Checkpoint.AspNetCore 1.11.9

dotnet add package Checkpoint.AspNetCore --version 1.11.9
                    
NuGet\Install-Package Checkpoint.AspNetCore -Version 1.11.9
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Checkpoint.AspNetCore" Version="1.11.9" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Checkpoint.AspNetCore" Version="1.11.9" />
                    
Directory.Packages.props
<PackageReference Include="Checkpoint.AspNetCore" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Checkpoint.AspNetCore --version 1.11.9
                    
#r "nuget: Checkpoint.AspNetCore, 1.11.9"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Checkpoint.AspNetCore@1.11.9
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Checkpoint.AspNetCore&version=1.11.9
                    
Install as a Cake Addin
#tool nuget:?package=Checkpoint.AspNetCore&version=1.11.9
                    
Install as a Cake Tool

ASP.NET Core middleware for AI agent detection and policy enforcement. Drop-in middleware that detects AI agents, enforces policies from the Checkpoint dashboard, and blocks/redirects automated traffic. The .NET equivalent of @kya-os/checkpoint-express.

Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages (1)

Showing the top 1 NuGet packages that depend on Checkpoint.AspNetCore:

Package Downloads
KyaOs.Checkpoint

AI agent detection and policy enforcement for any .NET HTTP server. Install this metapackage and NuGet automatically pulls in the right adapter for your runtime: Checkpoint.AspNetCore on modern .NET (ASP.NET Core 8+), or Checkpoint.AspNet on classic .NET Framework 4.6.2+ (System.Web / IIS). Same WASM-backed Rust detection engine on both stacks — same patterns, same scoring, same updates.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.11.9 35 10/9/2026
1.11.8 153 9/30/2026
1.11.7 184 9/20/2026
1.11.6 116 9/20/2026
1.11.5 126 9/19/2026
1.11.4 141 9/18/2026
1.11.3 126 9/17/2026
1.11.2 131 9/16/2026
1.11.1 113 9/16/2026
1.11.0 146 9/16/2026
1.10.0 133 9/15/2026
1.9.0 164 9/7/2026
1.8.1 202 9/3/2026
1.7.7 218 8/10/2026
1.7.6 135 8/7/2026
1.7.5 188 8/5/2026
1.7.4 167 8/4/2026
1.7.3 137 8/3/2026
1.7.2 146 8/3/2026
1.7.1 148 8/3/2026
Loading failed

1.11.9: consent recovery, authorization-host diagnostics and browser-posture enforcement

#5788: Core, AspNetCore and the metapackage add a compiled net10.0 target.
.NET 8 and 9 continue using net8.0; Web Forms keeps net462/netstandard2.0.
The net10.0 startup path no longer modifies the obsolete
ServicePointManager.SecurityProtocol; existing targets retain TLS 1.2 setup.
Core and AspNetCore unit and cross-runtime parity suites run on .NET 8 and 10.
The metapackage description corrects ASP.NET Core support to 8+; .NET 6/7
cannot load its existing net8.0 adapter. Package pruning is disabled so lock
file regeneration retains the existing dependency graph across SDK versions.

#5671: The opt-in WebMCP read-only browser module improves pending, timeout,
retry and restart states and safely renders cart summaries. Consent still requires
a prepared holder key and human approval. The original page must remain open:
its non-extractable private key is document-local and is lost on reload or close.
This release does not add a persistent wallet, purchase tools or universal agent
client support. Authorization Host consent/OAuth recovery is a separate rollout.

#5565: Configured Authorization Host registration failures report a structured,
credential-free consentHandoff outcome. Malformed registration responses, missing proofs or the known SDK placeholder
return retryable 503 kyaos/status-pending instead of a usable consent link. Bare host
configuration is normalized to HTTPS. RegisterAsync remains compatible; new
RegisterWithOutcomeAsync exposes the outcome. The unconfigured static fallback
is unchanged; configure and qualify the actual host before enabling native access.

#5546 and follow-ups: BrowserPostureOptions.Origins accepts additional allowed
page origins with canonical matching and restricted leftmost host wildcards.
Malformed origins, public-suffix wildcards or unusable verifier keys fail startup.
Use the canonical primary origin and the lowercase project UUID. Reports carry
postureOutcome and suppressed posture rejection counts; both adapters expose the
computed outcome to application handlers. Future nbf and malformed claim types
are rejected. Optional detection claims preserve the beacon's signed verdict.

Behavior change: disclosed browser automation can now set IsAgent=true and run
OnAgentDetected when its confidence meets the configured threshold. A signed
ai_agent/bot detection claim can also promote a human/incomplete-data baseline.
Corroborating-only evidence and agent-driven verdicts do not themselves run that
action. Requalify human, browser-agent and automated-test traffic and thresholds.
Optional trusted server network/proxy facts, IsBot, bot subtype/legitimacy and
edge HTTP protocol reach detection, policy and telemetry. Unknown, false and zero
remain distinct; an optional network provider failure omits enrichment.

#5742: ASP.NET Core telemetry moves to a bounded, event-driven in-memory queue
with stable retry event IDs, backpressure/drop accounting, retryable batch holding,
Retry-After handling, rejected-batch bisection and bounded shutdown drain. This is
not durable audit storage. Classic ASP.NET still awaits telemetry on enforcement
paths; the Core performance improvement does not apply to Web Forms. Reports
serialize a verified posture without a score as score:null. With positive policy
TTL and FailOpen=true, both adapters can serve cached policy during background
refresh; failed refresh uses the ten-second negative cache and invalidation
prevents an older refresh extending the cache. There is no maximum stale age.
FailOpen=false retains unavailable-policy denial.

Embedded WASM is refreshed for the OpenAI RFC 9421 vendor key, hardware-gated
Meta Muse detection, headless browser-brand detection and weak HTTP/1.x evidence.
These can change verdicts. Compiled rule-feed exports/trust roots are not used by
the .NET SDK; the 190-day rule-feed signing bound is not a shopper grant lifetime.
#5410 and #5539 already shipped in 1.11.8 (host-resolved IP on signature failure
and reproducible engine artifacts); this release retains those protections.

#5829: Windows qualification installs one retained four-package batch into direct
and metapackage Framework consumers, including legacy packages.config closures,
checks payload/native hashes and runs fresh-process native/Cedar startup. This
is qualification infrastructure, not a guarantee of a merchant's dependency graph.

All four packages advance together. Existing target frameworks and runtime
dependency versions are preserved; net10.0 is added as described above. Preserve merchant authentication, project,
issuer, application authorization, policy and cart integration. Qualify the real
Framework/IIS/dependency installation and matching Authorization Host before
broader enablement. This package cannot grant an agent tool execution permission
or prove external provider identity merely from its holder key.

Release history: https://github.com/Know-That-Ai/checkpoint/blob/main/packages/checkpoint-dotnet/CHANGELOG.md