Trax.Api.Auth.ApiKey
1.44.2
Prefix Reserved
See the version list below for details.
dotnet add package Trax.Api.Auth.ApiKey --version 1.44.2
NuGet\Install-Package Trax.Api.Auth.ApiKey -Version 1.44.2
<PackageReference Include="Trax.Api.Auth.ApiKey" Version="1.44.2" />
<PackageVersion Include="Trax.Api.Auth.ApiKey" Version="1.44.2" />
<PackageReference Include="Trax.Api.Auth.ApiKey" />
paket add Trax.Api.Auth.ApiKey --version 1.44.2
#r "nuget: Trax.Api.Auth.ApiKey, 1.44.2"
#:package Trax.Api.Auth.ApiKey@1.44.2
#addin nuget:?package=Trax.Api.Auth.ApiKey&version=1.44.2
#tool nuget:?package=Trax.Api.Auth.ApiKey&version=1.44.2
Trax.Api authentication and audit
Security disclaimer: read this first
NO WARRANTY FOR SECURITY. Trax.Api.Auth and Trax.Api.GraphQL.Audit are provided AS-IS. Trax, its authors, and contributors are NOT LIABLE for any security breach, credential leak, data loss, or damage arising from systems built on top of these packages. Securing your deployment is the SOLE RESPONSIBILITY OF THE CONSUMER.
Trax auth is plumbing, not a security product. It does not vet the strength of your keys, rotate secrets, detect compromised credentials, enforce TLS, rate-limit abusers, detect replay attacks, or threat-model on your behalf, and it is not a substitute for a professional security review. MIT's NO WARRANTY clause is not a formality: if your deployment is breached, the fault and the fix are yours.
The full disclaimer, including the consumer responsibility checklist, ships in this package as SECURITY-DISCLAIMER.md and is on GitHub: SECURITY-DISCLAIMER.md. Read it before you deploy.
What these packages are
Trax is a .NET framework for building trains (typed pipelines of junctions) with execution logging, scheduling and a GraphQL API. These packages connect ASP.NET Core authentication to the Trax GraphQL API (Trax.Api.GraphQL): every scheme projects the caller into a TraxPrincipal, which [TraxAuthorize] on a train checks and which junctions can inject.
| Package | What it does | Reference |
|---|---|---|
Trax.Api.Auth |
TraxPrincipal, ITraxPrincipalResolver<T> and the claim-type constants every scheme shares. Referenced by the scheme packages. |
TraxPrincipal |
Trax.Api.Auth.ApiKey |
Header-based API keys (X-Api-Key by default), salted and hashed at startup. |
AddTraxApiKeyAuth |
Trax.Api.Auth.Jwt |
JWT bearer tokens, validated by Microsoft.AspNetCore.Authentication.JwtBearer. |
AddTraxJwtAuth |
Trax.Api.Auth.Jwt.Cognito |
UseCognito(...) on the JWT builder: Amazon Cognito ID and access tokens and their claims. |
UseCognito |
Trax.Api.Auth.Jwt.Cognito.Issuer |
Mints Cognito-shaped RS256 tokens, with a refresh-token store contract. | Cognito issuer |
Trax.Api.Auth.Jwt.Testing |
A self-hosted JWKS server and token minters for integration tests. | JWT testing |
Trax.Api.Auth.Oidc |
OpenID Connect code flow with PKCE and a session cookie, for browser sign-in. | AddTraxOidcAuth |
Trax.Api.GraphQL.Audit |
Records each GraphQL request to your ITraxAuditSink from a bounded channel and a background writer. |
API Security |
Installation
dotnet add package Trax.Api.GraphQL
dotnet add package Trax.Api.Auth.ApiKey # or Trax.Api.Auth.Jwt, Trax.Api.Auth.Oidc
dotnet add package Trax.Api.GraphQL.Audit # optional
Example
An API-key scheme and a JWT scheme on one host, the GraphQL endpoint gated on either, and every request audited:
using Trax.Api.Auth.ApiKey;
using Trax.Api.Auth.Jwt;
using Trax.Api.GraphQL.Audit;
using Trax.Api.GraphQL.Extensions;
using Trax.Effect.Data.Postgres.Extensions;
using Trax.Effect.Extensions;
using Trax.Mediator.Extensions;
var builder = WebApplication.CreateBuilder(args);
builder.Services.AddTrax(trax =>
trax.AddEffects(effects => effects.UsePostgres(connectionString))
.AddMediator(typeof(Program).Assembly)
);
// Keys come from your secret manager, never from source control.
builder.Services.AddTraxApiKeyAuth(keys => keys
.Add(builder.Configuration["ApiKeys:Admin"]!, id: "admin", "Admin"));
builder.Services.AddTraxJwtAuth(jwt => jwt.UseAuthority(
authority: "https://login.example.com",
audience: "my-api"));
builder.Services.AddAuthorization();
// With no policy name, RequireAuthorization uses TraxAuthClaimTypes.TraxAuthPolicy, which
// every AddTrax*Auth call adds its scheme to: an API key or a JWT is accepted.
builder.Services.AddTraxGraphQL(graphql => graphql
.RequireAuthorization()
.AddAudit<MyAuditSink>());
var app = builder.Build();
app.UseAuthentication();
app.UseAuthorization();
app.UseTraxGraphQL(); // maps at /trax/graphql
app.Run();
public sealed class MyAuditSink : ITraxAuditSink
{
public Task WriteAsync(IReadOnlyList<TraxAuditEntry> batch, CancellationToken ct)
{
// Persist the batch. Redact sensitive variables first with an ITraxAuditRedactor.
return Task.CompletedTask;
}
}
Per-train authorization uses [TraxAuthorize] on the train class; see Authorization. Subscriptions carry credentials in the connection_init payload; see API Security.
Documentation
- API Security: every scheme, subscription auth, auditing and hardening defaults
- API Auth reference
- Trax documentation
- Source: github.com/TraxSharp/Trax.Api
License
MIT, with the security disclaimer above. See LICENSE.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Microsoft.EntityFrameworkCore (>= 10.0.12)
- Trax.Api.Auth (>= 1.44.2)
- Trax.Effect (>= 1.57.4)
- Trax.Effect.Data (>= 1.57.4)
- Trax.Mediator (>= 1.23.3)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 1.45.0 | 0 | 10/2/2026 |
| 1.44.2 | 43 | 10/1/2026 |
| 1.44.1 | 143 | 9/29/2026 |
| 1.44.0 | 44 | 9/29/2026 |
| 1.43.2 | 216 | 9/24/2026 |
| 1.43.1 | 175 | 9/16/2026 |
| 1.43.0 | 91 | 9/16/2026 |
| 1.42.0 | 136 | 9/15/2026 |
| 1.41.1 | 106 | 9/2/2026 |
| 1.41.0 | 100 | 9/2/2026 |
| 1.40.0 | 211 | 7/29/2026 |
| 1.39.0 | 227 | 7/8/2026 |
| 1.38.1 | 171 | 7/6/2026 |
| 1.38.0 | 272 | 6/2/2026 |
| 1.37.0 | 134 | 6/2/2026 |
| 1.36.0 | 124 | 6/2/2026 |
| 1.35.0 | 134 | 6/1/2026 |
| 1.34.1 | 371 | 5/21/2026 |
| 1.34.0 | 118 | 5/21/2026 |
| 1.33.0 | 117 | 5/19/2026 |
NO WARRANTY. Trax auth is plumbing, not a security product. You are solely responsible for securing systems that use it. See SECURITY-DISCLAIMER.md.