Noodloft.Identity.ResourceServer 0.0.1-alpha1

This is a prerelease version of Noodloft.Identity.ResourceServer.
dotnet add package Noodloft.Identity.ResourceServer --version 0.0.1-alpha1
                    
NuGet\Install-Package Noodloft.Identity.ResourceServer -Version 0.0.1-alpha1
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Noodloft.Identity.ResourceServer" Version="0.0.1-alpha1" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Noodloft.Identity.ResourceServer" Version="0.0.1-alpha1" />
                    
Directory.Packages.props
<PackageReference Include="Noodloft.Identity.ResourceServer" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Noodloft.Identity.ResourceServer --version 0.0.1-alpha1
                    
#r "nuget: Noodloft.Identity.ResourceServer, 0.0.1-alpha1"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Noodloft.Identity.ResourceServer@0.0.1-alpha1
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Noodloft.Identity.ResourceServer&version=0.0.1-alpha1&prerelease
                    
Install as a Cake Addin
#tool nuget:?package=Noodloft.Identity.ResourceServer&version=0.0.1-alpha1&prerelease
                    
Install as a Cake Tool

Noodloft.Identity.ResourceServer

Protect your ASP.NET Core API with access tokens issued by a Noodloft Identity server.

One call wires up bearer authentication via token introspection (RFC 7662), permission-based authorization policies, RFC 9470 step-up enforcement, and DPoP holder-of-key validation (RFC 9449).

Install

dotnet add package Noodloft.Identity.ResourceServer

Add a backend for push-based revocation eviction. It is required when more than one instance also needs a shared DPoP replay guard:

dotnet add package Noodloft.Identity.ResourceServer.Postgres   # default for a self-hosted Noodloft
# or
dotnet add package Noodloft.Identity.ResourceServer.Redis

Use

var builder = WebApplication.CreateBuilder(args);

builder.AddNoodloftResourceServer(opts =>
{
    opts.IdpBaseUrl = "https://id.example.com";
    opts.IntrospectionClientId = "my-api";
    opts.IntrospectionClientSecret = builder.Configuration["Idp:ClientSecret"]!;
});

// Optional on one node; required for push eviction and multi-node replay protection:
builder.AddNoodloftResourceServerPostgres();

var app = builder.Build();

app.UseAuthentication();
app.UseAuthorization();

app.MapGet("/orders", () => Results.Ok(/* ... */))
   .RequirePermission("orders.read");

// Machine-to-machine tokens have application scopes, not user permissions.
app.MapPost("/imports", () => Results.Accepted())
   .RequireScope("imports.write");

// Require a higher assurance level, re-authenticated within the last hour.
app.MapDelete("/orders/{id}", (string id) => Results.NoContent())
   .RequireStepUp("mfa", maxAgeSeconds: 3600);

app.Run();

RequirePermission, RequireScope, and RequireStepUp create the authorization policy for you — there is nothing to register per permission or scope.

What a caller sees

Situation Response
No or invalid token 401 Unauthorized
Valid token, missing permission 403 Forbidden
Valid token, insufficient acr 401 with a WWW-Authenticate: Bearer error="insufficient_user_authentication" challenge (RFC 9470)

Dependencies

This package deliberately carries no EF Core, no database driver, and no OpenIddict dependency — only Microsoft.IdentityModel.* for DPoP proof validation. A cache/revocation backend is opt-in via a companion package.

Licence

MIT

Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages (2)

Showing the top 2 NuGet packages that depend on Noodloft.Identity.ResourceServer:

Package Downloads
Noodloft.Identity.ResourceServer.Redis

Redis backend for Noodloft.Identity.ResourceServer: a cross-node DPoP replay guard and pub/sub revocation eviction. Use this instead of the Postgres backend when your deployment already runs Redis.

Noodloft.Identity.ResourceServer.Postgres

Postgres backend for Noodloft.Identity.ResourceServer: a cross-node DPoP replay guard and LISTEN/NOTIFY revocation eviction backed by the identity database. The default choice for a self-hosted Noodloft deployment.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
0.0.1-alpha1 94 8/1/2026