Integrating Nafath Identity & Biometric Verification in ASP.NET Core
Architectural guide to integrating Nafath National SSO into .NET backends — asynchronous verification state machine and biometric prompt handling.
· 10 min read · Intermediate
Key takeaways
- Architect an asynchronous polling and webhook receiver lifecycle for biometric prompts.
- Validate JWT cryptographic signatures and claims emitted by Nafath identity servers.
- Integrate seamless session mapping into ASP.NET Core Identity and Cookie middleware.
If you're building a government, financial, or enterprise platform requiring national SSO integration, integrating with Nafath — the National Single Sign-On service — handles biometric and multi-factor identity verification for citizens and residents.
Asynchronous State Machine for Nafath Verification
There's no synchronous version of this flow. Your app sends a request with the user's National or Iqama ID, Nafath generates a two-digit verification code, and the user has to go approve a biometric prompt on their phone before anything completes. Your backend spends that gap either polling or waiting on a webhook callback.
Encapsulate the Nafath polling lifecycle in an isolated, resilient background state machine to prevent blocking HTTP request threads.
Package that flow into a reusable library once, and every project after the first one gets it for free. That's what Nafath.Net is — inject INafathService, and signature validation, token caching, and ASP.NET Core Identity integration are a few lines of configuration instead of a re-implementation.