# Authentication Dotnet Jwt

> Đăng ký Jarvis JWT Bearer AddCoreJwtBearer trong callback AddJarvisAuthentication, section Authentication:Jwt:{scheme}. Dùng khi API cần xác thực Bearer token (OIDC hoặc symmetric key).

- **Type:** Skill
- **Install:** `agentstack add skill-hoangnh2412-ai-skills-jwt`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [hoangnh2412](https://agentstack.voostack.com/s/hoangnh2412)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [hoangnh2412](https://github.com/hoangnh2412)
- **Source:** https://github.com/hoangnh2412/ai-skills/tree/main/jarvis/skills/authentication-dotnet/providers/jwt

## Install

```sh
agentstack add skill-hoangnh2412-ai-skills-jwt
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# JWT Bearer

## Package

```xml

```

## Program.cs

Đăng ký **trong callback** của `AddJarvisAuthentication` (không gọi `AddAuthentication()` trực tiếp):

```csharp
using Jarvis.Authentication;          // AddJarvisAuthentication
using Jarvis.Authentication.Jwt;      // AddCoreJwtBearer
using Microsoft.AspNetCore.Authentication.JwtBearer;

builder.Services.AddJarvisAuthentication(builder.Configuration, auth =>
{
    auth.AddCoreJwtBearer(builder.Configuration, JwtBearerDefaults.AuthenticationScheme);
});
```

Scheme mặc định `"Bearer"`. Bind từ `Authentication:Jwt:{scheme}`.

## Hai chế độ validate

| Chế độ | Điều kiện | Dùng cho |
|--------|-----------|----------|
| **OIDC metadata** | có `Authority` | OpenIddict, Cognito, Azure AD — validate qua issuer metadata |
| **Symmetric key** | không `Authority`, có `IssuerSigningKeys` | dev/test |

Validator startup yêu cầu **`Authority` HOẶC `IssuerSigningKeys`** (khi `ValidateIssuerSigningKey`). `ClockSkew = 0`.
`MaxExpireMinutes > 0` → giới hạn lifetime token theo policy.

## Revoke / blacklist — IJwtTokenAccessChecker

Mặc định `AllowAllJwtTokenAccessChecker` (cho tất cả). Override để chặn token bị thu hồi:

```csharp
auth.AddCoreJwtBearer(builder.Configuration, "Bearer");
```

Checker đăng ký **Singleton**, gọi trong `OnTokenValidated` sau khi chữ ký + lifetime OK.
Tra DB → dùng `IDbContextFactory` / `IServiceScopeFactory` (không inject scoped `DbContext`).

## appsettings.json

```json
{
  "Authentication": {
    "Jwt": {
      "Bearer": {
        "Authority": "",
        "Audience": "",
        "IssuerSigningKeys": [],
        "ValidateAudience": true,
        "ValidateIssuer": false,
        "MaxExpireMinutes": 0
      }
    }
  }
}
```

Signing key / secret — env / secret store, không commit.

## Swagger

[swashbuckle-dotnet/providers/jwt-security](../../../swashbuckle-dotnet/providers/jwt-security/SKILL.md) — `SecuritySchemes: ["JWT"]`.

## Validate

- Endpoint `[Authorize]` → 401 khi thiếu token
- Token symmetric hợp lệ → 200
- (nếu có checker) token bị revoke → 401 dù chữ ký đúng

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [hoangnh2412](https://github.com/hoangnh2412)
- **Source:** [hoangnh2412/ai-skills](https://github.com/hoangnh2412/ai-skills)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-hoangnh2412-ai-skills-jwt
- Seller: https://agentstack.voostack.com/s/hoangnh2412
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
