Checkpoint.AspNetCore
1.11.9
dotnet add package Checkpoint.AspNetCore --version 1.11.9
NuGet\Install-Package Checkpoint.AspNetCore -Version 1.11.9
<PackageReference Include="Checkpoint.AspNetCore" Version="1.11.9" />
<PackageVersion Include="Checkpoint.AspNetCore" Version="1.11.9" />
<PackageReference Include="Checkpoint.AspNetCore" />
paket add Checkpoint.AspNetCore --version 1.11.9
#r "nuget: Checkpoint.AspNetCore, 1.11.9"
#:package Checkpoint.AspNetCore@1.11.9
#addin nuget:?package=Checkpoint.AspNetCore&version=1.11.9
#tool nuget:?package=Checkpoint.AspNetCore&version=1.11.9
ASP.NET Core middleware for AI agent detection and policy enforcement. Drop-in middleware that detects AI agents, enforces policies from the Checkpoint dashboard, and blocks/redirects automated traffic. The .NET equivalent of @kya-os/checkpoint-express.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Checkpoint.Core (>= 1.11.9)
-
net8.0
- Checkpoint.Core (>= 1.11.9)
NuGet packages (1)
Showing the top 1 NuGet packages that depend on Checkpoint.AspNetCore:
| Package | Downloads |
|---|---|
|
KyaOs.Checkpoint
AI agent detection and policy enforcement for any .NET HTTP server. Install this metapackage and NuGet automatically pulls in the right adapter for your runtime: Checkpoint.AspNetCore on modern .NET (ASP.NET Core 8+), or Checkpoint.AspNet on classic .NET Framework 4.6.2+ (System.Web / IIS). Same WASM-backed Rust detection engine on both stacks — same patterns, same scoring, same updates. |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 1.11.9 | 35 | 10/9/2026 |
| 1.11.8 | 153 | 9/30/2026 |
| 1.11.7 | 184 | 9/20/2026 |
| 1.11.6 | 116 | 9/20/2026 |
| 1.11.5 | 126 | 9/19/2026 |
| 1.11.4 | 141 | 9/18/2026 |
| 1.11.3 | 126 | 9/17/2026 |
| 1.11.2 | 131 | 9/16/2026 |
| 1.11.1 | 113 | 9/16/2026 |
| 1.11.0 | 146 | 9/16/2026 |
| 1.10.0 | 133 | 9/15/2026 |
| 1.9.0 | 164 | 9/7/2026 |
| 1.8.1 | 202 | 9/3/2026 |
| 1.7.7 | 218 | 8/10/2026 |
| 1.7.6 | 135 | 8/7/2026 |
| 1.7.5 | 188 | 8/5/2026 |
| 1.7.4 | 167 | 8/4/2026 |
| 1.7.3 | 137 | 8/3/2026 |
| 1.7.2 | 146 | 8/3/2026 |
| 1.7.1 | 148 | 8/3/2026 |
1.11.9: consent recovery, authorization-host diagnostics and browser-posture enforcement
#5788: Core, AspNetCore and the metapackage add a compiled net10.0 target.
.NET 8 and 9 continue using net8.0; Web Forms keeps net462/netstandard2.0.
The net10.0 startup path no longer modifies the obsolete
ServicePointManager.SecurityProtocol; existing targets retain TLS 1.2 setup.
Core and AspNetCore unit and cross-runtime parity suites run on .NET 8 and 10.
The metapackage description corrects ASP.NET Core support to 8+; .NET 6/7
cannot load its existing net8.0 adapter. Package pruning is disabled so lock
file regeneration retains the existing dependency graph across SDK versions.
#5671: The opt-in WebMCP read-only browser module improves pending, timeout,
retry and restart states and safely renders cart summaries. Consent still requires
a prepared holder key and human approval. The original page must remain open:
its non-extractable private key is document-local and is lost on reload or close.
This release does not add a persistent wallet, purchase tools or universal agent
client support. Authorization Host consent/OAuth recovery is a separate rollout.
#5565: Configured Authorization Host registration failures report a structured,
credential-free consentHandoff outcome. Malformed registration responses, missing proofs or the known SDK placeholder
return retryable 503 kyaos/status-pending instead of a usable consent link. Bare host
configuration is normalized to HTTPS. RegisterAsync remains compatible; new
RegisterWithOutcomeAsync exposes the outcome. The unconfigured static fallback
is unchanged; configure and qualify the actual host before enabling native access.
#5546 and follow-ups: BrowserPostureOptions.Origins accepts additional allowed
page origins with canonical matching and restricted leftmost host wildcards.
Malformed origins, public-suffix wildcards or unusable verifier keys fail startup.
Use the canonical primary origin and the lowercase project UUID. Reports carry
postureOutcome and suppressed posture rejection counts; both adapters expose the
computed outcome to application handlers. Future nbf and malformed claim types
are rejected. Optional detection claims preserve the beacon's signed verdict.
Behavior change: disclosed browser automation can now set IsAgent=true and run
OnAgentDetected when its confidence meets the configured threshold. A signed
ai_agent/bot detection claim can also promote a human/incomplete-data baseline.
Corroborating-only evidence and agent-driven verdicts do not themselves run that
action. Requalify human, browser-agent and automated-test traffic and thresholds.
Optional trusted server network/proxy facts, IsBot, bot subtype/legitimacy and
edge HTTP protocol reach detection, policy and telemetry. Unknown, false and zero
remain distinct; an optional network provider failure omits enrichment.
#5742: ASP.NET Core telemetry moves to a bounded, event-driven in-memory queue
with stable retry event IDs, backpressure/drop accounting, retryable batch holding,
Retry-After handling, rejected-batch bisection and bounded shutdown drain. This is
not durable audit storage. Classic ASP.NET still awaits telemetry on enforcement
paths; the Core performance improvement does not apply to Web Forms. Reports
serialize a verified posture without a score as score:null. With positive policy
TTL and FailOpen=true, both adapters can serve cached policy during background
refresh; failed refresh uses the ten-second negative cache and invalidation
prevents an older refresh extending the cache. There is no maximum stale age.
FailOpen=false retains unavailable-policy denial.
Embedded WASM is refreshed for the OpenAI RFC 9421 vendor key, hardware-gated
Meta Muse detection, headless browser-brand detection and weak HTTP/1.x evidence.
These can change verdicts. Compiled rule-feed exports/trust roots are not used by
the .NET SDK; the 190-day rule-feed signing bound is not a shopper grant lifetime.
#5410 and #5539 already shipped in 1.11.8 (host-resolved IP on signature failure
and reproducible engine artifacts); this release retains those protections.
#5829: Windows qualification installs one retained four-package batch into direct
and metapackage Framework consumers, including legacy packages.config closures,
checks payload/native hashes and runs fresh-process native/Cedar startup. This
is qualification infrastructure, not a guarantee of a merchant's dependency graph.
All four packages advance together. Existing target frameworks and runtime
dependency versions are preserved; net10.0 is added as described above. Preserve merchant authentication, project,
issuer, application authorization, policy and cart integration. Qualify the real
Framework/IIS/dependency installation and matching Authorization Host before
broader enablement. This package cannot grant an agent tool execution permission
or prove external provider identity merely from its holder key.
Release history: https://github.com/Know-That-Ai/checkpoint/blob/main/packages/checkpoint-dotnet/CHANGELOG.md