HardenLabs.Hmac.AspNetCore
1.1.0
dotnet add package HardenLabs.Hmac.AspNetCore --version 1.1.0
NuGet\Install-Package HardenLabs.Hmac.AspNetCore -Version 1.1.0
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="HardenLabs.Hmac.AspNetCore" Version="1.1.0" />
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="HardenLabs.Hmac.AspNetCore" Version="1.1.0" />
<PackageReference Include="HardenLabs.Hmac.AspNetCore" />
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add HardenLabs.Hmac.AspNetCore --version 1.1.0
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
#r "nuget: HardenLabs.Hmac.AspNetCore, 1.1.0"
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package HardenLabs.Hmac.AspNetCore@1.1.0
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=HardenLabs.Hmac.AspNetCore&version=1.1.0
#tool nuget:?package=HardenLabs.Hmac.AspNetCore&version=1.1.0
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
HardenLabs.Hmac
Cross-language HMAC-SHA256 request signing with a defined canonical string format. Guaranteed identical signatures across C#, Python, TypeScript, and Go.
Installation
dotnet add package HardenLabs.Hmac
dotnet add package HardenLabs.Hmac.AspNetCore # for middleware
Quick Start — Server (ASP.NET Core)
using HardenLabs.Hmac;
using HardenLabs.Hmac.AspNetCore;
var config = new HmacConfig
{
SignedHeaders = SignedHeadersConfig.Default,
TimestampToleranceSeconds = 30,
Clients = new Dictionary<string, HmacClientIdentity>
{
["order-service"] = new HmacClientIdentity { SharedSecret = "orders-base64-secret" },
["payment-service"] = new HmacClientIdentity { SharedSecret = "payments-base64-secret" },
},
};
var builder = WebApplication.CreateBuilder(args);
builder.Services.AddHardenHmac(config);
var app = builder.Build();
app.UseRouting();
app.UseHardenHmac();
// Protected — requires valid HMAC signature
app.MapGet("/api/hello", () => Results.Ok(new { message = "Authenticated!" }))
.WithMetadata(new HmacValidateAttribute());
// Unprotected — no attribute, no HMAC required
app.MapGet("/health", () => Results.Ok(new { status = "healthy" }));
app.Run();
Endpoints are not validated by default — use [HmacValidate] to opt in. Use [SkipHmacValidate] on actions to exempt them when the controller is protected.
Public API — Server
| Type | Description |
|---|---|
HmacValidateAttribute |
Opt-in HMAC validation for controllers or actions |
SkipHmacValidateAttribute |
Exempt actions from validation when controller is protected |
UseHardenHmac() |
Register middleware in the pipeline (after UseRouting()) |
AddHardenHmac(config) |
Register HMAC services for DI |
AddHardenHmac(configuration) |
Register from IConfiguration section |
Quick Start — Client (HttpClient)
using HardenLabs.Hmac;
using HardenLabs.Hmac.AspNetCore;
var config = new HmacConfig
{
SignedHeaders = SignedHeadersConfig.Default,
Targets = new Dictionary<string, HmacTargetConfig>
{
["order-service"] = new HmacTargetConfig
{
BaseUrl = "https://orders.example.com",
SharedSecret = "orders-base64-secret",
},
},
};
var factory = new HardenHmacClientFactory(config);
var client = factory.CreateClient("order-service"); // BaseAddress + signing pre-configured
var response = await client.GetAsync("/api/hello"); // automatically signed
Configuration from appsettings.json
{
"HardenHmac": {
"TimestampToleranceSeconds": 30,
"Clients": {
"order-service": { "SharedSecret": "orders-base64-secret" }
},
"Targets": {
"order-service": {
"BaseUrl": "https://orders.example.com",
"SharedSecret": "orders-base64-secret"
}
}
}
}
builder.Services.AddHardenHmac(builder.Configuration.GetSection("HardenHmac"));
Documentation
Full documentation, canonical string specification, and cross-language compatibility details: github.com/HardenLabs/HardenHMAC
License
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 was computed. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
-
net8.0
- HardenLabs.Hmac (>= 1.1.0)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.