Canton.Ledger.Auth
0.1.5-preview.1
Prefix Reserved
dotnet add package Canton.Ledger.Auth --version 0.1.5-preview.1
NuGet\Install-Package Canton.Ledger.Auth -Version 0.1.5-preview.1
<PackageReference Include="Canton.Ledger.Auth" Version="0.1.5-preview.1" />
<PackageVersion Include="Canton.Ledger.Auth" Version="0.1.5-preview.1" />
<PackageReference Include="Canton.Ledger.Auth" />
paket add Canton.Ledger.Auth --version 0.1.5-preview.1
#r "nuget: Canton.Ledger.Auth, 0.1.5-preview.1"
#:package Canton.Ledger.Auth@0.1.5-preview.1
#addin nuget:?package=Canton.Ledger.Auth&version=0.1.5-preview.1&prerelease
#tool nuget:?package=Canton.Ledger.Auth&version=0.1.5-preview.1&prerelease
Canton.Ledger.Auth
Authentication providers for Canton participant nodes. Supplies bearer tokens to the gRPC and PQS clients via the ITokenProvider interface.
Key Types
| Type | Purpose |
|---|---|
ITokenProvider |
Interface — Task<string> GetTokenAsync(CancellationToken) |
ITokenProvider.None |
Static singleton signaling unauthenticated access (no Authorization header) |
StaticTokenProvider |
Returns a fixed token string. Use for short-lived processes or testing |
ClientCredentialsProvider |
OAuth2 client-credentials flow with thread-safe TTL cache (SemaphoreSlim + Volatile reads/writes) |
ClientCredentialsOptions |
Config: Domain, ClientId, ClientSecret, Audience, TokenEndpoint, SafetyMargin |
Usage
Client-credentials (OAuth2) via DI
services.AddCantonAuth(configuration.GetSection("Canton:Auth"));
{
"Canton": {
"Auth": {
"Domain": "dev-peaceful.eu.auth0.com",
"ClientId": "my-client-id",
"ClientSecret": "my-client-secret",
"Audience": "https://canton.network/"
}
}
}
Domain accepts either a bare hostname (e.g. dev-peaceful.eu.auth0.com) or an absolute http/https URL (e.g. https://auth.example.com, or https://auth.example.com/tenant-a for per-tenant subpaths). If Domain is a bare hostname, it is treated as https://{hostname}. If it is an absolute http/https URL, that URL is used as the base. In both cases, /oauth/token is appended, preserving any existing path (https://auth.example.com/tenant-a → https://auth.example.com/tenant-a/oauth/token). Userinfo, query, and fragments are rejected. ClientCredentialsProvider caches tokens until expires_in - SafetyMargin (default 30s) and concurrent callers share a single HTTP request during refresh.
To override the token endpoint (e.g., non-standard OAuth2 servers like Keycloak's /realms/{realm}/protocol/openid-connect/token):
{
"Canton": {
"Auth": {
"TokenEndpoint": "https://custom.example.com/oauth/token",
"ClientId": "...",
"ClientSecret": "..."
}
}
}
Static token via DI
services.AddCantonStaticAuth("eyJ...");
Action-based configuration
services.AddCantonAuth(options =>
{
options.Domain = "https://auth.example.com";
options.ClientId = "my-client-id";
options.ClientSecret = "my-client-secret";
options.Audience = "https://canton.network/";
});
Registration precedence
All methods use TryAddSingleton — the first registration wins. Register explicit providers before calling AddLedgerClient/AddAdminClient to override auto-registration.
Unauthenticated access
When no ITokenProvider is registered, AddLedgerClient/AddAdminClient register ITokenProvider.None as a default. Clients detect this and skip the Authorization header. Use this for local development with unauthenticated Canton nodes.
Internals
IHttpClientFactorynamed client"CantonAuth"— nousingon theHttpClient(factory manages handler lifetime)TimeProviderfor testable time (passFakeTimeProviderin tests)Volatile.Read/Volatile.Writefor cache fields — write order: token before expiry (matches read order)- Validates
expires_in > 0andaccess_tokennon-empty after deserialization - Token endpoint is resolved once at construction — unresolvable options (no
TokenEndpoint, invalidDomain) throwInvalidOperationExceptionwhen the provider is constructed, not at the first token request
Related Packages
Canton.Ledger.Grpc.Client— gRPC client that consumesITokenProviderCanton.Ledger.Pqs.Client— PQS query client
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Microsoft.Extensions.Configuration.Abstractions (>= 10.0.9)
- Microsoft.Extensions.DependencyInjection.Abstractions (>= 10.0.9)
- Microsoft.Extensions.Http (>= 10.0.9)
- Microsoft.Extensions.Logging.Abstractions (>= 10.0.9)
- Microsoft.Extensions.Options (>= 10.0.9)
- Microsoft.Extensions.Options.ConfigurationExtensions (>= 10.0.9)
- Microsoft.Extensions.Options.DataAnnotations (>= 10.0.9)
- Peaceful.Extensions.Logging (>= 0.2.1-preview.2)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 0.1.5-preview.1 | 114 | 6/25/2026 |
| 0.1.4-preview.1 | 72 | 6/15/2026 |