Checkpoint.Core
1.11.9
dotnet add package Checkpoint.Core --version 1.11.9
NuGet\Install-Package Checkpoint.Core -Version 1.11.9
<PackageReference Include="Checkpoint.Core" Version="1.11.9" />
<PackageVersion Include="Checkpoint.Core" Version="1.11.9" />
<PackageReference Include="Checkpoint.Core" />
paket add Checkpoint.Core --version 1.11.9
#r "nuget: Checkpoint.Core, 1.11.9"
#:package Checkpoint.Core@1.11.9
#addin nuget:?package=Checkpoint.Core&version=1.11.9
#tool nuget:?package=Checkpoint.Core&version=1.11.9
Core AI agent detection engine for .NET. Detects AI agents (Claude, ChatGPT, Gemini, etc.) via user-agent patterns, header analysis, and behavioral signals. Platform-agnostic — use with any .NET HTTP server, including ASP.NET Core (via Checkpoint.AspNetCore) and classic .NET Framework 4.6.2+ (via Checkpoint.AspNet).
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net5.0 was computed. net5.0-windows was computed. net6.0 was computed. net6.0-android was computed. net6.0-ios was computed. net6.0-maccatalyst was computed. net6.0-macos was computed. net6.0-tvos was computed. net6.0-windows was computed. net7.0 was computed. net7.0-android was computed. net7.0-ios was computed. net7.0-maccatalyst was computed. net7.0-macos was computed. net7.0-tvos was computed. net7.0-windows was computed. net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
| .NET Core | netcoreapp2.0 was computed. netcoreapp2.1 was computed. netcoreapp2.2 was computed. netcoreapp3.0 was computed. netcoreapp3.1 was computed. |
| .NET Standard | netstandard2.0 is compatible. netstandard2.1 was computed. |
| .NET Framework | net461 was computed. net462 is compatible. net463 was computed. net47 was computed. net471 was computed. net472 was computed. net48 was computed. net481 was computed. |
| MonoAndroid | monoandroid was computed. |
| MonoMac | monomac was computed. |
| MonoTouch | monotouch was computed. |
| Tizen | tizen40 was computed. tizen60 was computed. |
| Xamarin.iOS | xamarinios was computed. |
| Xamarin.Mac | xamarinmac was computed. |
| Xamarin.TVOS | xamarintvos was computed. |
| Xamarin.WatchOS | xamarinwatchos was computed. |
-
.NETStandard 2.0
- BouncyCastle.Cryptography (>= 2.7.0)
- Microsoft.Extensions.Http (>= 8.0.1)
- Microsoft.Extensions.Logging.Abstractions (>= 8.0.3)
- Microsoft.Extensions.Options (>= 8.0.2)
- System.Net.Http.Json (>= 8.0.1)
- System.Text.Json (>= 8.0.6)
-
net10.0
- BouncyCastle.Cryptography (>= 2.7.0)
- Microsoft.Extensions.Http (>= 8.0.1)
- Microsoft.Extensions.Logging.Abstractions (>= 8.0.3)
- Microsoft.Extensions.Options (>= 8.0.2)
- System.Text.Json (>= 8.0.6)
- Wasmtime (>= 44.0.0)
-
net8.0
- BouncyCastle.Cryptography (>= 2.7.0)
- Microsoft.Extensions.Http (>= 8.0.1)
- Microsoft.Extensions.Logging.Abstractions (>= 8.0.3)
- Microsoft.Extensions.Options (>= 8.0.2)
- System.Text.Json (>= 8.0.6)
- Wasmtime (>= 44.0.0)
NuGet packages (2)
Showing the top 2 NuGet packages that depend on Checkpoint.Core:
| Package | Downloads |
|---|---|
|
Checkpoint.AspNetCore
ASP.NET Core middleware for AI agent detection and policy enforcement. Drop-in middleware that detects AI agents, enforces policies from the Checkpoint dashboard, and blocks/redirects automated traffic. The .NET equivalent of @kya-os/checkpoint-express. |
|
|
Checkpoint.AspNet
ASP.NET (System.Web) HTTP module for AI agent detection and policy enforcement. Drop-in IHttpModule that detects AI agents using the same Rust-compiled WASM engine as Checkpoint's Next.js, Express, and .NET Core packages — classic ASP.NET / MVC 5 / Web API 2 / Web Forms consumers get identical detection behavior to modern .NET consumers. Register via Web.config; zero code changes required. |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 1.11.9 | 70 | 10/9/2026 |
| 1.11.8 | 2,057 | 9/30/2026 |
| 1.11.7 | 3,495 | 9/20/2026 |
| 1.11.6 | 191 | 9/20/2026 |
| 1.11.5 | 221 | 9/19/2026 |
| 1.11.4 | 285 | 9/18/2026 |
| 1.11.3 | 192 | 9/17/2026 |
| 1.11.2 | 240 | 9/16/2026 |
| 1.11.1 | 168 | 9/16/2026 |
| 1.11.0 | 229 | 9/16/2026 |
| 1.10.0 | 225 | 9/15/2026 |
| 1.9.0 | 811 | 9/7/2026 |
| 1.8.1 | 520 | 9/3/2026 |
| 1.7.7 | 2,021 | 8/10/2026 |
| 1.7.6 | 308 | 8/7/2026 |
| 1.7.5 | 326 | 8/5/2026 |
| 1.7.4 | 312 | 8/4/2026 |
| 1.7.3 | 252 | 8/3/2026 |
| 1.7.2 | 200 | 8/3/2026 |
| 1.7.1 | 202 | 8/3/2026 |
1.11.9: consent recovery, authorization-host diagnostics and browser-posture enforcement
#5788: Core, AspNetCore and the metapackage add a compiled net10.0 target.
