Linbik.PasetoAuthManager 1.2.8

dotnet add package Linbik.PasetoAuthManager --version 1.2.8
                    
NuGet\Install-Package Linbik.PasetoAuthManager -Version 1.2.8
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Linbik.PasetoAuthManager" Version="1.2.8" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Linbik.PasetoAuthManager" Version="1.2.8" />
                    
Directory.Packages.props
<PackageReference Include="Linbik.PasetoAuthManager" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Linbik.PasetoAuthManager --version 1.2.8
                    
#r "nuget: Linbik.PasetoAuthManager, 1.2.8"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Linbik.PasetoAuthManager@1.2.8
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Linbik.PasetoAuthManager&version=1.2.8
                    
Install as a Cake Addin
#tool nuget:?package=Linbik.PasetoAuthManager&version=1.2.8
                    
Install as a Cake Tool

Linbik.PasetoAuthManager

PASETO Authentication Manager for Linbik Framework. Provides cookie-based login/logout endpoints, PASETO v4 token issuance/validation, and rate limiting β€” a drop-in alternative to Linbik.JwtAuthManager with the same endpoint shape.

πŸ“¦ Installation

dotnet add package Linbik.PasetoAuthManager

πŸš€ Features

  • Cookie-Based PASETO Auth β€” Login, callback, logout, and token refresh via minimal API endpoints
  • PASETO v4 β€” supports both v4.public (Ed25519 asymmetric signing) and v4.local (XChaCha20-Poly1305 symmetric encryption); see Choosing a Mode below
  • PKCE Support β€” Proof Key for Code Exchange for public clients
  • Rate Limiting β€” Shared LinbikAuth, LinbikGeneral, and LinbikStrict policies from Linbik.Core.Extensions.
  • Multi-Client Support β€” Web, Mobile, Admin via Clients configuration
  • Keyless Mode β€” Zero-config development with auto-provisioning
  • LinbikAuthorize Attribute β€” Protect endpoints with [LinbikAuthorize]
  • Fully implemented error paths β€” unlike Linbik.JwtAuthManager's ReturnAuthError (see PROJECT_STATUS.md Known Issues), this package's error handling for login/callback/refresh is complete

πŸ”§ Configuration

// In Program.cs
using Linbik.Core.Extensions;
using Linbik.PasetoAuthManager.Extensions;

var builder = WebApplication.CreateBuilder(args);

// 1. Add Linbik services
builder.Services.AddLinbik()
    .AddLinbikPasetoAuth();

var app = builder.Build();

// 2. Validate configuration at startup
app.EnsureLinbik();

// 3. if using controllers, add this.
app.UseRouting();

// 4. Add authentication and authorization middleware
app.UseAuthentication();
app.UseAuthorization();

// 5. Map endpoints: /api/Linbik/login, /api/Linbik/callback, /api/Linbik/logout, /api/Linbik/refresh
app.UseLinbikPasetoAuth();

app.Run();

πŸ” Configure PASETO Authentication

Choose one of the following approaches:

// Default configuration
AddLinbikPasetoAuth();

// From configuration
AddLinbikPasetoAuth(builder.Configuration.GetSection("Linbik:PasetoAuth"));

// Fluent configuration
AddLinbikPasetoAuth(opt => { });

appsettings.json

{
  "Linbik": {
    "PasetoAuth": {
      "Mode": "Public",
      "PrivateKeyBase64": "base64-ed25519-seed-plus-public-64-bytes",
      "PublicKeyBase64": "base64-ed25519-public-32-bytes",
      "Issuer": "Linbik",
      "Audience": "linbik-client",
      "AccessTokenExpirationMinutes": 60,
      "RefreshTokenExpirationDays": 14,
      "PkceEnabled": true
    }
  }
}

Endpoints

Path Method Description
/api/Linbik/login GET Initiate OAuth flow β†’ exchange code β†’ set cookies
/api/Linbik/callback GET OAuth callback for code exchange
/api/Linbik/logout GET Clear all auth cookies
/api/Linbik/refresh POST Refresh tokens using refresh cookie

πŸ”‘ Choosing a Mode

PasetoAuthOptions.Mode defaults to PasetoMode.Local (v4.local, symmetric SharedKeyBase64) for backwards compatibility, even though this package's PASETO usage is generally described as v4.public. Set Mode = PasetoMode.Public explicitly and configure PrivateKeyBase64/PublicKeyBase64 (Ed25519) if you want asymmetric signing β€” recommended for most deployments, since the private key never needs to be shared with token verifiers. Generate keys with IPasetoHelper.GenerateKeyPair() (public mode) or IPasetoHelper.GenerateSymmetricKey() (local mode).

