ToolUp.AuthProviders.Oidc.Client 0.25.1

Prefix Reserved
dotnet add package ToolUp.AuthProviders.Oidc.Client --version 0.25.1
                    
NuGet\Install-Package ToolUp.AuthProviders.Oidc.Client -Version 0.25.1
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="ToolUp.AuthProviders.Oidc.Client" Version="0.25.1" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="ToolUp.AuthProviders.Oidc.Client" Version="0.25.1" />
                    
Directory.Packages.props
<PackageReference Include="ToolUp.AuthProviders.Oidc.Client" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add ToolUp.AuthProviders.Oidc.Client --version 0.25.1
                    
#r "nuget: ToolUp.AuthProviders.Oidc.Client, 0.25.1"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package ToolUp.AuthProviders.Oidc.Client@0.25.1
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=ToolUp.AuthProviders.Oidc.Client&version=0.25.1
                    
Install as a Cake Addin
#tool nuget:?package=ToolUp.AuthProviders.Oidc.Client&version=0.25.1
                    
Install as a Cake Tool

ToolUp.AuthProviders.Oidc.Client

Client-side OIDC sign-in UI for ToolUp.Platform. Implements the OAuth 2.0 Authorization Code flow with PKCE against any OIDC-compliant issuer. Registers via the AuthUIProvider delegate registry; deployments select it through ClientConfig.AuthUI.

Automatic pre-expiry token refresh

A signed-in shell renews its own bearer, with nothing to wire. OidcAuthUI.OidcShell arms one browser timer at sign-in (and on mount over a restored session), refreshes at exp − 60 s, re-arms against the new expiry, and cancels on unmount.

It is on by default, and that is a decision rather than an oversight. An authenticated shell that quietly lets its bearer lapse and then fails the next API call is the worse default; long-lived sessions are the norm with offline / PWA support and co-editing. The expiry is read from the bearer the session is actually sending — the id_token under IdTokenBearer, the access token under AccessTokenBearer — so the bearer strategy and the timer agree by construction. A bearer whose exp cannot be read (an opaque access token, an encrypted-payload JWT) falls back to a fixed 300 s cadence.

Three behaviours cover ways a session used to die quietly:

  • A woken background tab catches up. Browsers throttle timers in background tabs, so a tab parked for an hour wakes with a timer that has not fired and a bearer that has already expired. The shell listens for visibilitychange and online while a timer is armed and refreshes at once when the session is inside its margin. A wake that is not inside the margin deliberately leaves the armed timer alone — a re-arm on every tab-focus would push an opaque-token refresh out indefinitely.
  • Offline, no request is made. A refresh with no link cannot succeed, and the failure it would produce is indistinguishable from an issuer refusing the grant. The timer re-checks in 30 s; a reconnect triggers an immediate check.
  • A transport failure is a retry, not a sign-out. The grant is intact, so the session survives an outage of any length. Any other failure means the issuer answered and refused, and the shell drops to sign-in with no half-authenticated state.

Concurrent triggers coalesce to a single refresh_token request — which matters against issuers that rotate refresh tokens, where a second concurrent POST presents a token the first has already consumed.

All of it is policy, adjustable on OidcAppConfig.RefreshPolicy; None (the default everywhere) reproduces the above byte for byte (GP 11):

// Slow or rate-limited token endpoint — start the refresh earlier.
OidcPresets.entraExternalId tenant clientId redirectUri
|> OidcPresets.withRefreshMargin 120.0

// Opaque-token provider with a short lifetime — the fallback cadence
// is the only lifetime the client can know about.
OidcPresets.google clientId redirectUri
|> OidcPresets.withRefreshFallback 600.0

// A host app renewing the bearer itself.
OidcPresets.generic issuer clientId redirectUri
|> OidcPresets.withoutAutoRefresh
Knob Default What it is for
Enabled on The deliberate opt-out.
SafetyMarginSeconds 60.0 Seconds ahead of exp; the refresh must complete before it.
FallbackSeconds 300.0 Cadence when the bearer carries no readable exp.
RefreshOnWake on The visibilitychange / online catch-up.

withRefreshPolicy sets all four at once; withoutRefreshOnWake disables just the catch-up. A non-positive or non-finite value falls back to the default rather than being honoured — a nan margin would arm a timer that never fires. The 5 s floor on a computed delay is a safety invariant, not a knob.

Consumers driving renewal manually call OidcClient.refreshAccessToken directly; that entry point is unchanged and is what the timer calls.

Licensed under Apache-2.0.

Part of the ToolUp Platform SDK — see github.com/ToolUp-Forge/toolup-forge for full documentation.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages (2)

Showing the top 2 NuGet packages that depend on ToolUp.AuthProviders.Oidc.Client:

Package Downloads
ToolUp.AuthProviders.EntraExternalId.Client

Client-side Microsoft Entra External ID sign-in UI for ToolUp.Platform: wraps ToolUp.AuthProviders.Oidc.Client with Entra-aware scope defaults, tenant-aware issuer construction, and sign-up / sign-in user-flow policy routing.

ToolUp.AuthProviders.GoogleIdentity.Client

Client-side Google Identity Services sign-in UI for ToolUp.Platform: idempotent GIS library bootstrap, Google's rendered branded button, opt-in One Tap prompt, and a credential bridge that admits the returned id_token to the same OIDC token store the redirect flow writes.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
0.25.1 0 10/9/2026
0.24.1 101 10/6/2026
0.23.0 106 9/23/2026
0.22.0 123 8/27/2026
0.21.0 122 8/26/2026
0.20.1 158 8/20/2026
0.20.0 139 8/19/2026