Andy.Auth
2026.7.21-rc.250
dotnet add package Andy.Auth --version 2026.7.21-rc.250
NuGet\Install-Package Andy.Auth -Version 2026.7.21-rc.250
<PackageReference Include="Andy.Auth" Version="2026.7.21-rc.250" />
<PackageVersion Include="Andy.Auth" Version="2026.7.21-rc.250" />
<PackageReference Include="Andy.Auth" />
paket add Andy.Auth --version 2026.7.21-rc.250
#r "nuget: Andy.Auth, 2026.7.21-rc.250"
#:package Andy.Auth@2026.7.21-rc.250
#addin nuget:?package=Andy.Auth&version=2026.7.21-rc.250&prerelease
#tool nuget:?package=Andy.Auth&version=2026.7.21-rc.250&prerelease
Andy Auth Server
Self-hosted OAuth 2.0 / OpenID Connect server built with ASP.NET Core and OpenIddict.
ALPHA RELEASE WARNING
This software is in ALPHA stage. NO GUARANTEES are made about its functionality, stability, or safety.
CRITICAL WARNINGS:
- This tool performs DESTRUCTIVE OPERATIONS on files and directories
- Permission management is NOT FULLY TESTED and may have security vulnerabilities
- DO NOT USE in production environments
- DO NOT USE on systems with critical or irreplaceable data
- DO NOT USE on systems without complete, verified backups
- The authors assume NO RESPONSIBILITY for data loss, system damage, or security breaches
USE AT YOUR OWN RISK
Features
- OAuth 2.0 & OpenID Connect - Standards-compliant authentication server
- Multiple Grant Types - Authorization Code, Client Credentials, Refresh Tokens
- PKCE Support - Secure authentication for public clients
- MCP Compatible - Full Model Context Protocol OAuth 2.1 support for AI assistants
- Dynamic Client Registration - RFC 7591/7592 compliant DCR
- User Management - Complete admin UI for managing users and OAuth clients
- Audit Logging - Track all authentication and authorization events
- Security Hardened - Rate limiting, account lockout, security headers
Quick Start
Prerequisites
- .NET 8.0 SDK
- Docker Desktop (for PostgreSQL)
- IDE (VS Code, Visual Studio, or Rider)
Local Development
# 1. Start PostgreSQL
docker-compose up -d
# 2. Run the server
cd src/Andy.Auth.Server
dotnet run
Server runs at: https://localhost:5001
Test credentials:
- Email:
test@andy.local - Password:
Test123!
See docs/LOCAL-SETUP.md for detailed setup instructions.
Andy.Auth Client Library
In addition to the OAuth server, this repository includes Andy.Auth, a NuGet library for easy integration with ASP.NET Core APIs.
Installation:
dotnet add package Andy.Auth
Usage:
// Add to Program.cs
builder.Services.AddAndyAuth(builder.Configuration);
See docs/LIBRARY.md for complete documentation.
What's Included
OAuth/OIDC Server
- Authorization endpoint (
/connect/authorize) - Token endpoint (
/connect/token) - Introspection endpoint (
/connect/introspect) - Revocation endpoint (
/connect/revoke) - Dynamic Client Registration (
/connect/register) - OpenID Discovery (
/.well-known/openid-configuration) - JWKS endpoint (
/.well-known/jwks)
Admin Dashboard
- Users: View, suspend, expire, soft delete users
- OAuth Clients: Manage registered applications
- Tokens: View and revoke active tokens
- Audit Logs: Track all authentication events
Access at: /Admin
Seeded OAuth Clients
| Client | Type | Use Case |
|---|---|---|
andy-docs-api |
Confidential | Server-to-server communication |
wagram-web |
Public SPA | Angular/React web applications |
claude-desktop |
Public | Claude Desktop MCP integration |
chatgpt |
Public | ChatGPT MCP integration |
cline |
Public | Cline VS Code extension |
roo |
Public | Roo VS Code extension |
continue-dev |
Public | Continue.dev extension |
Security Features
- Rate limiting on all auth endpoints
- Account lockout (30 min after 5 failed attempts)
- Password requirements (8+ chars, uppercase, lowercase, digit)
- Security headers (CSP, X-Frame-Options, HSTS)
- CSRF protection on all forms
- SQL injection protection (EF Core)
- XSS protection (Razor auto-encoding)
- HTTPS enforcement in production
See docs/SECURITY.md for complete security documentation.
