Trax.Api.Auth
1.44.2
Prefix Reserved
See the version list below for details.
dotnet add package Trax.Api.Auth --version 1.44.2
NuGet\Install-Package Trax.Api.Auth -Version 1.44.2
<PackageReference Include="Trax.Api.Auth" Version="1.44.2" />
<PackageVersion Include="Trax.Api.Auth" Version="1.44.2" />
<PackageReference Include="Trax.Api.Auth" />
paket add Trax.Api.Auth --version 1.44.2
#r "nuget: Trax.Api.Auth, 1.44.2"
#:package Trax.Api.Auth@1.44.2
#addin nuget:?package=Trax.Api.Auth&version=1.44.2
#tool nuget:?package=Trax.Api.Auth&version=1.44.2
Trax.Api authentication and audit
Security disclaimer: read this first
NO WARRANTY FOR SECURITY. Trax.Api.Auth and Trax.Api.GraphQL.Audit are provided AS-IS. Trax, its authors, and contributors are NOT LIABLE for any security breach, credential leak, data loss, or damage arising from systems built on top of these packages. Securing your deployment is the SOLE RESPONSIBILITY OF THE CONSUMER.
Trax auth is plumbing, not a security product. It does not vet the strength of your keys, rotate secrets, detect compromised credentials, enforce TLS, rate-limit abusers, detect replay attacks, or threat-model on your behalf, and it is not a substitute for a professional security review. MIT's NO WARRANTY clause is not a formality: if your deployment is breached, the fault and the fix are yours.
The full disclaimer, including the consumer responsibility checklist, ships in this package as SECURITY-DISCLAIMER.md and is on GitHub: SECURITY-DISCLAIMER.md. Read it before you deploy.
What these packages are
Trax is a .NET framework for building trains (typed pipelines of junctions) with execution logging, scheduling and a GraphQL API. These packages connect ASP.NET Core authentication to the Trax GraphQL API (Trax.Api.GraphQL): every scheme projects the caller into a TraxPrincipal, which [TraxAuthorize] on a train checks and which junctions can inject.
| Package | What it does | Reference |
|---|---|---|
Trax.Api.Auth |
TraxPrincipal, ITraxPrincipalResolver<T> and the claim-type constants every scheme shares. Referenced by the scheme packages. |
TraxPrincipal |
Trax.Api.Auth.ApiKey |
Header-based API keys (X-Api-Key by default), salted and hashed at startup. |
AddTraxApiKeyAuth |
Trax.Api.Auth.Jwt |
JWT bearer tokens, validated by Microsoft.AspNetCore.Authentication.JwtBearer. |
AddTraxJwtAuth |
Trax.Api.Auth.Jwt.Cognito |
UseCognito(...) on the JWT builder: Amazon Cognito ID and access tokens and their claims. |
UseCognito |
Trax.Api.Auth.Jwt.Cognito.Issuer |
Mints Cognito-shaped RS256 tokens, with a refresh-token store contract. | Cognito issuer |
Trax.Api.Auth.Jwt.Testing |
A self-hosted JWKS server and token minters for integration tests. | JWT testing |
Trax.Api.Auth.Oidc |
OpenID Connect code flow with PKCE and a session cookie, for browser sign-in. | AddTraxOidcAuth |
Trax.Api.GraphQL.Audit |
Records each GraphQL request to your ITraxAuditSink from a bounded channel and a background writer. |
API Security |
Installation
dotnet add package Trax.Api.GraphQL
dotnet add package Trax.Api.Auth.ApiKey # or Trax.Api.Auth.Jwt, Trax.Api.Auth.Oidc
dotnet add package Trax.Api.GraphQL.Audit # optional
Example
An API-key scheme and a JWT scheme on one host, the GraphQL endpoint gated on either, and every request audited:
using Trax.Api.Auth.ApiKey;
using Trax.Api.Auth.Jwt;
using Trax.Api.GraphQL.Audit;
using Trax.Api.GraphQL.Extensions;
using Trax.Effect.Data.Postgres.Extensions;
using Trax.Effect.Extensions;
using Trax.Mediator.Extensions;
var builder = WebApplication.CreateBuilder(args);
builder.Services.AddTrax(trax =>
trax.AddEffects(effects => effects.UsePostgres(connectionString))
.AddMediator(typeof(Program).Assembly)
);
// Keys come from your secret manager, never from source control.
builder.Services.AddTraxApiKeyAuth(keys => keys
.Add(builder.Configuration["ApiKeys:Admin"]!, id: "admin", "Admin"));
builder.Services.AddTraxJwtAuth(jwt => jwt.UseAuthority(
authority: "https://login.example.com",
audience: "my-api"));
builder.Services.AddAuthorization();
// With no policy name, RequireAuthorization uses TraxAuthClaimTypes.TraxAuthPolicy, which
// every AddTrax*Auth call adds its scheme to: an API key or a JWT is accepted.
