Checkpoint.AspNet
1.11.8
dotnet add package Checkpoint.AspNet --version 1.11.8
NuGet\Install-Package Checkpoint.AspNet -Version 1.11.8
<PackageReference Include="Checkpoint.AspNet" Version="1.11.8" />
<PackageVersion Include="Checkpoint.AspNet" Version="1.11.8" />
<PackageReference Include="Checkpoint.AspNet" />
paket add Checkpoint.AspNet --version 1.11.8
#r "nuget: Checkpoint.AspNet, 1.11.8"
#:package Checkpoint.AspNet@1.11.8
#addin nuget:?package=Checkpoint.AspNet&version=1.11.8
#tool nuget:?package=Checkpoint.AspNet&version=1.11.8
ASP.NET (System.Web) HTTP module for AI agent detection and policy enforcement. Drop-in IHttpModule that detects AI agents using the same Rust-compiled WASM engine as Checkpoint's Next.js, Express, and .NET Core packages — classic ASP.NET / MVC 5 / Web API 2 / Web Forms consumers get identical detection behavior to modern .NET consumers. Register via Web.config; zero code changes required.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET Framework | net462 is compatible. net463 was computed. net47 was computed. net471 was computed. net472 was computed. net48 was computed. net481 was computed. |
-
.NETFramework 4.6.2
- Checkpoint.Core (>= 1.11.8)
NuGet packages (1)
Showing the top 1 NuGet packages that depend on Checkpoint.AspNet:
| Package | Downloads |
|---|---|
|
KyaOs.Checkpoint
AI agent detection and policy enforcement for any .NET HTTP server. Install this metapackage and NuGet automatically pulls in the right adapter for your runtime: Checkpoint.AspNetCore on modern .NET (ASP.NET Core 6+), or Checkpoint.AspNet on classic .NET Framework 4.6.2+ (System.Web / IIS). Same WASM-backed Rust detection engine on both stacks — same patterns, same scoring, same updates. |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 1.11.8 | 68 | 9/30/2026 |
| 1.11.7 | 1,242 | 9/20/2026 |
| 1.11.6 | 95 | 9/20/2026 |
| 1.11.5 | 113 | 9/19/2026 |
| 1.11.4 | 117 | 9/18/2026 |
| 1.11.3 | 107 | 9/17/2026 |
| 1.11.2 | 115 | 9/16/2026 |
| 1.11.1 | 98 | 9/16/2026 |
| 1.11.0 | 106 | 9/16/2026 |
| 1.10.0 | 106 | 9/15/2026 |
| 1.9.0 | 127 | 9/7/2026 |
| 1.8.1 | 145 | 9/3/2026 |
| 1.7.7 | 183 | 8/10/2026 |
| 1.7.6 | 118 | 8/7/2026 |
| 1.7.5 | 147 | 8/5/2026 |
| 1.7.4 | 145 | 8/4/2026 |
| 1.7.3 | 121 | 8/3/2026 |
| 1.7.2 | 115 | 8/3/2026 |
| 1.7.1 | 116 | 8/3/2026 |
| 1.7.0 | 154 | 7/23/2026 |
1.11.8: live Noisy-Or scoring, opt-in WebMCP read-only mode and dependency refresh
#5235: Includes rebuilt detection WASM artifacts. The Noisy-Or combiner now
scores live with an embedded production-fitted calibration curve, so
DetectionResult.Confidence for a request the engine scores can differ from 1.11.7
for the same input. This SDK exposes no option to pin the combiner mode. Requalify
any policy, alert or dashboard that keys off Confidence thresholds before broader
enablement.
#5097: Adds CheckpointOptions.EdgeTrustPolicy. The default, Direct, leaves the
engine's transport signals null; a host behind a trusted proxy opts in explicitly.
The engine now receives client and transport signals built by the SDK. The
rebuilt WASM artifact also moves the combiner default from Off to Shadow, which
is superseded by #5235 above.
#4999: Adds DetectionResult.RiskScore and RiskScoreSource, the raw uncalibrated
Noisy-Or score, and forwards the engine's shadow_ keys as detection.shadowMetadata
on the log-detection payload. RiskScore is null when the combiner did not run.
#5258: Adds CheckpointOptions.SessionVelocityEscalation (default true) and
CheckpointOptions.ScannerMisclassificationHint (default On). Session velocity
uses a bounded in-process request-volume tracker (5,000 clients, 30-minute window)
keyed per client from the project, remote IP, TLS fingerprint, user agent and
beacon session token, and only runs when the project id and remote IP are
available. With the hint On, a zero-evidence request whose Cloudflare
bot-management evidence contradicts its browser user agent classifies
IncompleteData instead of Human; it never produces a Bot or AiAgent verdict on
its own. Set SessionVelocityEscalation to false to opt out of session velocity
escalation, or ScannerMisclassificationHint to Off to keep zero-evidence requests
classified Human at confidence 10.
