Skip to content
CAI
Software that uses CAICheck a score

Azure/AAD.fs

70.5

Strong · 3 October 2026

1.1k

lines of production code

F#

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

AAD.fs is an open-source F\# library that provides abstractions for Azure Active Directory role-based authentication and authorization. It offers core JWT token validation, claim demand evaluation, and transparent proxy authentication, with specific integration modules for the Giraffe and Suave web frameworks. The system supports both .NET Tasks and F\# Async workflows and includes caching for OpenID Connect configuration.

Features

Initial open-source release of AAD.fs library

This release makes the AAD.fs library available as open-source software under the MIT License. The package provides F\# abstractions for Azure AD role-based protection, including core libraries for Async and Task-based operations, along with specific integrations for Suave and Giraffe web frameworks. The repository includes a FAKE-based build system, solution structure, and documentation to support consumption and contribution.

(repo-wide) · high confidence

Initial release of AAD.fs library

This change introduces the AAD.fs library, providing core components for Azure Active Directory authentication and token validation. It includes domain models (ClientName, Scope, Audience, etc.), a Demand system for evaluating JWT claims with support for space-delimited values, and an Awaitable abstraction that allows the library to operate on either .NET Tasks or F\# Async workflows via a compile-time flag. The library also features a Requestor interface for transparent authentication of proxies and a ResourceOwner module for validating tokens against specific demands.

AAD.fs · high confidence

Initial release of Giraffe and Suave integration modules

This change introduces the initial OSS release of the AAD.Giraffe and AAD.Suave libraries, providing framework-specific implementations for Azure AD authentication. The AAD.Giraffe module adds \PartProtector\ and \ReadersAndWriters\ modules to handle JWT token verification, introspection, and HTTP handler composition within the Giraffe web framework. Similarly, the AAD.Suave module provides corresponding \PartProtector\ and \Readers\ modules for the Suave framework, enabling stateful token protection and bearer token extraction. Both modules include \Noop\ variants for testing or bypassing verification, and implement caching for OpenID Connect configuration retrieval with a 24-hour expiration.

AAD.Giraffe, AAD.Suave · high confidence

Test coverage

Added integration tests for AAD task authorization; Initial test suite for AAD authentication and authorization.

Dependencies

Upgrade to .NET 8/10 and update core dependencies

The project now targets .NET 8.0 and .NET 10.0, replacing previous framework versions. Core libraries have been upgraded to align with these targets: Microsoft.Identity.Client is updated to 4.84.2, System.IdentityModel.Tokens.Jwt to 8.19.1, and Microsoft.IdentityModel.Protocols.OpenIdConnect to 8.19.1. Additionally, Newtonsoft.Json is upgraded to 13.0.3 in the test project, and Microsoft.Extensions.Caching.Memory is set to 10.0.9.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 70 → 70 (+0.1)
  • Rubric changed (rubric-2026.09.15 → rubric-2026.10.1) — scores are not directly comparable.

Lenses

  • Code Health 98 → 98 (+0.0)
  • Architecture 93 → 97 (+4.3)
  • Maturity 57 → 57 (+0.0)
  • Readiness 73 → 73 (+0.0)
  • Security 89 → 88 (-1.8)

New (1)

  • Documentation: no project overview (README.md)

Architecture

  • Containers 0 added · 0 removed · contexts 2 added · 0 removed · edges 0 added · 0 removed

Added bounded contexts (2)

  • AAD.Test
  • AAD.fs.tasks

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

Azure/AAD.fs was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 3 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 7bd968fdc2a5ec480c6d2c1f8bd76f3e8ecdd74b — the exact code this score is about.
  • Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-4f4226d619ea.