Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions astro/src/content/docs/identityserver/samples/saml.mdx
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
---
title: "SAML"
description: "Samples demonstrating SAML 2.0 integration with Duende IdentityServer as an Identity Provider."
date: 2026-06-02
sidebar:
order: 45
---
Expand Down
41 changes: 41 additions & 0 deletions astro/src/content/docs/identityserver/samples/usermanagement.mdx
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
---
title: "User Management"
description: "Sample demonstrating a complete IdentityServer v8 implementation using Duende User Management with multiple authentication methods, profile management, and ASP.NET Identity migration."
date: 2026-06-02
sidebar:
order: 48
---

import { LinkCard } from "@astrojs/starlight/components";

This section contains a sample demonstrating [Duende User Management](/identityserver/usermanagement/index.mdx) with IdentityServer.
User Management is a user store and authentication platform that ships as a NuGet package and replaces ASP.NET Identity for IdentityServer scenarios.

### User Management Sample

This sample demonstrates a full IdentityServer deployment using Duende User Management for user storage and authentication.
It covers multiple authentication methods working together in a single application, orchestrated by .NET Aspire.

**Authentication methods demonstrated:**

- **Email OTP**: enter email, receive a code via SMTP, verify, and sign in (unknown emails are auto-registered)
- **Password + TOTP 2FA**: email/password login with time-based one-time password as a second factor
- **Passkeys**: after first OTP login, users are prompted to register a passkey for future passwordless sign-in
- **Passkey as second factor**: after password verification, users can tap a passkey instead of entering a TOTP code
- **Google external login**: OAuth callback creates or links a local profile automatically

**Additional features:**

- **User profile management** using a schema-driven attribute model (extensible attributes rather than a fixed user table)
- **ASP.NET Identity migration**: the Admin Import page demonstrates bulk-importing users from an existing ASP.NET Identity database, including password hash compatibility, claims-to-attributes mapping, and deterministic subject ID generation
- **Second factor state management**: encrypted cookies coordinate the 2FA flow between password verification and TOTP/passkey completion

The sample uses .NET Aspire to orchestrate IdentityServer, a client application, and Mailpit (for local email testing)
in a single `dotnet run` command.

<LinkCard
description="GitHub Repository for the User Management Sample"
href="https://github.com/DuendeSoftware/samples/tree/main/IdentityServer/v8/UserManagement"
title="User Management Sample"
target="_blank"
/>
Original file line number Diff line number Diff line change
Expand Up @@ -158,4 +158,5 @@ The best starting point depends on where your users live today:
<LinkCard title="Migrating from ASP.NET Identity" href="/identityserver/usermanagement/import/aspnet-identity" description="Step-by-step guide covering source data extraction, password hash verification, and building import records." />
<LinkCard title="Import API reference" href="/identityserver/usermanagement/import/reference" description="Full reference for IUserImporter, UserImportRecord, conflict resolution, and result handling." />
<LinkCard title="Password hashing algorithms" href="/identityserver/usermanagement/reference/password-hashing" description="Implement and register a custom IPasswordHashAlgorithm to verify hashes from your source system." />
<LinkCard title="User Management Sample" href="/identityserver/samples/usermanagement" description="A working sample that includes ASP.NET Identity migration with password hash compatibility and claims-to-attributes mapping." />
</CardGrid>
Original file line number Diff line number Diff line change
Expand Up @@ -79,4 +79,5 @@ See the [glossary](/general/glossary.mdx) for definitions of terms used througho
<LinkCard title="IdentityServer Integration" href="/identityserver/usermanagement/identityserver-integration" description="Add User Management to an existing or new IdentityServer deployment." />
<LinkCard title="Authentication Flows" href="/identityserver/usermanagement/authentication/overview" description="Compare OTP, TOTP, passkeys, passwords, external providers, and recovery codes." />
<LinkCard title="Configuration Reference" href="/identityserver/usermanagement/reference/configuration" description="All configuration options for authentication, profiles, and membership modules." />
<LinkCard title="Sample Application" href="/identityserver/samples/usermanagement" description="A complete sample showing OTP, passwords, passkeys, external login, profile management, and ASP.NET Identity migration." />
</CardGrid>
Loading