Azure/AAD.fs
70.5
Strong · 3 October 2026
1.1k
lines of production code
F#
primary language
2
measurements over time
What this system is
AAD.fs is an open-source F\# library that provides abstractions for Azure Active Directory role-based authentication and authorization. It offers core JWT token validation, claim demand evaluation, and transparent proxy authentication, with specific integration modules for the Giraffe and Suave web frameworks. The system supports both .NET Tasks and F\# Async workflows and includes caching for OpenID Connect configuration.
Features
Initial open-source release of AAD.fs library
This release makes the AAD.fs library available as open-source software under the MIT License. The package provides F\# abstractions for Azure AD role-based protection, including core libraries for Async and Task-based operations, along with specific integrations for Suave and Giraffe web frameworks. The repository includes a FAKE-based build system, solution structure, and documentation to support consumption and contribution.
(repo-wide) · high confidence
Initial release of AAD.fs library
This change introduces the AAD.fs library, providing core components for Azure Active Directory authentication and token validation. It includes domain models (ClientName, Scope, Audience, etc.), a Demand system for evaluating JWT claims with support for space-delimited values, and an Awaitable abstraction that allows the library to operate on either .NET Tasks or F\# Async workflows via a compile-time flag. The library also features a Requestor interface for transparent authentication of proxies and a ResourceOwner module for validating tokens against specific demands.
AAD.fs · high confidence
Initial release of Giraffe and Suave integration modules
This change introduces the initial OSS release of the AAD.Giraffe and AAD.Suave libraries, providing framework-specific implementations for Azure AD authentication. The AAD.Giraffe module adds \PartProtector\ and \ReadersAndWriters\ modules to handle JWT token verification, introspection, and HTTP handler composition within the Giraffe web framework. Similarly, the AAD.Suave module provides corresponding \PartProtector\ and \Readers\ modules for the Suave framework, enabling stateful token protection and bearer token extraction. Both modules include \Noop\ variants for testing or bypassing verification, and implement caching for OpenID Connect configuration retrieval with a 24-hour expiration.
AAD.Giraffe, AAD.Suave · high confidence
Test coverage
Added integration tests for AAD task authorization; Initial test suite for AAD authentication and authorization.
Dependencies
Upgrade to .NET 8/10 and update core dependencies
The project now targets .NET 8.0 and .NET 10.0, replacing previous framework versions. Core libraries have been upgraded to align with these targets: Microsoft.Identity.Client is updated to 4.84.2, System.IdentityModel.Tokens.Jwt to 8.19.1, and Microsoft.IdentityModel.Protocols.OpenIdConnect to 8.19.1. Additionally, Newtonsoft.Json is upgraded to 13.0.3 in the test project, and Microsoft.Extensions.Caching.Memory is set to 10.0.9.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 70 → 70 (+0.1)
- Rubric changed (rubric-2026.09.15 → rubric-2026.10.1) — scores are not directly comparable.
Lenses
- Code Health 98 → 98 (+0.0)
- Architecture 93 → 97 (+4.3)
- Maturity 57 → 57 (+0.0)
- Readiness 73 → 73 (+0.0)
- Security 89 → 88 (-1.8)
New (1)
- Documentation: no project overview (README.md)
Architecture
- Containers 0 added · 0 removed · contexts 2 added · 0 removed · edges 0 added · 0 removed
Added bounded contexts (2)
- AAD.Test
- AAD.fs.tasks
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
Azure/AAD.fs was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 3 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 7bd968fdc2a5ec480c6d2c1f8bd76f3e8ecdd74b — the exact code this score is about.
- Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-4f4226d619ea.