PenguinConverters.Keyra.Core
3.3.5
dotnet add package PenguinConverters.Keyra.Core --version 3.3.5
NuGet\Install-Package PenguinConverters.Keyra.Core -Version 3.3.5
<PackageReference Include="PenguinConverters.Keyra.Core" Version="3.3.5" />
<PackageVersion Include="PenguinConverters.Keyra.Core" Version="3.3.5" />
<PackageReference Include="PenguinConverters.Keyra.Core" />
paket add PenguinConverters.Keyra.Core --version 3.3.5
#r "nuget: PenguinConverters.Keyra.Core, 3.3.5"
#:package PenguinConverters.Keyra.Core@3.3.5
#addin nuget:?package=PenguinConverters.Keyra.Core&version=3.3.5
#tool nuget:?package=PenguinConverters.Keyra.Core&version=3.3.5
PenguinConverters.Keyra.Core
Core abstractions and interfaces for the Keyra secret vault system.
Overview
Keyra.Core defines the foundational interfaces and base classes for secret management, key storage, and authentication. It is designed to be provider-agnostic, allowing different implementations for key storage (DPAPI-NG, AES-GCM, HSM) and secret storage (Directory, Database, Cloud).
┌─────────────────────────────────────────────────────────────────────┐
│ Keyra.Core │
├─────────────────────────────────────────────────────────────────────┤
│ │
│ ┌─────────────────┐ ┌─────────────────┐ ┌─────────────────────┐ │
│ │ Entities │ │ KeyStorageProvider│ │SecretStorageProvider│ │
│ │ │ │ │ │ │ │
│ │ • IVault │ │ • IKey │ │ • IProvider │ │
│ │ • ISecret │ │ • IProvider │ │ • IConfiguration │ │
│ │ • IFolder │ │ • IConfiguration│ │ │ │
│ │ • IAuthenticity │ │ │ │ │ │
│ └─────────────────┘ └─────────────────┘ └─────────────────────┘ │
│ │
│ ┌─────────────────────────────────────────────────────────────┐ │
│ │ Authentication │ │
│ │ │ │
│ │ • IKeyAuthenticator • IChainableAuthenticator │ │
│ │ • IKeyCredential • IAuthenticatorChain │ │
│ │ • AuthenticatorType • AuthenticatorConfiguration │ │
│ │ • VaultKeyProtection │ │
│ └─────────────────────────────────────────────────────────────┘ │
│ │
└─────────────────────────────────────────────────────────────────────┘
Package Information
| Property | Value |
|---|---|
| Package ID | PenguinConverters.Keyra.Core |
| Target Framework | net8.0 |
| Platform | Cross-platform |
| Dependencies | System.Text.Json |
Core Concepts
Vault
A vault is a container for secrets, protected by an encryption key.
┌─────────────────────────────────────────────────────────────┐
│ Vault │
│ │
│ Name: "Production" │
│ Created: 2025-01-19 │
│ Identifier: "vaults/production" │
│ │
│ ┌─────────────┐ ┌────────────────────────────────────┐ │
│ │ Key │ │ Secrets │ │
│ │ │ │ │ │
│ │ AES-256-GCM │ │ ┌─────────┐ ┌─────────┐ │ │
│ │ Id: keyra. │ │ │db-pass │ │api-key │ ... │ │
│ │ abc123... │ │ └─────────┘ └─────────┘ │ │
│ └─────────────┘ └────────────────────────────────────┘ │
│ │
│ ┌────────────────────────────────────────────────────────┐ │
│ │ Folders │ │
│ │ ┌──────────┐ ┌──────────┐ ┌──────────┐ │ │
│ │ │ servers │ │ services │ │ users │ │ │
│ │ └──────────┘ └──────────┘ └──────────┘ │ │
│ └────────────────────────────────────────────────────────┘ │
└─────────────────────────────────────────────────────────────┘
Secret
A secret stores encrypted sensitive data with metadata.
public interface ISecret
{
string Name { get; }
string? Username { get; }
string? Value { get; } // Encrypted ciphertext
DateTimeOffset Created { get; }
IAuthenticity Authenticity { get; }
IKey Key { get; }
bool TrySetValue(string plaintext); // Encrypts and stores
string? TryGetValue(); // Decrypts and returns
}
Key Storage Provider
Abstraction for encryption key management.
┌─────────────────────────────────────────────────────────────┐
│ IKeyStorageProvider │
├─────────────────────────────────────────────────────────────┤
│ │
│ GenerateKey() → Creates new encryption key │
│ LoadKey(identifier) → Loads existing key │
│ SaveKey(key) → Persists key to storage │
│ │
├─────────────────────────────────────────────────────────────┤
│ Implementations: │
│ │
│ ┌─────────────┐ ┌─────────────┐ ┌─────────────┐ │
│ │ DPAPI-NG │ │ AES-GCM │ │ HSM │ │
│ │ (File) │ │ (Windows) │ │ (Hardware) │ │
│ └─────────────┘ └─────────────┘ └─────────────┘ │
└─────────────────────────────────────────────────────────────┘
Secret Storage Provider
Abstraction for secret persistence.
