Mingoll.OpenIddict.Management.Storage.EfCore
2.0.0
dotnet add package Mingoll.OpenIddict.Management.Storage.EfCore --version 2.0.0
NuGet\Install-Package Mingoll.OpenIddict.Management.Storage.EfCore -Version 2.0.0
<PackageReference Include="Mingoll.OpenIddict.Management.Storage.EfCore" Version="2.0.0" />
<PackageVersion Include="Mingoll.OpenIddict.Management.Storage.EfCore" Version="2.0.0" />
<PackageReference Include="Mingoll.OpenIddict.Management.Storage.EfCore" />
paket add Mingoll.OpenIddict.Management.Storage.EfCore --version 2.0.0
#r "nuget: Mingoll.OpenIddict.Management.Storage.EfCore, 2.0.0"
#:package Mingoll.OpenIddict.Management.Storage.EfCore@2.0.0
#addin nuget:?package=Mingoll.OpenIddict.Management.Storage.EfCore&version=2.0.0
#tool nuget:?package=Mingoll.OpenIddict.Management.Storage.EfCore&version=2.0.0
OpenIddict.Management.Storage.EfCore
OpenIddict.Management.Storage.EfCore (Mingoll.OpenIddict.Management.Storage.EfCore) delivers complete Entity Framework Core persistence implementations for the OpenIddict Management ecosystem.
Install this package when using EF Core (SQL Server, PostgreSQL, SQLite, MySQL) as your backing database. It provides out-of-the-box management store implementations (EfCoreApplicationManagementStore, EfCoreTokenStore, EfCoreAuthorizationStore, EfCoreScopeManagementStore), enhanced entity types with auditing and metadata properties, batch/bulk operation execution, client secret rotation, and fluent ModelBuilder extensions.
Installation
Install via the .NET CLI:
dotnet add package Mingoll.OpenIddict.Management.Storage.EfCore
Or via the Visual Studio Package Manager Console:
Install-Package Mingoll.OpenIddict.Management.Storage.EfCore
Prerequisites & Dependencies
Supported Frameworks
- .NET 8.0 (LTS)
- .NET 9.0 (STS)
- .NET 10.0
Required Package Dependencies
Mingoll.OpenIddict.Management.Core(Abstractions, models, contracts, audit logging)OpenIddict.EntityFrameworkCore(>= 6.x / 7.x)Microsoft.EntityFrameworkCore.Relational(>= 8.x / 9.x / 10.x)
Companion Database Providers
You must reference your preferred EF Core database provider in your host application:
Microsoft.EntityFrameworkCore.SqlServerMicrosoft.EntityFrameworkCore.SqliteNpgsql.EntityFrameworkCore.PostgreSQLPomelo.EntityFrameworkCore.MySql
Configuration & Setup
1. Configure the DbContext
Extend DbContext and register the enhanced management entities. In OnModelCreating, invoke modelBuilder.UseOpenIddictManagement():
using Microsoft.EntityFrameworkCore;
using OpenIddict.Management.Storage.EfCore.Entities;
using OpenIddict.Management.Storage.EfCore.Extensions;
public class ApplicationDbContext(DbContextOptions<ApplicationDbContext> options) : DbContext(options)
{
public DbSet<ManagementApplication<Guid>> Applications => Set<ManagementApplication<Guid>>();
public DbSet<ManagementAuthorization<Guid>> Authorizations => Set<ManagementAuthorization<Guid>>();
public DbSet<ManagementScope<Guid>> Scopes => Set<ManagementScope<Guid>>();
public DbSet<ManagementToken<Guid>> Tokens => Set<ManagementToken<Guid>>();
protected override void OnModelCreating(ModelBuilder modelBuilder)
{
base.OnModelCreating(modelBuilder);
// Configures table mappings, indexes, and relationships for OpenIddict Management entities
modelBuilder.UseOpenIddictManagement();
// For custom primary key types (e.g., int, string):
// modelBuilder.UseOpenIddictManagement<string>();
}
}
2. Register Services in Program.cs
Option A: Unified Registration (Core + EF Core Stores) — Recommended
using Microsoft.EntityFrameworkCore;
