NginxApiClient 1.1.0

dotnet add package NginxApiClient --version 1.1.0
                    
NuGet\Install-Package NginxApiClient -Version 1.1.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="NginxApiClient" Version="1.1.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="NginxApiClient" Version="1.1.0" />
                    
Directory.Packages.props
<PackageReference Include="NginxApiClient" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add NginxApiClient --version 1.1.0
                    
#r "nuget: NginxApiClient, 1.1.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package NginxApiClient@1.1.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=NginxApiClient&version=1.1.0
                    
Install as a Cake Addin
#tool nuget:?package=NginxApiClient&version=1.1.0
                    
Install as a Cake Tool

NginxApiClient

A comprehensive C# client library for the NGINX Proxy Manager REST API.

License: MIT

Features

  • Full API coverage — all 11 NPM resource groups (proxy hosts, certificates, redirection hosts, dead hosts, streams, access lists, users, settings, audit log, reports)
  • Multi-target — supports .NET Framework 4.8 through .NET 9 via sub-package architecture
  • Async-first — all methods are async with CancellationToken support
  • Transparent authentication — JWT token lifecycle managed automatically
  • Strongly-typed — typed request/response models with IntelliSense
  • Testable — INginxProxyManagerClient interface for easy mocking
  • DI-ready — IServiceCollection extension methods for ASP.NET Core
  • Version-aware — auto-detects the NPM server version and adapts the certificate API (NPM 2.12–2.15+)

Installation

Modern .NET (.NET 8 / .NET 9)

dotnet add package NginxApiClient
dotnet add package NginxApiClient.SystemTextJson

.NET Framework 4.8

Install-Package NginxApiClient
Install-Package NginxApiClient.NewtonsoftJson

Quick Start

using NginxApiClient;
using NginxApiClient.SystemTextJson;

// Create client
var serializer = new SystemTextJsonSerializer();
var options = new NginxProxyManagerClientOptions
{
    BaseUrl = "http://localhost:81",
    Credentials = new NginxCredentials("admin@example.com", "changeme"),
};

// Authentication is handled automatically
var client = NginxProxyManagerClientFactory.Create(options, serializer);

// List all proxy hosts
var hosts = await client.ProxyHosts.ListAsync();
foreach (var host in hosts)
{
    Console.WriteLine($"{host.Id}: {string.Join(", ", host.DomainNames)} -> {host.ForwardHost}:{host.ForwardPort}");
}

ASP.NET Core DI Registration

// In Program.cs or Startup.cs
services.AddNginxApiClient(options =>
{
    options.BaseUrl = "http://npm:81";
    options.Credentials = new NginxCredentials("admin@example.com", "changeme");
});

// Inject into your services
public class MyService
{
    private readonly INginxProxyManagerClient _npmClient;

    public MyService(INginxProxyManagerClient npmClient)
    {
        _npmClient = npmClient;
    }

    public async Task CreateProxyHostAsync(string domain, string backendHost, int backendPort)
    {
        await _npmClient.ProxyHosts.CreateAsync(new CreateProxyHostRequest
        {
            DomainNames = new List<string> { domain },
            ForwardScheme = "http",
            ForwardHost = backendHost,
            ForwardPort = backendPort,
            SslForced = true,
            Http2Support = true,
        });
    }
}

Create a Proxy Host with SSL

var proxyHost = await client.ProxyHosts.CreateAsync(new CreateProxyHostRequest
{
    DomainNames = new List<string> { "app.example.com" },
    ForwardScheme = "http",
    ForwardHost = "192.168.1.100",
    ForwardPort = 8080,
    SslForced = true,
    HstsEnabled = true,
    Http2Support = true,
    BlockExploits = true,
    AllowWebsocketUpgrade = true,
    CertificateId = 5,  // ID of an existing certificate
});

Console.WriteLine($"Created proxy host {proxyHost.Id} for {string.Join(", ", proxyHost.DomainNames)}");

Certificate Management

// List certificates and check expiry
var certs = await client.Certificates.ListAsync();
foreach (var cert in certs)
{
    var daysUntilExpiry = (cert.ExpiresOn - DateTime.UtcNow).Days;
    Console.WriteLine($"{cert.NiceName}: expires in {daysUntilExpiry} days");

    if (daysUntilExpiry < 30)
    {
        await client.Certificates.RenewAsync(cert.Id);
        Console.WriteLine($"  -> Renewed!");
    }
}

// Provision a new Let's Encrypt certificate
var newCert = await client.Certificates.CreateAsync(new CreateCertificateRequest
{
    DomainNames = new List<string> { "new.example.com" },
    Provider = "letsencrypt",
    // On NPM 2.13+ these are ignored (NPM uses the account email); see "NPM Version Compatibility".
    Meta = new CertificateMeta { LetsencryptEmail = "admin@example.com", LetsencryptAgree = true },
});

NPM Version Compatibility

NGINX Proxy Manager changed its certificate-creation schema in v2.13: the Let's Encrypt account email and terms agreement are no longer sent per-certificate (NPM reads the email from the authenticated user account and agrees to the terms automatically), and v2.14 added an optional key_type. Sending the old fields to a 2.13+ server returns HTTP 400 — data/meta must NOT have additional properties.

