Andy.Auth 2026.7.21-rc.250

This is a prerelease version of Andy.Auth.
dotnet add package Andy.Auth --version 2026.7.21-rc.250
                    
NuGet\Install-Package Andy.Auth -Version 2026.7.21-rc.250
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Andy.Auth" Version="2026.7.21-rc.250" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Andy.Auth" Version="2026.7.21-rc.250" />
                    
Directory.Packages.props
<PackageReference Include="Andy.Auth" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Andy.Auth --version 2026.7.21-rc.250
                    
#r "nuget: Andy.Auth, 2026.7.21-rc.250"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Andy.Auth@2026.7.21-rc.250
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Andy.Auth&version=2026.7.21-rc.250&prerelease
                    
Install as a Cake Addin
#tool nuget:?package=Andy.Auth&version=2026.7.21-rc.250&prerelease
                    
Install as a Cake Tool

Andy Auth Server

Self-hosted OAuth 2.0 / OpenID Connect server built with ASP.NET Core and OpenIddict.

ALPHA RELEASE WARNING

This software is in ALPHA stage. NO GUARANTEES are made about its functionality, stability, or safety.

CRITICAL WARNINGS:

  • This tool performs DESTRUCTIVE OPERATIONS on files and directories
  • Permission management is NOT FULLY TESTED and may have security vulnerabilities
  • DO NOT USE in production environments
  • DO NOT USE on systems with critical or irreplaceable data
  • DO NOT USE on systems without complete, verified backups
  • The authors assume NO RESPONSIBILITY for data loss, system damage, or security breaches

USE AT YOUR OWN RISK

Features

  • OAuth 2.0 & OpenID Connect - Standards-compliant authentication server
  • Multiple Grant Types - Authorization Code, Client Credentials, Refresh Tokens
  • PKCE Support - Secure authentication for public clients
  • MCP Compatible - Full Model Context Protocol OAuth 2.1 support for AI assistants
  • Dynamic Client Registration - RFC 7591/7592 compliant DCR
  • User Management - Complete admin UI for managing users and OAuth clients
  • Audit Logging - Track all authentication and authorization events
  • Security Hardened - Rate limiting, account lockout, security headers

Quick Start

Prerequisites

  • .NET 8.0 SDK
  • Docker Desktop (for PostgreSQL)
  • IDE (VS Code, Visual Studio, or Rider)

Local Development

# 1. Start PostgreSQL
docker-compose up -d

# 2. Run the server
cd src/Andy.Auth.Server
dotnet run

Server runs at: https://localhost:5001

Test credentials:

  • Email: test@andy.local
  • Password: Test123!

See docs/LOCAL-SETUP.md for detailed setup instructions.

Andy.Auth Client Library

In addition to the OAuth server, this repository includes Andy.Auth, a NuGet library for easy integration with ASP.NET Core APIs.

Installation:

dotnet add package Andy.Auth

Usage:

// Add to Program.cs
builder.Services.AddAndyAuth(builder.Configuration);

See docs/LIBRARY.md for complete documentation.

What's Included

OAuth/OIDC Server

  • Authorization endpoint (/connect/authorize)
  • Token endpoint (/connect/token)
  • Introspection endpoint (/connect/introspect)
  • Revocation endpoint (/connect/revoke)
  • Dynamic Client Registration (/connect/register)
  • OpenID Discovery (/.well-known/openid-configuration)
  • JWKS endpoint (/.well-known/jwks)

Admin Dashboard

  • Users: View, suspend, expire, soft delete users
  • OAuth Clients: Manage registered applications
  • Tokens: View and revoke active tokens
  • Audit Logs: Track all authentication events

Access at: /Admin

Seeded OAuth Clients

Client Type Use Case
andy-docs-api Confidential Server-to-server communication
wagram-web Public SPA Angular/React web applications
claude-desktop Public Claude Desktop MCP integration
chatgpt Public ChatGPT MCP integration
cline Public Cline VS Code extension
roo Public Roo VS Code extension
continue-dev Public Continue.dev extension

Security Features

  • Rate limiting on all auth endpoints
  • Account lockout (30 min after 5 failed attempts)
  • Password requirements (8+ chars, uppercase, lowercase, digit)
  • Security headers (CSP, X-Frame-Options, HSTS)
  • CSRF protection on all forms
  • SQL injection protection (EF Core)
  • XSS protection (Razor auto-encoding)
  • HTTPS enforcement in production

See docs/SECURITY.md for complete security documentation.

