ThinkAgentKit.ToolManifest 0.1.0

dotnet tool install --global ThinkAgentKit.ToolManifest --version 0.1.0
                    
This package contains a .NET tool you can call from the shell/command line.
dotnet new tool-manifest
                    
if you are setting up this repo
dotnet tool install --local ThinkAgentKit.ToolManifest --version 0.1.0
                    
This package contains a .NET tool you can call from the shell/command line.
#tool dotnet:?package=ThinkAgentKit.ToolManifest&version=0.1.0
                    
nuke :add-package ThinkAgentKit.ToolManifest --version 0.1.0
                    

ThinkAgentKit for ASP.NET Core

ThinkAgentKit.AspNetCore is the host half of a ThinkAgentKit deployment. It owns the security boundary a browser and a Cloudflare Worker meet at, and it owns the tool capabilities a remote agent may invoke.

What it provides

  • Connection grants. A short-lived ES256 token bound to exactly one route, one purpose, and one single-use identifier, published for verification through a rotating JWKS document.
  • Authority leases. An opaque, revocable, hashed-at-rest credential the Worker stores in connection state. The browser never sees one.
  • A tool kernel. Typed C# descriptors that are the single source of truth for names, schemas, permissions, approval metadata, timeouts, and idempotency, plus a canonical manifest and its hash.

Registration

builder.Services.AddThinkAgentKit(builder.Configuration);

// The four seams a host application must supply.
builder.Services.AddSingleton<IThinkAuthorizationService, MyAuthorizationService>();
builder.Services.AddSingleton<IThinkSigningKeyProvider, MySigningKeys>();
builder.Services.AddSingleton<IGrantRedemptionStore, MyRedemptionStore>();
builder.Services.AddSingleton<IAuthorityLeaseStore, MyLeaseStore>();
builder.Services.AddThinkToolCatalog(MyTools.CreateCatalog());

var app = builder.Build();
app.UseAuthentication();
app.UseAuthorization();
app.MapThinkAgentKit();

ThinkAgentKit:LeaseHashSalt and ThinkAgentKit:WorkloadCredential are required secrets with no source-code default; startup fails without them.

Threat boundaries

Boundary What is trusted What fails closed
Browser to host The authenticated session, an allowed origin, and a double-submit antiforgery token Any cross-site request, any route or project the current user cannot access, any lifetime beyond policy
Browser to Worker Nothing. The Worker verifies the grant against published keys Signature, time, purpose, route, protocol version, origin, or a replayed identifier
Worker to host The Worker's own workload credential, plus a lease the host resolves server-side An unknown, revoked, expired, or route-mismatched lease; a membership that has since been removed; a manifest hash that is not the active one
Approval The verified identity recorded when the action was proposed Anyone other than the requester, and any authority that is no longer current at execution time

Claims and invocation envelopes are provenance, never authorization: every tool call re-asks the application whether this principal may still act on this project. Error responses are bounded stable codes, and no token, lease, cookie, or handler detail is ever logged or returned.

Running the tests

dotnet test                                       # every host test
dotnet test --filter FullyQualifiedName~Security  # one suite

Generating the Worker contract

npm run generate:host-tools   # writes the manifest and the Worker's tool module
npm run check:host-tools      # regenerates twice and fails on any difference

An unsupported C# schema shape fails generation rather than emitting an untyped wrapper.

Package installation

ThinkAgentKit connects an ASP.NET Core host to the ThinkAgentKit Cloudflare Worker and Angular libraries.

  • ThinkAgentKit.AspNetCore supplies host integration, security contracts and tool descriptors.
  • ThinkAgentKit.AspNetCore.Testing supplies reference adapters and test helpers without a test framework dependency.
  • ThinkAgentKit.AspNetCore.Conformance supplies xUnit suites for host implementations.
  • ThinkAgentKit.ToolManifest is a local .NET tool that generates the Worker contract from a compiled host catalog.

Install the runtime with dotnet add package ThinkAgentKit.AspNetCore --version 0.1.0. Install the generator with dotnet tool install ThinkAgentKit.ToolManifest --local --version 0.1.0 after creating a tool manifest with dotnet new tool-manifest.

Run the generator with dotnet tool run think-agent-kit-manifest -- <output-directory> <host-assembly> <Namespace.Type.CatalogMember>. Use matching versions of the generator, host package and Worker package.

Requires .NET 10. Source and integration documentation: https://github.com/Polycrest-Labs/ThinkAgentKit

Licensed under MIT. Copyright (c) 2026 Polycrest Labs.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

This package has no dependencies.

Version Downloads Last Updated
0.1.0 99 9/10/2026