- 🗺 Roadmap
- 🌟 Why UltimateAuth
- 🚀 Quick Start
- 💡 Usage
- 📘 Documentation
- 🤝 Contributing
- ⭐ Acknowledgements
UltimateAuth is an open-source auth framework with platform-level capabilities that unifies secure session, cookie and token based Auth, modern PKCE flows, Blazor/Maui-ready client experiences - eliminating the complexity of traditional Auth systems while providing a clean, lightweight, extensible and developer-first architecture.
| Phase | Version | Scope | Status | Release Date |
|---|---|---|---|---|
| First Preview | 0.1.0-preview | "Stable" Preview Core | ✅ Completed | 07.04.2026 |
| First Release* | 0.1.0 | Fully Documented & Quality Tested | ✅ Completed | 04.10.2026 |
| Product Expansion | 0.2.0 | Full Auth Modes | 🟡 In Progress | Q4 2026 |
| Security Expansion | 0.3.0 | MFA, Reauth, Rate Limiting | 🟡 In Progress | Q4 2026 |
| Infrastructure Expansion | 0.4.0 | Redis, Distributed Cache, Password Hasher | 🔜 Planned | Q1 2027 |
| Multi-Tenant Expansion | 0.5.0 | Multi tenant management | 🔜 Planned | Q1 2027 |
| Extensibility Expansion | 0.6.0 | Audit, events, hooks | 🔜 Planned | Q1 2027 |
| Performance Expansion | 0.7.0 | Benchmarks, caching | 🔜 Planned | Q1 2027 |
| Ecosystem Expansion | 0.8.0 | Migration tools | 🔜 Planned | Q2 2027 |
| v1.0 | 1.0.0 | Locked API, align with .NET 11 | 🔜 Planned | Q2 2027 |
*v 0.1.0 already provides a skeleton of multi tenancy, MFA, reauth etc. Expansion releases will enhance these areas.
The project roadmap is actively maintained as a GitHub issue:
👉 #8
We keep it up-to-date with current priorities, planned features, and progress. Feel free to follow, comment, or contribute ideas.
The Six-Point Principles
One solution, one mental model — across Blazor Server, WASM, MAUI, and APIs. UltimateAuth eliminates fragmentation by handling client differences internally and exposing a single, consistent API.
Built-in capabilities designed for real-world scenarios:
- Automatic client profile detection (blazor server - WASM - MAUI)
- Selectable authentication modes (Session / Token / Hybrid / SemiHybrid)
- Device-aware sessions
- PKCE flows out of the box
- Unified session + token lifecycle
- Event-driven extensibility
No boilerplate. No hidden complexity.
Clean APIs, predictable behavior, minimal ceremony — designed to make authentication pleasant.
Modern security built-in by default:
- PKCE support
- Session reuse detection
- Device tracking
- Hardened auth flows
- Safe defaults
Start simple, scale infinitely:
- Works out of the box with sensible defaults
- Replace any component when needed
- No forced architecture decisions
Designed specifically for real-world .NET environments:
- Blazor Server
- Blazor WASM
- Blazor Web App
- .NET MAUI & Hybrid Apps
- Backend APIs
Traditional auth solutions struggle here — UltimateAuth embraces it.
⏱ Takes ~2 minutes to get started
This Quick Start uses a Blazor Server application with in-memory persistence. It is intentionally designed as the simplest path to a working UltimateAuth application.
For Entity Framework Core, Blazor WebAssembly, Blazor Web App, Resource API, persistent storage, and other real-world configurations, see the Real-World Setup guide.
dotnet add package CodeBeam.UltimateAuth.InMemory.Bundle
dotnet add package CodeBeam.UltimateAuth.Client.BlazorRegister UltimateAuth in Program.cs:
// Server registration
builder.Services
.AddUltimateAuthServer()
.AddUltimateAuthInMemory();
// Client registration
builder.Services.AddUltimateAuthClientBlazor();Usage by application type:
- Blazor Server App → Use both Server and Client registrations
- Blazor WASM / MAUI → Use Client only
- UAuthHub (Auth Server) / Resource API → Use Server only
Add the UltimateAuth middleware and endpoints:
// app.UseHttpsRedirection();
// app.UseStaticFiles();
app.UseUltimateAuthWithAspNetCore(); // Includes UseAuthentication() and UseAuthorization()
// Place Antiforgery or something else before endpoint registration if needed
app.MapUltimateAuthEndpoints();
app.MapRazorComponents<App>()
.AddInteractiveServerRenderMode()
.AddUltimateAuthRoutes(UAuthAssemblies.BlazorClient());UltimateAuth uses UAuthApp as the root integration point for its client authentication state and Blazor lifecycle.
