Soenneker.Entra.Middlewares.JwtAuth.Functions 4.0.311

Prefix Reserved
dotnet add package Soenneker.Entra.Middlewares.JwtAuth.Functions --version 4.0.311
                    
NuGet\Install-Package Soenneker.Entra.Middlewares.JwtAuth.Functions -Version 4.0.311
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Soenneker.Entra.Middlewares.JwtAuth.Functions" Version="4.0.311" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Soenneker.Entra.Middlewares.JwtAuth.Functions" Version="4.0.311" />
                    
Directory.Packages.props
<PackageReference Include="Soenneker.Entra.Middlewares.JwtAuth.Functions" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Soenneker.Entra.Middlewares.JwtAuth.Functions --version 4.0.311
                    
#r "nuget: Soenneker.Entra.Middlewares.JwtAuth.Functions, 4.0.311"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Soenneker.Entra.Middlewares.JwtAuth.Functions@4.0.311
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Soenneker.Entra.Middlewares.JwtAuth.Functions&version=4.0.311
                    
Install as a Cake Addin
#tool nuget:?package=Soenneker.Entra.Middlewares.JwtAuth.Functions&version=4.0.311
                    
Install as a Cake Tool

alternate text is missing from this package README image alternate text is missing from this package README image alternate text is missing from this package README image alternate text is missing from this package README image

Soenneker.Entra.Middlewares.JwtAuth.Functions

Bearer-token authentication middleware for .NET isolated Azure Functions using Microsoft Entra OpenID Connect metadata and signing keys.

Install

dotnet add package Soenneker.Entra.Middlewares.JwtAuth.Functions

Configuration

{
  "Jwt": {
    "MetadataAddress": "https://login.microsoftonline.com/<tenant-id>/v2.0/.well-known/openid-configuration",
    "ValidIssuers": [
      "https://login.microsoftonline.com/<tenant-id>/v2.0"
    ],
    "ValidAudiences": [
      "api://<api-application-id>"
    ],
    "ValidAlgorithms": ["RS256"],
    "ExpectedAzpOrAppId": "<authorized-caller-application-id>",
    "ClockSkewSeconds": 120,
    "EnableVerboseLogging": false
  }
}

MetadataAddress, at least one issuer, and at least one audience are required. The metadata address must be an absolute HTTPS URL. Issuer and audience validation cannot be disabled by supplying empty arrays.

ValidAlgorithms defaults to RS256; an explicitly empty list is rejected. ClockSkewSeconds defaults to 120. Keep skew as small as your deployment's clock synchronization permits.

The middleware also requires either the token's azp claim (v2) or appid claim (v1) to equal ExpectedAzpOrAppId. If that setting is omitted, it defaults to 99045fe1-7639-4a75-9d4a-577b6ca3810f, the Microsoft Entra External ID custom-authentication-extension caller. Set it explicitly for other callers.

Register the middleware

using Soenneker.Entra.Middlewares.JwtAuth.Functions.Registrars;

builder.UseEntraFunctionsJwtAuth();

Register it before middleware or function code that assumes an authenticated principal.

Read the authenticated principal

After signature, issuer, audience, lifetime, algorithm, and caller-app validation succeeds, the principal is stored in FunctionContext.Items under "User":

using System.Security.Claims;

if (context.Items.TryGetValue("User", out object? value) &&
    value is ClaimsPrincipal principal)
{
    string? subject = principal.FindFirst("sub")?.Value;
}

The middleware authenticates the token; it does not enforce scopes, app roles, tenant-specific business rules, or resource ownership. Perform those authorization checks in downstream middleware or the function.

Anonymous and non-HTTP functions

All HTTP-triggered functions are protected by default. Mark an individual function method with AllowAnonymousFunction to bypass validation:

using Soenneker.Functions.Attributes.AllowAnonymous;

[AllowAnonymousFunction]
[Function("Health")]
public HttpResponseData Health(
    [HttpTrigger(AuthorizationLevel.Anonymous, "get")] HttpRequestData request)
{
    return request.CreateResponse(HttpStatusCode.OK);
}

The attribute is method-only. Non-HTTP triggers bypass JWT validation automatically.

Missing, malformed, expired, incorrectly signed, wrong-issuer, wrong-audience, wrong-algorithm, or wrong-caller tokens receive an unauthorized response and the function is not invoked. OpenID configuration is cached per middleware instance and refreshed when a signing key is not found.

Verbose logging reports validation flow and key identifiers but never logs the bearer token. Successful authentication logs only the function and HTTP method; claims and request URLs are not written at information level.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
4.0.311 55 10/1/2026
4.0.310 47 9/30/2026
4.0.309 102 9/25/2026
4.0.308 89 9/25/2026
4.0.307 100 9/19/2026
4.0.306 120 9/16/2026
4.0.305 96 9/16/2026
4.0.304 97 9/16/2026
4.0.303 97 9/15/2026
4.0.302 97 9/13/2026
4.0.301 102 9/13/2026
4.0.300 96 9/13/2026
4.0.299 108 9/13/2026
4.0.298 94 9/12/2026
4.0.297 102 9/12/2026
4.0.296 96 9/12/2026
4.0.295 90 9/12/2026
4.0.294 92 9/12/2026
4.0.293 105 9/12/2026
4.0.292 113 9/9/2026
Loading failed

Updated Soenneker.Extensions.Configuration to 4.0.898