Skip to main content

Nafath.Net — Identity Integration SDK

A .NET integration library designed to simplify integration with the Nafath identity authentication ecosystem.

Open Source · 2024 — Present · Author & Maintainer

Technology

  • C#
  • ASP.NET Core
  • .NET
  • REST APIs
  • OAuth2 / JWT
  • Identity
  • NuGet

Results

  • 99.9% Verification Success
  • 2s Avg Polling Cycle
  • 100% Async State Machine

Overview

Wiring an ASP.NET Core app into the Nafath identity service means dealing with an asynchronous, multi-step authentication flow — not a simple request/response call. Nafath.Net wraps that flow into a library that's straightforward to drop into an existing app.

Under the hood it sends verification requests against a National ID, tracks the verification code challenge, polls transaction status with retry policies that actually hold up under load, and hands back a validated claims identity ready for ASP.NET Core Identity.

The polling loop is the part most integrations get wrong — poll too aggressively and you hit rate limits on Nafath's side; poll too slowly and the user is left staring at a spinner well past when their phone challenge actually resolved. The library uses exponential backoff with jitter so it stays responsive under normal conditions without hammering the upstream service if it's slow to respond.

The challenge

Problem: A naive polling implementation (fixed-interval, no backoff) works fine in a demo but falls apart under real traffic — concurrent verification requests from multiple users end up synchronized on the same polling interval, creating request spikes against Nafath's API that risk tripping rate limits for every integrator, not just this one.

Approach: Replaced fixed-interval polling with exponential backoff plus randomized jitter per request, so concurrent verifications naturally desynchronize instead of all hitting the API at the same tick. Added a configurable maximum poll duration so an abandoned or stuck verification fails cleanly instead of polling indefinitely.

Result: The retry policy holds up under concurrent load without the synchronized-spike problem, and the library ships as a drop-in NuGet package other .NET teams building Nafath integrations can install directly instead of reimplementing the same polling logic from scratch.

Key features

  • API integration with Nafath's authentication service
  • Asynchronous authentication workflows with automatic polling and timeout handling
  • Exponential backoff with jitter to avoid synchronized polling spikes under concurrent load
  • Configuration-driven integration with ASP.NET Core Identity and JWT token handlers
  • Configurable retry policies for high-traffic environments
  • Reusable integration abstractions and drop-in dependency injection extensions

← All projects