EbrahimMansur.Dpop
0.1.1
dotnet add package EbrahimMansur.Dpop --version 0.1.1
NuGet\Install-Package EbrahimMansur.Dpop -Version 0.1.1
<PackageReference Include="EbrahimMansur.Dpop" Version="0.1.1" />
<PackageVersion Include="EbrahimMansur.Dpop" Version="0.1.1" />
<PackageReference Include="EbrahimMansur.Dpop" />
paket add EbrahimMansur.Dpop --version 0.1.1
#r "nuget: EbrahimMansur.Dpop, 0.1.1"
#:package EbrahimMansur.Dpop@0.1.1
#addin nuget:?package=EbrahimMansur.Dpop&version=0.1.1
#tool nuget:?package=EbrahimMansur.Dpop&version=0.1.1
EbrahimMansur.Dpop
Framework-agnostic RFC 9449 DPoP (Demonstrating Proof of Possession) proof validation for .NET.
This package implements the DPoP protocol core — proof parsing, JWK/thumbprint handling, ES256
signature verification, and the full validation pipeline (typ, alg, jwk, signature, jti,
iat, htm, htu, ath, nonce, replay, and cnf.jkt key binding). It has no dependency on
ASP.NET Core, so it can be used from any .NET application.
For ASP.NET Core APIs, use EbrahimMansur.Dpop.AspNetCore
instead, which wires this package into authentication/authorization and adds AddDpop() /
RequireDpop().
Usage
var validator = new DpopProofValidator(
new DpopCryptoProvider(),
new InMemoryDpopReplayStore(),
new InMemoryDpopNonceStore(clock, options),
new SystemDpopClock(),
options,
logger);
var result = await validator.ValidateAsync(new DpopValidationContext
{
HttpMethod = "GET",
HttpUri = new Uri("https://api.example.com/orders"),
DpopProof = request.Headers["DPoP"],
AccessToken = accessToken,
ExpectedJkt = expectedJktFromAccessToken,
});
if (!result.Succeeded)
{
// result.Failure has the internal reason; never surface it to the client directly.
}
See the RFC 9449 specification for the full protocol.
Source, issues, and contributing
Source code, issue tracker, and contributing guidelines live at github.com/ebrahimmansur/dpop-dotnet. Found a bug or unexpected behavior? Open an issue with a minimal repro and your package version.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 is compatible. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 was computed. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net8.0
- Microsoft.Extensions.Logging.Abstractions (>= 10.0.10)
- Microsoft.Extensions.Options (>= 10.0.10)
-
net9.0
- Microsoft.Extensions.Logging.Abstractions (>= 10.0.10)
- Microsoft.Extensions.Options (>= 10.0.10)
NuGet packages (1)
Showing the top 1 NuGet packages that depend on EbrahimMansur.Dpop:
| Package | Downloads |
|---|---|
|
EbrahimMansur.Dpop.AspNetCore
ASP.NET Core integration for DPoP (RFC 9449): AddDpop(), RequireDpop() for Minimal APIs and MVC, and authorization-pipeline enforcement that composes with existing JWT Bearer authentication. |
GitHub repositories
This package is not used by any popular GitHub repositories.