WebApiTools.Authentication.Bearer 1.1.3

There is a newer version of this package available.
See the version list below for details.
dotnet add package WebApiTools.Authentication.Bearer --version 1.1.3
                    
NuGet\Install-Package WebApiTools.Authentication.Bearer -Version 1.1.3
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="WebApiTools.Authentication.Bearer" Version="1.1.3" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="WebApiTools.Authentication.Bearer" Version="1.1.3" />
                    
Directory.Packages.props
<PackageReference Include="WebApiTools.Authentication.Bearer" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add WebApiTools.Authentication.Bearer --version 1.1.3
                    
#r "nuget: WebApiTools.Authentication.Bearer, 1.1.3"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package WebApiTools.Authentication.Bearer@1.1.3
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=WebApiTools.Authentication.Bearer&version=1.1.3
                    
Install as a Cake Addin
#tool nuget:?package=WebApiTools.Authentication.Bearer&version=1.1.3
                    
Install as a Cake Tool

Nuget Nuget License

WebApiTools.Authentication.Bearer

This library provides extensions to easily configure JWT Bearer Authentication in your ASP.NET Core applications.

Installation

dotnet add package WebApiTools.Authentication.Bearer

1. Quick Setup (Simplest)

If your configuration file contains a JwtOptions section, you can add authentication in one line:

var builder = WebApplication.CreateBuilder(args);

builder.AddJwtAuthentication();

var app = builder.Build();
app.UseCors();
app.UseJwtAuthentication();
app.UseHttpsRedirection();

2. Using Configuration Section Explicitly

If you want to be explicit about where the configuration comes from:

var builder = WebApplication.CreateBuilder(args);

builder.Services.AddJwtAuthentication(builder.Configuration);

var app = builder.Build();
app.UseCors();
app.UseJwtAuthentication();
app.UseHttpsRedirection();

3. Full Customization (Manual Options Binding)

If you prefer to configure JwtOptions programmatically:

var builder = WebApplication.CreateBuilder(args);

builder.Services.AddJwtAuthentication(options =>
{
    options.Issuer = "MyIssuer";
    options.Audience = "MyAudience";
    options.SecretKey = "SuperSecretKey123456";
    options.ExpirationInDays = 7;
    options.ValidateIssuer = true;
    options.ValidateAudience = true;
    options.ValidateLifetime = true;
    options.ValidateIssuerSigningKey = true;
});

var app = builder.Build();
app.UseCors();
app.UseJwtAuthentication();
app.UseHttpsRedirection();

4. Advanced Usage with Custom Events

You can now handle JWT Bearer events for advanced scenarios:

var builder = WebApplication.CreateBuilder(args);

builder.Services.AddJwtAuthentication(options =>
{
    options.Issuer = "MyIssuer";
    options.Audience = "MyAudience";
    options.SecretKey = "SuperSecretKey123456";
    options.ExpirationInDays = 7;
}, new JwtEvents        // all are optionals, so only one can be used
{
    OnMessageReceived = async (context) =>
    {
        // Custom token extraction logic
        var token = context.Request.Headers["X-Custom-Token"].FirstOrDefault();
        if (!string.IsNullOrEmpty(token))
        {
            context.Token = token;
        }
        await Task.CompletedTask;
    },
    
    OnAuthenticationFailed = async (context) =>
    {
        // Custom error handling
        Console.WriteLine($"Authentication failed: {context.Exception.Message}");
        await Task.CompletedTask;
    },
    
    OnTokenValidated = async (context) =>
    {
        // Add custom claims or validation
        var claimsIdentity = context.Principal.Identity as ClaimsIdentity;
        claimsIdentity?.AddClaim(new Claim("CustomClaim", "CustomValue"));
        await Task.CompletedTask;
    },
    
    OnChallenge = async (context) =>
    {
        // Custom challenge response
        context.Response.Headers.Append("X-Custom-Challenge", "Bearer error=\"invalid_token\"");
        await Task.CompletedTask;
    },
    
    OnForbidden = async (context) =>
    {
        // Custom forbidden response
        context.Response.StatusCode = 403;
        await context.Response.WriteAsync("Custom forbidden message");
        await Task.CompletedTask;
    }
});

var app = builder.Build();
app.UseCors();
app.UseJwtAuthentication();
app.UseHttpsRedirection();

JwtOptions Configuration

JwtOptions allows you to configure:

  • Issuer: The expected token issuer.
  • Audience: The expected token audience.
  • SecretKey: The symmetric security key used for signing tokens.
  • ExpirationInDays: Default token expiration.
  • ValidateIssuer: Whether to validate the issuer.
  • ValidateAudience: Whether to validate the audience.
  • ValidateLifetime: Whether to check token expiration.
  • ValidateIssuerSigningKey: Whether to validate the signing key.

JwtEvents Configuration

JwtEvents allows you to handle JWT Bearer authentication events:

  • OnMessageReceived: Invoked when a token has been received.
  • OnAuthenticationFailed: Invoked if authentication fails.
  • OnTokenValidated: Invoked after the token has been validated.
  • OnChallenge: Invoked before a challenge is sent.
  • OnForbidden: Invoked if authorization fails and results in a forbidden response.

Available Extension Methods

// From builder simple
builder.AddJwtAuthentication();

// From builder custom events
builder.AddJwtAuthentication(JwtEvents events);

// custom configuration
// From IConfiguration
builder.Services.AddJwtAuthentication(IConfiguration configuration);

// With custom events
builder.Services.AddJwtAuthentication(JwtEvents events);

// With custom Authorization options
builder.Services.AddJwtAuthentication(Action<AuthorizationOptions> options);

// With manual options configuration
builder.Services.AddJwtAuthentication(Action<JwtOptions> configuration);

// With manual options configuration and authorization options
builder.Services.AddJwtAuthentication(Action<JwtOptions> configuration, Action<AuthorizationOptions> options);

// With manual options configuration and events
builder.Services.AddJwtAuthentication(Action<JwtOptions> configuration, JwtEvents events);

// With manual options configuration, authorization options and events
builder.Services.AddJwtAuthentication(Action<JwtOptions> configuration, Action<AuthorizationOptions> options, JwtEvents events);

// using authentication
...
app.UseJwtAuthentication();
...
app.MapGet("", () => Results.Ok("Hello world!")).RequireAuthorization();

Best Practices

  1. Always store SecretKey securely (use environment variables or secrets manager).
  2. Place app.UseJwtAuthentication(); before mapping endpoints.
  3. Use the simplest overload unless you need advanced customization.
  4. For production, use strong secret keys and consider key rotation.
  5. Use custom events for logging, custom token validation, or specialized error handling.

Example appsettings.json

{
  "JwtOptions": {
    "Issuer": "MyApp",
    "Audience": "MyAppUsers",
    "SecretKey": "YourSuperSecretKeyHereAtLeast32CharactersLong",
    "ExpirationInDays": 7,
    "ValidateIssuer": true,
    "ValidateAudience": true,
    "ValidateLifetime": true,
    "ValidateIssuerSigningKey": true
  }
}

Dependencies

  • Microsoft.AspNetCore.Authentication.JwtBearer

Contributing

If you encounter issues or have suggestions for improvements, please submit an issue or pull request to the repository hosting this library.

Product Compatible and additional computed target framework versions.
.NET net9.0 is compatible.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.1.4 248 12/25/2025
1.1.3 212 12/24/2025
1.1.2 222 11/27/2025
1.0.1 240 11/25/2025
1.0.0 239 8/17/2025

Update all extensions methods to have new JwtEvents parameter. Update documentation. Update dependencies.