EbrahimMansur.Dpop 0.1.1

dotnet add package EbrahimMansur.Dpop --version 0.1.1
                    
NuGet\Install-Package EbrahimMansur.Dpop -Version 0.1.1
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="EbrahimMansur.Dpop" Version="0.1.1" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="EbrahimMansur.Dpop" Version="0.1.1" />
                    
Directory.Packages.props
<PackageReference Include="EbrahimMansur.Dpop" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add EbrahimMansur.Dpop --version 0.1.1
                    
#r "nuget: EbrahimMansur.Dpop, 0.1.1"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package EbrahimMansur.Dpop@0.1.1
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=EbrahimMansur.Dpop&version=0.1.1
                    
Install as a Cake Addin
#tool nuget:?package=EbrahimMansur.Dpop&version=0.1.1
                    
Install as a Cake Tool

EbrahimMansur.Dpop

Framework-agnostic RFC 9449 DPoP (Demonstrating Proof of Possession) proof validation for .NET.

This package implements the DPoP protocol core — proof parsing, JWK/thumbprint handling, ES256 signature verification, and the full validation pipeline (typ, alg, jwk, signature, jti, iat, htm, htu, ath, nonce, replay, and cnf.jkt key binding). It has no dependency on ASP.NET Core, so it can be used from any .NET application.

For ASP.NET Core APIs, use EbrahimMansur.Dpop.AspNetCore instead, which wires this package into authentication/authorization and adds AddDpop() / RequireDpop().

Usage

var validator = new DpopProofValidator(
    new DpopCryptoProvider(),
    new InMemoryDpopReplayStore(),
    new InMemoryDpopNonceStore(clock, options),
    new SystemDpopClock(),
    options,
    logger);

var result = await validator.ValidateAsync(new DpopValidationContext
{
    HttpMethod = "GET",
    HttpUri = new Uri("https://api.example.com/orders"),
    DpopProof = request.Headers["DPoP"],
    AccessToken = accessToken,
    ExpectedJkt = expectedJktFromAccessToken,
});

if (!result.Succeeded)
{
    // result.Failure has the internal reason; never surface it to the client directly.
}

See the RFC 9449 specification for the full protocol.

Source, issues, and contributing

Source code, issue tracker, and contributing guidelines live at github.com/ebrahimmansur/dpop-dotnet. Found a bug or unexpected behavior? Open an issue with a minimal repro and your package version.

Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 is compatible.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages (1)

Showing the top 1 NuGet packages that depend on EbrahimMansur.Dpop:

Package Downloads
EbrahimMansur.Dpop.AspNetCore

ASP.NET Core integration for DPoP (RFC 9449): AddDpop(), RequireDpop() for Minimal APIs and MVC, and authorization-pipeline enforcement that composes with existing JWT Bearer authentication.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
0.1.1 145 8/10/2026
0.1.0 123 8/9/2026