πŸ’» Usage

Protect Endpoints

[LinbikAuthorize]
[HttpGet]
public IActionResult Protected()
{
    var userId = User.FindFirst("sub")?.Value;
    return Ok(new { userId });
}

or with minimal APIs:

app.MapGet("/protected", [LinbikAuthorize] (ClaimsPrincipal user) =>
{
    var userId = user.FindFirst("sub")?.Value;
    return Results.Ok(new { userId });
});

Note: PasetoBearerHandler builds the ClaimsIdentity from raw token claims with no type mapping, so use the short claim key "sub".

Access Integration Tokens

// Get a specific integration token from cookies
var paymentToken = HttpContext.GetIntegrationToken("payment-gateway");

// Check if user has any integrations
var hasIntegrations = HttpContext.HasIntegrations();

πŸ”’ Rate Limiting

// In Program.cs
builder.Services.AddLinbikRateLimiting();

// In middleware pipeline
app.UseLinbikRateLimiting();
{
  "Linbik": {
    "RateLimiting": {
      "PermitLimit": 100,
      "WindowSeconds": 60,
      "QueueLimit": 2
    },
    "Resilience": {
      "StrictTokenLimit": 10,
      "StrictReplenishmentPeriodSeconds": 60,
      "StrictTokensPerPeriod": 5,
      "StrictQueueLimit": 0
    }
  }
}

Rate Limiting Policies

Policy Use Case
LinbikAuth Login and logout endpoints (fixed/sliding window)
LinbikStrict Callback and refresh endpoints β€” token exchange (token-bucket)
LinbikGeneral Registered for general-purpose use in your own endpoints (more permissive fixed window)
[EnableRateLimiting("LinbikAuth")]
public IActionResult RateLimitedAction() => Ok();

Import Linbik.Core.Extensions to use the shared rate limiting extensions with either authentication provider.

πŸ“– Documentation

πŸ“„ License

MIT License

Contact: info@linbik.com


Version: 1.2.0 Platform: ASP.NET Core 10.0 (net10.0) Last Updated: 9 EylΓΌl 2026

Local refresh tokens

After a successful callback, an upstream Linbik refresh token is used unchanged. When none is returned, AuthManager creates a cryptographically random local refresh token and stores only its SHA-256 hash and the authenticated user's profile. POST the configured RefreshPath (default /api/Linbik/refresh) to renew either kind. Local refresh does not call Linbik or mint integration tokens. Upstream failures never fall back to local sessions. Core's IAuthService is an upstream API helper, not this AuthManager refresh endpoint; do not use it to renew local sessions.

Local tokens rotate atomically on every use. Reusing a consumed token revokes the whole session. Clients must serialize refresh requests (including across browser tabs). The absolute session expiry is established at login using RefreshTokenExpirationDays and is not extended by rotation. LogoutPath revokes the local refresh session and clears cookies; already-issued access tokens remain valid until their own expiry.

The default InMemoryLinbikRefreshTokenStore is process-local. Restarting loses all local refresh sessions. It cannot support multiple application instances. Expired entries are evicted by MemoryCache. No database driver or new package is required. AuthManager.Shared is linked source compiled into each existing AuthManager assembly; its public types live under the selected AuthManager's Services namespace.

To use application-owned storage, implement ILinbikRefreshTokenStore and register it AFTER AddLinbikJwtAuth / AddLinbikPasetoAuth (or before, since defaults use TryAdd):

// using Linbik.PasetoAuthManager.Services; // or Linbik.JwtAuthManager.Services
builder.Services.AddScoped<ILinbikRefreshTokenStore, MyRefreshTokenStore>();

CreateAsync must persist hashes and immutable session data. RotateAsync must perform expiry/revocation validation and replacement atomically, retain consumed hashes until session expiry to detect reuse, and revoke all replacements when reuse is detected. RevokeAsync must invalidate the entire session even when passed an older hash. Persisting a custom store also requires stable access-token signing keys across restarts. Keep those keys in application secret configuration, never source control.

Read-only web session

UseLinbikPasetoAuth() also maps GET /api/Linbik/session (configurable via PasetoAuthOptions.SessionPath). It authenticates through LinbikScheme and returns LBaseResponse with userId, username, displayName and integration cookie names. An absent/invalid access token returns 401; the endpoint never refreshes tokens or writes cookies. Responses are private, no-store. Integration names are UI hints, not authorization evidence. The web SDK's getSession() supports this endpoint. See Nuxt SSR/CSR example.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.2.8 108 9/20/2026
1.2.7 111 9/10/2026
1.2.5 113 9/7/2026
1.2.3 123 9/1/2026
1.2.1 149 7/16/2026
1.2.0-preview.3 75 5/30/2026