.NET 8 and 9 continue using net8.0; Web Forms keeps net462/netstandard2.0.
The net10.0 startup path no longer modifies the obsolete
ServicePointManager.SecurityProtocol; existing targets retain TLS 1.2 setup.
Core and AspNetCore unit and cross-runtime parity suites run on .NET 8 and 10.
The metapackage description corrects ASP.NET Core support to 8+; .NET 6/7
cannot load its existing net8.0 adapter. Package pruning is disabled so lock
file regeneration retains the existing dependency graph across SDK versions.
#5671: The opt-in WebMCP read-only browser module improves pending, timeout,
retry and restart states and safely renders cart summaries. Consent still requires
a prepared holder key and human approval. The original page must remain open:
its non-extractable private key is document-local and is lost on reload or close.
This release does not add a persistent wallet, purchase tools or universal agent
client support. Authorization Host consent/OAuth recovery is a separate rollout.
#5565: Configured Authorization Host registration failures report a structured,
credential-free consentHandoff outcome. Malformed registration responses, missing proofs or the known SDK placeholder
return retryable 503 kyaos/status-pending instead of a usable consent link. Bare host
configuration is normalized to HTTPS. RegisterAsync remains compatible; new
RegisterWithOutcomeAsync exposes the outcome. The unconfigured static fallback
is unchanged; configure and qualify the actual host before enabling native access.
#5546 and follow-ups: BrowserPostureOptions.Origins accepts additional allowed
page origins with canonical matching and restricted leftmost host wildcards.
Malformed origins, public-suffix wildcards or unusable verifier keys fail startup.
Use the canonical primary origin and the lowercase project UUID. Reports carry
postureOutcome and suppressed posture rejection counts; both adapters expose the
computed outcome to application handlers. Future nbf and malformed claim types
are rejected. Optional detection claims preserve the beacon's signed verdict.
Behavior change: disclosed browser automation can now set IsAgent=true and run
OnAgentDetected when its confidence meets the configured threshold. A signed
ai_agent/bot detection claim can also promote a human/incomplete-data baseline.
Corroborating-only evidence and agent-driven verdicts do not themselves run that
action. Requalify human, browser-agent and automated-test traffic and thresholds.
Optional trusted server network/proxy facts, IsBot, bot subtype/legitimacy and
edge HTTP protocol reach detection, policy and telemetry. Unknown, false and zero
remain distinct; an optional network provider failure omits enrichment.
#5742: ASP.NET Core telemetry moves to a bounded, event-driven in-memory queue
with stable retry event IDs, backpressure/drop accounting, retryable batch holding,
Retry-After handling, rejected-batch bisection and bounded shutdown drain. This is
not durable audit storage. Classic ASP.NET still awaits telemetry on enforcement
paths; the Core performance improvement does not apply to Web Forms. Reports
serialize a verified posture without a score as score:null. With positive policy
TTL and FailOpen=true, both adapters can serve cached policy during background
refresh; failed refresh uses the ten-second negative cache and invalidation
prevents an older refresh extending the cache. There is no maximum stale age.
FailOpen=false retains unavailable-policy denial.
Embedded WASM is refreshed for the OpenAI RFC 9421 vendor key, hardware-gated
Meta Muse detection, headless browser-brand detection and weak HTTP/1.x evidence.
These can change verdicts. Compiled rule-feed exports/trust roots are not used by
the .NET SDK; the 190-day rule-feed signing bound is not a shopper grant lifetime.
#5410 and #5539 already shipped in 1.11.8 (host-resolved IP on signature failure
and reproducible engine artifacts); this release retains those protections.
#5829: Windows qualification installs one retained four-package batch into direct
and metapackage Framework consumers, including legacy packages.config closures,
checks payload/native hashes and runs fresh-process native/Cedar startup. This
is qualification infrastructure, not a guarantee of a merchant's dependency graph.
All four packages advance together. Existing target frameworks and runtime
dependency versions are preserved; net10.0 is added as described above. Preserve merchant authentication, project,
issuer, application authorization, policy and cart integration. Qualify the real
Framework/IIS/dependency installation and matching Authorization Host before
broader enablement. This package cannot grant an agent tool execution permission
or prove external provider identity merely from its holder key.
Release history: https://github.com/Know-That-Ai/checkpoint/blob/main/packages/checkpoint-dotnet/CHANGELOG.md