Skip to content

Instantly share code, notes, and snippets.

Created December 5, 2020 17:09
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save manoj-choudhari-git/b2927cb5a09834c7e772460eba292872 to your computer and use it in GitHub Desktop.
Save manoj-choudhari-git/b2927cb5a09834c7e772460eba292872 to your computer and use it in GitHub Desktop.
.NET 5 Web API startup for sample implementation of access token and refresh token
public class Startup
public Startup(IConfiguration configuration)
Configuration = configuration;
public IConfiguration Configuration { get; }
// This method gets called by the runtime. Use this method to add services to the container.
public void ConfigureServices(IServiceCollection services)
services.AddDbContext<ApplicationDbContext>(options =>
services.AddIdentity<ApplicationUser, IdentityRole>(options => options.SignIn.RequireConfirmedAccount = true)
// configure strongly typed settings objects
var jwtSection = Configuration.GetSection("JwtBearerTokenSettings");
var jwtBearerTokenSettings = jwtSection.Get<JwtBearerTokenSettings>();
var key = Encoding.ASCII.GetBytes(jwtBearerTokenSettings.SecretKey);
services.AddAuthentication(options =>
options.DefaultAuthenticateScheme = JwtBearerDefaults.AuthenticationScheme;
options.DefaultChallengeScheme = JwtBearerDefaults.AuthenticationScheme;
.AddJwtBearer(options =>
options.RequireHttpsMetadata = false;
options.SaveToken = true;
options.TokenValidationParameters = new TokenValidationParameters()
ValidateIssuer = true,
ValidIssuer = jwtBearerTokenSettings.Issuer,
ValidateAudience = true,
ValidAudience = jwtBearerTokenSettings.Audience,
ValidateIssuerSigningKey = true,
IssuerSigningKey = new SymmetricSecurityKey(key),
ValidateLifetime = true,
ClockSkew = TimeSpan.Zero // To immediately reject the access token
// This method gets called by the runtime. Use this method to configure the HTTP request pipeline.
public void Configure(IApplicationBuilder app, IWebHostEnvironment env)
app.UseCors(x => x
if (env.IsDevelopment())
app.UseEndpoints(endpoints =>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment