Authlink.Auth.ServiceStack 2.1.0

dotnet add package Authlink.Auth.ServiceStack --version 2.1.0
                    
NuGet\Install-Package Authlink.Auth.ServiceStack -Version 2.1.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Authlink.Auth.ServiceStack" Version="2.1.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Authlink.Auth.ServiceStack" Version="2.1.0" />
                    
Directory.Packages.props
<PackageReference Include="Authlink.Auth.ServiceStack" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Authlink.Auth.ServiceStack --version 2.1.0
                    
#r "nuget: Authlink.Auth.ServiceStack, 2.1.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Authlink.Auth.ServiceStack@2.1.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Authlink.Auth.ServiceStack&version=2.1.0
                    
Install as a Cake Addin
#tool nuget:?package=Authlink.Auth.ServiceStack&version=2.1.0
                    
Install as a Cake Tool

📦 Overview

Authlink.Auth.ServiceStack enables secure token-based authentication in ServiceStack applications using the IIdentityClient abstraction from Authlink.Identity.Client.Core.

It allows your ServiceStack APIs to:

  • Authenticate users via your Authlink Identity Provider
  • Automatically resolve user claims and populate sessions
  • Support access and refresh token flows via OIDC

🚀 Installation

dotnet add package Authlink.Auth.ServiceStack

Or via NuGet Package Manager:

PM> Install-Package Authlink.Auth.ServiceStack

🔧 Usage Example

In your AppHost.cs:

var client = Container.GetRequiredService<IIdentityClient>();

var provider = new JwtAuthProviderReader(
    "https://identity.authlink.co.za",
    ["https://api.example.com"],
    "client-id",
    client);

Plugins.Add(new AuthFeature(() => new AuthUserSession(), [provider]));

⚙️ Configuration

Property Default Description
RequireSecureCookies true Whether cookies should be marked as Secure (HTTPS-only). Set to false for local development.
ClockSkew 1 minute Clock skew tolerance applied when validating token lifetime. Increase if host clocks may drift.
UseCookies true Whether tokens should be stored in cookies.
JwksRefreshInterval 1 hour How long a cached JWKS snapshot is considered fresh before an opportunistic refresh. Matches the Identity Provider's Cache-Control: max-age.
UnknownKidRefreshThrottle 30 seconds Minimum interval between JWKS refreshes triggered by a token referencing an unknown kid. Bounds refresh traffic against the JWKS endpoint.
FailedRefreshBackoff 10 seconds Minimum interval between JWKS refresh attempts after a failed fetch. Prevents an Identity Provider outage from amplifying into one JWKS call per request.
provider.RequireSecureCookies = !environment.IsDevelopment();
provider.ClockSkew = TimeSpan.FromMinutes(2);
provider.JwksRefreshInterval = TimeSpan.FromMinutes(15);

🔑 JWKS caching & key rotation

The provider keeps an immutable in-memory snapshot of the Identity Provider's signing keys and validates tokens locally. The JWKS endpoint (/api/connect/jwks) is only contacted when:

  • the cache has not yet been populated (cold start);
  • JwksRefreshInterval has elapsed since the last successful refresh;
  • a token references a kid that is not in the current snapshot (throttled by UnknownKidRefreshThrottle).

Requests without a JWT never contact the Identity Provider. Concurrent refreshes are coalesced into a single fetch, and if a refresh fails the previous valid snapshot continues to be served while further attempts are suppressed for FailedRefreshBackoff, so an outage cannot amplify into one JWKS call per request. Malformed keys in a JWKS response are skipped individually rather than failing the refresh.

Because the Identity Provider announces new signing keys as pending in JWKS ahead of activation (a propagation period), a snapshot refreshed within that window will already contain the next key before any token is signed with it, so unknown-kid refreshes are rare in normal rotation. Note that emergency key revocation propagates on the next interval refresh rather than instantly.

📚 Documentation

Coming soon at: https://docs.authlink.co.za

📄 License

MIT

Product Compatible and additional computed target framework versions.
.NET net9.0 is compatible.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
2.1.0 365 7/24/2026
2.0.0 110 7/24/2026
1.3.0 536 4/28/2026
1.2.3 302 1/23/2026
1.2.2 132 1/23/2026
1.2.1 293 11/3/2025
1.2.0 250 10/30/2025
1.1.0 340 8/6/2025
1.0.3 405 6/10/2025
1.0.2 201 6/6/2025