Rag.NET.Api
0.1.0
dotnet add package Rag.NET.Api --version 0.1.0
NuGet\Install-Package Rag.NET.Api -Version 0.1.0
<PackageReference Include="Rag.NET.Api" Version="0.1.0" />
<PackageVersion Include="Rag.NET.Api" Version="0.1.0" />
<PackageReference Include="Rag.NET.Api" />
paket add Rag.NET.Api --version 0.1.0
#r "nuget: Rag.NET.Api, 0.1.0"
#:package Rag.NET.Api@0.1.0
#addin nuget:?package=Rag.NET.Api&version=0.1.0
#tool nuget:?package=Rag.NET.Api&version=0.1.0
Rag.NET.Api
ASP.NET Core REST endpoints for a Rag.NET pipeline: MapRagNetApi() exposes ingest,
retrieve, ask and delete over HTTP with API-key authentication, and MapRagNetWebhooks()
adds an HMAC-verified ingestion webhook.
Install
dotnet add package Rag.NET.Api
Setup
using Rag.NET.Api.DependencyInjection;
using Rag.NET.DependencyInjection;
var builder = WebApplication.CreateBuilder(args);
builder.Services.AddRagNet(); // configure your pipeline as usual
builder.Services.AddRagNetApi(o => o.ApiKeys = ["your-api-key"]);
var app = builder.Build();
app.UseRagNetApiAuthentication(); // X-Api-Key middleware
app.MapRagNetApi();
app.Run();
Authentication is an explicit decision: AddRagNetApi throws at startup when
RagApiOptions.ApiKeys is empty, unless you opt out deliberately with
o.AllowAnonymous = true (for example behind a trusted gateway that authenticates
upstream). Setting both at once is rejected as a contradiction. The middleware also
fails closed at request time — if the options end up with no keys and no opt-out,
requests get 401 rather than an accidentally open API.
Example
Event-driven ingestion via the webhook endpoint — callers authenticate with an HMAC-SHA256 signature over the raw request body instead of the API key:
builder.Services.AddRagNetWebhooks(o =>
{
o.Secret = builder.Configuration["Webhooks:Secret"]!; // required, non-empty
});
app.UseRagNetApiAuthentication();
app.MapRagNetWebhooks(); // POST /rag/webhooks/ingest
The webhook route prefix is exempted from API-key auth (the HMAC signature replaces the
key). MapRagNetApi() refuses to start if that exemption would also cover any of the
API's own routes — a WebhookOptions.RoutePrefix such as "/rag" that is a parent of
/rag/ingest throws at mapping time instead of silently disabling authentication.
curl -X POST https://localhost:5001/rag/webhooks/ingest \
-H "X-Signature-256: sha256=<hex hmac of body>" \
-d '{"documentId":"doc-1","content":"full document text"}'
Full guide
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Rag.NET (>= 0.1.0)
- Rag.NET.Mediator (>= 0.1.0)
NuGet packages (1)
Showing the top 1 NuGet packages that depend on Rag.NET.Api:
| Package | Downloads |
|---|---|
|
Rag.NET.Api.Client
HTTP client for Rag.NET.Api — implements IRagPipeline over HTTP |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 0.1.0 | 58 | 8/11/2026 |