#5243: A browser posture token may carry an optional cnf.jkt holder-of-key
binding, verified with the new BrowserPostureProofVerifier (ES256). A token that
carries a malformed cnf claim is rejected. Tokens without cnf verify as before.
#5168: Adds the default-disabled CheckpointOptions.WebMcpReadOnly. Only when it
is enabled and validated does the ASP.NET module serve
/.well-known/checkpoint-webmcp/config and /.well-known/checkpoint-webmcp/readonly.js
from the embedded browser module. Existing routes and policies are unchanged.
#5201 and #5228 revise the wording of that embedded module's tool descriptions
and do not change any server behavior.
#5274: Classic ASP.NET emits startup diagnostics through System.Diagnostics.Trace
that separate startup phases from readiness (see docs/startup-diagnostics.md).
Authorization behavior and timeouts are unchanged.
#5163: Refreshes the OpenAI RFC 9421 signing key used by ChatGptKeyProvider and
ChatGptSignatureVerifier. This does not add signing capabilities for agent
clients and does not establish vendor identity for unsigned callers.
#5177: Runtime dependency updates: Microsoft.Extensions.Logging.Abstractions
8.0.2 to 8.0.3, System.Text.Json 8.0.5 to 8.0.6 and BouncyCastle.Cryptography
2.6.2 to 2.7.0.
#5370: Rebuilt WASM artifacts export engine_render_json and engine_info_json, and
the runtime gained internal entry points for them. Nothing in the SDK calls them
yet, so there is no behavior change.
#5224: Removes comments only. No behavior change.
#5387: Browser posture is also read from the KYA-Posture and KYA-Posture-Session
request headers, which a page on another host, or one that blocks cookies, sends
from the beacon's onReceipt. Each header wins over its cookie; a header sent twice
or comma-joined is trusted by no one. BrowserPostureVerifier.FromRequest,
RequestValue and the PostureHeader/PostureSessionHeader constants are new;
FromCookies and the three-argument BrowserIntegrityPolicy.Observe are unchanged.
Both the ASP.NET Core middleware and the classic ASP.NET module pass the headers.
#5437: Rebuilt WASM artifacts retune user-agent patterns and add a header rule, so
verdicts can differ from 1.11.7 for the same input. A Mozilla/ user agent with no
Accept-Language and no pattern match adds the missing-browser-headers signal, so a
scripted client sending a browser user agent classifies Unknown instead of Human
at confidence 0.10. Model-name substrings (gpt-4, claude-3), Google-Extended and
Comet no longer match, Pinterest, eBay and copilot match more narrowly, and
ExaSearchBot, AI2Bot, Diffbot, KimiBot, Meta-ExternalFetcher, Google-GeminiNotebook,
PetalBot and TikTokSpider are recognized. KnownAgents mirrors the change.
#5436: Rebuilt WASM artifacts weigh a lone confirmed-proxy flag at 0.1 instead of
0.4, so it calibrates to about 2 and crosses 70 only beside independent evidence.
Only requests whose network signals mark the client as a proxy are affected.
#5440: Rebuilt WASM artifacts export applyRuleBundle for signed remote rule
bundles. Nothing in this SDK calls it and the engine trust root ships empty, so
there is no behavior change.
#5487: Rebuilt WASM artifacts carry the refreshed OpenAI RFC 9421 vendor key pin.
No source change in the SDK.
#5503: Rebuilt WASM artifacts recognize the meta-webindexer crawler as a Meta AI
crawler instead of a generic bot.
#5442: Corrects the DetectionResult.RiskScore documentation, which claimed Confidence
stays on the static verdict. Documentation only; no behavior change.
#5410: After a failed HTTP signature, the embedded engine uses the host-resolved
client IP instead of re-reading X-Real-IP or X-Forwarded-For. Both .NET adapters
already provide the resolved client IP; untrusted forwarding headers cannot
replace it on the signature-failure path.
#5539: Rebuilds the embedded WASM on the canonical x86_64 Linux toolchain and
updates its artifact pins. This changes the bundled bytes without an intended
engine-source behavior change.
All four packages advance together. Preserve existing project, issuer, application
authorization and cart configuration. Qualify the deployed site before broader
enablement; Authorization Host runtime updates remain a separate release.
Release history: https://github.com/Know-That-Ai/checkpoint/blob/main/packages/checkpoint-dotnet/CHANGELOG.md