IBeam.Billing.Api 2.12.2

There is a newer version of this package available.
See the version list below for details.
dotnet add package IBeam.Billing.Api --version 2.12.2
                    
NuGet\Install-Package IBeam.Billing.Api -Version 2.12.2
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="IBeam.Billing.Api" Version="2.12.2" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="IBeam.Billing.Api" Version="2.12.2" />
                    
Directory.Packages.props
<PackageReference Include="IBeam.Billing.Api" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add IBeam.Billing.Api --version 2.12.2
                    
#r "nuget: IBeam.Billing.Api, 2.12.2"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package IBeam.Billing.Api@2.12.2
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=IBeam.Billing.Api&version=2.12.2
                    
Install as a Cake Addin
#tool nuget:?package=IBeam.Billing.Api&version=2.12.2
                    
Install as a Cake Tool

IBeam.Billing.Api

IBeam.Billing.Api provides optional ASP.NET Core controller wiring for public checkout, billing administration, and provider-event ingestion.

dotnet add package IBeam.Billing.Api

Quick Start

using IBeam.Billing.Api;

builder.Services.AddAuthentication();
builder.Services.AddAuthorization();
builder.Services.AddIBeamBillingApi(builder.Configuration);

var app = builder.Build();

app.UseAuthentication();
app.UseAuthorization();
app.UseRateLimiter();
app.MapControllers();

Endpoint Overview

POST /api/commerce/checkout-sessions
GET  /api/commerce/purchases/{purchaseId}/status?token={statusToken}
POST /api/billing/webhooks/{providerName}
GET  /api/billing/tenants/{tenantId}/customers
GET  /api/billing/tenants/{tenantId}/subscriptions
GET  /api/billing/tenants/{tenantId}/invoices
GET  /api/billing/tenants/{tenantId}/provider-events
POST /api/billing/provider-events
GET  /api/billing/commerce/tenants/{tenantId}/purchases/{purchaseId}
POST /api/billing/commerce/tenants/{tenantId}/provider-events/{providerName}/{providerEventId}/retry
POST /api/billing/commerce/tenants/{tenantId}/purchases/{purchaseId}/retry-fulfillment
POST /api/billing/commerce/tenants/{tenantId}/purchases/{purchaseId}/resend-claim
POST /api/billing/commerce/tenants/{tenantId}/purchases/{purchaseId}/corrections

Configure public checkout with an adapter-owned signing secret and explicit return origins:

{
  "IBeam": {
    "Billing": {
      "PublicCheckout": {
        "DefaultProviderName": "stripe",
        "AllowedReturnOrigins": [ "https://app.example.com" ],
        "StatusTokenSigningKey": "load-at-least-32-secret-characters-from-key-vault"
      }
    }
  }
}

The public endpoints are anonymous but rate limited. Checkout creation requires an idempotency key, validates the configured offer and total seats, and rejects return URLs outside the allow-list. Status responses require a short-lived signed token and omit buyer email and provider references.

Provider webhooks are anonymous because processor callbacks cannot sign in to the consuming app. The registered provider gateway verifies the raw body and signature headers before Billing records or mutates anything. Gateways map payloads to BillingCommerceEventTypes; processed and intentionally ignored events are idempotent by provider plus event id, while failed processing can be retried safely.

The read endpoints are intended for admin/internal tools. The provider-event endpoint records safe provider event metadata and remains idempotent through IBillingProviderEventService.

Security

Commerce recovery endpoints require an authenticated principal whose tenant claim matches the route and who has the Owner, Administrator, or Admin role or the billing.commerce.admin permission. Register AddIBeamBillingLicenseReconciliation in the host to provide the commerce administration service. Recovery and correction requests require a support reason, corrections also require an idempotency key, and the operation executor writes the configured audit trail. Inspection responses redact buyer email and omit claim hashes and provider payload references.

Public checkout uses signed status tokens and explicit return-origin allow-lists; webhook authenticity is delegated to the selected provider gateway before state changes.

Billing APIs do not authorize runtime application access. Runtime services should enforce access through Licensing and Credits.

See the commerce integration guide for the public purchase, Identity onboarding, seat, recovery, and provider migration sequence.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
2.14.0 126 9/28/2026
2.13.1 81 9/28/2026
2.13.0 85 9/25/2026
2.12.3 187 9/18/2026
2.12.2 173 9/11/2026
2.12.1 102 9/11/2026
2.12.0 95 9/10/2026
2.11.0 167 8/30/2026
2.10.1 141 8/23/2026
2.10.0 112 8/23/2026
2.9.45 183 8/10/2026
2.9.44 120 8/3/2026
2.9.43 120 7/29/2026