---
title: "Orleans.Lattice.Api.Auth configuration"
url: "https://nsta1.github.io/Orleans.Lattice/docs/lattice.api.auth/configuration.html"
source: "https://github.com/NSTA1/Orleans.Lattice/blob/release/9.9/docs/lattice.api.auth/configuration.md"
package: "Orleans.Lattice.Api.Auth"
version: "9.9.0"
documents: "Orleans.Lattice 9.9.0 (release line 9.9)"
built: "2026-10-04"
all-pages: "https://nsta1.github.io/Orleans.Lattice/llms.txt"
bundle: "https://nsta1.github.io/Orleans.Lattice/docs/lattice.api.auth/llms-full.txt"
---
# Orleans.Lattice.Api.Auth configuration

Part of the [Api.Auth documentation](README.md).

The facade package (`Orleans.Lattice.Api.Auth`) has one public options type, `LatticeApiAuthOptions`, the configuration and control facade for membership and authorization policy administration. It is bound through the `AddLatticeAuthApi` registration extension and resolvable via `IOptions<LatticeApiAuthOptions>`. The sibling gRPC binding package (`Orleans.Lattice.Api.Auth.Grpc`) adds one more public options type, `LatticeAuthApiGrpcOptions`, documented in [gRPC binding options](#grpc-binding-options) below.

The facade adds no authorization posture of its own beyond requiring an administrator: every operation routes through the same enforcement the in-cluster data path uses, anchored on the authorization package's bootstrap root-of-trust. Its single knob bounds the debugging / dashboard reads so a single call cannot enumerate an unbounded rule set.

## `LatticeApiAuthOptions`

Bounds the introspection reads of the auth control facade. Bind it through `AddLatticeAuthApi(configure)`.

| Property | Type | Default | Meaning |
|---|---|---|---|
| `MaxExplanationRules` | `int` | `1000` | Largest number of applying rules an explain / effective-permissions introspection result collects before it stops scanning, bounding the work and payload of a single introspection call. |

## gRPC binding options

`LatticeAuthApiGrpcOptions` (namespace `Orleans.Lattice.Api.Auth.Grpc`) controls the server-side gRPC binding of the auth control plane. Because administering policy is the most sensitive surface in the cluster, the defaults are fail-closed. Bind it through the gRPC package's `AddLatticeAuthApiGrpc(configure)` registration extension (the endpoint is then mapped with `MapLatticeAuthApiGrpc`).

| Property | Type | Default | Meaning |
|---|---|---|---|
| `RequireAuthorization` | `bool` | `true` | Whether the binding's authorization interceptor enforces the registered authorizer on every inbound admin call (default-deny). Turning it off does not open the surface: the facade's own per-call administrator check still runs. |
| `CredentialHeaderName` | `string` | `"authorization"` | The inbound request-header (gRPC metadata) name carrying the caller's credential token, bridged into the ambient Lattice credential so the facade's administrator check can resolve the caller's subject. |
| `CredentialScheme` | `string` | `"Bearer"` | The authentication scheme stamped on the bridged credential, matched by a registered credential authenticator to resolve the caller's subject. A case-insensitive scheme prefix on the header value (for example `"Bearer "`) is stripped before the remaining token is used. |
| `ActiveTenantHeaderName` | `string?` | `"lattice-active-tenant"` | The inbound request-header (gRPC metadata) name carrying the caller's asserted active tenant. Honoured only by a `ListRules` call whose `AuthPageRequest.ActiveTenantOnly` is set; every other auth call is cluster-wide and ignores it. The assertion is re-validated against the caller's own membership before it narrows anything, and an assertion the caller may not make fails the call with `PermissionDenied`. `null` or empty disables it, so a narrowed listing resolves the reserved default tenant. |