using OpenIddict.Management.Storage.EfCore.Extensions;
var builder = WebApplication.CreateBuilder(args);
builder.Services.AddDbContext<ApplicationDbContext>(options =>
{
options.UseSqlServer(builder.Configuration.GetConnectionString("DefaultConnection"));
});
// Registers Core services, EF Core stores, event dispatching, and OpenIddict Core entity mappings in one call
builder.Services.AddOpenIddictManagement<ApplicationDbContext>(options =>
{
options.RoutePrefix = "/api/management";
options.RequireHttps = true;
options.EnableAuditLogging = true;
});
Option B: Fluent Builder Registration
using OpenIddict.Management.Extensions;
using OpenIddict.Management.Storage.EfCore.Extensions;
builder.Services.AddOpenIddictManagement(options =>
{
options.EnableAuditLogging = true;
})
.AddEfCoreStores<ApplicationDbContext>();
Option C: Custom Primary Key Type (TKey)
If your database uses string or int identifiers instead of Guid:
builder.Services.AddOpenIddictManagement<ApplicationDbContext, string>();
Option D: Individual Store Override
If you need to customize an individual store while preserving the rest:
builder.Services.AddApplicationManagementStore<MyCustomAppStore>();
builder.Services.AddTokenStore<MyCustomTokenStore>();
Store Implementations & Features
EfCoreApplicationManagementStore(IApplicationManagementService):- Full CRUD operations with rich entity mapping (
Status,Environment,Tags,AllowedRolesJson,Description,ExtraData). - Native client secret rotation with
UpdateClientSecretAsync. - Batch operations:
BulkCreateAsyncandBulkDeleteAsyncreturningBulkOperationResultDto. - Environment-wide status transitions via
SetStatusByEnvironmentAsync. - Automatic event dispatching to
IManagementEventPublisherfor audit trail tracking.
- Full CRUD operations with rich entity mapping (
EfCoreScopeManagementStore(IScopeManagementService):- Scope CRUD, resource mappings, descriptions, and paginated searches.
- Batch creation (
BulkCreateAsync) and batch deletion (BulkDeleteAsync).
EfCoreTokenStore(IOpenIddictTokenManager):- Filtered token queries, token count aggregations, and daily issuance timelines.
- Revocation by user ID, client ID, session ID, or individual token ID.
EfCoreAuthorizationStore(IOpenIddictAuthorizationManager):- Authorization tracking, session queries, and bulk session revocation.
Usage Example
Injecting and Using Management Services
using OpenIddict.Abstractions;
using OpenIddict.Management.Contracts;
using OpenIddict.Management.Dto;
using OpenIddict.Management.Enums;
using OpenIddict.Management.Results;
public class IdentityAdministrationService(
IApplicationManagementService applicationService,
IOpenIddictTokenManager tokenManager,
IScopeManagementService scopeService)
{
public async Task CreateClientAppAsync(CancellationToken cancellationToken)
{
// 1. Create a client application
var createResult = await applicationService.CreateAsync(new ApplicationCreateDto
{
ClientId = "mobile-portal-app",
DisplayName = "Mobile Portal Application",
ClientSecret = "SuperSecretKey987654!",
Environment = ApplicationEnvironment.Production,
ContactEmail = "security@enterprise.local",
Organization = "Enterprise Mobile Team",
Tags = ["Mobile", "iOS", "Android"],
Permissions = [
OpenIddictConstants.Permissions.Endpoints.Token,
OpenIddictConstants.Permissions.Endpoints.Authorization,
OpenIddictConstants.Permissions.GrantTypes.AuthorizationCode,
OpenIddictConstants.Permissions.GrantTypes.RefreshToken,
OpenIddictConstants.Permissions.ResponseTypes.Code,