builder.Services.AddTraxGraphQL(graphql => graphql
.RequireAuthorization()
.AddAudit<MyAuditSink>());
var app = builder.Build();
app.UseAuthentication();
app.UseAuthorization();
app.UseTraxGraphQL(); // maps at /trax/graphql
app.Run();
public sealed class MyAuditSink : ITraxAuditSink
{
public Task WriteAsync(IReadOnlyList<TraxAuditEntry> batch, CancellationToken ct)
{
// Persist the batch. Redact sensitive variables first with an ITraxAuditRedactor.
return Task.CompletedTask;
}
}
Per-train authorization uses [TraxAuthorize] on the train class; see Authorization. Subscriptions carry credentials in the connection_init payload; see API Security.
Documentation
- API Security: every scheme, subscription auth, auditing and hardening defaults
- API Auth reference
- Trax documentation
- Source: github.com/TraxSharp/Trax.Api
License
MIT, with the security disclaimer above. See LICENSE.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Microsoft.EntityFrameworkCore (>= 10.0.12)
- Trax.Effect (>= 1.57.4)
- Trax.Effect.Data (>= 1.57.4)
- Trax.Mediator (>= 1.23.3)
NuGet packages (5)
Showing the top 5 NuGet packages that depend on Trax.Api.Auth:
| Package | Downloads |
|---|---|
|
Trax.Api.GraphQL
GraphQL API for Trax on HotChocolate: runs and queues trains, exposes executions, manifests and the work queue, and generates queries from [TraxQueryModel] entities. Install it to give a Trax host a GraphQL endpoint (AddTraxGraphQL, UseTraxGraphQL). |
|
|
Trax.Api.Auth.Jwt
JWT bearer authentication scheme for Trax: thin wrapper over Microsoft.AspNetCore.Authentication.JwtBearer that projects validated tokens into a TraxPrincipal. NO WARRANTY. Trax auth is plumbing, not a security product. You are solely responsible for securing systems that use it. See SECURITY-DISCLAIMER.md. |
|
|
Trax.Api.Auth.ApiKey
API-key authentication for the Trax GraphQL API: an X-Api-Key header handler with salted, hashed keys, registered with AddTraxApiKeyAuth. Install to authenticate service-to-service callers. NO WARRANTY. Trax auth is plumbing, not a security product. You are solely responsible for securing systems that use it. See SECURITY-DISCLAIMER.md. |
|
|
Trax.Api.GraphQL.Audit
Request-level audit pipeline for the Trax GraphQL API: a bounded-channel listener and background batch writer that hand each request to your ITraxAuditSink, registered with AddAudit on the GraphQL builder. NO WARRANTY. Trax auth is plumbing, not a security product. You are solely responsible for securing systems that use it. See SECURITY-DISCLAIMER.md. |
|
|
Trax.Api.Auth.Oidc
OpenID Connect authentication scheme for Trax: code flow with PKCE, session cookie, and a resolver hook that projects ID-token claims into a TraxPrincipal. NO WARRANTY. Trax auth is plumbing, not a security product. You are solely responsible for securing systems that use it. See SECURITY-DISCLAIMER.md. |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated | |
|---|---|---|---|
| 1.45.0 | 0 | 10/2/2026 | |
| 1.44.2 | 57 | 10/1/2026 | |
| 1.44.1 | 184 | 9/29/2026 | |
| 1.44.0 | 96 | 9/29/2026 | |
| 1.43.2 | 515 | 9/24/2026 | |
| 1.43.1 | 1,320 | 9/16/2026 | |
| 1.43.0 | 170 | 9/16/2026 | |
| 1.42.0 | 1,551 | 9/15/2026 | |
| 1.41.1 | 1,015 | 9/2/2026 | |
| 1.41.0 | 196 | 9/2/2026 | |
| 1.40.0 | 406 | 7/29/2026 | |
| 1.39.0 | 412 | 7/8/2026 | |
| 1.38.1 | 2,159 | 7/6/2026 | |
| 1.38.0 | 1,376 | 6/2/2026 | |
| 1.37.0 | 495 | 6/2/2026 | |
| 1.36.0 | 248 | 6/2/2026 | |
| 1.35.0 | 273 | 6/1/2026 | |
| 1.34.1 | 744 | 5/21/2026 | |
| 1.34.0 | 206 | 5/21/2026 | |
| 1.33.0 | 261 | 5/19/2026 |
NO WARRANTY. Trax auth is plumbing, not a security product. You are solely responsible for securing systems that use it. See SECURITY-DISCLAIMER.md.