sd-jwt-dotnet

agent
Guvenlik Denetimi
Basarisiz
Health Uyari
  • License — License: Apache-2.0
  • Description — Repository has a description
  • Active repo — Last push 0 days ago
  • Low visibility — Only 5 GitHub stars
Code Basarisiz
  • rm -rf — Recursive force deletion command in .github/workflows/ci-validation.yml
Permissions Gecti
  • Permissions — No dangerous permissions requested

Bu listing icin henuz AI raporu yok.

SUMMARY

Selective Disclosure for JWTs (SD-JWT) .Net implement

README.md

SD-JWT .NET Ecosystem

SD-JWT .NET Logo

NuGet Version
CI
License

Standards-first .NET infrastructure for Selective Disclosure JSON Web Tokens (SD-JWTs), verifiable credentials, wallet interoperability, and delegated agent trust.

This project provides reusable building blocks for issuers, verifiers, wallet frameworks, enterprise APIs, and agentic systems. It is not a standalone consumer wallet. Instead, it provides the protocol, cryptographic, policy, and reference infrastructure that digital identity and trust systems can build on.

For package maturity classifications, see MATURITY.md. See also What SD-JWT .NET Is - and Is Not and Standards and Maturity Status.

What This Project Is

  • A standards-first .NET implementation of SD-JWT and related credential protocols.
  • A reusable library ecosystem for issuers, verifiers, wallet frameworks, and enterprise APIs.
  • A reference infrastructure layer for wallet and EUDIW-style interoperability.
  • A preview experimentation space for Agent Trust and delegated tool-call governance.

What This Project Is Not

  • Not a standalone consumer wallet application.
  • Not an identity provider.
  • Not a certification authority.
  • Not a finished standard for AI-agent authorization.

Choose Your Path

I need core SD-JWT

Use SdJwt.Net for RFC 9901 issuance, disclosure, presentation, key binding, and verification.

I am building issuers, verifiers, or wallet infrastructure

Use SdJwt.Net.Vc, SdJwt.Net.Oid4Vci, SdJwt.Net.Oid4Vp, SdJwt.Net.Mdoc, SdJwt.Net.HAIP, and related packages.

I am securing AI agents or enterprise tool calls

Use the preview SdJwt.Net.AgentTrust.* packages for scoped capability tokens, policy enforcement, MCP/API governance, telemetry, and delegation chains.

Quick Start

# Core SD-JWT functionality
dotnet add package SdJwt.Net

# Verifiable Credentials
dotnet add package SdJwt.Net.Vc

# Try the samples
git clone https://github.com/openwallet-foundation-labs/sd-jwt-dotnet.git
cd sd-jwt-dotnet/samples/SdJwt.Net.Samples
dotnet run

Package Ecosystem

Maturity Legend

Status Meaning
Stable Suitable for production use, subject to semantic versioning.
Spec-Tracking Tracks an active draft or evolving specification. APIs may change as the specification changes.
Profile Implements or supports a constrained profile over one or more base specifications.
Reference Reference infrastructure or integration pattern, not a standalone product.
Preview Experimental or early-access package. APIs and claims may change.

Core

Package Release Specification Status
SdJwt.Net NuGet (MinVer) RFC 9901 Stable

Credential Formats, Status & Assurance Profiles

Package Release Specification Status
SdJwt.Net.Vc NuGet (MinVer) draft-ietf-oauth-sd-jwt-vc-16 Spec-Tracking
SdJwt.Net.StatusList NuGet (MinVer) draft-ietf-oauth-status-list-20 Spec-Tracking
SdJwt.Net.VcDm NuGet (MinVer) W3C VCDM 2.0 Stable
SdJwt.Net.HAIP NuGet (MinVer) HAIP 1.0 Profile

OpenID Identity Protocols

Package Release Specification Status
SdJwt.Net.Oid4Vci NuGet (MinVer) OpenID4VCI 1.0 Stable
SdJwt.Net.Oid4Vp NuGet (MinVer) OpenID4VP 1.0 Stable
SdJwt.Net.SiopV2 NuGet (MinVer) SIOPv2 draft-13 Spec-Tracking

Protocol & Interoperability

Package Release Specification Status
SdJwt.Net.OidFederation NuGet (MinVer) OpenID Federation 1.0 Stable
SdJwt.Net.PresentationExchange NuGet (MinVer) DIF PEX v2.1.1 Stable

ISO Credential Formats

Package Release Specification Status
SdJwt.Net.Mdoc NuGet (MinVer) ISO 18013-5 mDL Stable

Reference Infrastructure

Package Release Purpose Status
SdJwt.Net.Wallet NuGet (MinVer) Holder-side reference infrastructure for credential storage, key abstraction, format plugins, and issuance/presentation orchestration Reference
SdJwt.Net.Eudiw NuGet (MinVer) EUDIW / ARF reference helpers for PID-style credentials, trust metadata, relying-party models, and regional validation patterns Reference

Reference packages are intended for samples, interoperability testing, architecture guidance, and framework builders. They are not standalone wallet products or compliance-certified implementations.

