Types
ApiResource
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/Resource-1 ➔ System.Identity-2.22.0/ApiResource-1 No description available currently.
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System.Identity-2/RequireResourceIndicator | False | ||
| System.Identity-2/Secrets | False | ||
| System.Identity-2/Scopes | False | ||
| System.Identity-2/AllowedAccessTokenSigningAlgorithms | False |
ApiScope
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/Resource-1 ➔ System.Identity-2.22.0/ApiScope-1 No description available currently.
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System.Identity-2/IsEmphasized | False | ||
| System.Identity-2/IsRequired | False |
AzureEntraIdIdentityProvider
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/IdentityProvider-1 ➔ System.Identity-2.22.0/AzureEntraIdIdentityProvider-1 No description available currently.
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System-2/TenantId | False | ||
| System.Identity-2/Authority | True | ||
| System.Identity-2/ClientId | False | ||
| System.Identity-2/ClientSecret | False |
Client
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/Client-1 No description available currently.
Outbound Associations
| Outbound Name | Outbound Multiplicity | CkRoleId | TargetCKTypeId | Target Attributes |
|---|---|---|---|---|
| AssignedRoles | N | System.Identity-2/AssignedRole | System.Identity-2/Role |
Inbound Associations
| Inbound Name | Inbound Multiplicity | CkRoleId | TargetCKTypeId | Target Attributes |
|---|---|---|---|---|
| Impersonators | N | System.Identity-2/MayActAs | System.Identity-2/Client |
ClientMirror
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/ClientMirror-1
Tracks a ClientCredentials client that the parent tenant has auto-provisioned into a child tenant. Lives in the parent tenant's database. One row per (parentClientId × childTenantId) pair.
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System.Identity-2/ClientId | False | ||
| System.Identity-2/ParentTenantId | False | ||
| System.Identity-2/ChildTenantId | False | ||
| System.Identity-2/ProvisionedAt | False | ||
| System.Identity-2/SecretHashVersion | False |
DataPermission
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/DataPermission-1
Named data permission (dot-namespaced), granted to roles via GrantsPermission; DataPolicies bind it to CK types (AB#4972).
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System.Identity-2/PermissionId | False | ||
| System-2/Description | True |
DataPolicy
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/DataPolicy-1
Binds a DataPermission to CK types with actions, scope and enforcement mode. A CK type is protected as soon as any policy targets it (AB#4972).
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System.Identity-2/TargetCkTypeIds | False | ||
| System.Identity-2/PolicyActions | False | ||
| System.Identity-2/PolicyScope | False | ||
| System.Identity-2/PolicyEnforcementMode | False |
Outbound Associations
| Outbound Name | Outbound Multiplicity | CkRoleId | TargetCKTypeId | Target Attributes |
|---|---|---|---|---|
| Permission | One | System.Identity-2/PolicyPermission | System.Identity-2/DataPermission |
DataProtectionKey
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/DataProtectionKey-1
ASP.NET Data Protection key-ring element. Service-global data persisted in the system tenant so every identity pod shares one key ring (replaces the file-system/PVC key store).
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System.Identity-2/FriendlyName | False | ||
| System.Identity-2/XmlData | False | ||
| System.Identity-2/CreationDateTime | False |
EmailDomainGroupRule
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/EmailDomainGroupRule-1
Maps an email domain pattern to a group for automatic group assignment on user login.
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System.Identity-2/EmailDomainPattern | False | ||
| System.Identity-2/TargetGroupRtId | False | ||
| System-2/Description | True |
ExternalTenantUserMapping
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/ExternalTenantUserMapping-1
Maps a user from a parent tenant to roles in this (child) tenant.
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System.Identity-2/SourceTenantId | False | ||
| System.Identity-2/SourceUserId | False | ||
| System.Identity-2/SourceUserName | False | ||
| System.Identity-2/MappedRoleIds | True |
FacebookIdentityProvider
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/IdentityProvider-1 ➔ System.Identity-2.22.0/FacebookIdentityProvider-1 No description available currently.
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System.Identity-2/ClientId | False | ||
| System.Identity-2/ClientSecret | False |
GoogleIdentityProvider
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/IdentityProvider-1 ➔ System.Identity-2.22.0/GoogleIdentityProvider-1 No description available currently.
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System.Identity-2/ClientId | False | ||
| System.Identity-2/ClientSecret | False |
Group
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/Group-1
A group that can be assigned roles. Users and other groups can be members.