┌─────────────────────────────────────────────────────────────┐
│ ISecretStorageProvider │
├─────────────────────────────────────────────────────────────┤
│ │
│ SaveSecret(secret) → Persists encrypted secret │
│ LoadSecret(name) → Retrieves secret │
│ DeleteSecret(name) → Removes secret │
│ ListSecrets() → Enumerates all secrets │
│ │
├─────────────────────────────────────────────────────────────┤
│ Implementations: │
│ │
│ ┌─────────────┐ ┌─────────────┐ ┌─────────────┐ │
│ │ Directory │ │ Database │ │ Cloud │ │
│ │ (Files) │ │ (SQL) │ │ (Azure/AWS)│ │
│ └─────────────┘ └─────────────┘ └─────────────┘ │
└─────────────────────────────────────────────────────────────┘
Authentication System
Authenticator Types
public enum AuthenticatorType
{
None = 0, // Certificate Store (no password)
Password = 1, // Password-based
YubiKey = 2, // YubiKey HMAC-SHA1
WindowsHello = 3, // Biometric/PIN
SmartCard = 4 // PIV smart card
}
Single Authenticator (Legacy)
public interface IKeyAuthenticator
{
string DisplayName { get; }
AuthenticatorType Type { get; }
bool IsAvailable { get; }
Task<IKeyCredential?> AuthenticateAsync(string vaultName, bool isNewCredential);
}
Authenticator Chain (v2)
Multiple authenticators can be chained for defense-in-depth.
The chain is recipe-driven (see docs/crypto-primitives.md §3): authenticators only
collect inputs; the derivation itself is a KDF recipe built by KdfRecipeFactory.ForChain
and executed once by the Rust engine (keyra_ffi_recipe_execute).
┌─────────────────────────────────────────────────────────────────┐
│ Authenticator Chain (recipe-driven) │
│ │
│ ┌─────────────────────────────────────────────────────────┐ │
│ │ Initial Challenge (32 bytes random, keyprotection.json) │ │
│ └────────────────────────┬────────────────────────────────┘ │
│ │ │
│ ▼ │
│ ┌─────────────────────────────────────────────────────────┐ │
│ │ Passwords (0..n) — input password[i] (UTF-16LE) │ │
│ │ Argon2id(password[i], salt=challenge‖LE32(i), │ │
│ │ m=64 MiB, t=3, p=1) per password │ │
│ │ → xor_combine (ordered: position i has its own salt) │ │
│ └────────────────────────┬────────────────────────────────┘ │
│ │ running material │
│ ▼ │
│ ┌─────────────────────────────────────────────────────────┐ │
│ │ YubiKeys (0..m, sequential by order) — input hw[j] │ │
│ │ Device: HMAC-SHA1 challenge-response over the │ │
│ │ running material (20-byte response) │ │
│ │ Recipe: hkdf_sha256(ikm=hw[j], salt=running, │ │
│ │ info="KeyraYubiKeyDerivedKey.v2") │ │
│ └────────────────────────┬────────────────────────────────┘ │
│ │ │
│ Active Directory: pass-through — contributes NO key │
│ material (its factor is the DPAPI-NG protection descriptor) │
│ │ │
│ ▼ │
│ ┌─────────────────────────────────────────────────────────┐ │
│ │ Final: hmac_sha256(running, "KeyraVaultKey") │ │
│ │ Output: 32 B → Base64 → key storage provider password │ │
│ └─────────────────────────────────────────────────────────┘ │
│ │
│ Empty chain: HMAC(SHA256(challenge), "KeyraVaultKey") │
│ AD-only (passthru): HMAC(challenge, "KeyraVaultKey") │
└─────────────────────────────────────────────────────────────────┘
IChainableAuthenticator Interface
public interface IChainableAuthenticator
{
string AuthenticatorId { get; } // e.g., "yubikey-12345678-slot1"
string DisplayName { get; } // e.g., "YubiKey 12345678 (Slot 1)"
AuthenticatorType Type { get; }
int Order { get; set; } // Position in chain
bool IsAvailable { get; }
// Core method: collect this authenticator's raw KDF-recipe input (password bytes,
// hardware device response, or ChainInput.None for a pass-through). The chain executes
// the vault's stored kdfRecipe over the collected inputs through the single Rust
// recipe interpreter — authenticators never derive key material themselves (issue #48).
Task<ChainInput?> CollectInputAsync(byte[] chainChallenge, bool isNewCredential,
ICredentialProvider? credentialProvider);
// Serialization
AuthenticatorConfiguration GetConfiguration();
void LoadConfiguration(AuthenticatorConfiguration configuration);
}
VaultKeyProtection Storage Format
Version 2 format supporting authenticator chains:
{
"version": 2,
"initialChallenge": "base64-encoded-32-bytes...",
"authenticators": [
{
"type": 1,
"order": 0,
"authenticatorId": "password",
"parameters": {}
},
{
"type": 2,
"order": 1,
"authenticatorId": "yubikey-12345678-slot1",
"parameters": {
"serialNumber": "12345678",
"slot": "1",
"challenge": "base64-encoded-challenge..."