Agent Trust Kits

Preview implementations of emerging patterns for Agent Trust and bounded delegation. They are designed for early adopters and researchers exploring scoped SD-JWT capability tokens, key binding, selective disclosure, policy, telemetry, and enterprise tool-call governance.

Package Release Specification / Design Source Status
SdJwt.Net.AgentTrust.Core NuGet (MinVer) Capability SD-JWT profile (project proposal) Preview
SdJwt.Net.AgentTrust.Policy NuGet (MinVer) Rule-based policy and delegation model Preview
SdJwt.Net.AgentTrust.AspNetCore NuGet (MinVer) ASP.NET Core middleware integration Preview
SdJwt.Net.AgentTrust.Maf NuGet (MinVer) MAF/MCP middleware and adapter integration Preview
SdJwt.Net.AgentTrust.OpenTelemetry NuGet (MinVer) Agent trust metrics and telemetry Preview
SdJwt.Net.AgentTrust.Policy.Opa NuGet (MinVer) OPA external policy engine integration Preview
SdJwt.Net.AgentTrust.Mcp NuGet (MinVer) MCP trust interceptor and guard Preview
SdJwt.Net.AgentTrust.A2A NuGet (MinVer) Agent-to-agent delegation chains Preview

Key Features

Enterprise Security

  • RFC 9901 Implementation: Implements SD-JWT issuance, disclosure, presentation, key binding, and verification flows.
  • HAIP Profile Support: Provides helpers and validation patterns for high-assurance SD-JWT VC deployments.
  • Algorithm Enforcement: Blocks weak algorithms (MD5, SHA-1), enforces SHA-2 family
  • Defensive Verification: Includes validation for weak algorithms, replay-sensitive inputs, signature integrity, key binding, and verifier-side checks.
  • Secretless Deployment Patterns: Documentation covers integration with Azure Key Vault, managed identity, workload identity, and HSM-backed key custody.
  • Verify-First Design: All tokens and claims are cryptographically verified before use

High Performance

  • Multi-Target: .NET 8, .NET 9, .NET 10, and .NET Standard 2.1 where package dependencies allow
  • Platform-Aware Crypto: Uses SHA256.HashData() on .NET 6+ where available
  • Batch Throughput: Designed for high-volume issuance and verification
  • Low Allocation: Reduced allocations for high-volume scenarios

Standards-Aligned

  • IETF Standards and Drafts: RFC 9901, SD-JWT VC draft-16, and Token Status List draft-20
  • OpenID Foundation: OpenID4VCI, OpenID4VP, Federation, HAIP
  • W3C: Verifiable Credentials data model compatibility
  • DIF: Presentation Exchange v2.1.1
  • ISO: ISO 18013-5 mdoc support

Developer Experience

  • Samples: Console tutorials organized by skill level and use case
  • Fluent APIs: Chainable builder interfaces
  • Documentation: Guides, deep dives, and security reference
  • Tested: 2,500+ xUnit tests across the implemented packages

Ecosystem Architecture

The SD-JWT .NET Ecosystem can be understood as five adoption layers. For the detailed package dependency model, see Ecosystem Architecture.

Ecosystem Architecture

See MATURITY.md for the maturity classification of each package.

Reference Patterns

Reference pattern documentation lives under docs/reference-patterns. The repository also includes runnable console examples under samples/SdJwt.Net.Samples.

