Upgrading IdentityServer v7 to v8
When to Use This Skill
- Upgrading a Duende IdentityServer project from v7.4 to v8.0
- Fixing build errors after updating NuGet packages to v8
- Migrating custom stores/services to new v8 interfaces
- Running EF Core database migrations for v8 (SAML tables)
- Replacing deprecated APIs (ICache, IClock, IAuthorizationParametersMessageStore)
Core Principles
- v8.0 requires .NET 10 — update TFM before anything else
- All breaking changes are compile-time errors (no silent behavior changes)
- Migration is mechanical — find/replace patterns work for most changes
- Run EF migrations even if you don't use SAML (schema must match)
- Always check the latest stable 8.x package version on NuGet before upgrading — do not hardcode
8.0.1; use whatever the latest stable (non-prerelease) 8.x version is at the time of the upgrade.
Docs: https://docs.duendesoftware.com/identityserver/upgrades/v7_4-to-v8_0/
Step-by-Step Migration
1. Update Target Framework
2. Update NuGet Packages
Check NuGet for the latest stable 8.x version. At time of writing, that is 8.0.1, but use whatever is current:
3. Run EF Database Migrations
Two migrations are required — one for the Configuration Store and one for the Operational Store:
Both are required even if you don't use SAML (schema must match).
4. Replace ICache<T> with HybridCache
Key: use keyed service "ConfigurationStoreCache" (ServiceProviderKeys.ConfigurationStoreCache). CachingOptions.CacheLockTimeout is obsolete.
5. Replace IClock with TimeProvider
Note: GetUtcNow() (method) replaces UtcNow (property).
6. Add CancellationToken to All Async Interfaces
All store and service interfaces now require CancellationToken ct as the last parameter:
Affected interfaces include: IClientStore, IResourceStore, IPersistedGrantStore, IDeviceFlowStore, ICorsPolicyService, IProfileService, and all custom stores/services.
Also: ICancellationTokenProvider is removed entirely.
7. Add GetAllClientsAsync to IClientStore
Used by Financial-Grade Security features and conformance reports.
8. Update Refresh Token Service
9. Remove IAuthorizationParametersMessageStore
10. Fix Return Type Changes
Nine interfaces changed IEnumerable<T> → IReadOnlyCollection<T>:
11. Fix DPoP Type Names
12. Update Licensing Code
New v8 License Key Format
- v8 introduced a new license key file format: the v8 key is a signed JWT carrying a
kidheader. - A v7/earlier key still works with v8 core — no new purchase is needed to run v8 core on an existing key.
- A v8 key does NOT work on v7/earlier OR on the BFF Security Framework runtime. It fails signature validation with Microsoft.IdentityModel error:
IDX10503: Signature validation failed. Token does not have a kid.- That exact error is the tell-tale sign of a v8 key loaded into a v7 or BFF runtime.
- Add-ons require a v8-format key in production: using SAML or Duende User Management in production on v8 REQUIRES a new v8-format license key. Older-format keys run v8 core, but not these add-ons in production.
Runtime License Enforcement Changed (behavioral reversal)
v8 validates feature usage at runtime. When a license IS present but lacks the entitlement, behavior splits into two tiers:
- If NO license is configured (local dev / non-prod), Tier-A features downgrade to logging instead of throwing.
- Guidance: use your production license key in lower environments so entitlement gaps (e.g. Server-Side Sessions) surface before production.
- Contrast with v7 and earlier: those versions disabled some features at runtime when unlicensed (Server-Side Sessions, DPoP, Resource Isolation, PAR, Dynamic Identity Providers, CIBA). v8 no longer disables — it logs or throws per the tiers above.
Editions → Plans
The product moved from fixed Starter / Business / Enterprise editions to generic plans. The old three editions are still honored for legacy/long-term customers only. The Community edition remains. Update any code or docs that hard-code "three editions" to reflect the plan model.
13. Update EF Identity Provider Store
14. Rename AuthorizationError → InteractionError
Values remain the same: AccessDenied, LoginRequired, InteractionRequired.
15. Rename DenyAuthorizationAsync → DenyAuthenticationAsync
16. Rename ProfileDataRequestContext.Client → .Application
17. Update ITokenValidator.ValidateAccessTokenAsync
18. Relocate PreviewFeatureOptions
PreviewFeatureOptions and IdentityServerOptions.Preview are removed. Options relocated:
Other Notable Changes
- NRT enabled: All assemblies use nullable reference types. Fix nullable warnings.
