Duende.Labs.IdentityModel 2026.922.37

Prefix Reserved
dotnet add package Duende.Labs.IdentityModel --version 2026.922.37
                    
NuGet\Install-Package Duende.Labs.IdentityModel -Version 2026.922.37
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Duende.Labs.IdentityModel" Version="2026.922.37" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Duende.Labs.IdentityModel" Version="2026.922.37" />
                    
Directory.Packages.props
<PackageReference Include="Duende.Labs.IdentityModel" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Duende.Labs.IdentityModel --version 2026.922.37
                    
#r "nuget: Duende.Labs.IdentityModel, 2026.922.37"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Duende.Labs.IdentityModel@2026.922.37
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Duende.Labs.IdentityModel&version=2026.922.37
                    
Install as a Cake Addin
#tool nuget:?package=Duende.Labs.IdentityModel&version=2026.922.37
                    
Install as a Cake Tool

IdentityModel for .NET

Modern OpenID Connect and OAuth 2.0 client library for .NET 10+.

Installation

dotnet add package Duende.Labs.IdentityModel

Note This package is experimental/preview. For production scenarios, consider Duende.IdentityModel.

Typed client

IdentityModel uses named HttpClient instances and named options. Register an authority once:

services.AddIdentityModelClient(options =>
{
    options.Authority = new Uri("https://demo.duendesoftware.com");
    options.DefaultClientCredential = new ClientCredential("m2m", "secret");
    options.Scope = "api";
});

Inject IIdentityModelClientFactory and asynchronously create an initialized client:

public sealed class Worker(IIdentityModelClientFactory factory)
{
    public async Task RunAsync(CancellationToken ct)
    {
        var creation = await factory.CreateAsync(ct);
        if (!creation.IsSuccess)
        {
            // Inspect creation.Error.
            return;
        }

        var client = creation.Client;
        if (!client.SupportsClientCredentials)
        {
            return;
        }

        var token = await client.RequestClientCredentialsTokenAsync(ct);
    }
}

The factory retrieves and validates discovery, resolves protocol endpoints, and returns an immutable client snapshot. Calls do not require callers to copy endpoint URIs out of discovery or construct endpoint-bearing request objects.

Capabilities

The initialized client exposes capabilities such as SupportsClientCredentials, SupportsUserInfo, SupportsDeviceAuthorization, and SupportsPushedAuthorization.

Capability validation is strict by default. Strict mode checks endpoint presence and relevant advertised metadata, including grant types and client authentication methods. An unsupported call fails locally with ProtocolErrorType.UnsupportedFeature.

Providers with incomplete discovery documents can use relaxed mode:

services.AddIdentityModelClient(options =>
{
    options.Authority = new Uri("https://provider.example.com");
    options.CapabilityValidationMode = CapabilityValidationMode.Relaxed;
});

Relaxed mode requires a resolved endpoint but does not block a call because other advertised metadata is missing.

Endpoint overrides and limited clients

Explicit endpoint overrides take precedence over discovery and may be absolute or relative to the authority:

services.AddIdentityModelClient(options =>
{
    options.Authority = new Uri("https://provider.example.com");
    options.TokenEndpoint = new Uri("/oauth/token", UriKind.Relative);
});

If discovery fails but one or more explicit endpoints are usable, creation succeeds with a limited client. DiscoveryError preserves the failure and only explicitly configured capabilities are available. Creation fails when discovery fails and no usable override exists.

Named clients

services.AddIdentityModelClient("customers", options => { /* ... */ });
services.AddIdentityModelClient("partners", options => { /* ... */ });

var customers = await factory.CreateAsync("customers", ct);

Each factory call uses the current named options and creates a fresh discovery snapshot. The factory does not retain typed clients or impose a discovery cache lifetime.

Per-call customization

Overloads accept a transform for operation-specific values:

var result = await client.RequestClientCredentialsTokenAsync(
    request => request with { Scope = "api.read" },
    ct);

The client supplies endpoint and configured defaults before invoking the transform.

HTTP handlers, resilience, and caching

AddIdentityModelClient returns the backing IHttpClientBuilder, so handlers apply to discovery and protocol requests:

services
    .AddIdentityModelClient(options => { /* ... */ })
    .AddHttpMessageHandler<MyHandler>()
    .AddStandardResilienceHandler();

IdentityModel does not cache discovery or protocol responses. Applications choose caching policy, storage, and handler ordering through the normal HttpClient pipeline. The Caching sample demonstrates RFC 9111 response caching.

Configuration binding

services.AddIdentityModelClient(builder.Configuration.GetSection("IdentityProvider"));

Recognized keys include Authority, ClientId, ClientSecret, ClientCredentialStyle, Scope, CapabilityValidationMode, and endpoint overrides. Values are read explicitly to preserve trimming and Native AOT compatibility.

Features

The typed client supports:

  • Discovery and JSON Web Keys
  • Client credentials, authorization code, and refresh token requests
  • Token introspection and revocation
  • UserInfo
  • Device authorization
  • Pushed Authorization Requests and Rich Authorization Requests
  • CIBA backchannel authentication
  • Dynamic client registration and RFC 7592 registration management

Generic SetBearerToken helpers remain available for setting an OAuth bearer token on an HttpClient or HttpRequestMessage.

License

IdentityModel is open source under the Apache 2.0 license.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages (3)

Showing the top 3 NuGet packages that depend on Duende.Labs.IdentityModel:

Package Downloads
Duende.Labs.AccessTokenManagement

Automatic access token management for OAuth client credential flows

Duende.Labs.IdentityModel.OidcClient

RFC8252 compliant and certified OpenID Connect and OAuth 2.0 client library for native applications

Duende.Labs.IdentityModel.DependencyInjection

Dependency injection and IHttpClientFactory integration for Duende.Labs.IdentityModel

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
2026.922.37 81 9/22/2026
2026.806.21 128 8/6/2026
2026.804.20 121 8/4/2026
2026.729.19 122 7/29/2026
2026.729.18 108 7/29/2026
2026.729.17 105 7/29/2026
2026.728.16 109 7/28/2026
2026.728.15 116 7/28/2026
2026.727.14 482 7/27/2026
2026.727.13 105 7/27/2026
2026.726.12 147 7/26/2026
2026.725.11 746 7/25/2026
2026.724.10 125 7/24/2026
2026.724.9 108 7/24/2026
2026.724.8 97 7/24/2026
Loading failed