Architecture Overview

Architecture Overview

Quick Examples

Basic SD-JWT

using SdJwt.Net.Issuer;

// Create issuer
var issuer = new SdIssuer(signingKey, SecurityAlgorithms.EcdsaSha256);

// Issue with selective disclosure
var credential = issuer.Issue(claims, new SdIssuanceOptions
{
    DisclosureStructure = new { email = true, address = new { city = true } }
});

// Holder creates presentation
var holder = new SdJwtHolder(credential.Issuance);
var presentation = holder.CreatePresentation(
    disclosure => disclosure.ClaimName == "email");

HAIP-Oriented Verifiable Credentials

using SdJwt.Net.Vc.Issuer;
using SdJwt.Net.HAIP;

// High-assurance issuer policy check
var haipValidator = new HaipCryptoValidator(HaipLevel.Level3_Sovereign, logger);
var keyValidation = haipValidator.ValidateKeyCompliance(signingKey, "ES512");

if (keyValidation.IsCompliant)
{
    var vcIssuer = new SdJwtVcIssuer(issuerKey, algorithm);
    var credential = vcIssuer.Issue("https://gov.example/national-id", vcPayload, options);
}

Status Management

using SdJwt.Net.StatusList.Issuer;

// Create status list
var statusManager = new StatusListManager(statusKey, algorithm);
var statusValues = new byte[] { 0, 1, 2 }; // valid, invalid, suspended
var statusList = await statusManager.CreateStatusListTokenAsync(
    statusListUrl, statusValues, bits: 2);

// Check credential status
var statusVerifier = new StatusListVerifier(httpClient);
var statusResult = await statusVerifier.CheckStatusAsync(statusClaim, keyResolver);
var isValid = statusResult.IsValid;

Preview Agent Trust

var minted = await adapter.MintForToolCallAsync(
    toolName: "ledger",
    arguments: new Dictionary<string, object> { ["action"] = "Read" },
    context: new CapabilityContext
    {
        CorrelationId = Guid.NewGuid().ToString("N"),
        WorkflowId = "wf-ledger-sync"
    });

request.Headers.Authorization = $"SdJwt {minted.Token}";

Security, Platform, and Performance

  • Security Model - Cryptographic controls, defensive verification, HAIP profile guidance, privacy, and deployment considerations
  • Platform Support - Target frameworks, supported platforms, and BenchmarkDotNet performance harness
  • Package Maturity - Stable, Spec-Tracking, Profile, Reference, and Preview classifications

Documentation

Getting Started

Standards Implementation

Advanced Features

Enterprise Planning

Installation

Core Package

dotnet add package SdJwt.Net

Install by Capability

# Core SD-JWT
dotnet add package SdJwt.Net

# Verifiable credentials
dotnet add package SdJwt.Net.Vc
dotnet add package SdJwt.Net.VcDm
dotnet add package SdJwt.Net.StatusList

# OpenID4VC protocols
dotnet add package SdJwt.Net.Oid4Vci
dotnet add package SdJwt.Net.Oid4Vp
dotnet add package SdJwt.Net.SiopV2

# Advanced features
dotnet add package SdJwt.Net.OidFederation
dotnet add package SdJwt.Net.PresentationExchange
dotnet add package SdJwt.Net.HAIP

# ISO credential formats
dotnet add package SdJwt.Net.Mdoc

# Preview: Agent Trust
dotnet add package SdJwt.Net.AgentTrust.Core
dotnet add package SdJwt.Net.AgentTrust.Policy
dotnet add package SdJwt.Net.AgentTrust.AspNetCore
dotnet add package SdJwt.Net.AgentTrust.Maf
dotnet add package SdJwt.Net.AgentTrust.OpenTelemetry
dotnet add package SdJwt.Net.AgentTrust.Policy.Opa
dotnet add package SdJwt.Net.AgentTrust.Mcp
dotnet add package SdJwt.Net.AgentTrust.A2A

# Wallet infrastructure
dotnet add package SdJwt.Net.Wallet
dotnet add package SdJwt.Net.Eudiw

Try the Examples

git clone https://github.com/openwallet-foundation-labs/sd-jwt-dotnet.git
cd sd-jwt-dotnet/samples/SdJwt.Net.Samples
dotnet run

Contributing

We welcome contributions! Please see the CONTRIBUTING.md file for detailed guidelines and instructions.

Community & Support

Getting Help

Community

  • Open Wallet Foundation: Part of the OpenWallet Foundation ecosystem
  • Standards Alignment: Tracks and implements specifications from IETF OAuth WG, OpenID Foundation, DIF, W3C, ISO, and OWF ecosystems.

License

Licensed under the Apache License 2.0 - see the LICENSE file for details.

This permissive license allows commercial use, modification, distribution, and private use while providing license and copyright notice requirements.

Acknowledgments

This project builds on work from the identity standards community:

Special Thanks

  • All specification editors and contributors
  • Early adopters and feedback providers
  • Security researchers and auditors
  • The broader .NET and identity communities

Yorumlar (0)

Sonuc bulunamadi