTargetCKTypeIdTarget Attributes
PermissionOneSystem.Identity-2/PolicyPermissionSystem.Identity-2/DataPermission

DataProtectionKey​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/DataProtectionKey-1

ASP.NET Data Protection key-ring element. Service-global data persisted in the system tenant so every identity pod shares one key ring (replaces the file-system/PVC key store).

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System.Identity-2/FriendlyNameFalse
System.Identity-2/XmlDataFalse
System.Identity-2/CreationDateTimeFalse

EmailDomainGroupRule​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/EmailDomainGroupRule-1

Maps an email domain pattern to a group for automatic group assignment on user login.

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System.Identity-2/EmailDomainPatternFalse
System.Identity-2/TargetGroupRtIdFalse
System-2/DescriptionTrue

ExternalTenantUserMapping​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/ExternalTenantUserMapping-1

Maps a user from a parent tenant to roles in this (child) tenant.

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System.Identity-2/SourceTenantIdFalse
System.Identity-2/SourceUserIdFalse
System.Identity-2/SourceUserNameFalse
System.Identity-2/MappedRoleIdsTrue

FacebookIdentityProvider​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/IdentityProvider-1 ➔ System.Identity-2.22.0/FacebookIdentityProvider-1 No description available currently.

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System.Identity-2/ClientIdFalse
System.Identity-2/ClientSecretFalse

GoogleIdentityProvider​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/IdentityProvider-1 ➔ System.Identity-2.22.0/GoogleIdentityProvider-1 No description available currently.

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System.Identity-2/ClientIdFalse
System.Identity-2/ClientSecretFalse

Group​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/Group-1

A group that can be assigned roles. Users and other groups can be members.

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System.Identity-2/GroupNameFalse
System.Identity-2/NormalizedGroupNameFalse
System.Identity-2/GroupDescriptionTrue

Outbound Associations​

Outbound NameOutbound MultiplicityCkRoleIdTargetCKTypeIdTarget Attributes
AssignedRolesNSystem.Identity-2/AssignedRoleSystem.Identity-2/Role

Inbound Associations​

Inbound NameInbound MultiplicityCkRoleIdTargetCKTypeIdTarget Attributes
ParentGroupsNSystem.Identity-2/ChildGroupSystem.Identity-2/Group

IdentityProvider​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/IdentityProvider-1 No description available currently.

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System-2/NameFalse
System-2/EnabledFalse
System-2/DisplayNameTrue
System-2/DescriptionTrue
System.Identity-2/AllowSelfRegistrationFalse
System.Identity-2/DefaultGroupRtIdTrue

IdentityResource​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/Resource-1 ➔ System.Identity-2.22.0/IdentityResource-1 No description available currently.

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System.Identity-2/IsEmphasizedFalse
System.Identity-2/IsRequiredFalse

MicrosoftAdIdentityProvider​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/IdentityProvider-1 ➔ System.Identity-2.22.0/MicrosoftAdIdentityProvider-1 No description available currently.

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System.Identity-2/HostFalse
System.Identity-2/UseTlsFalse
System.Identity-2/PortFalse
System.Identity-2/UserBaseDnTrue
System.Identity-2/UserNameAttributeTrue

MicrosoftIdentityProvider​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/IdentityProvider-1 ➔ System.Identity-2.22.0/MicrosoftIdentityProvider-1 No description available currently.

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System.Identity-2/ClientIdFalse
System.Identity-2/ClientSecretFalse

OAuthAuthorization​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/OAuthAuthorization-1

OpenIddict authorization (AB#4989/AB#4991): the durable link between a subject, a client and the granted scopes - permanent authorizations represent remembered consent, ad-hoc authorizations tie the tokens of one flow together. Replaces the consent/authorization role of PersistedGrant after the OpenIddict migration (AB#4989).

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System.Identity-2/SubjectIdTrue
System.Identity-2/ClientIdFalse
System.Identity-2/AuthorizationTypeTrue
System.Identity-2/StatusTrue
System.Identity-2/ScopesFalse
System.Identity-2/PropertiesTrue
System.Identity-2/CreationDateTimeTrue

OAuthToken​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/OAuthToken-1

OpenIddict token (AB#4989/AB#4991): server-side record of authorization codes, refresh tokens and device/user codes - status, lifetime and (for reference tokens) the protected payload looked up via the hashed ReferenceId. Replaces the token role of PersistedGrant after the OpenIddict migration (AB#4989). Stored per tenant like PersistedGrant (AB#1586).

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System.Identity-2/AuthorizationRtIdTrue
System.Identity-2/TokenTypeTrue
System.Identity-2/ReferenceIdTrue
System.Identity-2/SubjectIdTrue
System.Identity-2/ClientIdTrue
System.Identity-2/StatusTrue
System.Identity-2/PayloadTrue
System.Identity-2/PropertiesTrue
System.Identity-2/CreationDateTimeTrue
System.Identity-2/ExpirationDateTimeTrue
System.Identity-2/RedemptionDateTimeTrue

OctoTenantIdentityProvider​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/IdentityProvider-1 ➔ System.Identity-2.22.0/OctoTenantIdentityProvider-1

Identity provider that delegates authentication to a parent tenant.

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System.Identity-2/ParentTenantIdFalse

OpenLdapIdentityProvider​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/IdentityProvider-1 ➔ System.Identity-2.22.0/OpenLdapIdentityProvider-1 No description available currently.

