Ship the first-party Authentication, OAuth, and Authorization stack.
- Authentication is separate from OAuth: global
IdentityId, isolated credential vault, no password grant. - OAuth is Authorization Code + mandatory S256 PKCE, client credentials, rotating refresh tokens, ES384 JWTs, and RFC 8414 discovery.
- Authorization is tenant-scoped RBAC with groups, roles, composite roles, and default deny.
- Packable surfaces:
Novolis.Security.Authentication.*,Novolis.Security.OAuth.*,Novolis.Security.Authorization.*.
GitHub Packages: 2026.1.* from merge.yml. nuget.org versions use this release line plus the release workflow run number.