Technology Stack

  • Framework: ASP.NET Core 8.0
  • Authentication: ASP.NET Core Identity
  • OAuth/OIDC: OpenIddict 5.x
  • Database: PostgreSQL 16
  • ORM: Entity Framework Core
  • UI: Razor Views with custom CSS

Deployment

Railway

Deploy to Railway:

  1. Push to GitHub
  2. Connect Railway project
  3. Configure environment variables
  4. Deploy

See docs/DEPLOYMENT.md for complete deployment guide.

Docker

docker build -t andy-auth .
docker run -p 8080:8080 andy-auth

Examples

Working example applications for integrating with Andy Auth:

Example Language/Framework Description
csharp-web C# / ASP.NET Core .NET 8 with OpenID Connect
python-flask Python / Flask OAuth 2.0 + PKCE
javascript-express JavaScript / Express OAuth 2.0 + PKCE
typescript-express TypeScript / Express Type-safe OAuth 2.0
java-spring Java / Spring Boot Spring Security OAuth
go-oauth Go Standard library + oauth2
rust-oauth Rust / Axum Axum + oauth2 crate

Run all examples tests:

./examples/test-examples.sh

Documentation

Interactive docs: Run the server and visit /docs/ for full documentation with tutorials.

Document Description
LOCAL-SETUP.md Development setup guide
ARCHITECTURE.md System architecture
SECURITY.md Security features
ADMIN.md Admin UI documentation
DEPLOYMENT.md Production deployment
testing.md Testing guide
LIBRARY.md Client library documentation
ASSISTANT-INTEGRATION.md AI assistant setup

Testing

Run all tests:

# .NET unit tests
dotnet test

# Python OAuth tests (against UAT)
cd tests/oauth-python
ANDY_AUTH_TEST_PASSWORD="Test123!" python3 run_all_tests.py --env uat

Current Status: See docs/testing.md for the latest test counts and pass rates.

See docs/testing.md for testing guide.

Contributing

Contributions are welcome! Please feel free to submit issues, feature requests, and pull requests.

  1. Fork the repository
  2. Create a feature branch (git checkout -b feature/amazing-feature)
  3. Commit your changes (git commit -m 'Add amazing feature')
  4. Push to the branch (git push origin feature/amazing-feature)
  5. Open a Pull Request

License

Apache 2.0


Status: Alpha (UAT deployed for testing) Version: 0.1.0-alpha Last Updated: 2026-01-13

Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
2026.7.21-rc.250 80 7/21/2026
2026.7.2-rc.234 77 7/2/2026
2026.6.13-rc.233 77 6/13/2026
2026.6.9-rc.231 69 6/9/2026
2026.6.5-rc.229 79 6/5/2026
2026.6.4-rc.227 82 6/4/2026
2026.6.3-rc.225 72 6/3/2026
2026.5.29-rc.223 77 5/29/2026
2026.5.22-rc.220 77 5/22/2026
2026.5.18-rc.217 73 5/18/2026
2026.5.18-rc.216 67 5/18/2026
2026.5.18-rc.215 65 5/18/2026
2026.5.17-rc.214 72 5/17/2026
2026.5.17-rc.212 71 5/17/2026
2026.5.17-rc.211 74 5/17/2026
2026.5.17-rc.210 71 5/17/2026
2026.5.17-rc.209 69 5/17/2026
2026.5.17-rc.207 74 5/17/2026
2026.5.17-rc.206 67 5/17/2026
2026.5.17-rc.204 84 5/17/2026
Loading failed