Noodloft.Identity.ResourceServer
0.0.1-alpha1
dotnet add package Noodloft.Identity.ResourceServer --version 0.0.1-alpha1
NuGet\Install-Package Noodloft.Identity.ResourceServer -Version 0.0.1-alpha1
<PackageReference Include="Noodloft.Identity.ResourceServer" Version="0.0.1-alpha1" />
<PackageVersion Include="Noodloft.Identity.ResourceServer" Version="0.0.1-alpha1" />
<PackageReference Include="Noodloft.Identity.ResourceServer" />
paket add Noodloft.Identity.ResourceServer --version 0.0.1-alpha1
#r "nuget: Noodloft.Identity.ResourceServer, 0.0.1-alpha1"
#:package Noodloft.Identity.ResourceServer@0.0.1-alpha1
#addin nuget:?package=Noodloft.Identity.ResourceServer&version=0.0.1-alpha1&prerelease
#tool nuget:?package=Noodloft.Identity.ResourceServer&version=0.0.1-alpha1&prerelease
Noodloft.Identity.ResourceServer
Protect your ASP.NET Core API with access tokens issued by a Noodloft Identity server.
One call wires up bearer authentication via token introspection (RFC 7662), permission-based authorization policies, RFC 9470 step-up enforcement, and DPoP holder-of-key validation (RFC 9449).
Install
dotnet add package Noodloft.Identity.ResourceServer
Add a backend for push-based revocation eviction. It is required when more than one instance also needs a shared DPoP replay guard:
dotnet add package Noodloft.Identity.ResourceServer.Postgres # default for a self-hosted Noodloft
# or
dotnet add package Noodloft.Identity.ResourceServer.Redis
Use
var builder = WebApplication.CreateBuilder(args);
builder.AddNoodloftResourceServer(opts =>
{
opts.IdpBaseUrl = "https://id.example.com";
opts.IntrospectionClientId = "my-api";
opts.IntrospectionClientSecret = builder.Configuration["Idp:ClientSecret"]!;
});
// Optional on one node; required for push eviction and multi-node replay protection:
builder.AddNoodloftResourceServerPostgres();
var app = builder.Build();
app.UseAuthentication();
app.UseAuthorization();
app.MapGet("/orders", () => Results.Ok(/* ... */))
.RequirePermission("orders.read");
// Machine-to-machine tokens have application scopes, not user permissions.
app.MapPost("/imports", () => Results.Accepted())
.RequireScope("imports.write");
// Require a higher assurance level, re-authenticated within the last hour.
app.MapDelete("/orders/{id}", (string id) => Results.NoContent())
.RequireStepUp("mfa", maxAgeSeconds: 3600);
app.Run();
RequirePermission, RequireScope, and RequireStepUp create the authorization policy for you — there is nothing
to register per permission or scope.
What a caller sees
| Situation | Response |
|---|---|
| No or invalid token | 401 Unauthorized |
| Valid token, missing permission | 403 Forbidden |
Valid token, insufficient acr |
401 with a WWW-Authenticate: Bearer error="insufficient_user_authentication" challenge (RFC 9470) |
Dependencies
This package deliberately carries no EF Core, no database driver, and no OpenIddict dependency — only
Microsoft.IdentityModel.* for DPoP proof validation. A cache/revocation backend is opt-in via a companion
package.
Licence
MIT
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Noodloft.Identity.Abstractions (>= 0.0.1-alpha1)
-
net8.0
- Noodloft.Identity.Abstractions (>= 0.0.1-alpha1)
NuGet packages (2)
Showing the top 2 NuGet packages that depend on Noodloft.Identity.ResourceServer:
| Package | Downloads |
|---|---|
|
Noodloft.Identity.ResourceServer.Redis
Redis backend for Noodloft.Identity.ResourceServer: a cross-node DPoP replay guard and pub/sub revocation eviction. Use this instead of the Postgres backend when your deployment already runs Redis. |
|
|
Noodloft.Identity.ResourceServer.Postgres
Postgres backend for Noodloft.Identity.ResourceServer: a cross-node DPoP replay guard and LISTEN/NOTIFY revocation eviction backed by the identity database. The default choice for a self-hosted Noodloft deployment. |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 0.0.1-alpha1 | 94 | 8/1/2026 |