The client handles this for you. By default it auto-detects the server version (one cached, unauthenticated GET /api/ probe) and shapes the certificate payload to match:

NPM version NpmVersion Certificate meta behaviour
≤ 2.12 V2_12 sends letsencrypt_email + letsencrypt_agree
2.13 V2_13 omits both (email from account, agreement automatic)
≥ 2.14 (incl. 2.15) V2_14 omits both; supports key_type (rsa/ecdsa)
// Default — auto-detect (recommended). No configuration needed.
var options = new NginxProxyManagerClientOptions
{
    BaseUrl = "http://localhost:81",
    Credentials = new NginxCredentials("admin@example.com", "changeme"),
    // Version = NpmVersion.Auto,   // the default

    // Or pin the version explicitly to skip the detection probe:
    // Version = NpmVersion.V2_14,
};

If the probe fails (server unreachable or an unexpected response), the client falls back to the latest known generation rather than throwing.

Heads-up for NPM 2.13+: the Let's Encrypt account email must be set on the NPM user you authenticate as — it is no longer taken from CreateCertificateRequest. Any LetsencryptEmail/LetsencryptAgree you set are silently ignored on 2.13+. Setting KeyType while targeting a version below 2.14 throws NginxVersionCompatibilityException.

Error Handling

using NginxApiClient.Exceptions;

try
{
    var host = await client.ProxyHosts.GetAsync(999);
}
catch (NginxNotFoundException ex)
{
    Console.WriteLine($"Proxy host not found: {ex.ErrorDetail}");
}
catch (NginxAuthenticationException ex)
{
    Console.WriteLine($"Authentication failed: {ex.ErrorDetail}");
}
catch (NginxApiException ex)
{
    Console.WriteLine($"API error {ex.StatusCode}: {ex.ErrorDetail}");
}

Available Resource Clients

Property Interface Description
client.ProxyHosts IProxyHostClient Manage reverse proxy hosts
client.Certificates ICertificateClient Manage SSL certificates and Let's Encrypt
client.RedirectionHosts IRedirectionHostClient Manage URL redirections
client.DeadHosts IDeadHostClient Manage custom 404 pages
client.Streams IStreamClient Manage TCP/UDP stream forwarding
client.AccessLists IAccessListClient Manage IP and auth-based access restrictions
client.Users IUserClient Manage NPM users and permissions
client.Settings ISettingsClient Get/update NPM settings
client.AuditLog IAuditLogClient Read audit log entries
client.Reports IReportsClient Access host statistics

NUGET Packages

NUGET Package Target Purpose
NginxApiClient .NET Standard 2.0 Core interfaces, models, exceptions
NginxApiClient.SystemTextJson .NET 8, .NET 9 System.Text.Json serialization + DI
NginxApiClient.NewtonsoftJson .NET Standard 2.0 Newtonsoft.Json serialization + DI

Examples

See the examples/ folder for runnable console projects:

License

MIT License - see LICENSE for details.

Product Compatible and additional computed target framework versions.
.NET net5.0 was computed.  net5.0-windows was computed.  net6.0 was computed.  net6.0-android was computed.  net6.0-ios was computed.  net6.0-maccatalyst was computed.  net6.0-macos was computed.  net6.0-tvos was computed.  net6.0-windows was computed.  net7.0 was computed.  net7.0-android was computed.  net7.0-ios was computed.  net7.0-maccatalyst was computed.  net7.0-macos was computed.  net7.0-tvos was computed.  net7.0-windows was computed.  net8.0 was computed.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
.NET Core netcoreapp2.0 was computed.  netcoreapp2.1 was computed.  netcoreapp2.2 was computed.  netcoreapp3.0 was computed.  netcoreapp3.1 was computed. 
.NET Standard netstandard2.0 is compatible.  netstandard2.1 was computed. 
.NET Framework net461 was computed.  net462 was computed.  net463 was computed.  net47 was computed.  net471 was computed.  net472 was computed.  net48 was computed.  net481 was computed. 
MonoAndroid monoandroid was computed. 
MonoMac monomac was computed. 
MonoTouch monotouch was computed. 
Tizen tizen40 was computed.  tizen60 was computed. 
Xamarin.iOS xamarinios was computed. 
Xamarin.Mac xamarinmac was computed. 
Xamarin.TVOS xamarintvos was computed. 
Xamarin.WatchOS xamarinwatchos was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
  • .NETStandard 2.0

    • No dependencies.

NuGet packages (2)

Showing the top 2 NuGet packages that depend on NginxApiClient:

Package Downloads
NginxApiClient.NewtonsoftJson

Newtonsoft.Json serialization implementation for NginxApiClient. Use this package with .NET Framework 4.8 or any .NET Standard 2.0 compatible runtime.

NginxApiClient.SystemTextJson

System.Text.Json serialization implementation for NginxApiClient. Use this package with .NET 8 or .NET 10.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.1.0 228 6/28/2026
1.0.4 199 5/7/2026
1.0.3 170 5/1/2026
1.0.2 169 5/1/2026
1.0.0 192 4/17/2026