HardenLabs.Hmac
1.1.0
dotnet add package HardenLabs.Hmac --version 1.1.0
NuGet\Install-Package HardenLabs.Hmac -Version 1.1.0
<PackageReference Include="HardenLabs.Hmac" Version="1.1.0" />
<PackageVersion Include="HardenLabs.Hmac" Version="1.1.0" />
<PackageReference Include="HardenLabs.Hmac" />
paket add HardenLabs.Hmac --version 1.1.0
#r "nuget: HardenLabs.Hmac, 1.1.0"
#:package HardenLabs.Hmac@1.1.0
#addin nuget:?package=HardenLabs.Hmac&version=1.1.0
#tool nuget:?package=HardenLabs.Hmac&version=1.1.0
HardenLabs.Hmac
Cross-language HMAC-SHA256 request signing with a defined canonical string format. Guaranteed identical signatures across C#, Python, TypeScript, and Go.
Installation
dotnet add package HardenLabs.Hmac
dotnet add package HardenLabs.Hmac.AspNetCore # for middleware
Quick Start — Server (ASP.NET Core)
using HardenLabs.Hmac;
using HardenLabs.Hmac.AspNetCore;
var config = new HmacConfig
{
SignedHeaders = SignedHeadersConfig.Default,
TimestampToleranceSeconds = 30,
Clients = new Dictionary<string, HmacClientIdentity>
{
["order-service"] = new HmacClientIdentity { SharedSecret = "orders-base64-secret" },
["payment-service"] = new HmacClientIdentity { SharedSecret = "payments-base64-secret" },
},
};
var builder = WebApplication.CreateBuilder(args);
builder.Services.AddHardenHmac(config);
var app = builder.Build();
app.UseRouting();
app.UseHardenHmac();
// Protected — requires valid HMAC signature
app.MapGet("/api/hello", () => Results.Ok(new { message = "Authenticated!" }))
.WithMetadata(new HmacValidateAttribute());
// Unprotected — no attribute, no HMAC required
app.MapGet("/health", () => Results.Ok(new { status = "healthy" }));
app.Run();
Endpoints are not validated by default — use [HmacValidate] to opt in. Use [SkipHmacValidate] on actions to exempt them when the controller is protected.
Public API — Server
| Type | Description |
|---|---|
HmacValidateAttribute |
Opt-in HMAC validation for controllers or actions |
SkipHmacValidateAttribute |
Exempt actions from validation when controller is protected |
UseHardenHmac() |
Register middleware in the pipeline (after UseRouting()) |
AddHardenHmac(config) |
Register HMAC services for DI |
AddHardenHmac(configuration) |
Register from IConfiguration section |
Quick Start — Client (HttpClient)
using HardenLabs.Hmac;
using HardenLabs.Hmac.AspNetCore;
var config = new HmacConfig
{
SignedHeaders = SignedHeadersConfig.Default,
Targets = new Dictionary<string, HmacTargetConfig>
{
["order-service"] = new HmacTargetConfig
{
BaseUrl = "https://orders.example.com",
SharedSecret = "orders-base64-secret",
},
},
};
var factory = new HardenHmacClientFactory(config);
var client = factory.CreateClient("order-service"); // BaseAddress + signing pre-configured
var response = await client.GetAsync("/api/hello"); // automatically signed
Configuration from appsettings.json
{
"HardenHmac": {
"TimestampToleranceSeconds": 30,
"Clients": {
"order-service": { "SharedSecret": "orders-base64-secret" }
},
"Targets": {
"order-service": {
"BaseUrl": "https://orders.example.com",
"SharedSecret": "orders-base64-secret"
}
}
}
}
builder.Services.AddHardenHmac(builder.Configuration.GetSection("HardenHmac"));
Documentation
Full documentation, canonical string specification, and cross-language compatibility details: github.com/HardenLabs/HardenHMAC
License
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 was computed. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net8.0
- No dependencies.
NuGet packages (1)
Showing the top 1 NuGet packages that depend on HardenLabs.Hmac:
| Package | Downloads |
|---|---|
|
HardenLabs.Hmac.AspNetCore
ASP.NET Core middleware and HttpClient handler for HardenHMAC request signing. |
GitHub repositories
This package is not used by any popular GitHub repositories.