SdJwt.Net.SiopV2
1.0.10
dotnet add package SdJwt.Net.SiopV2 --version 1.0.10
NuGet\Install-Package SdJwt.Net.SiopV2 -Version 1.0.10
<PackageReference Include="SdJwt.Net.SiopV2" Version="1.0.10" />
<PackageVersion Include="SdJwt.Net.SiopV2" Version="1.0.10" />
<PackageReference Include="SdJwt.Net.SiopV2" />
paket add SdJwt.Net.SiopV2 --version 1.0.10
#r "nuget: SdJwt.Net.SiopV2, 1.0.10"
#:package SdJwt.Net.SiopV2@1.0.10
#addin nuget:?package=SdJwt.Net.SiopV2&version=1.0.10
#tool nuget:?package=SdJwt.Net.SiopV2&version=1.0.10
SdJwt.Net.SiopV2 - Self-Issued OpenID Provider v2
SIOPv2 helpers for subject-signed ID Tokens and OpenID4VP combined flows.
Features
- Subject-signed ID Token issuance
- SIOPv2 ID Token validation for JWK thumbprint subject syntax (draft-13 Section 6.1)
- DID subject syntax validation via
IDidKeyResolver(draft-13 Section 6.2) - Concrete resolvers for
did:key(Ed25519, P-256, P-384, P-521) anddid:jwk - RFC 7638 JWK thumbprint subject calculation
- Static
siopv2:andopenid:provider metadata helpers
JWK Thumbprint Subject (default)
using Microsoft.IdentityModel.Tokens;
using SdJwt.Net.SiopV2;
using System.Security.Cryptography;
using var ecdsa = ECDsa.Create(ECCurve.NamedCurves.nistP256);
var signingKey = new ECDsaSecurityKey(ecdsa);
var publicJwk = JsonWebKeyConverter.ConvertFromSecurityKey(signingKey);
var issuer = new SelfIssuedIdTokenIssuer(signingKey, SecurityAlgorithms.EcdsaSha256, publicJwk);
var idToken = issuer.Issue(new SelfIssuedIdTokenOptions
{
Audience = "https://rp.example.com",
Nonce = "nonce-123"
});
var validator = new SelfIssuedIdTokenValidator();
var result = await validator.ValidateAsync(idToken, new SelfIssuedIdTokenValidationParameters
{
ExpectedAudience = "https://rp.example.com",
ExpectedNonce = "nonce-123"
});
DID Subject Syntax
Use IDidKeyResolver to validate tokens where sub is a Decentralized Identifier.
Two concrete resolvers are provided out of the box.
did:key
Supports Ed25519 (multicodec 0xED01), P-256 (0x1200), P-384 (0x1201), and P-521 (0x1202).
The multibase prefix z (base58btc) is the only accepted encoding per spec.
using SdJwt.Net.SiopV2.Did;
var resolver = new DidKeyResolver();
var result = await validator.ValidateAsync(idToken, new SelfIssuedIdTokenValidationParameters
{
ExpectedAudience = "https://rp.example.com",
ExpectedNonce = "nonce-123",
DidKeyResolver = resolver
});
// result.Subject == "did:key:z6Mk..."
did:jwk
The DID encodes a JSON Web Key as a base64url string directly in the DID identifier.
using SdJwt.Net.SiopV2.Did;
var resolver = new DidJwkResolver();
var result = await validator.ValidateAsync(idToken, new SelfIssuedIdTokenValidationParameters
{
ExpectedAudience = "https://rp.example.com",
ExpectedNonce = "nonce-123",
DidKeyResolver = resolver
});
// result.Subject == "did:jwk:eyJrdHkiOiJFQyIsImNydiI6IlAtMjU2IiwieCI6Ii4uLiIsInkiOiIuLi4ifQ"
Custom DID method
Implement IDidKeyResolver to support any DID method:
public class MyDidResolver : IDidKeyResolver
{
public async Task<SecurityKey> ResolveKeyAsync(
string did, string? keyId, CancellationToken cancellationToken = default)
{
// resolve did document, return verification key
}
}
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net5.0 was computed. net5.0-windows was computed. net6.0 was computed. net6.0-android was computed. net6.0-ios was computed. net6.0-maccatalyst was computed. net6.0-macos was computed. net6.0-tvos was computed. net6.0-windows was computed. net7.0 was computed. net7.0-android was computed. net7.0-ios was computed. net7.0-maccatalyst was computed. net7.0-macos was computed. net7.0-tvos was computed. net7.0-windows was computed. net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 is compatible. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
| .NET Core | netcoreapp3.0 was computed. netcoreapp3.1 was computed. |
| .NET Standard | netstandard2.1 is compatible. |
| MonoAndroid | monoandroid was computed. |
| MonoMac | monomac was computed. |
| MonoTouch | monotouch was computed. |
| Tizen | tizen60 was computed. |
| Xamarin.iOS | xamarinios was computed. |
| Xamarin.Mac | xamarinmac was computed. |
| Xamarin.TVOS | xamarintvos was computed. |
| Xamarin.WatchOS | xamarinwatchos was computed. |
-
.NETStandard 2.1
- System.IdentityModel.Tokens.Jwt (>= 8.12.1)
-
net10.0
- System.IdentityModel.Tokens.Jwt (>= 8.12.1)
-
net8.0
- System.IdentityModel.Tokens.Jwt (>= 8.12.1)
-
net9.0
- System.IdentityModel.Tokens.Jwt (>= 8.12.1)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
Initial SIOPv2 support with subject-signed ID Tokens and JWK thumbprint subject syntax.