Skip to main content

Integrating Nafath Identity & Biometric Verification in ASP.NET Core

Architectural guide to integrating Nafath National SSO into .NET backends — asynchronous verification state machine and biometric prompt handling.

· 10 min read · Intermediate

Key takeaways

  • Architect an asynchronous polling and webhook receiver lifecycle for biometric prompts.
  • Validate JWT cryptographic signatures and claims emitted by Nafath identity servers.
  • Integrate seamless session mapping into ASP.NET Core Identity and Cookie middleware.

If you're building a government, financial, or enterprise platform requiring national SSO integration, integrating with Nafath — the National Single Sign-On service — handles biometric and multi-factor identity verification for citizens and residents.

Asynchronous State Machine for Nafath Verification

There's no synchronous version of this flow. Your app sends a request with the user's National or Iqama ID, Nafath generates a two-digit verification code, and the user has to go approve a biometric prompt on their phone before anything completes. Your backend spends that gap either polling or waiting on a webhook callback.

Encapsulate the Nafath polling lifecycle in an isolated, resilient background state machine to prevent blocking HTTP request threads.

Package that flow into a reusable library once, and every project after the first one gets it for free. That's what Nafath.Net is — inject INafathService, and signature validation, token caching, and ASP.NET Core Identity integration are a few lines of configuration instead of a re-implementation.

← All guides