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System.Identity-2/HostFalse
System.Identity-2/UseTlsFalse
System.Identity-2/PortFalse
System.Identity-2/UserBaseDnFalse
System.Identity-2/UserNameAttributeFalse

Permission​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/Permission-1 No description available currently.

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System.Identity-2/PermissionIdFalse
System.Identity-2/IdentityRoleIdsFalse

PermissionRole​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/PermissionRole-1 No description available currently.

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System-2/NameFalse
System.Identity-2/RoleIdFalse
System.Identity-2/SubjectIdsFalse
System.Identity-2/IdentityRoleIdsFalse

PersistedGrant​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/PersistedGrant-1 No description available currently.

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System.Identity-2/GrantKeyFalse
System.Identity-2/GrantTypeFalse
System.Identity-2/SubjectIdFalse
System.Identity-2/SessionIdTrue
System.Identity-2/ClientIdFalse
System-2/DescriptionTrue
System.Identity-2/CreationDateTimeFalse
System.Identity-2/ExpirationDateTimeTrue
System.Identity-2/ConsumedDateTimeTrue
System.Identity-2/DataFalse

Resource​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/Resource-1 No description available currently.

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System-2/EnabledFalse
System-2/NameFalse
System-2/DisplayNameTrue
System-2/DescriptionTrue
System.Identity-2/ResourceClaimsFalse
System.Identity-2/ShowInDiscoveryDocumentFalse

Role​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/Role-1 No description available currently.

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System-2/NameFalse
System.Identity-2/NormalizedNameFalse
System.Identity-2/SubjectIdsFalse
System.Identity-2/IdentityRoleIdsFalse
System.Identity-2/RoleClaimsTrue

Outbound Associations​

Outbound NameOutbound MultiplicityCkRoleIdTargetCKTypeIdTarget Attributes
GrantedPermissionsNSystem.Identity-2/GrantsPermissionSystem.Identity-2/DataPermission

Inbound Associations​

Inbound NameInbound MultiplicityCkRoleIdTargetCKTypeIdTarget Attributes
AssignedEntitiesNSystem.Identity-2/AssignedRoleSystem.Identity-2/Client

ServerSideSession​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/ServerSideSession-1

Server-side authentication session (cookie ticket store). Holds the data-protected authentication ticket server-side so the per-tenant browser cookie only carries a session key (fixes multi-KB cookie bloat).

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System.Identity-2/SessionKeyFalse
System.Identity-2/SchemeFalse
System.Identity-2/SubjectIdFalse
System.Identity-2/SessionIdFalse
System.Identity-2/DisplayNameTrue
System.Identity-2/CreationDateTimeFalse
System.Identity-2/RenewalDateTimeFalse
System.Identity-2/ExpirationDateTimeTrue
System.Identity-2/TicketFalse

User​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/User-1 No description available currently.

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System.Identity-2/UserNameTrue
System.Identity-2/NormalizedUserNameTrue
System.Identity-2/FirstNameTrue
System.Identity-2/LastNameTrue
System-2/DescriptionTrue
System.Identity-2/EmailTrue
System.Identity-2/NormalizedEmailTrue
System.Identity-2/EmailConfirmedFalse
System.Identity-2/PasswordHashTrue
System.Identity-2/SecurityStampTrue
System.Identity-2/PhoneNumberTrue
System.Identity-2/PhoneNumberConfirmedFalse
System.Identity-2/TwoFactorEnabledFalse
System.Identity-2/PreferredChannelBindingIdTrue
System.Identity-2/LockoutEndTrue
System.Identity-2/LockoutEnabledFalse
System.Identity-2/AccessFailedCountFalse
System.Identity-2/ResetPasswordOnLoginFalse
System.Identity-2/UserClaimsTrue
System.Identity-2/UserLoginsTrue
System.Identity-2/UserTokensTrue

Outbound Associations​

Outbound NameOutbound MultiplicityCkRoleIdTargetCKTypeIdTarget Attributes
AssignedRolesNSystem.Identity-2/AssignedRoleSystem.Identity-2/Role

Inbound Associations​

Inbound NameInbound MultiplicityCkRoleIdTargetCKTypeIdTarget Attributes
MemberOfGroupsNSystem.Identity-2/GroupMemberSystem.Identity-2/Group

VerifiedExternalIdentifier​

Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/VerifiedExternalIdentifier-1

Maps a verified external identifier (phone number, e-mail address, EntraID object id or client certificate fingerprint) to an OctoMesh user, carrying the ENROLLMENT trust dimension of the two-dimension channel-identity trust model (AB#5122, Epic AB#4979). The second dimension (per-message trust) is NOT stored here: it depends on the incoming message (Signal protocol / DKIM validity) and is combined by the resolver at resolution time as effective = min(enrollmentTrust, messageTrust). Uniqueness: an (IdentifierKind, IdentifierValue) pair resolves to at most one user within a tenant, enforced by the Unique index below.

IDAuto Complete ValuesAuto Increment ReferenceIs Optional
System.Identity-2/IdentifierKindFalse
System.Identity-2/IdentifierValueFalse
System.Identity-2/EnrollmentTrustFalse
System.Identity-2/RequiredMessageAuthenticationFalse
System.Identity-2/IdentifierSourceFalse
System.Identity-2/EnrolledAtTrue
System.Identity-2/LastVerifiedAtTrue
System.Identity-2/ValidUntilTrue

Outbound Associations​

Outbound NameOutbound MultiplicityCkRoleIdTargetCKTypeIdTarget Attributes
UserOneSystem.Identity-2/IdentifiesUserSystem.Identity-2/User