ThinkAgentKit.AspNetCore.Testing
0.1.0
dotnet add package ThinkAgentKit.AspNetCore.Testing --version 0.1.0
NuGet\Install-Package ThinkAgentKit.AspNetCore.Testing -Version 0.1.0
<PackageReference Include="ThinkAgentKit.AspNetCore.Testing" Version="0.1.0" />
<PackageVersion Include="ThinkAgentKit.AspNetCore.Testing" Version="0.1.0" />
<PackageReference Include="ThinkAgentKit.AspNetCore.Testing" />
paket add ThinkAgentKit.AspNetCore.Testing --version 0.1.0
#r "nuget: ThinkAgentKit.AspNetCore.Testing, 0.1.0"
#:package ThinkAgentKit.AspNetCore.Testing@0.1.0
#addin nuget:?package=ThinkAgentKit.AspNetCore.Testing&version=0.1.0
#tool nuget:?package=ThinkAgentKit.AspNetCore.Testing&version=0.1.0
ThinkAgentKit for ASP.NET Core
ThinkAgentKit.AspNetCore is the host half of a ThinkAgentKit deployment. It
owns the security boundary a browser and a Cloudflare Worker meet at, and it
owns the tool capabilities a remote agent may invoke.
What it provides
- Connection grants. A short-lived ES256 token bound to exactly one route, one purpose, and one single-use identifier, published for verification through a rotating JWKS document.
- Authority leases. An opaque, revocable, hashed-at-rest credential the Worker stores in connection state. The browser never sees one.
- A tool kernel. Typed C# descriptors that are the single source of truth for names, schemas, permissions, approval metadata, timeouts, and idempotency, plus a canonical manifest and its hash.
Registration
builder.Services.AddThinkAgentKit(builder.Configuration);
// The four seams a host application must supply.
builder.Services.AddSingleton<IThinkAuthorizationService, MyAuthorizationService>();
builder.Services.AddSingleton<IThinkSigningKeyProvider, MySigningKeys>();
builder.Services.AddSingleton<IGrantRedemptionStore, MyRedemptionStore>();
builder.Services.AddSingleton<IAuthorityLeaseStore, MyLeaseStore>();
builder.Services.AddThinkToolCatalog(MyTools.CreateCatalog());
var app = builder.Build();
app.UseAuthentication();
app.UseAuthorization();
app.MapThinkAgentKit();
ThinkAgentKit:LeaseHashSalt and ThinkAgentKit:WorkloadCredential are
required secrets with no source-code default; startup fails without them.
Threat boundaries
| Boundary | What is trusted | What fails closed |
|---|---|---|
| Browser to host | The authenticated session, an allowed origin, and a double-submit antiforgery token | Any cross-site request, any route or project the current user cannot access, any lifetime beyond policy |
| Browser to Worker | Nothing. The Worker verifies the grant against published keys | Signature, time, purpose, route, protocol version, origin, or a replayed identifier |
| Worker to host | The Worker's own workload credential, plus a lease the host resolves server-side | An unknown, revoked, expired, or route-mismatched lease; a membership that has since been removed; a manifest hash that is not the active one |
| Approval | The verified identity recorded when the action was proposed | Anyone other than the requester, and any authority that is no longer current at execution time |
Claims and invocation envelopes are provenance, never authorization: every tool call re-asks the application whether this principal may still act on this project. Error responses are bounded stable codes, and no token, lease, cookie, or handler detail is ever logged or returned.
Running the tests
dotnet test # every host test
dotnet test --filter FullyQualifiedName~Security # one suite
Generating the Worker contract
npm run generate:host-tools # writes the manifest and the Worker's tool module
npm run check:host-tools # regenerates twice and fails on any difference
An unsupported C# schema shape fails generation rather than emitting an untyped wrapper.
Package installation
ThinkAgentKit connects an ASP.NET Core host to the ThinkAgentKit Cloudflare Worker and Angular libraries.
- ThinkAgentKit.AspNetCore supplies host integration, security contracts and tool descriptors.
- ThinkAgentKit.AspNetCore.Testing supplies reference adapters and test helpers without a test framework dependency.
- ThinkAgentKit.AspNetCore.Conformance supplies xUnit suites for host implementations.
- ThinkAgentKit.ToolManifest is a local .NET tool that generates the Worker contract from a compiled host catalog.
Install the runtime with dotnet add package ThinkAgentKit.AspNetCore --version 0.1.0.
Install the generator with dotnet tool install ThinkAgentKit.ToolManifest --local --version 0.1.0 after creating a tool manifest with dotnet new tool-manifest.
Run the generator with dotnet tool run think-agent-kit-manifest -- <output-directory> <host-assembly> <Namespace.Type.CatalogMember>.
Use matching versions of the generator, host package and Worker package.
Requires .NET 10. Source and integration documentation: https://github.com/Polycrest-Labs/ThinkAgentKit
Licensed under MIT. Copyright (c) 2026 Polycrest Labs.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Microsoft.IdentityModel.JsonWebTokens (>= 8.22.0)
- ThinkAgentKit.AspNetCore (>= 0.1.0)
NuGet packages (1)
Showing the top 1 NuGet packages that depend on ThinkAgentKit.AspNetCore.Testing:
| Package | Downloads |
|---|---|
|
ThinkAgentKit.AspNetCore.Conformance
Executable xUnit conformance contracts for ThinkAgentKit host adapters. |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 0.1.0 | 108 | 9/10/2026 |