Zeeget.Zitadel.Core
0.19.1
dotnet add package Zeeget.Zitadel.Core --version 0.19.1
NuGet\Install-Package Zeeget.Zitadel.Core -Version 0.19.1
<PackageReference Include="Zeeget.Zitadel.Core" Version="0.19.1" />
<PackageVersion Include="Zeeget.Zitadel.Core" Version="0.19.1" />
<PackageReference Include="Zeeget.Zitadel.Core" />
paket add Zeeget.Zitadel.Core --version 0.19.1
#r "nuget: Zeeget.Zitadel.Core, 0.19.1"
#:package Zeeget.Zitadel.Core@0.19.1
#addin nuget:?package=Zeeget.Zitadel.Core&version=0.19.1
#tool nuget:?package=Zeeget.Zitadel.Core&version=0.19.1
ZZitadel
A Zitadel-first .NET library for Zeeget SaaS applications. It makes Zitadel integration straightforward for .NET projects: authenticating users, resolving the current user and organization/tenant, reading roles and memberships, and bootstrapping organization access.
This library is intentionally coupled to Zitadel. It does not provide a generic identity abstraction, and you should not expect to swap Zitadel out behind it.
Status: 0.4.0. The functional core is complete — authentication, provisioning (register, invite, resend invitation, grant/revoke, org-scoped removal, and social sign-up that creates a tenant), organization rename, role resolution with an optional Management-API fallback, listing the current user's organizations from claims, readiness health checks, and an observability seam — covered by unit tests, real-Zitadel integration tests, and a headless browser e2e for the social flow. Pre-1.0: the public API is not yet stable and minor releases may include breaking changes (see the changelog).
Packages
| Package | Purpose |
|---|---|
Zeeget.Zitadel.Core |
Typed Zitadel Management/Auth API client (REST) and domain primitives — organizations, users, memberships, roles — plus the provisioning orchestration. No ASP.NET Core dependency. |
Zeeget.Zitadel.AspNetCore |
ASP.NET Core integration — DI wiring, OIDC/JWT bearer authentication, current-user / current-organization (tenant) / roles accessors, and the provisioning entry point. |
Zeeget.Zitadel.AspNetCore depends on Zeeget.Zitadel.Core; never the reverse. The library
owns no datastore — resilience comes from idempotent check-then-act against Zitadel.
Getting started
dotnet add package Zeeget.Zitadel.AspNetCore # also pulls in Zeeget.Zitadel.Core
Wire inbound authentication (validates Zitadel JWTs locally against the issuer's JWKS) and the claims accessors:
builder.Services.AddZitadelAuthentication(builder.Configuration); // binds the "Zitadel" section
Wire provisioning (registration, invitations, role grant/revoke, org-scoped removal) — calls Zitadel's Management API as a service identity:
builder.Services.AddZitadelProvisioning(builder.Configuration);
Configuration (the Zitadel section — supply secrets from your secret store, never in code):
{
"Zitadel": {
"Authority": "https://your-instance.zitadel.cloud",
"Audience": "<project or app id expected in the token's aud>",
"ServiceUserKey": "<JWT-profile key JSON for the management service identity>",
"ProjectId": "<id of the project whose roles you grant>"
}
}
See docs/setup/zitadel.md for the Zitadel-side setup (app token type = JWT, service user/key, scopes/claims). For a full runnable example, follow the sample walkthrough.
Capabilities
- Authenticate users against Zitadel via standard OIDC / JWT bearer (local JWKS validation).
- Register a user (manual or social sign-up) and, in one flow, create their organization (tenant) and make them its owner.
- Invite other users into an organization with an application role.
- Resolve the current user and current organization (tenant), and the user's roles within an organization, from the request's token claims.
- Grant / revoke application roles by key, and read a user's membership and roles in an organization via the Management API (the role taxonomy is the consuming app's; the library only knows the native organization owner).
- Remove a user from an organization (org-scoped and multi-org-safe).
A Zitadel Organization is the application tenant, and a user may belong to one or more organizations. See docs/architecture/zitadel-model.md.