- HTTP 303: POST endpoint redirects now unconditionally use 303 (FAPI 2.0 compliance).
PersistedGrantFilter.ClientIds/Types: Now non-nullable with empty collection defaults. Replace null checks with.Count > 0.- IUserSession: Three new SAML session methods added (implement as no-op if not using SAML):
AddSamlSessionAsync,GetSamlSessionListAsync,RemoveSamlSessionAsync
- Log levels: Secret validation failures changed from Error to Debug — update alerting to watch for Warning-level entries at endpoint level instead.
- Device flow consent: "Remember My Decision" no longer offered —
RememberConsentalwaysfalseduring device flow (RFC 8628 security). - License key from IConfiguration: IdentityServer now reads license key automatically from
Duende:IdentityServer:LicenseKeyorDuende:LicenseKeyin configuration. DPoPExtensions→DPoPServiceCollectionExtensions: Class renamed in JwtBearer package.- Token cleanup performance: When no
IOperationalStoreNotificationregistered, uses singleExecuteDeleteAsynccall (automatic improvement, no action needed). - Orphaned grants revoked on session overwrite: When server-side sessions enabled and session cookie reused by different user, previous user's grants are automatically revoked.
Migration Checklist
- ☐ Update TFM to
net10.0 - ☐ Update all Duende.* packages to latest stable 8.x (check NuGet)
- ☐ Run EF migrations (both
ConfigurationDbContextandPersistedGrantDbContext) - ☐ Replace
ICache<T>→ keyedHybridCache - ☐ Replace
IClock→TimeProvider - ☐ Add
CancellationTokento all async store/service methods - ☐ Remove
ICancellationTokenProviderreferences - ☐ Add
GetAllClientsAsyncto customIClientStore(returnsIAsyncEnumerable<Client>) - ☐ Update
IRefreshTokenServiceimplementations (request objects) - ☐ Remove
IAuthorizationParametersMessageStore(use PAR) - ☐ Fix
IEnumerable<T>→IReadOnlyCollection<T>return types - ☐ Fix DPoP type name typos
- ☐ Update licensing references (
IdentityServerLicense→LicenseInformation) - ☐ Rename
AuthorizationError→InteractionError - ☐ Rename
DenyAuthorizationAsync→DenyAuthenticationAsync - ☐ Rename
ProfileDataRequestContext.Client→.Application - ☐ Update
ITokenValidator.ValidateAccessTokenAsynccalls (addexpectedScopeparam) - ☐ Relocate
PreviewFeatureOptionssettings - ☐ Fix nullable reference type warnings
- ☐ Test build and run
Common Pitfalls
- Forgetting EF migration: Even without SAML, the schema must be updated or EF will throw at runtime.
- HybridCache keyed service: Must use
[FromKeyedServices("ConfigurationStoreCache")]— plainHybridCacheinjection gets a different instance. - CancellationToken propagation: Don't pass
CancellationToken.Noneeverywhere — propagate from the method parameter for proper request cancellation. - GetAllClientsAsync performance: Return all clients from your store; used rarely but must be implemented.
- PAR migration: If you used
IAuthorizationParametersMessageStorefor large auth requests, switch clients to use PAR (require_pushed_authorization_requests). IDX10503after dropping in a v8 key: A v8-format license key (signed JWT with akidheader) fails signature validation on v7/earlier or the BFF Security Framework runtime withIDX10503: Signature validation failed. Token does not have a kid.Keep the v7-format key for those runtimes — it still works on v8 core; only SAML/User Management add-ons in production require the new v8-format key.- Entitlement gaps surface late: v8 no longer silently disables unlicensed features — Server-Side Sessions, Automatic Key Management, and SAML now throw at startup when a license is present but missing the entitlement. Run lower environments with the production license key to catch this before deploying.
Related Skills
identityserver-configuration— IdentityServer host configuration and optionsidentityserver-stores— Store implementation patterns (affected by CancellationToken changes)identityserver-saml— SAML 2.0 support (new in v8, requires EF migration)identityserver-usermanagement— User Management (new in v8)


