AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Authentication Dotnet Jwt

skill-hoangnh2412-ai-skills-jwt · by hoangnh2412

Đăng ký Jarvis JWT Bearer AddCoreJwtBearer trong callback AddJarvisAuthentication, section Authentication:Jwt:{scheme}. Dùng khi API cần xác thực Bearer token (OIDC hoặc symmetric key).

No reviews yet
0 installs
0 views
view→install

Install

$ agentstack add skill-hoangnh2412-ai-skills-jwt

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-hoangnh2412-ai-skills-jwt)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
4d ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Authentication Dotnet Jwt? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

JWT Bearer

Package

Program.cs

Đăng ký trong callback của AddJarvisAuthentication (không gọi AddAuthentication() trực tiếp):

using Jarvis.Authentication;          // AddJarvisAuthentication
using Jarvis.Authentication.Jwt;      // AddCoreJwtBearer
using Microsoft.AspNetCore.Authentication.JwtBearer;

builder.Services.AddJarvisAuthentication(builder.Configuration, auth =>
{
    auth.AddCoreJwtBearer(builder.Configuration, JwtBearerDefaults.AuthenticationScheme);
});

Scheme mặc định "Bearer". Bind từ Authentication:Jwt:{scheme}.

Hai chế độ validate

| Chế độ | Điều kiện | Dùng cho | |--------|-----------|----------| | OIDC metadata | có Authority | OpenIddict, Cognito, Azure AD — validate qua issuer metadata | | Symmetric key | không Authority, có IssuerSigningKeys | dev/test |

Validator startup yêu cầu Authority HOẶC IssuerSigningKeys (khi ValidateIssuerSigningKey). ClockSkew = 0. MaxExpireMinutes > 0 → giới hạn lifetime token theo policy.

Revoke / blacklist — IJwtTokenAccessChecker

Mặc định AllowAllJwtTokenAccessChecker (cho tất cả). Override để chặn token bị thu hồi:

auth.AddCoreJwtBearer(builder.Configuration, "Bearer");

Checker đăng ký Singleton, gọi trong OnTokenValidated sau khi chữ ký + lifetime OK. Tra DB → dùng IDbContextFactory / IServiceScopeFactory (không inject scoped DbContext).

appsettings.json

{
  "Authentication": {
    "Jwt": {
      "Bearer": {
        "Authority": "",
        "Audience": "",
        "IssuerSigningKeys": [],
        "ValidateAudience": true,
        "ValidateIssuer": false,
        "MaxExpireMinutes": 0
      }
    }
  }
}

Signing key / secret — env / secret store, không commit.

Swagger

[swashbuckle-dotnet/providers/jwt-security](../../../swashbuckle-dotnet/providers/jwt-security/SKILL.md) — SecuritySchemes: ["JWT"].

Validate

  • Endpoint [Authorize] → 401 khi thiếu token
  • Token symmetric hợp lệ → 200
  • (nếu có checker) token bị revoke → 401 dù chữ ký đúng

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.