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System.Identity-2/GroupName | False | ||
| System.Identity-2/NormalizedGroupName | False | ||
| System.Identity-2/GroupDescription | True |
Outbound Associations
| Outbound Name | Outbound Multiplicity | CkRoleId | TargetCKTypeId | Target Attributes |
|---|---|---|---|---|
| AssignedRoles | N | System.Identity-2/AssignedRole | System.Identity-2/Role |
Inbound Associations
| Inbound Name | Inbound Multiplicity | CkRoleId | TargetCKTypeId | Target Attributes |
|---|---|---|---|---|
| ParentGroups | N | System.Identity-2/ChildGroup | System.Identity-2/Group |
IdentityProvider
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/IdentityProvider-1 No description available currently.
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System-2/Name | False | ||
| System-2/Enabled | False | ||
| System-2/DisplayName | True | ||
| System-2/Description | True | ||
| System.Identity-2/AllowSelfRegistration | False | ||
| System.Identity-2/DefaultGroupRtId | True |
IdentityResource
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/Resource-1 ➔ System.Identity-2.22.0/IdentityResource-1 No description available currently.
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System.Identity-2/IsEmphasized | False | ||
| System.Identity-2/IsRequired | False |
MicrosoftAdIdentityProvider
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/IdentityProvider-1 ➔ System.Identity-2.22.0/MicrosoftAdIdentityProvider-1 No description available currently.
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System.Identity-2/Host | False | ||
| System.Identity-2/UseTls | False | ||
| System.Identity-2/Port | False | ||
| System.Identity-2/UserBaseDn | True | ||
| System.Identity-2/UserNameAttribute | True |
MicrosoftIdentityProvider
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/IdentityProvider-1 ➔ System.Identity-2.22.0/MicrosoftIdentityProvider-1 No description available currently.
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System.Identity-2/ClientId | False | ||
| System.Identity-2/ClientSecret | False |
OAuthAuthorization
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/OAuthAuthorization-1
OpenIddict authorization (AB#4989/AB#4991): the durable link between a subject, a client and the granted scopes - permanent authorizations represent remembered consent, ad-hoc authorizations tie the tokens of one flow together. Replaces the consent/authorization role of PersistedGrant after the OpenIddict migration (AB#4989).
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System.Identity-2/SubjectId | True | ||
| System.Identity-2/ClientId | False | ||
| System.Identity-2/AuthorizationType | True | ||
| System.Identity-2/Status | True | ||
| System.Identity-2/Scopes | False | ||
| System.Identity-2/Properties | True | ||
| System.Identity-2/CreationDateTime | True |
OAuthToken
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/OAuthToken-1
OpenIddict token (AB#4989/AB#4991): server-side record of authorization codes, refresh tokens and device/user codes - status, lifetime and (for reference tokens) the protected payload looked up via the hashed ReferenceId. Replaces the token role of PersistedGrant after the OpenIddict migration (AB#4989). Stored per tenant like PersistedGrant (AB#1586).
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System.Identity-2/AuthorizationRtId | True | ||
| System.Identity-2/TokenType | True | ||
| System.Identity-2/ReferenceId | True | ||
| System.Identity-2/SubjectId | True | ||
| System.Identity-2/ClientId | True | ||
| System.Identity-2/Status | True | ||
| System.Identity-2/Payload | True | ||
| System.Identity-2/Properties | True | ||
| System.Identity-2/CreationDateTime | True | ||
| System.Identity-2/ExpirationDateTime | True | ||
| System.Identity-2/RedemptionDateTime | True |
OctoTenantIdentityProvider
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/IdentityProvider-1 ➔ System.Identity-2.22.0/OctoTenantIdentityProvider-1
Identity provider that delegates authentication to a parent tenant.
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System.Identity-2/ParentTenantId | False |
OpenLdapIdentityProvider
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/IdentityProvider-1 ➔ System.Identity-2.22.0/OpenLdapIdentityProvider-1 No description available currently.
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System.Identity-2/Host | False | ||
| System.Identity-2/UseTls | False | ||
| System.Identity-2/Port | False | ||
| System.Identity-2/UserBaseDn | False | ||
| System.Identity-2/UserNameAttribute | False |
Permission
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/Permission-1 No description available currently.
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System.Identity-2/PermissionId | False | ||
| System.Identity-2/IdentityRoleIds | False |
PermissionRole
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/PermissionRole-1 No description available currently.
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System-2/Name | False | ||
| System.Identity-2/RoleId | False | ||
| System.Identity-2/SubjectIds | False | ||
| System.Identity-2/IdentityRoleIds | False |
PersistedGrant
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/PersistedGrant-1 No description available currently.
