RudeAuth 0.1.0

dotnet add package RudeAuth --version 0.1.0
                    
NuGet\Install-Package RudeAuth -Version 0.1.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="RudeAuth" Version="0.1.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="RudeAuth" Version="0.1.0" />
                    
Directory.Packages.props
<PackageReference Include="RudeAuth" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add RudeAuth --version 0.1.0
                    
#r "nuget: RudeAuth, 0.1.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package RudeAuth@0.1.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=RudeAuth&version=0.1.0
                    
Install as a Cake Addin
#tool nuget:?package=RudeAuth&version=0.1.0
                    
Install as a Cake Tool

RudeAuth C# SDK

.NET client for a RudeAuth licensing server. The client embeds only an application id and an Ed25519 public key. Every response is signed and verified against that key before any field is trusted, so a patched binary cannot be talked into a forged "success".

Crypto is libsodium via NSec: Ed25519, X25519, HKDF, and XChaCha20-Poly1305.

Install

dotnet add package RudeAuth

Targets .NET Standard 2.1 and .NET 8, so it runs on .NET 5 and later, Unity 2021 and later, and Mono. .NET Framework caps at .NET Standard 2.0, which the crypto backend does not reach, so it is not yet supported.

Quick start

using RudeAuth;

// appId and publicKey come from `rudeauth-cli app create`. Both are safe to
// embed: the public key verifies responses, it cannot forge them.
using var client = new RudeAuthClient(appId, publicKey, "https://api.yourproduct.com");

Session sess;
try
{
    sess = client.Authenticate(userEnteredKey);
}
catch (RudeAuthException e) when (e.Code == ErrorCode.LicenseExpired)
{
    // expired is not device-limit is not banned; e.Code says which
    return;
}
using (sess)
{
    string offset = sess.Variable("offset"); // server-side, rotatable
    byte[] core = sess.File("core.dll");     // never shipped in your binary
}

Async equivalents (AuthenticateAsync, VariableAsync, FileAsync) are available.

No "is licensed" boolean, by design

There is deliberately no method returning a bool that means "is this user licensed". Authenticate returns a Session or throws a RudeAuthException, and the gating calls exist only on a Session, which cannot be built without a response signature that verified against the key you compiled in.

Errors

Every failure throws RudeAuthException; read its Code:

Network, BadResponse, SignatureInvalid, NonceMismatch, ClockSkew, LicenseInvalid, LicenseExpired, DeviceLimit, DeviceBlacklisted, RateLimited, SessionExpired, EndpointDisabled, AppDisabled, ResetUnavailable, FileNotFound, ServerError.

Behaviour worth knowing

  • No offline mode, no cache. If the server is unreachable, calls fail. A cached "last known good" state is exactly what an attacker induces by blocking the network.
  • A missed heartbeat is not a logout. The session retries until its TTL lapses. Dispose stops the heartbeat and zeroes the session key.
  • Fewer than two readable hardware components and the SDK refuses to authenticate.
  • Fingerprints are forgeable. Device binding deters casual licence sharing, nothing more.

Platforms

Hardware fingerprinting follows a shared per-OS component set: Windows (machine GUID, volume serial, CPU, BIOS, board), Linux (machine-id, DMI ids), macOS (IOPlatformUUID, serial).

Tests

The crypto is checked against known-answer vectors generated by the server's own code, and the protocol flow against an in-process handler that signs and seals exactly as the real server does.

dotnet test

License

MIT. The SDK holds only a public key; there is nothing in it to protect.

Product Compatible and additional computed target framework versions.
.NET net5.0 was computed.  net5.0-windows was computed.  net6.0 was computed.  net6.0-android was computed.  net6.0-ios was computed.  net6.0-maccatalyst was computed.  net6.0-macos was computed.  net6.0-tvos was computed.  net6.0-windows was computed.  net7.0 was computed.  net7.0-android was computed.  net7.0-ios was computed.  net7.0-maccatalyst was computed.  net7.0-macos was computed.  net7.0-tvos was computed.  net7.0-windows was computed.  net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
.NET Core netcoreapp3.0 was computed.  netcoreapp3.1 was computed. 
.NET Standard netstandard2.1 is compatible. 
MonoAndroid monoandroid was computed. 
MonoMac monomac was computed. 
MonoTouch monotouch was computed. 
Tizen tizen60 was computed. 
Xamarin.iOS xamarinios was computed. 
Xamarin.Mac xamarinmac was computed. 
Xamarin.TVOS xamarintvos was computed. 
Xamarin.WatchOS xamarinwatchos was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
0.1.0 114 8/19/2026