OpenIddictConstants.Permissions.Prefixes.Scope + "api_read"
],
RedirectUris = ["https://mobile.enterprise.local/callback"]
}, cancellationToken);
if (!createResult.IsSuccess)
{
throw new InvalidOperationException($"Creation failed: {createResult.Error.Description}");
}
// 2. Rotate client secret
await applicationService.UpdateClientSecretAsync(
createResult.Value!.Id,
"NewRotatedSecretKey987654!",
cancellationToken);
// 3. Batch delete applications
await applicationService.BulkDeleteAsync(["old-app-id-1", "old-app-id-2"], cancellationToken);
}
public async Task RevokeUserSessionsAsync(string userId, CancellationToken cancellationToken)
{
// Revoke all active tokens for a specific user across all clients
Result<RevocationResultDto> revocationResult = await tokenManager.RevokeByUserAsync(userId, cancellationToken);
if (revocationResult.IsSuccess)
{
Console.WriteLine($"Revoked {revocationResult.Value.RevokedTokensCount} tokens for user {userId}.");
}
}
public async Task<PagedResult<TokenListDto>> QueryActiveTokensAsync(CancellationToken cancellationToken)
{
// Query tokens with typed filters
var filter = new TokenFilterRequest
{
Page = 1,
PageSize = 25,
Status = TokenStatus.Valid,
Type = OpenIddictConstants.TokenTypeHints.AccessToken
};
var result = await tokenManager.ListTokensAsync(filter, cancellationToken);
return result.Value;
}
}
Related Packages
| Package | Purpose |
|---|---|
Mingoll.OpenIddict.Management.Core |
Shared contracts, DTOs, domain models, audit trail models, and options. |
Mingoll.OpenIddict.Management.Endpoints |
Ready-to-map ASP.NET Core Minimal API endpoint groups. |
Mingoll.OpenIddict.Management.Dashboard |
Razor Class Library admin dashboard UI for visual database administration. |
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 is compatible. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Microsoft.EntityFrameworkCore (>= 10.0.12)
- Microsoft.EntityFrameworkCore.Relational (>= 10.0.12)
- Microsoft.Extensions.DependencyInjection (>= 10.0.12)
- Microsoft.Extensions.Hosting.Abstractions (>= 10.0.12)
- Microsoft.Extensions.Logging.Abstractions (>= 10.0.12)
- Microsoft.Extensions.Options (>= 10.0.12)
- Mingoll.OpenIddict.Management.Core (>= 2.0.0)
- OpenIddict.Abstractions (>= 7.7.1)
- OpenIddict.Core (>= 7.7.1)
- OpenIddict.EntityFrameworkCore (>= 7.7.1)
- OpenIddict.Server (>= 7.7.1)
- OpenIddict.Validation (>= 7.7.1)
-
net8.0
- Microsoft.EntityFrameworkCore (>= 8.0.31)
- Microsoft.EntityFrameworkCore.Relational (>= 8.0.31)
- Microsoft.Extensions.DependencyInjection (>= 8.0.1)
- Microsoft.Extensions.Hosting.Abstractions (>= 8.0.1)
- Microsoft.Extensions.Logging.Abstractions (>= 8.0.2)
- Microsoft.Extensions.Options (>= 8.0.2)
- Mingoll.OpenIddict.Management.Core (>= 2.0.0)
- OpenIddict.Abstractions (>= 7.7.1)
- OpenIddict.Core (>= 7.7.1)
- OpenIddict.EntityFrameworkCore (>= 7.7.1)
- OpenIddict.Server (>= 7.7.1)
- OpenIddict.Validation (>= 7.7.1)
-
net9.0
- Microsoft.EntityFrameworkCore (>= 9.0.20)
- Microsoft.EntityFrameworkCore.Relational (>= 9.0.20)
- Microsoft.Extensions.DependencyInjection (>= 9.0.20)
- Microsoft.Extensions.Hosting.Abstractions (>= 9.0.20)
- Microsoft.Extensions.Logging.Abstractions (>= 9.0.20)
- Microsoft.Extensions.Options (>= 9.0.20)
- Mingoll.OpenIddict.Management.Core (>= 2.0.0)
- OpenIddict.Abstractions (>= 7.7.1)
- OpenIddict.Core (>= 7.7.1)
- OpenIddict.EntityFrameworkCore (>= 7.7.1)
- OpenIddict.Server (>= 7.7.1)
- OpenIddict.Validation (>= 7.7.1)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.