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System.Identity-2/GrantKey | False | ||
| System.Identity-2/GrantType | False | ||
| System.Identity-2/SubjectId | False | ||
| System.Identity-2/SessionId | True | ||
| System.Identity-2/ClientId | False | ||
| System-2/Description | True | ||
| System.Identity-2/CreationDateTime | False | ||
| System.Identity-2/ExpirationDateTime | True | ||
| System.Identity-2/ConsumedDateTime | True | ||
| System.Identity-2/Data | False |
Resource
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/Resource-1 No description available currently.
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System-2/Enabled | False | ||
| System-2/Name | False | ||
| System-2/DisplayName | True | ||
| System-2/Description | True | ||
| System.Identity-2/ResourceClaims | False | ||
| System.Identity-2/ShowInDiscoveryDocument | False |
Role
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/Role-1 No description available currently.
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System-2/Name | False | ||
| System.Identity-2/NormalizedName | False | ||
| System.Identity-2/SubjectIds | False | ||
| System.Identity-2/IdentityRoleIds | False | ||
| System.Identity-2/RoleClaims | True |
Outbound Associations
| Outbound Name | Outbound Multiplicity | CkRoleId | TargetCKTypeId | Target Attributes |
|---|---|---|---|---|
| GrantedPermissions | N | System.Identity-2/GrantsPermission | System.Identity-2/DataPermission |
Inbound Associations
| Inbound Name | Inbound Multiplicity | CkRoleId | TargetCKTypeId | Target Attributes |
|---|---|---|---|---|
| AssignedEntities | N | System.Identity-2/AssignedRole | System.Identity-2/Client |
ServerSideSession
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/ServerSideSession-1
Server-side authentication session (cookie ticket store). Holds the data-protected authentication ticket server-side so the per-tenant browser cookie only carries a session key (fixes multi-KB cookie bloat).
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System.Identity-2/SessionKey | False | ||
| System.Identity-2/Scheme | False | ||
| System.Identity-2/SubjectId | False | ||
| System.Identity-2/SessionId | False | ||
| System.Identity-2/DisplayName | True | ||
| System.Identity-2/CreationDateTime | False | ||
| System.Identity-2/RenewalDateTime | False | ||
| System.Identity-2/ExpirationDateTime | True | ||
| System.Identity-2/Ticket | False |
User
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/User-1 No description available currently.
Outbound Associations
| Outbound Name | Outbound Multiplicity | CkRoleId | TargetCKTypeId | Target Attributes |
|---|---|---|---|---|
| AssignedRoles | N | System.Identity-2/AssignedRole | System.Identity-2/Role |
Inbound Associations
| Inbound Name | Inbound Multiplicity | CkRoleId | TargetCKTypeId | Target Attributes |
|---|---|---|---|---|
| MemberOfGroups | N | System.Identity-2/GroupMember | System.Identity-2/Group |
VerifiedExternalIdentifier
Inheritance: System-2.5.0/Entity-1 ➔ System.Identity-2.22.0/VerifiedExternalIdentifier-1
Maps a verified external identifier (phone number, e-mail address, EntraID object id or client certificate fingerprint) to an OctoMesh user, carrying the ENROLLMENT trust dimension of the two-dimension channel-identity trust model (AB#5122, Epic AB#4979). The second dimension (per-message trust) is NOT stored here: it depends on the incoming message (Signal protocol / DKIM validity) and is combined by the resolver at resolution time as effective = min(enrollmentTrust, messageTrust). Uniqueness: an (IdentifierKind, IdentifierValue) pair resolves to at most one user within a tenant, enforced by the Unique index below.
| ID | Auto Complete Values | Auto Increment Reference | Is Optional |
|---|---|---|---|
| System.Identity-2/IdentifierKind | False | ||
| System.Identity-2/IdentifierValue | False | ||
| System.Identity-2/EnrollmentTrust | False | ||
| System.Identity-2/RequiredMessageAuthentication | False | ||
| System.Identity-2/IdentifierSource | False | ||
| System.Identity-2/EnrolledAt | True | ||
| System.Identity-2/LastVerifiedAt | True | ||
| System.Identity-2/ValidUntil | True |
Outbound Associations
| Outbound Name | Outbound Multiplicity | CkRoleId | TargetCKTypeId | Target Attributes |
|---|---|---|---|---|
| User | One | System.Identity-2/IdentifiesUser | System.Identity-2/User |