Technology Stack
- Framework: ASP.NET Core 8.0
- Authentication: ASP.NET Core Identity
- OAuth/OIDC: OpenIddict 5.x
- Database: PostgreSQL 16
- ORM: Entity Framework Core
- UI: Razor Views with custom CSS
Deployment
Railway
Deploy to Railway:
- Push to GitHub
- Connect Railway project
- Configure environment variables
- Deploy
See docs/DEPLOYMENT.md for complete deployment guide.
Docker
docker build -t andy-auth .
docker run -p 8080:8080 andy-auth
Examples
Working example applications for integrating with Andy Auth:
| Example | Language/Framework | Description |
|---|---|---|
| csharp-web | C# / ASP.NET Core | .NET 8 with OpenID Connect |
| python-flask | Python / Flask | OAuth 2.0 + PKCE |
| javascript-express | JavaScript / Express | OAuth 2.0 + PKCE |
| typescript-express | TypeScript / Express | Type-safe OAuth 2.0 |
| java-spring | Java / Spring Boot | Spring Security OAuth |
| go-oauth | Go | Standard library + oauth2 |
| rust-oauth | Rust / Axum | Axum + oauth2 crate |
Run all examples tests:
./examples/test-examples.sh
Documentation
Interactive docs: Run the server and visit /docs/ for full documentation with tutorials.
| Document | Description |
|---|---|
| LOCAL-SETUP.md | Development setup guide |
| ARCHITECTURE.md | System architecture |
| SECURITY.md | Security features |
| ADMIN.md | Admin UI documentation |
| DEPLOYMENT.md | Production deployment |
| testing.md | Testing guide |
| LIBRARY.md | Client library documentation |
| ASSISTANT-INTEGRATION.md | AI assistant setup |
Testing
Run all tests:
# .NET unit tests
dotnet test
# Python OAuth tests (against UAT)
cd tests/oauth-python
ANDY_AUTH_TEST_PASSWORD="Test123!" python3 run_all_tests.py --env uat
Current Status: See docs/testing.md for the latest test counts and pass rates.
See docs/testing.md for testing guide.
Contributing
Contributions are welcome! Please feel free to submit issues, feature requests, and pull requests.
- Fork the repository
- Create a feature branch (
git checkout -b feature/amazing-feature) - Commit your changes (
git commit -m 'Add amazing feature') - Push to the branch (
git push origin feature/amazing-feature) - Open a Pull Request
License
Apache 2.0
Status: Alpha (UAT deployed for testing) Version: 0.1.0-alpha Last Updated: 2026-01-13
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 was computed. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net8.0
- Microsoft.AspNetCore.Authentication.JwtBearer (>= 8.0.0)
- System.IdentityModel.Tokens.Jwt (>= 7.3.1)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 2026.7.21-rc.250 | 80 | 7/21/2026 |
| 2026.7.2-rc.234 | 77 | 7/2/2026 |
| 2026.6.13-rc.233 | 77 | 6/13/2026 |
| 2026.6.9-rc.231 | 69 | 6/9/2026 |
| 2026.6.5-rc.229 | 79 | 6/5/2026 |
| 2026.6.4-rc.227 | 82 | 6/4/2026 |
| 2026.6.3-rc.225 | 72 | 6/3/2026 |
| 2026.5.29-rc.223 | 77 | 5/29/2026 |
| 2026.5.22-rc.220 | 77 | 5/22/2026 |
| 2026.5.18-rc.217 | 73 | 5/18/2026 |
| 2026.5.18-rc.216 | 67 | 5/18/2026 |
| 2026.5.18-rc.215 | 65 | 5/18/2026 |
| 2026.5.17-rc.214 | 72 | 5/17/2026 |
| 2026.5.17-rc.212 | 71 | 5/17/2026 |
| 2026.5.17-rc.211 | 74 | 5/17/2026 |
| 2026.5.17-rc.210 | 71 | 5/17/2026 |
| 2026.5.17-rc.209 | 69 | 5/17/2026 |
| 2026.5.17-rc.207 | 74 | 5/17/2026 |
| 2026.5.17-rc.206 | 67 | 5/17/2026 |
| 2026.5.17-rc.204 | 84 | 5/17/2026 |