}
}
]
}
Migration from v1
The system automatically migrates legacy single-authenticator format:
┌─────────────────────────┐ ┌─────────────────────────────┐
│ Version 1 (Legacy) │ │ Version 2 (Chain) │
├─────────────────────────┤ ├─────────────────────────────┤
│ │ │ │
│ { │ ──────► │ { │
│ "authenticatorType":1,│ Migrate │ "version": 2, │
│ "yubiKeyChallenge":...│ │ "initialChallenge": ..., │
│ } │ │ "authenticators": [...] │
│ │ │ } │
└─────────────────────────┘ └─────────────────────────────┘
Interface Extensions
IExportable / IImportable
public interface IExportable
{
Package Export(IKey key);
}
public interface IImportable
{
void Import(Package package, IKey key);
}
IPersistable
public interface IPersistable
{
void Save(string path);
void Load(string path);
}
IGitConfiguration
public interface IGitConfiguration
{
bool IsAllowedByPolicy { get; }
string? DefaultRemote { get; }
bool AutoCommit { get; }
}
JSON Converters
Custom JSON converters for serialization:
| Converter | Purpose |
|---|---|
IKeyConverter |
Serializes IKey implementations |
IKeyStorageProviderConverter |
Serializes provider references |
ISecretStorageProviderConverter |
Serializes provider references |
Usage Example
using PenguinConverters.Keyra.Core;
using PenguinConverters.Keyra.Core.Entities;
using PenguinConverters.Keyra.Core.Authentication;
// Create a vault with authentication chain
VaultKeyProtection protection = VaultKeyProtection.ForChain(
initialChallenge: RandomBytes(32),
authenticators: new List<AuthenticatorConfiguration>
{
new() { Type = AuthenticatorType.Password, Order = 0, AuthenticatorId = "password" },
new() { Type = AuthenticatorType.YubiKey, Order = 1, AuthenticatorId = "yubikey-123-slot1" }
}
);
// Create vault
Vault vault = new Vault
{
Name = "MyVault",
Created = DateTimeOffset.UtcNow,
Identifier = "vaults/myvault"
};
// Add a secret — value crypto runs through the vault's cipher, never the key itself
Secret secret = new Secret
{
Name = "database-password",
Username = "admin",
Cipher = vault.Cipher
};
secret.TrySetValue("SuperSecretPassword123!");
NuGet Installation
dotnet add package PenguinConverters.Keyra.Core
License
Proprietary - PenguinConverters
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 was computed. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net8.0
- Microsoft.Extensions.Logging.Abstractions (>= 9.0.0)
- PenguinConverters.CandyStore (>= 3.3.5)
NuGet packages (3)
Showing the top 3 NuGet packages that depend on PenguinConverters.Keyra.Core:
| Package | Downloads |
|---|---|
|
PenguinConverters.Keyra
Keyra developer SDK: load a vault key from a .keyra package, an armored share (KEYRA: ... :ARYEK), a key.json, or a vault directory, then encrypt and decrypt application secrets and configuration entries (Settings.Secret). Add a KeyStorageProvider package (DpapiNg or AesGcm) for provider-backed keys. |
|
|
PenguinConverters.Keyra.KeyStorageProvider.DpapiNg
Keyra key storage provider for Windows DPAPI-NG (NCrypt): protects vault master keys with the Windows identity (domain or local SID). Windows-only by design; install alongside the Keyra SDK to open Windows / Active Directory vaults. |
|
|
PenguinConverters.Keyra.KeyStorageProvider.AesGcm
Keyra key storage provider for password-derived AES-256-GCM keys (Argon2id KEK via the Rust engine). Cross-platform, no OS binding; install alongside the Keyra SDK for provider-backed portable keys. |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 3.3.5 | 53 | 10/5/2026 |
| 3.3.3 | 74 | 10/4/2026 |
| 3.3.1 | 99 | 10/1/2026 |
| 3.3.0 | 121 | 9/28/2026 |
| 3.2.0 | 111 | 9/28/2026 |
| 3.1.2 | 130 | 9/23/2026 |
| 3.1.1.9 | 123 | 9/23/2026 |
| 3.1.1.8 | 128 | 9/22/2026 |
| 3.1.1 | 124 | 9/21/2026 |
| 3.0.0 | 138 | 9/11/2026 |
| 2.23.7 | 130 | 9/7/2026 |
| 2.23.5 | 130 | 9/7/2026 |
| 2.23.3 | 134 | 9/7/2026 |
| 2.22.0 | 138 | 9/1/2026 |
| 2.21.0 | 136 | 8/31/2026 |
| 2.20.0 | 128 | 8/31/2026 |
| 2.19.2 | 185 | 8/28/2026 |
| 2.19.0 | 246 | 8/19/2026 |
| 2.18.0 | 152 | 8/18/2026 |
| 2.17.0 | 156 | 8/17/2026 |