Replace the default router in your App.razor or Routes.razor with:
@using CodeBeam.UltimateAuth.Client.Blazor
<UAuthApp UseBuiltInRouter="true" AppAssembly="typeof(Program).Assembly" DefaultLayout="typeof(Layout.MainLayout)">
<ChildContent>
@* Add application-wide UI providers or other root components here. *@
</ChildContent>
<NotAuthorized>
<p>Not authorized.</p>
</NotAuthorized>
</UAuthApp>UAuthApp can provide the built-in router, authentication state, and UltimateAuth client lifecycle integration for your component tree.
Need full control over routing?
UAuthApp also supports applications that provide their own Blazor Router. See the Blazor Routing guide for advanced routing configuration.
Place this in App.razor or index.html in your Blazor client application:
<script src="_content/CodeBeam.UltimateAuth.Client.Blazor/uauth.min.js"></script>Add this in _Imports.razor:
@using CodeBeam.UltimateAuth.Client.BlazorFor the fastest way to try auth process, install the UltimateAuth sample seed package:
dotnet add package CodeBeam.UltimateAuth.Sample.SeedRegister the development seed:
builder.Services.AddUltimateAuthSampleSeed();Then seed the application during development:
if (app.Environment.IsDevelopment())
{
await app.SeedUltimateAuthAsync();
}The development seed includes ready-to-use accounts:
| Identifier | Secret |
|---|---|
admin |
admin |
user |
user |
You can use these credentials to test the auth flows immediately.
Development only: Sample users and credentials are intended for evaluation and local development. Do not use them in production.
One Client. Your Auth Application API.
For most application-level authentication and identity operations, start with IUAuthClient.
IUAuthClient provides a single entry point to UltimateAuth capabilities such as authentication flows, users, sessions, tokens, profiles, credentials, and authorization — without requiring your application code to manage the underlying authentication transport.
UltimateAuth treats authentication and identity as application services. Your application works with explicit operations and structured results while UltimateAuth handles the underlying authentication flow.
Login
[Inject] IUAuthClient UAuthClient { get; set; } = null!;
private async Task Login()
{
var request = new LoginRequest
{
Identifier = "admin",
Secret = "admin",
};
await UAuthClient.Flows.LoginAsync(request);
}Register
[Inject] IUAuthClient UAuthClient { get; set; } = null!;
private async Task Register()
{
var request = new CreateUserRequest
{
UserName = "NewUser",
Password = "NewUserPassword",
Email = "newuser@example.com",
};
var result = await UAuthClient.Users.CreateAsync(request);
if (result.IsSuccess)
{
Console.WriteLine("User created successfully.");
}
else
{
Console.WriteLine(result.ErrorText ?? "Failed to create user.");
}
}LogoutAll But Keep Current Device
[Inject] IUAuthClient UAuthClient { get; set; } = null!;
private async Task LogoutOthersAsync()
{
var result = await UAuthClient.Flows.LogoutMyOtherDevicesAsync();
Console.WriteLine(result.IsSuccess);
}With IUAuthClient, common application code doesn't need to manually orchestrate:
- token handling
- authentication HTTP calls
- session operations
- redirect plumbing
- client-specific authentication flows
Start with the simple API. Drop down to UltimateAuth's extensibility points when your application needs more control.
Two documentation experiences are provided:
Guides, API reference, tutorials - https://ultimateauth.com
Create accounts, simulate devices, test auth flows, and observe UltimateAuth in action.
UltimateAuth is a community-first framework.
We welcome proposals, discussions, architectural insights, and contributions of all sizes.
Discussions are open — your ideas matter.
UltimateAuth is built with love by CodeBeam and shaped by real-world .NET development —
for teams who want authentication to be secure, predictable, extensible, and a joy to use.
Reimagine how .NET does authentication.
Welcome to UltimateAuth.
