Regira-Packages

Regira Security

Regira Security provides encryption, password hashing, JWT authentication, and API Key authentication for .NET applications.

Projects

Project Package Purpose
Common.Security Regira.Security Symmetric encryption and PBKDF2 hashing
Security.Hashing.BCryptNet Regira.Security.Hashing.BCryptNet BCrypt password hashing
Security.Authentication Regira.Security.Authentication JWT tokens and API Key auth
Security.Authentication.Web Regira.Security.Authentication.Web Pre-built auth controllers

Installation

<!-- Core encryption + hashing -->
<PackageReference Include="Regira.Security" Version="6.*" />

<!-- BCrypt password hashing -->
<PackageReference Include="Regira.Security.Hashing.BCryptNet" Version="6.*" />

<!-- JWT + API Key auth -->
<PackageReference Include="Regira.Security.Authentication" Version="6.*" />

<!-- Pre-built Identity controllers -->
<PackageReference Include="Regira.Security.Authentication.Web" Version="6.*" />

Choosing an authentication scheme

You need Use Reference
Sign in users this application owns Self-issued JWT + refresh tokens JWT Authentication
Authenticate a machine caller API key API Key Authentication
Accept tokens from Entra ID or another IdP External bearer validation External Identity Providers
Redirect users to an IdP to sign in OpenID Connect External Identity Providers
Server-rendered app or same-site SPA Cookie sessions Cookie Authentication
More than one of the above in one app Scheme composition Composing Multiple Schemes
Account / password / user endpoints without writing them Regira.Security.Authentication.Web Pre-built Auth Controllers

Encryption and password hashing stand apart from the schemes above and are covered in Encryption & Hashing. Regira.Security.Hashing.BCryptNet is the recommended password hasher.


Overview

  1. Index — Overview, projects, and choosing a scheme
  2. Encryption & Hashing — Symmetric encryption, PBKDF2 and BCrypt password hashing
  3. JWT Authentication — Self-issued bearer tokens, claims, and refresh tokens
  4. API Key Authentication — Key-based auth for machine callers
  5. External Identity Providers — Validating external bearer tokens; OpenID Connect sign-in
  6. Cookie Authentication — Cookie-backed sessions
  7. Composing Multiple Schemes — Running several schemes side by side
  8. Pre-built Auth Controllers — Account, password and user endpoints
  9. Practical Examples — Complete implementation examples

License

Apache License 2.0 — this package contains no license validation and no runtime limits. See LICENSE. A few companion packages are commercially licensed with a free tier; see the licensing overview.