Orleans.Lattice.Membership 9.9.0

dotnet add package Orleans.Lattice.Membership --version 9.9.0
                    
NuGet\Install-Package Orleans.Lattice.Membership -Version 9.9.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Orleans.Lattice.Membership" Version="9.9.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Orleans.Lattice.Membership" Version="9.9.0" />
                    
Directory.Packages.props
<PackageReference Include="Orleans.Lattice.Membership" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Orleans.Lattice.Membership --version 9.9.0
                    
#r "nuget: Orleans.Lattice.Membership, 9.9.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Orleans.Lattice.Membership@9.9.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Orleans.Lattice.Membership&version=9.9.0
                    
Install as a Cake Addin
#tool nuget:?package=Orleans.Lattice.Membership&version=9.9.0
                    
Install as a Cake Tool

Orleans.Lattice.Membership

Optional, opt-in caller-identity resolution add-on for Orleans.Lattice. Resolves who is calling into a LatticeSubject - a stable subject id, the fully transitively-expanded set of group ids, and an optional flat claim bag - so the authorization layer (Orleans.Lattice.Auth) can make an access decision.

Design

AddLatticeMembership() contributes the real credential-resolving context. It selects the first registered ILatticeCredentialAuthenticator that recognizes the ambient LatticeCredential, maps the resulting principal against an introspectable ILatticeMembershipDirectory, and expands group membership to its full transitive closure with cycle detection, so downstream policy always evaluates a flat, uniform group set. Nested (group-in-group) membership is supported, and under the default Union merge mode token-asserted groups are themselves expanded through the directory closure (TokenOnly bypasses the directory, and DirectoryOnly ignores token-asserted groups).

The directory dogfoods reserved sys-membership-* ILattice trees (a groups tree, and an edges tree that stores each membership edge in both directions for forward/reverse scans - there is no separate user record), so every record is readable through the ordinary scan / change-feed surface and every mutation is durably auditable through an auto-enabled per-key history view. Resolution is served from a per-silo cache bounded by the minimum of the configured lifetime and the inbound token's own expiry, and flushed on any sys-membership-* mutation the silo commits, so a membership change is reflected without a process restart (another silo keeps its pre-change entry until that entry expires).

  • Opt-in and zero-cost when absent. Core ships only an allow-nothing default membership context that always resolves Anonymous; nothing runs until AddLatticeMembership() is called.
  • Extensible authenticators. A built-in JwtCredentialAuthenticator (issuer / audience / signing-key / lifetime validation plus claim-to-subject and claim-to-groups mapping, registered per trusted issuer via AddLatticeJwtAuthenticator) is the base for provider-specific authenticators such as Orleans.Lattice.Membership.Entra; AnonymousCredentialAuthenticator is the fallback default.

Registration

siloBuilder
    .AddLattice((silo, name) => silo.AddMemoryGrainStorage(name))
    .AddLatticeMembership()
    .AddLatticeJwtAuthenticator(options => { /* issuer, audience, signing key */ });

Group-merge policy (Union / TokenOnly / DirectoryOnly), the resolution-cache lifetime, history retention, and an optional claim-to-group projection are configured through LatticeMembershipOptions.

See the Membership documentation for the full guide.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages (7)

Showing the top 5 NuGet packages that depend on Orleans.Lattice.Membership:

Package Downloads
Orleans.Lattice.Auth

Authorization add-on for Orleans.Lattice. Ships the authorization rule model, durable policy store, decision engine, credential context, and read/write enforcement seams that gate lattice operations through a fail-closed access policy backed by reserved lattice trees with per-key history.

Orleans.Lattice.Api.Abstractions

Shared contract package for the Orleans.Lattice API facades. Holds the transport-agnostic service interfaces and request/response models for the state, data, auth, backup, schema, tree-administration, tenancy, replication, telemetry, installable-app control, and region-discovery surfaces, so binding packages depend on a public, versioned contract instead of another package's internals. Contains no implementation and starts nothing; the facade packages implement these contracts and are registered separately.

Orleans.Lattice.Api.Auth

Optional configuration and control facade add-on for Orleans.Lattice authorization. Exposes a single transport-agnostic admin surface (and, via a sibling binding, a gRPC surface) for administering the membership directory and the authorization policy store: CRUD groups, memberships, and rules, plus ExplainAsync (why a subject is or is not authorized) and EffectivePermissionsAsync (the rules in effect for a subject). Every operation is authorized as an administrator through the same enforcement the in-cluster path uses, so an admin API can never rewrite policy for an unauthorized caller. Opt-in and absent by default; registered with a single AddLatticeAuthApi(...) call.

Orleans.Lattice.Membership.Entra

Microsoft Entra ID (Azure AD) credential authenticator for Orleans.Lattice.Membership. Specializes the built-in JWT authenticator with tenant-aware OIDC/JWKS discovery and signing-key rotation, Entra v2.0 claim conventions (oid subject, tid tenant, groups, app roles), single- and multi-tenant issuer allow-listing, and pluggable groups-overage resolution. Keeps the Entra dependency stack out of the core membership package.

Orleans.Lattice.Api.Replication

Optional transport-agnostic facade add-on for Orleans.Lattice runtime per-tree replication configuration and peer status. Implements ILatticeReplicationControl over the replication engine's config-authoring seam, so an authorized operator can enable replication for a tree (fixing its wire merge mode), disable it, and inspect the runtime replicated-tree set. Also implements ILatticeReplicationStatus over the peer-status read path. Authoring and status reads are authorized fail-closed through the shared Lattice access gate (default-deny anonymous); the gRPC and MCP transports adapt over these surfaces.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
9.9.0 265 10/2/2026
9.8.0 429 9/26/2026
9.7.0 344 9/21/2026
9.6.2 353 9/9/2026
9.6.1 126 9/7/2026
9.6.0 700 9/5/2026
9.5.1 111 9/7/2026
9.5.0 378 9/2/2026
9.4.0 713 8/29/2026
9.3.0 398 8/25/2026
9.2.0 452 8/23/2026
9.1.0 473 8/20/2026
9.0.0 399 8/14/2026
8.0.0 999 7/20/2026
7.9.1 166 7/14/2026
7.9.0 170 7/9/2026
7.8.0 175 7/4/2026