How it talks to Zitadel (hybrid)
- Authentication uses standard ASP.NET Core OIDC / JWT bearer against Zitadel.
- Management (organizations, users, memberships, roles) calls Zitadel's Management & Auth APIs directly over REST. No mandatory third-party Zitadel SDK.
Observability
The library is instrumented with OpenTelemetry-compatible traces and metrics plus
structured ILogger logs (ADR-0021). It ships no
exporter and forces no backend — you own export. Subscribe by name via the public
constants on ZitadelDiagnostics:
using Zeeget.Zitadel.Core.Diagnostics;
builder.Services.AddOpenTelemetry()
.WithTracing(t => t.AddSource(ZitadelDiagnostics.ActivitySourceName).AddOtlpExporter())
.WithMetrics(m => m.AddMeter(ZitadelDiagnostics.MeterName).AddOtlpExporter());
What it emits:
- Traces — one span per provisioning operation (
register,invite,grant_role,revoke_role,remove_from_organization), tagged with the outcome and the opaque Zitadel ids it acted on. - Metrics — a
zitadel.provisioning.operationscounter and azitadel.provisioning.operation.durationhistogram, tagged low-cardinality byoperationandoutcome(pluserror.typeon failures). HTTP-level retry/circuit metrics come from the resilientHttpClientpipeline's own built-in telemetry. - No secrets or PII ever reach a metric tag, span tag, or log — opaque ids appear on spans only, never on metric tags.
Swap AddOtlpExporter() for AddConsoleExporter() or any other exporter — the library is
exporter-agnostic.
Requirements
- .NET 10 (LTS) or later.
- A reachable Zitadel instance (issuer + a service identity for management calls).
Documentation
- Architecture: decisions · boundaries · Zitadel model
- Workflows: development · testing · release
- Setup: Zitadel instance/app configuration · user onboarding (registration, invitation, landing) · securing access (Console restricted to admins).
- Sample: a runnable minimal-API wiring walkthrough.
- Observability: wiring OpenTelemetry export.
- Contributors and AI agents: start with CLAUDE.md / AGENTS.md.
License
MIT © Zeeget. See LICENSE.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Microsoft.Extensions.Http (>= 10.0.11)
- Microsoft.Extensions.Http.Resilience (>= 10.8.0)
- Microsoft.Extensions.Logging.Abstractions (>= 10.0.11)
- Microsoft.IdentityModel.JsonWebTokens (>= 8.19.1)
NuGet packages (1)
Showing the top 1 NuGet packages that depend on Zeeget.Zitadel.Core:
| Package | Downloads |
|---|---|
|
Zeeget.Zitadel.AspNetCore
ASP.NET Core integration for Zitadel: OIDC/JWT bearer authentication (local JWKS validation) and current-user / current-organization (tenant) / roles accessors derived from token claims. Builds on Zeeget.Zitadel.Core. |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 0.19.1 | 118 | 9/18/2026 |
| 0.19.0 | 96 | 9/17/2026 |
| 0.18.0 | 137 | 9/6/2026 |
| 0.17.0 | 127 | 9/5/2026 |
| 0.16.0 | 126 | 8/28/2026 |
| 0.15.0 | 109 | 8/28/2026 |
| 0.14.1 | 109 | 8/28/2026 |
| 0.14.0 | 111 | 8/27/2026 |
| 0.13.4 | 208 | 8/4/2026 |
| 0.13.3 | 141 | 7/29/2026 |
| 0.13.2 | 174 | 6/17/2026 |
| 0.13.1 | 138 | 6/17/2026 |
| 0.13.0 | 192 | 6/17/2026 |
| 0.12.0 | 141 | 6/16/2026 |
| 0.11.0 | 187 | 6/10/2026 |
| 0.10.0 | 157 | 6/10/2026 |
| 0.9.0 | 151 | 6/9/2026 |
| 0.8.0 | 172 | 6/9/2026 |
| 0.7.0 | 164 | 6/8/2026 |
| 0.6.0 | 182 | 6/7/2026 |