TraxAuthClaimTypes
NO WARRANTY. Trax auth is plumbing, not a security product. You are solely responsible for securing systems that use it. See API Security.
Canonical claim URNs used by every Trax authentication scheme.
| Constant | Value | Produced by |
|---|---|---|
PrincipalId | trax:principal-id | TraxPrincipal.Id, qualified by the scheme: {scheme}:{id} |
PrincipalType | trax:principal-type | TraxPrincipal.PrincipalType (optional) |
TraxAuthPolicy | TraxAuthPolicy | Combined authorization policy that accepts any registered Trax auth scheme. |
The id is qualified by the scheme that authenticated it, so the same sub from two issuers is two principals: sub = "abc" on a JWT scheme named Customer is Customer:abc. TraxPrincipalId.Qualify(scheme, id) computes it; a scheme name containing : is refused. See Qualified Principal Ids.
Using a custom URN (trax:principal-id) instead of ClaimTypes.NameIdentifier avoids collisions with ASP.NET Core Identity. Read via ClaimsPrincipal.TryGetPrincipalId(out var id) or FindFirst(TraxAuthClaimTypes.PrincipalId).