Dloizides.ApiKeys 1.1.0

dotnet add package Dloizides.ApiKeys --version 1.1.0
                    
NuGet\Install-Package Dloizides.ApiKeys -Version 1.1.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Dloizides.ApiKeys" Version="1.1.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Dloizides.ApiKeys" Version="1.1.0" />
                    
Directory.Packages.props
<PackageReference Include="Dloizides.ApiKeys" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Dloizides.ApiKeys --version 1.1.0
                    
#r "nuget: Dloizides.ApiKeys, 1.1.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Dloizides.ApiKeys@1.1.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Dloizides.ApiKeys&version=1.1.0
                    
Install as a Cake Addin
#tool nuget:?package=Dloizides.ApiKeys&version=1.1.0
                    
Install as a Cake Tool

Dloizides.ApiKeys

Storage-agnostic, per-tenant API-key authentication for ASP.NET Core services. Extracted from PROOViD AMLService (2nd consumer: Ichnos), following the Dloizides.Credits pattern — the package owns the logic (generation, hashing, the auth handler); the host owns the storage.

What it does

  • Generates high-entropy prefixed keys ({prefix}live_… / {prefix}test_…) — plaintext shown once.
  • Stores only a SHA-256 hash (deterministic → O(1) lookup; keys are 192-bit random, so no pepper is needed and none is used).
  • Resolves X-Api-Key (or Authorization: Bearer {prefix}…) to a tenant principal via an ASP.NET AuthenticationHandler, emitting the exact claim contract each product configures.

Wiring (host)

builder.Services.AddApiKeyGenerator(o => o.KeyPrefix = "ichnos_");
builder.Services.AddScoped<IApiKeyStore, EfApiKeyStore>();   // your DB
builder.Services.AddAuthentication()
    .AddApiKeyScheme(o =>
    {
        o.KeyPrefix       = "ichnos_";
        o.TenantClaimType = "tenantId";   // AMLService uses "tenant_id"
        o.Role            = "api";
    });

The host implements IApiKeyStore (resolve an active key's hash → (TenantId, KeyId), encapsulating any tenant-status rules; touch last-used) and its own issue/list/revoke endpoints + key entity.

Multi-targeted net8.0;net10.0.

Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
  • net10.0

    • No dependencies.
  • net8.0

    • No dependencies.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.1.0 133 7/28/2026
1.0.0 132 7/11/2026