Regira Security provides encryption, password hashing, JWT authentication, and API Key authentication for .NET applications.
| Project | Package | Purpose |
|---|---|---|
Common.Security |
Regira.Security |
Symmetric encryption and PBKDF2 hashing |
Security.Hashing.BCryptNet |
Regira.Security.Hashing.BCryptNet |
BCrypt password hashing |
Security.Authentication |
Regira.Security.Authentication |
JWT tokens and API Key auth |
Security.Authentication.Web |
Regira.Security.Authentication.Web |
Pre-built auth controllers |
<!-- Core encryption + hashing -->
<PackageReference Include="Regira.Security" Version="6.*" />
<!-- BCrypt password hashing -->
<PackageReference Include="Regira.Security.Hashing.BCryptNet" Version="6.*" />
<!-- JWT + API Key auth -->
<PackageReference Include="Regira.Security.Authentication" Version="6.*" />
<!-- Pre-built Identity controllers -->
<PackageReference Include="Regira.Security.Authentication.Web" Version="6.*" />
| You need | Use | Reference |
|---|---|---|
| Sign in users this application owns | Self-issued JWT + refresh tokens | JWT Authentication |
| Authenticate a machine caller | API key | API Key Authentication |
| Accept tokens from Entra ID or another IdP | External bearer validation | External Identity Providers |
| Redirect users to an IdP to sign in | OpenID Connect | External Identity Providers |
| Server-rendered app or same-site SPA | Cookie sessions | Cookie Authentication |
| More than one of the above in one app | Scheme composition | Composing Multiple Schemes |
| Account / password / user endpoints without writing them | Regira.Security.Authentication.Web |
Pre-built Auth Controllers |
Encryption and password hashing stand apart from the schemes above and are covered in
Encryption & Hashing. Regira.Security.Hashing.BCryptNet is the
recommended password hasher.
Apache License 2.0 — this package contains no license validation and no runtime limits. See LICENSE. A few companion packages are commercially licensed with a free tier; see the licensing overview.