Wiaoj.WellKnown.JwtBearer
0.3.0-alpha.1
This is a prerelease version of Wiaoj.WellKnown.JwtBearer.
dotnet add package Wiaoj.WellKnown.JwtBearer --version 0.3.0-alpha.1
NuGet\Install-Package Wiaoj.WellKnown.JwtBearer -Version 0.3.0-alpha.1
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Wiaoj.WellKnown.JwtBearer" Version="0.3.0-alpha.1" />
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Wiaoj.WellKnown.JwtBearer" Version="0.3.0-alpha.1" />
<PackageReference Include="Wiaoj.WellKnown.JwtBearer" />
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Wiaoj.WellKnown.JwtBearer --version 0.3.0-alpha.1
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
#r "nuget: Wiaoj.WellKnown.JwtBearer, 0.3.0-alpha.1"
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Wiaoj.WellKnown.JwtBearer@0.3.0-alpha.1
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Wiaoj.WellKnown.JwtBearer&version=0.3.0-alpha.1&prerelease
#tool nuget:?package=Wiaoj.WellKnown.JwtBearer&version=0.3.0-alpha.1&prerelease
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
Wiaoj.WellKnown.JwtBearer
Advertises a protected resource's RFC 9728 metadata in the WWW-Authenticate challenge that JwtBearer sends on a 401.
Installation
dotnet add package Wiaoj.WellKnown.JwtBearer
Usage
builder.Services.AddOAuthProtectedResource(r => r.Resource = "https://api.example.com/v1");
builder.Services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
.AddJwtBearer(options => { ... })
.AddProtectedResourceMetadataChallenge();
app.MapOAuthProtectedResource();
A request with no token receives:
HTTP/1.1 401 Unauthorized
WWW-Authenticate: Bearer resource_metadata="https://api.example.com/.well-known/oauth-protected-resource/v1"
An expired token keeps JwtBearer's own error, in the same challenge:
WWW-Authenticate: Bearer error="invalid_token", error_description="The token expired at ...", resource_metadata="https://api.example.com/.well-known/oauth-protected-resource/v1"
How it behaves
- Additive. The parameter is added as the response starts, after JwtBearer has written its challenge.
error,error_description,scopeandrealmare left untouched (§5.1). Only 401 responses are changed; a403 insufficient_scopeis not. - Composes with your events. An
Events.OnChallengeyou set still runs first. If it callsHandleResponse(), your response is left exactly as you wrote it. - Derived URL. The URL comes from
ProtectedResourceMetadataUri.For(resource), which is the routeMapOAuthProtectedResource()serves. With several named resources, choose one per scheme withAddProtectedResourceMetadataChallenge(scheme, resourceName: "admin"). EventsTypeis not supported. Events resolved fromJwtBearerOptions.EventsTypecannot be composed with, and that combination throws instead of silently advertising nothing. CallProtectedResourceChallenge.AddOnStarting(context.HttpContext, metadataUrl)from your events type'sChallengemethod instead.- Other handlers. The same
ProtectedResourceChallenge.AddOnStartingcall works for an authentication handler other than JwtBearer.
Migrating from AttachProtectedResourceMetadata
context.AttachProtectedResourceMetadata(url) inside OnChallenge is obsolete.
- What changed. It used to call
HandleResponse()and replace the header, which dropped the token error. It now adds the parameter without handling the response. - What to do. Remove the call and register
AddProtectedResourceMetadataChallenge()instead. The URL is then derived from the registered resource, so there is nothing to keep in step.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
-
net10.0
- Microsoft.AspNetCore.Authentication.JwtBearer (>= 10.0.12)
- Wiaoj.Preconditions (>= 0.3.0-alpha.1)
- Wiaoj.WellKnown (>= 0.3.0-alpha.1)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 0.3.0-alpha.1 | 42 | 10/5/2026 |
| 0.2.0-alpha.3 | 49 | 9/24/2026 |
| 0.2.0-alpha.2 | 44 | 9/24/2026 |
| 0.2.0-alpha.1 | 47 | 9/24/2026 |
| 0.1.0-alpha.9 | 131 | 9/21/2026 |
| 0.1.0-alpha.8 | 45 | 9/21/2026 |
| 0.1.0-alpha.7 | 55 | 9/18/2026 |
| 0.1.0-alpha.6 | 49 | 9/16/2026 |
| 0.1.0-alpha.5 | 49 | 9/16/2026 |
| 0.1.0-alpha.4 | 54 | 9/16/2026 |
| 0.1.0-alpha.3 | 46 | 9/15/2026 |
| 0.1.0-alpha.2 | 50 | 9/15/2026 |
| 0.1.0-alpha.1 | 51 | 9/14/2026 |
| 0.0.1-alpha.112-preview | 55 | 9/13/2026 |
| 0.0.1-alpha.111-preview | 48 | 9/13/2026 |