Authlink.Auth.ServiceStack
2.1.0
dotnet add package Authlink.Auth.ServiceStack --version 2.1.0
NuGet\Install-Package Authlink.Auth.ServiceStack -Version 2.1.0
<PackageReference Include="Authlink.Auth.ServiceStack" Version="2.1.0" />
<PackageVersion Include="Authlink.Auth.ServiceStack" Version="2.1.0" />
<PackageReference Include="Authlink.Auth.ServiceStack" />
paket add Authlink.Auth.ServiceStack --version 2.1.0
#r "nuget: Authlink.Auth.ServiceStack, 2.1.0"
#:package Authlink.Auth.ServiceStack@2.1.0
#addin nuget:?package=Authlink.Auth.ServiceStack&version=2.1.0
#tool nuget:?package=Authlink.Auth.ServiceStack&version=2.1.0
📦 Overview
Authlink.Auth.ServiceStack enables secure token-based authentication in ServiceStack applications using the IIdentityClient abstraction from Authlink.Identity.Client.Core.
It allows your ServiceStack APIs to:
- Authenticate users via your Authlink Identity Provider
- Automatically resolve user claims and populate sessions
- Support access and refresh token flows via OIDC
🚀 Installation
dotnet add package Authlink.Auth.ServiceStack
Or via NuGet Package Manager:
PM> Install-Package Authlink.Auth.ServiceStack
🔧 Usage Example
In your AppHost.cs:
var client = Container.GetRequiredService<IIdentityClient>();
var provider = new JwtAuthProviderReader(
"https://identity.authlink.co.za",
["https://api.example.com"],
"client-id",
client);
Plugins.Add(new AuthFeature(() => new AuthUserSession(), [provider]));
⚙️ Configuration
| Property | Default | Description |
|---|---|---|
RequireSecureCookies |
true |
Whether cookies should be marked as Secure (HTTPS-only). Set to false for local development. |
ClockSkew |
1 minute |
Clock skew tolerance applied when validating token lifetime. Increase if host clocks may drift. |
UseCookies |
true |
Whether tokens should be stored in cookies. |
JwksRefreshInterval |
1 hour |
How long a cached JWKS snapshot is considered fresh before an opportunistic refresh. Matches the Identity Provider's Cache-Control: max-age. |
UnknownKidRefreshThrottle |
30 seconds |
Minimum interval between JWKS refreshes triggered by a token referencing an unknown kid. Bounds refresh traffic against the JWKS endpoint. |
FailedRefreshBackoff |
10 seconds |
Minimum interval between JWKS refresh attempts after a failed fetch. Prevents an Identity Provider outage from amplifying into one JWKS call per request. |
provider.RequireSecureCookies = !environment.IsDevelopment();
provider.ClockSkew = TimeSpan.FromMinutes(2);
provider.JwksRefreshInterval = TimeSpan.FromMinutes(15);
🔑 JWKS caching & key rotation
The provider keeps an immutable in-memory snapshot of the Identity Provider's signing keys and validates
tokens locally. The JWKS endpoint (/api/connect/jwks) is only contacted when:
- the cache has not yet been populated (cold start);
JwksRefreshIntervalhas elapsed since the last successful refresh;- a token references a
kidthat is not in the current snapshot (throttled byUnknownKidRefreshThrottle).
Requests without a JWT never contact the Identity Provider. Concurrent refreshes are coalesced into a
single fetch, and if a refresh fails the previous valid snapshot continues to be served while further
attempts are suppressed for FailedRefreshBackoff, so an outage cannot amplify into one JWKS call per
request. Malformed keys in a JWKS response are skipped individually rather than failing the refresh.
Because the Identity Provider announces new signing keys as pending in JWKS ahead of activation (a
propagation period), a snapshot refreshed within that window will already contain the next key before any
token is signed with it, so unknown-kid refreshes are rare in normal rotation. Note that emergency key
revocation propagates on the next interval refresh rather than instantly.
📚 Documentation
Coming soon at: https://docs.authlink.co.za
📄 License
MIT
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net9.0 is compatible. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 was computed. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net9.0
- Authlink.Identity.Client.Core (>= 3.0.0)
- Microsoft.IdentityModel.JsonWebTokens (>= 8.9.0)
- Microsoft.IdentityModel.Tokens (>= 8.9.0)
- ServiceStack (>= 8.9.0)
- System.IdentityModel.Tokens.Jwt (>= 8.9.0)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.