Linbik.JwtAuthManager 1.2.8

dotnet add package Linbik.JwtAuthManager --version 1.2.8
                    
NuGet\Install-Package Linbik.JwtAuthManager -Version 1.2.8
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Linbik.JwtAuthManager" Version="1.2.8" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Linbik.JwtAuthManager" Version="1.2.8" />
                    
Directory.Packages.props
<PackageReference Include="Linbik.JwtAuthManager" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Linbik.JwtAuthManager --version 1.2.8
                    
#r "nuget: Linbik.JwtAuthManager, 1.2.8"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Linbik.JwtAuthManager@1.2.8
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Linbik.JwtAuthManager&version=1.2.8
                    
Install as a Cake Addin
#tool nuget:?package=Linbik.JwtAuthManager&version=1.2.8
                    
Install as a Cake Tool

Linbik.JwtAuthManager

JWT Authentication Manager for Linbik Framework. Provides cookie-based login/logout endpoints, RSA-256 JWT validation, and rate limiting.

πŸ“¦ Installation

dotnet add package Linbik.JwtAuthManager

πŸš€ Features

  • Cookie-Based JWT Auth β€” Login, logout, and token refresh via minimal API endpoints
  • RSA-256 JWT Signing β€” Industry-standard asymmetric cryptography
  • PKCE Support β€” Proof Key for Code Exchange for public clients
  • Rate Limiting β€” Configurable LinbikAuth, LinbikGeneral, and LinbikStrict policies
  • Multi-Client Support β€” Web, Mobile, Admin via Clients configuration
  • Keyless Mode β€” Zero-config development with auto-provisioning
  • LinbikAuthorize Attribute β€” Protect endpoints with [LinbikAuthorize]

πŸ”§ Configuration

// In Program.cs
using Linbik.Core.Extensions;
using Linbik.JwtAuthManager.Extensions;

var builder = WebApplication.CreateBuilder(args);

// 1. Add Linbik services
builder.Services.AddLinbik()
    .AddLinbikJwtAuth();

var app = builder.Build();

// 2. Validate configuration at startup
app.EnsureLinbik();

// 3. if using controllers, add this.
app.UseRouting();  

// 4. Add authentication and authorization middleware
app.UseAuthentication();
app.UseAuthorization();

// 5. Map endpoints: /api/linbik/login, /api/linbik/logout, /api/linbik/refresh
app.UseLinbikJwtAuth();

app.Run();

πŸ” Configure JWT Authentication

Choose one of the following approaches:

// Default configuration
AddLinbikJwtAuth();

// From configuration
AddLinbikJwtAuth(builder.Configuration.GetSection("Linbik:JwtAuth"));

// Fluent configuration
AddLinbikJwtAuth(opt => { });

Endpoints

Path Method Description
/api/Linbik/login GET Initiate OAuth flow β†’ exchange code β†’ set cookies
/api/Linbik/callback GET OAuth callback for code exchange
/api/Linbik/logout GET Clear all auth cookies
/api/Linbik/refresh POST Refresh tokens using refresh cookie

⚠️ Login/callback/logout/refresh error paths currently crash with a NotImplementedException instead of returning a response β€” see PROJECT_STATUS.md Known Issues. Linbik.PasetoAuthManager's equivalent handler is the reference fix.

πŸ’» Usage

Protect Endpoints

[LinbikAuthorize]
[HttpGet]
public IActionResult Protected()
{
    var userId = User.FindFirst("sub")?.Value;
    return Ok(new { userId });
}

or with minimal APIs:

app.MapGet("/protected", [LinbikAuthorize] (ClaimsPrincipal user) =>
{
    var userId = user.FindFirst("sub")?.Value;
    return Results.Ok(new { userId });
});

app.MapGet("/protected", (HttpContext context) =>
{
    var userId = context.User.FindFirst("sub")?.Value;
    return Results.Ok(new { userId });
})
.RequireAuthorization("LinbikAuthorize");

Note: jwtBearerOptions.MapInboundClaims = false is set, so claim types stay as the raw JWT names (sub, preferred_username, name) instead of being remapped to long ClaimTypes.* URIs β€” matching Linbik.PasetoAuthManager's claim structure.

Access Integration Tokens

// Get a specific integration token from cookies
var paymentToken = HttpContext.GetIntegrationToken("payment-gateway");

// Check if user has any integrations
var hasIntegrations = HttpContext.HasIntegrations();

πŸ”’ Rate Limiting

Rate limiting is shared through Linbik.Core.Extensions. All overloads of AddLinbikRateLimiting, including the parameterless overload, register the policies.

