TraxAuthClaimTypes

NO WARRANTY. Trax auth is plumbing, not a security product. You are solely responsible for securing systems that use it. See API Security.

Canonical claim URNs used by every Trax authentication scheme.

ConstantValueProduced by
PrincipalIdtrax:principal-idTraxPrincipal.Id, qualified by the scheme: {scheme}:{id}
PrincipalTypetrax:principal-typeTraxPrincipal.PrincipalType (optional)
TraxAuthPolicyTraxAuthPolicyCombined authorization policy that accepts any registered Trax auth scheme.

The id is qualified by the scheme that authenticated it, so the same sub from two issuers is two principals: sub = "abc" on a JWT scheme named Customer is Customer:abc. TraxPrincipalId.Qualify(scheme, id) computes it; a scheme name containing : is refused. See Qualified Principal Ids.

Using a custom URN (trax:principal-id) instead of ClaimTypes.NameIdentifier avoids collisions with ASP.NET Core Identity. Read via ClaimsPrincipal.TryGetPrincipalId(out var id) or FindFirst(TraxAuthClaimTypes.PrincipalId).