Skip to content

ValidationParameters Class

Defines parameters used during the validation of a JSON Web Token (JWT).

C#
public record ValidationParameters : System.IEquatable<Abblix.Jwt.ValidationParameters>

Inheritance System.Object → ValidationParameters

Implements System.IEquatable<ValidationParameters>

Properties

ValidationParameters.AllowedSigningAlgorithms Property

JWS signing algorithms (per RFC 7518) that the validator MUST accept; any other alg in the JOSE header causes rejection. When null or empty the check is skipped - the validator only enforces the basic RequireSignedTokens rule (which forbids none) and lets any registered signer match.

C#
public System.Collections.Generic.IReadOnlySet<string>? AllowedSigningAlgorithms { get; init; }

Property Value

System.Collections.Generic.IReadOnlySet<System.String>

Remarks

Use this to express policy beyond "signed-or-not" without writing per-algorithm matchers in callers: pass the asymmetric-only set to enforce DPoP RFC 9449 section 4.2, pass {RS256, ES256} to require small-footprint algorithms only, and so on. Comparison is byte-exact per RFC 7515 section 5.3.

ValidationParameters.ClockSkew Property

How far this token's timestamps may sit either side of this clock and still be honoured. None unless the caller says otherwise.

C#
public Abblix.Jwt.ClockSkew ClockSkew { get; set; }

Property Value

ClockSkew

ValidationParameters.ExpectedTokenTypes Property

Token-type values (per RFC 7515 section 4.1.9 typ header) that the JWT MUST match. When non-null and non-empty the validator pins typ per RFC 8725 section 3.11 to prevent token-type confusion: a JWS signed for one type (id_token, logout_token, request_object, DPoP proof, JARM response, OAuth access_token) cannot be replayed as another by relying parties that trust the same issuer for several classes.

C#
public System.Collections.Generic.IReadOnlySet<string>? ExpectedTokenTypes { get; init; }

Property Value

System.Collections.Generic.IReadOnlySet<System.String>

Remarks

Matching is case-insensitive and accepts either spelling of the application/ prefix on either side, so at+jwt and application/AT+JWT name the same class. A typ is a media type, and RFC 7515 section 4.1.9 adopts RFC 2045 section 5.1 for it: "Matching of media type and subtype is ALWAYS case-insensitive". The general string-comparison rules of RFC 7515 section 5.3 do not govern this parameter; that section ends by exempting it by name. The comparer carried by the set is NOT what produces this behaviour and is not consulted for matching - the validator compares explicitly, so that its rules cannot be widened or narrowed by how a host happened to construct the collection. Supply any comparer, or none. When this property is null or empty the validator skips the check, preserving historical behaviour for callers that have not opted in.

ValidationParameters.Options Property

Options that control various aspects of JWT validation.

C#
public Abblix.Jwt.ValidationOptions Options { get; init; }

Property Value

ValidationOptions

ValidationParameters.ResolveIssuerSigningKeys Property

Delegate that resolves the signing keys for a given issuer, used during token signature validation.

C#
public Abblix.Jwt.ValidationParameters.ResolveIssuerSigningKeysDelegate? ResolveIssuerSigningKeys { get; set; }

Property Value

ResolveIssuerSigningKeysDelegate(string)

ValidationParameters.ResolveTokenDecryptionKeys Property

Delegate that resolves decryption keys for a given issuer, used during token decryption.

C#
public Abblix.Jwt.ValidationParameters.ResolveTokenDecryptionKeysDelegate? ResolveTokenDecryptionKeys { get; set; }

Property Value

ResolveTokenDecryptionKeysDelegate(string)

ValidationParameters.ValidateAudience Property

Delegate used to validate one or more token audiences.

C#
public Abblix.Jwt.ValidationParameters.ValidateAudienceDelegate? ValidateAudience { get; set; }

Property Value

ValidateAudienceDelegate(IEnumerable<string>)

ValidationParameters.ValidateIssuer Property

Delegate used to verify the validity of a token issuer.

C#
public Abblix.Jwt.ValidationParameters.ValidateIssuersDelegate? ValidateIssuer { get; set; }

Property Value

ValidateIssuersDelegate(string)