// In Program.cs
builder.Services.AddLinbikRateLimiting(builder.Configuration.GetSection("Linbik:RateLimiting"));

// In middleware pipeline
app.UseLinbikRateLimiting();
{
  "Linbik": {
    "RateLimiting": {
      "PermitLimit": 100,
      "WindowSeconds": 60,
      "QueueLimit": 2
    },
    "Resilience": {
      "StrictTokenLimit": 10,
      "StrictReplenishmentPeriodSeconds": 60,
      "StrictTokensPerPeriod": 5,
      "StrictQueueLimit": 0
    }
  }
}

Rate Limiting Policies

Policy Use Case
LinbikAuth Login and logout endpoints (fixed/sliding window)
LinbikStrict Callback and refresh endpoints β€” token exchange (token-bucket)
LinbikGeneral Registered for general-purpose use in your own endpoints (more permissive fixed window)
[EnableRateLimiting("LinbikAuth")]
public IActionResult RateLimitedAction() => Ok();

πŸ“– Documentation

πŸ“„ License

MIT License

Contact: info@linbik.com


Version: 1.2.0
Platform: ASP.NET Core 10.0 (net10.0)
Last Updated: 9 EylΓΌl 2026

Local refresh tokens

After a successful callback, an upstream Linbik refresh token is used unchanged. When none is returned, AuthManager creates a cryptographically random local refresh token and stores only its SHA-256 hash and the authenticated user's profile. POST the configured RefreshPath (default /api/Linbik/refresh) to renew either kind. Local refresh does not call Linbik or mint integration tokens. Upstream failures never fall back to local sessions. Core's IAuthService is an upstream API helper, not this AuthManager refresh endpoint; do not use it to renew local sessions.

Local tokens rotate atomically on every use. Reusing a consumed token revokes the whole session. Clients must serialize refresh requests (including across browser tabs). The absolute session expiry is established at login using RefreshTokenExpirationDays and is not extended by rotation. LogoutPath revokes the local refresh session and clears cookies; already-issued access tokens remain valid until their own expiry.

The default InMemoryLinbikRefreshTokenStore is process-local. Restarting loses all local refresh sessions. It cannot support multiple application instances. Expired entries are evicted by MemoryCache. No database driver or new package is required. AuthManager.Shared is linked source compiled into each existing AuthManager assembly; its public types live under the selected AuthManager's Services namespace.

To use application-owned storage, implement ILinbikRefreshTokenStore and register it AFTER AddLinbikJwtAuth / AddLinbikPasetoAuth (or before, since defaults use TryAdd):

// using Linbik.PasetoAuthManager.Services; // or Linbik.JwtAuthManager.Services
builder.Services.AddScoped<ILinbikRefreshTokenStore, MyRefreshTokenStore>();

CreateAsync must persist hashes and immutable session data. RotateAsync must perform expiry/revocation validation and replacement atomically, retain consumed hashes until session expiry to detect reuse, and revoke all replacements when reuse is detected. RevokeAsync must invalidate the entire session even when passed an older hash. Persisting a custom store also requires stable access-token signing keys across restarts. Keep those keys in application secret configuration, never source control.

Read-only web session

UseLinbikJwtAuth() also maps GET /api/Linbik/session (configurable via JwtAuthOptions.SessionPath). It authenticates through LinbikScheme and returns LBaseResponse with userId, username, displayName and integration cookie names. An absent/invalid access token returns 401; the endpoint never refreshes tokens or writes cookies. Responses are private, no-store. Integration names are UI hints, not authorization evidence. The web SDK's getSession() supports this endpoint. See Nuxt SSR/CSR example.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.2.8 97 9/20/2026
1.2.7 102 9/10/2026
1.2.5 104 9/7/2026
1.2.3 97 9/1/2026
1.2.1 139 7/16/2026
1.2.0-preview.3 71 5/30/2026
1.2.0-preview.2 102 4/26/2026
1.2.0-preview.1 126 4/2/2026
1.1.0 419 12/5/2025
1.1.0-beta0007 124 3/6/2026
1.0.7 173 3/6/2026
1.0.1 251 12/14/2025
1.0.0 114 3/6/2026
0.60.1 123 3/6/2026
0.46.0 389 11/30/2025
0.45.12 385 11/30/2025
0.45.7 271 8/31/2025
0.45.6 243 8/31/2025
0.45.5 257 8/27/2025
0.44.0 273 8/24/2025
Loading failed