KoraSafe.SDK 0.2.0

dotnet add package KoraSafe.SDK --version 0.2.0
                    
NuGet\Install-Package KoraSafe.SDK -Version 0.2.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="KoraSafe.SDK" Version="0.2.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="KoraSafe.SDK" Version="0.2.0" />
                    
Directory.Packages.props
<PackageReference Include="KoraSafe.SDK" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add KoraSafe.SDK --version 0.2.0
                    
#r "nuget: KoraSafe.SDK, 0.2.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package KoraSafe.SDK@0.2.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=KoraSafe.SDK&version=0.2.0
                    
Install as a Cake Addin
#tool nuget:?package=KoraSafe.SDK&version=0.2.0
                    
Install as a Cake Tool

KoraSafe .NET SDK

Two surfaces in one package:

  • KoraSafeClient — guardian scans, audit workflows, knowledge graph, policy packs, prelaunch checks, finding submission. ASP.NET Core middleware + MVC action filter.
  • KoraTrace (in KoraSafe.SDK.Trace) — chain-of-thought capture (plan, LLM calls, tool calls, reasoning, human approvals).

Install

dotnet add package KoraSafe.SDK

Set the API key in the process environment:

export KORASAFE_API_KEY=ks_...

ASP.NET Core agent example

using KoraSafe.SDK.Trace;

var builder = WebApplication.CreateBuilder(args);
var trace = new KoraTrace();
var app = builder.Build();

app.MapPost("/classify", async (string text) =>
{
    return await trace.RunAsync("classify_claim", async _ =>
    {
        trace.Plan(new[] { "look up policy", "score risk", "route" });
        trace.LlmCall(new LlmCallInput { Provider = "openai", Model = "gpt-4o", Input = text, Output = "tier=gold", InputTokens = 120, OutputTokens = 30 });
        trace.ToolCall(new ToolCallInput { Name = "policy_lookup", Parameters = new Dictionary<string, object?> { ["id"] = "pol-7" }, Response = new Dictionary<string, object?> { ["tier"] = "gold" }, Status = "ok" });
        trace.HumanApproval(new HumanApprovalInput { ReviewerId = "user-42", Decision = "approved" });
        await Task.CompletedTask;
        return "tier=gold";
    });
});

app.Run();

Events appear in the KoraSafe audit log within 5 seconds. Configure via env vars or new KoraTrace(new KoraTraceOptions { ApiKey = "...", BatchSize = 10, FlushInterval = TimeSpan.FromSeconds(5) }).

Client

using KoraSafe.SDK;

var client = new KoraSafeClient(new KoraSafeOptions
{
    ApiKey = Environment.GetEnvironmentVariable("KORASAFE_API_KEY"),
    BaseUrl = new Uri("https://korasafe.app")
});

var decision = await client.ScanAsync(new ScanInput
{
    Operation = "chat_completion",
    Text = prompt
}, new ScanContext
{
    SystemId = "sys_123",
    TraceId = requestId,
    Surface = "sdk-dotnet",
    Trigger = "runtime"
});

var gate = await client.GateAsync(decision, GateAction.Allow);
if (!gate.Allowed)
{
    throw new InvalidOperationException($"Blocked by KoraSafe: {string.Join(",", gate.Reasons)}");
}

ASP.NET Core

using KoraSafe.SDK;

var builder = WebApplication.CreateBuilder(args);

builder.Services.AddKoraSafe(options =>
{
    options.ApiKey = builder.Configuration["KoraSafe:ApiKey"]
        ?? Environment.GetEnvironmentVariable("KORASAFE_API_KEY");
    options.BaseUrl = new Uri(builder.Configuration["KoraSafe:BaseUrl"] ?? "https://korasafe.app");
});

var app = builder.Build();
app.UseKoraSafe();

The default middleware sends metadata only: method, path, host, user agent, trace id, and source reference. It does not read request bodies. To scan content, explicitly map approved fields:

app.UseKoraSafe(options =>
{
    options.ScanInput = http => new ScanInput
    {
        Operation = "chat_completion",
        Metadata = new Dictionary<string, object?>
        {
            ["route"] = http.Request.Path.Value
        }
    };
});

Controller Filter

[ApiController]
[Route("chat")]
public sealed class ChatController : ControllerBase
{
    [HttpPost]
    [KoraSafeScan(SystemId = "sys_123", Guardians = new[] { "prompt-injection" })]
    public IActionResult Create(ChatRequest request) => Ok();
}

API Surface

  • KoraSafeClient.ScanAsync(input, context, cancellationToken)
  • KoraSafeClient.GateAsync(decision, action, cancellationToken)
  • KoraSafeClient.SubmitFindingAsync(finding, cancellationToken)
  • KoraSafeClient.SubmitAuditAsync(request, cancellationToken)
  • KoraSafeClient.GetAuditFindingsAsync(query, cancellationToken)
  • KoraSafeClient.GetAuditRunsAsync(query, cancellationToken)
  • KoraSafeClient.RemediateAsync(request, cancellationToken)
  • KoraSafeClient.GetRegulationsAsync(query, cancellationToken)
  • KoraSafeClient.GetControlsAsync(query, cancellationToken)
  • KoraSafeClient.GetSystemStatusAsync(query, cancellationToken)
  • KoraSafeClient.ListPolicyPacksAsync(query, cancellationToken)
  • KoraSafeClient.SubscribePolicyPackAsync(request, cancellationToken)
  • KoraSafeClient.GetVscodeInlineWarningsAsync(request, cancellationToken)
  • KoraSafeClient.RequestAsync<T>(method, path, body, query, cancellationToken)
  • services.AddKoraSafe(options => ...)
  • app.UseKoraSafe(options => ...)
  • [KoraSafeScan]

SubmitFindingAsync posts to /api/audit/findings and defaults producer_id to sdk-dotnet. SubmitAuditAsync matches the TypeScript SDK defaults: frameworks=["eu-ai-act","gdpr"], surface="platform", and trigger="manual".

NuGet

The package targets net8.0 and net6.0, generates XML documentation, and is configured for NuGet packaging as KoraSafe.SDK v0.2.0.

Product Compatible and additional computed target framework versions.
.NET net6.0 is compatible.  net6.0-android was computed.  net6.0-ios was computed.  net6.0-maccatalyst was computed.  net6.0-macos was computed.  net6.0-tvos was computed.  net6.0-windows was computed.  net7.0 was computed.  net7.0-android was computed.  net7.0-ios was computed.  net7.0-maccatalyst was computed.  net7.0-macos was computed.  net7.0-tvos was computed.  net7.0-windows was computed.  net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
  • net6.0

    • No dependencies.
  • net8.0

    • No dependencies.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
0.2.0 159 6/4/2026