Duende.Labs.IdentityModel
2026.922.37
Prefix Reserved
dotnet add package Duende.Labs.IdentityModel --version 2026.922.37
NuGet\Install-Package Duende.Labs.IdentityModel -Version 2026.922.37
<PackageReference Include="Duende.Labs.IdentityModel" Version="2026.922.37" />
<PackageVersion Include="Duende.Labs.IdentityModel" Version="2026.922.37" />
<PackageReference Include="Duende.Labs.IdentityModel" />
paket add Duende.Labs.IdentityModel --version 2026.922.37
#r "nuget: Duende.Labs.IdentityModel, 2026.922.37"
#:package Duende.Labs.IdentityModel@2026.922.37
#addin nuget:?package=Duende.Labs.IdentityModel&version=2026.922.37
#tool nuget:?package=Duende.Labs.IdentityModel&version=2026.922.37
IdentityModel for .NET
Modern OpenID Connect and OAuth 2.0 client library for .NET 10+.
Installation
dotnet add package Duende.Labs.IdentityModel
Note This package is experimental/preview. For production scenarios, consider Duende.IdentityModel.
Typed client
IdentityModel uses named HttpClient instances and named options. Register an authority once:
services.AddIdentityModelClient(options =>
{
options.Authority = new Uri("https://demo.duendesoftware.com");
options.DefaultClientCredential = new ClientCredential("m2m", "secret");
options.Scope = "api";
});
Inject IIdentityModelClientFactory and asynchronously create an initialized client:
public sealed class Worker(IIdentityModelClientFactory factory)
{
public async Task RunAsync(CancellationToken ct)
{
var creation = await factory.CreateAsync(ct);
if (!creation.IsSuccess)
{
// Inspect creation.Error.
return;
}
var client = creation.Client;
if (!client.SupportsClientCredentials)
{
return;
}
var token = await client.RequestClientCredentialsTokenAsync(ct);
}
}
The factory retrieves and validates discovery, resolves protocol endpoints, and returns an immutable client snapshot. Calls do not require callers to copy endpoint URIs out of discovery or construct endpoint-bearing request objects.
Capabilities
The initialized client exposes capabilities such as SupportsClientCredentials,
SupportsUserInfo, SupportsDeviceAuthorization, and SupportsPushedAuthorization.
Capability validation is strict by default. Strict mode checks endpoint presence and relevant
advertised metadata, including grant types and client authentication methods. An unsupported call
fails locally with ProtocolErrorType.UnsupportedFeature.
Providers with incomplete discovery documents can use relaxed mode:
services.AddIdentityModelClient(options =>
{
options.Authority = new Uri("https://provider.example.com");
options.CapabilityValidationMode = CapabilityValidationMode.Relaxed;
});
Relaxed mode requires a resolved endpoint but does not block a call because other advertised metadata is missing.
Endpoint overrides and limited clients
Explicit endpoint overrides take precedence over discovery and may be absolute or relative to the authority:
services.AddIdentityModelClient(options =>
{
options.Authority = new Uri("https://provider.example.com");
options.TokenEndpoint = new Uri("/oauth/token", UriKind.Relative);
});
If discovery fails but one or more explicit endpoints are usable, creation succeeds with a limited
client. DiscoveryError preserves the failure and only explicitly configured capabilities are
available. Creation fails when discovery fails and no usable override exists.
Named clients
services.AddIdentityModelClient("customers", options => { /* ... */ });
services.AddIdentityModelClient("partners", options => { /* ... */ });
var customers = await factory.CreateAsync("customers", ct);
Each factory call uses the current named options and creates a fresh discovery snapshot. The factory does not retain typed clients or impose a discovery cache lifetime.
Per-call customization
Overloads accept a transform for operation-specific values:
var result = await client.RequestClientCredentialsTokenAsync(
request => request with { Scope = "api.read" },
ct);
The client supplies endpoint and configured defaults before invoking the transform.
HTTP handlers, resilience, and caching
AddIdentityModelClient returns the backing IHttpClientBuilder, so handlers apply to discovery
and protocol requests:
services
.AddIdentityModelClient(options => { /* ... */ })
.AddHttpMessageHandler<MyHandler>()
.AddStandardResilienceHandler();
IdentityModel does not cache discovery or protocol responses. Applications choose caching policy,
storage, and handler ordering through the normal HttpClient pipeline. The
Caching sample demonstrates RFC 9111 response caching.
Configuration binding
services.AddIdentityModelClient(builder.Configuration.GetSection("IdentityProvider"));
Recognized keys include Authority, ClientId, ClientSecret, ClientCredentialStyle, Scope,
CapabilityValidationMode, and endpoint overrides. Values are read explicitly to preserve trimming
and Native AOT compatibility.
Features
The typed client supports:
- Discovery and JSON Web Keys
- Client credentials, authorization code, and refresh token requests
- Token introspection and revocation
- UserInfo
- Device authorization
- Pushed Authorization Requests and Rich Authorization Requests
- CIBA backchannel authentication
- Dynamic client registration and RFC 7592 registration management
Generic SetBearerToken helpers remain available for setting an OAuth bearer token on an
HttpClient or HttpRequestMessage.
License
IdentityModel is open source under the Apache 2.0 license.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Microsoft.Extensions.Configuration.Abstractions (>= 10.0.9)
- Microsoft.Extensions.Http (>= 10.0.9)
- Microsoft.Extensions.Options (>= 10.0.9)
NuGet packages (3)
Showing the top 3 NuGet packages that depend on Duende.Labs.IdentityModel:
| Package | Downloads |
|---|---|
|
Duende.Labs.AccessTokenManagement
Automatic access token management for OAuth client credential flows |
|
|
Duende.Labs.IdentityModel.OidcClient
RFC8252 compliant and certified OpenID Connect and OAuth 2.0 client library for native applications |
|
|
Duende.Labs.IdentityModel.DependencyInjection
Dependency injection and IHttpClientFactory integration for Duende.Labs.IdentityModel |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 2026.922.37 | 81 | 9/22/2026 |
| 2026.806.21 | 128 | 8/6/2026 |
| 2026.804.20 | 121 | 8/4/2026 |
| 2026.729.19 | 122 | 7/29/2026 |
| 2026.729.18 | 108 | 7/29/2026 |
| 2026.729.17 | 105 | 7/29/2026 |
| 2026.728.16 | 109 | 7/28/2026 |
| 2026.728.15 | 116 | 7/28/2026 |
| 2026.727.14 | 482 | 7/27/2026 |
| 2026.727.13 | 105 | 7/27/2026 |
| 2026.726.12 | 147 | 7/26/2026 |
| 2026.725.11 | 746 | 7/25/2026 |
| 2026.724.10 | 125 | 7/24/2026 |
| 2026.724.9 | 108 | 7/24/2026 |
| 2026.724.8 | 97 | 7/24/2026 |