Cirreum.Identity.Descope 1.0.1

Suggested Alternatives

Cirreum.Identity.Oidc

The owner has unlisted this package. This could mean that the package is deprecated, has security vulnerabilities or shouldn't be used anymore.
dotnet add package Cirreum.Identity.Descope --version 1.0.1
                    
NuGet\Install-Package Cirreum.Identity.Descope -Version 1.0.1
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Cirreum.Identity.Descope" Version="1.0.1" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Cirreum.Identity.Descope" Version="1.0.1" />
                    
Directory.Packages.props
<PackageReference Include="Cirreum.Identity.Descope" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Cirreum.Identity.Descope --version 1.0.1
                    
#r "nuget: Cirreum.Identity.Descope, 1.0.1"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Cirreum.Identity.Descope@1.0.1
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Cirreum.Identity.Descope&version=1.0.1
                    
Install as a Cake Addin
#tool nuget:?package=Cirreum.Identity.Descope&version=1.0.1
                    
Install as a Cake Tool

Cirreum.Identity.Descope

NuGet Version NuGet Downloads GitHub Release License .NET

User provisioning for Descope HTTP Connector callbacks.

Overview

Cirreum.Identity.Descope hosts the HTTP endpoint that a Descope Flow calls through an HTTP Connector action before issuing a session token. When a user signs in, the flow posts user context to your endpoint — this library validates the call, provisions the user, and returns roles that the flow embeds on the user record and/or in the issued JWT.

The library is framework-independent and can run in any ASP.NET host: your main API, an Azure Function, or a dedicated service.

How it works

  1. Authenticates the inbound call by comparing a shared secret against the header Descope attaches to every connector request
  2. Provisions the user via your IUserProvisioner implementation
  3. Returns a decision (allowed + roles) the Descope flow consumes via connector.response.*

Installation

dotnet add package Cirreum.Identity.Descope

This package depends transitively on Cirreum.Identity.Abstractions, which defines the provider-agnostic contracts (IUserProvisioner, ProvisionContext, ProvisionResult, IProvisionedUser, IPendingInvitation, UserProvisionerBase<TUser>).

Quick start

// Program.cs
builder.AddDescopeProvisioning<AppUserProvisioner>();

var app = builder.Build();
app.MapDescopeProvisioning();

Implement the provisioner

using Cirreum.Identity;

public sealed class AppUserProvisioner(AppDbContext db)
    : UserProvisionerBase<AppUser> {

    protected override Task<AppUser?> FindUserAsync(
        string externalUserId, CancellationToken ct) =>
        db.Users.FirstOrDefaultAsync(u => u.ExternalUserId == externalUserId, ct);

    protected override async Task<AppUser?> RedeemInvitationAsync(
        string email, string externalUserId, CancellationToken ct) {
        var invitation = await db.Invitations
            .FirstOrDefaultAsync(i => i.Email == email && !i.IsRedeemed, ct);
        if (invitation is null || invitation.IsExpired) return null;

        var user = new AppUser {
            ExternalUserId = externalUserId,
            Email = email,
            Roles = [invitation.Role]
        };
        db.Users.Add(user);
        invitation.IsRedeemed = true;
        await db.SaveChangesAsync(ct);
        return user;
    }
}

Cirreum framework users: If your app uses the full Cirreum runtime, also implement IApplicationUser on your user class so it integrates with IUserState and the authentication post-processor pipeline.

Configuration

{
  "Cirreum": {
    "Identity": {
      "Descope": {
        "Route": "/auth/descope/provision",
        "SharedSecret": "<long-random-secret-matching-the-descope-connector>",
        "AuthorizationHeaderName": "Authorization",
        "AuthorizationScheme": "Bearer",
        "AllowedAppIds": "<descope-project-id-or-app-id>"
      }
    }
  }
}

Documentation

See SETUP.md for Descope Console configuration, flow/connector wiring, and local development instructions.

Relationship to other Cirreum.Identity packages

This package, together with Cirreum.Identity.EntraExternalId, implements the provider-specific half of Cirreum's identity integration. Both packages depend on Cirreum.Identity.Abstractions so an application can swap providers without rewriting its provisioner.

Contribution Guidelines

  1. Be conservative with new abstractions The API surface must remain stable and meaningful.

  2. Limit dependency expansion Only add foundational, version-stable dependencies.

  3. Favor additive, non-breaking changes Breaking changes ripple through the entire ecosystem.

  4. Include thorough unit tests All primitives and patterns should be independently testable.

  5. Document architectural decisions Context and reasoning should be clear for future maintainers.

  6. Follow .NET conventions Use established patterns from Microsoft.Extensions.* libraries.

Versioning

Cirreum.Identity.Descope follows Semantic Versioning:

  • Major - Breaking API changes
  • Minor - New features, backward compatible
  • Patch - Bug fixes, backward compatible

License

This project is licensed under the MIT License - see the LICENSE file for details.


Cirreum Foundation Framework
Layered simplicity for modern .NET

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated