Soenneker.Entra.Middlewares.JwtAuth.Functions
4.0.311
Prefix Reserved
dotnet add package Soenneker.Entra.Middlewares.JwtAuth.Functions --version 4.0.311
NuGet\Install-Package Soenneker.Entra.Middlewares.JwtAuth.Functions -Version 4.0.311
<PackageReference Include="Soenneker.Entra.Middlewares.JwtAuth.Functions" Version="4.0.311" />
<PackageVersion Include="Soenneker.Entra.Middlewares.JwtAuth.Functions" Version="4.0.311" />
<PackageReference Include="Soenneker.Entra.Middlewares.JwtAuth.Functions" />
paket add Soenneker.Entra.Middlewares.JwtAuth.Functions --version 4.0.311
#r "nuget: Soenneker.Entra.Middlewares.JwtAuth.Functions, 4.0.311"
#:package Soenneker.Entra.Middlewares.JwtAuth.Functions@4.0.311
#addin nuget:?package=Soenneker.Entra.Middlewares.JwtAuth.Functions&version=4.0.311
#tool nuget:?package=Soenneker.Entra.Middlewares.JwtAuth.Functions&version=4.0.311
Soenneker.Entra.Middlewares.JwtAuth.Functions
Bearer-token authentication middleware for .NET isolated Azure Functions using Microsoft Entra OpenID Connect metadata and signing keys.
Install
dotnet add package Soenneker.Entra.Middlewares.JwtAuth.Functions
Configuration
{
"Jwt": {
"MetadataAddress": "https://login.microsoftonline.com/<tenant-id>/v2.0/.well-known/openid-configuration",
"ValidIssuers": [
"https://login.microsoftonline.com/<tenant-id>/v2.0"
],
"ValidAudiences": [
"api://<api-application-id>"
],
"ValidAlgorithms": ["RS256"],
"ExpectedAzpOrAppId": "<authorized-caller-application-id>",
"ClockSkewSeconds": 120,
"EnableVerboseLogging": false
}
}
MetadataAddress, at least one issuer, and at least one audience are required. The metadata address must be an absolute HTTPS URL. Issuer and audience validation cannot be disabled by supplying empty arrays.
ValidAlgorithms defaults to RS256; an explicitly empty list is rejected. ClockSkewSeconds defaults to 120. Keep skew as small as your deployment's clock synchronization permits.
The middleware also requires either the token's azp claim (v2) or appid claim (v1) to equal ExpectedAzpOrAppId. If that setting is omitted, it defaults to 99045fe1-7639-4a75-9d4a-577b6ca3810f, the Microsoft Entra External ID custom-authentication-extension caller. Set it explicitly for other callers.
Register the middleware
using Soenneker.Entra.Middlewares.JwtAuth.Functions.Registrars;
builder.UseEntraFunctionsJwtAuth();
Register it before middleware or function code that assumes an authenticated principal.
Read the authenticated principal
After signature, issuer, audience, lifetime, algorithm, and caller-app validation succeeds, the principal is stored in FunctionContext.Items under "User":
using System.Security.Claims;
if (context.Items.TryGetValue("User", out object? value) &&
value is ClaimsPrincipal principal)
{
string? subject = principal.FindFirst("sub")?.Value;
}
The middleware authenticates the token; it does not enforce scopes, app roles, tenant-specific business rules, or resource ownership. Perform those authorization checks in downstream middleware or the function.
Anonymous and non-HTTP functions
All HTTP-triggered functions are protected by default. Mark an individual function method with AllowAnonymousFunction to bypass validation:
using Soenneker.Functions.Attributes.AllowAnonymous;
[AllowAnonymousFunction]
[Function("Health")]
public HttpResponseData Health(
[HttpTrigger(AuthorizationLevel.Anonymous, "get")] HttpRequestData request)
{
return request.CreateResponse(HttpStatusCode.OK);
}
The attribute is method-only. Non-HTTP triggers bypass JWT validation automatically.
Missing, malformed, expired, incorrectly signed, wrong-issuer, wrong-audience, wrong-algorithm, or wrong-caller tokens receive an unauthorized response and the function is not invoked. OpenID configuration is cached per middleware instance and refreshed when a signing key is not found.
Verbose logging reports validation flow and key identifiers but never logs the bearer token. Successful authentication logs only the function and HTTP method; claims and request URLs are not written at information level.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Microsoft.Azure.Functions.Worker (>= 2.52.0)
- Microsoft.IdentityModel.Protocols.OpenIdConnect (>= 8.23.0)
- Soenneker.Extensions.Configuration (>= 4.0.898)
- Soenneker.Extensions.HttpRequestDatas (>= 4.0.152)
- Soenneker.Extensions.Task (>= 4.0.131)
- Soenneker.Extensions.ValueTask (>= 4.0.124)
- Soenneker.Functions.Attributes.AllowAnonymous (>= 4.0.24)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 4.0.311 | 55 | 10/1/2026 |
| 4.0.310 | 47 | 9/30/2026 |
| 4.0.309 | 102 | 9/25/2026 |
| 4.0.308 | 89 | 9/25/2026 |
| 4.0.307 | 100 | 9/19/2026 |
| 4.0.306 | 120 | 9/16/2026 |
| 4.0.305 | 96 | 9/16/2026 |
| 4.0.304 | 97 | 9/16/2026 |
| 4.0.303 | 97 | 9/15/2026 |
| 4.0.302 | 97 | 9/13/2026 |
| 4.0.301 | 102 | 9/13/2026 |
| 4.0.300 | 96 | 9/13/2026 |
| 4.0.299 | 108 | 9/13/2026 |
| 4.0.298 | 94 | 9/12/2026 |
| 4.0.297 | 102 | 9/12/2026 |
| 4.0.296 | 96 | 9/12/2026 |
| 4.0.295 | 90 | 9/12/2026 |
| 4.0.294 | 92 | 9/12/2026 |
| 4.0.293 | 105 | 9/12/2026 |
| 4.0.292 | 113 | 9/9/2026 |
Updated Soenneker.Extensions.Configuration to 4.0.898