Choose the capability level. Build the integration. Prove the control.
A unified path through editions, source packages, application setup, detailed tutorials, source code, Test Mode, API references, enterprise controls, and production promotion.
Most capable to entry edition
The description column is intentionally compact so the capabilities remain visible without horizontal hunting.
Regulated deployments, large organizations, partner ecosystems, and centralized governance.
- Everything in Premium
- Enterprise Developer Portal
- Multi-project and multi-team administration
- Delegated administration
- Entitlement controls
- Centralized audit and evidence
Shared platforms and engineering organizations needing advanced controls and complete samples.
- Everything in Starter
- ServiceStack support
- Advanced suspension
- Full sample library
- Platform implementation patterns
- Team operating guidance
Production applications requiring the complete authentication and application-control baseline.
- Everything in Community
- All authentication schemes
- MFA
- IP firewall
- Production sample integrations
- Test Mode guidance
Learning, evaluation, proofs of concept, and core B5 security foundations.
- Security pipeline
- Authentication foundations
- ADA foundations
- Basic source samples
- Basic tutorials
- Community documentation
See what each edition unlocks
Higher editions include the capabilities of every edition below them.
| Capability | Enterprise | Premium | Starter | Community |
|---|---|---|---|---|
| Security pipeline, authentication, and ADA foundations | ✓ | ✓ | ✓ | ✓ |
| All authentication schemes | ✓ | ✓ | ✓ | — |
| MFA and IP firewall | ✓ | ✓ | ✓ | — |
| ServiceStack and advanced suspension | ✓ | ✓ | — | — |
| Full sample library | ✓ | ✓ | Selected | Basic |
| Enterprise Developer Portal | ✓ | — | — | — |
| Delegated administration, entitlement, evidence, and oversight | ✓ | — | — | — |
Need the package view? Open the Source Package Grades page for the source-delivery map.
A clear path from zero to a protected request
Define
Register the enterprise, project, application, environment, audience, scopes, owners, and callbacks.
Open Start Here →Install
Register B5 SecurityKit, place the middleware, and protect the first endpoint.
Download .NET tutorial →Test
Prove success and deliberate denial, including replay, audience, scope, suspension, and MFA.
Open Test Mode →Promote
Complete security, evidence, operational, rotation, incident, and rollback gates.
Download promotion checklist →Learn by completing a real security task
Every tutorial has a working destination and is downloadable as a Markdown guide.
Choose the right B5 edition
Enterprise, Premium, Starter, and Community decision guide.
Secure your first .NET 10 app
Registration, middleware order, protected route, and denial tests.
Configure authentication schemes
HMAC, Service-HMAC, AuthCookie, and Service-Key selection.
Apply ADA authorization
Activity, resource, data, tenant, delegation, and runtime context.
Enable MFA and IP firewall
Step-up authentication and network-origin policy.
Test success and deliberate denial
Replay, audience, scope, suspension, MFA, and webhook cases.
Integrate ServiceStack
B5SecurityKitFeature registration and request-flow requirements.
Verify webhooks
Freshness, constant-time verification, idempotency, and rotation.
Secure iOS and Android apps
PKCE, device keys, callbacks, and server-side policy.
Secure a Chrome extension
Manifest V3, short-lived authority, and minimal permissions.
Connect on-premises and partner APIs
Outbound connectors, workload identity, and delegation boundaries.
Promote to production
Security, engineering, evidence, operations, rotation, and rollback gates.
Open, inspect, adapt, test, and download
Every card resolves to a real B5 webpage or a downloadable file.
Registration and protected endpoints
AddB5SecurityKit(), UseB5SecurityKit(), endpoint authorization, ADA context, and configuration.
Negative-test automation
C#, PowerShell, and Bash assets for credential, signature, replay, audience, and scope denials.
B5SecurityKitFeature starter
ServiceStack registration plus request-flow, policy, and evidence guidance.
Signed requests and Postman
Request signing, PowerShell, Bash, Test Mode collection, environment, and OpenAPI assets.
iOS, Android, and Chrome
PKCE, device-key, Keystore, Manifest V3, and public-client starting points.
Developer control plane
Developers, projects, apps, credentials, webhooks, deployments, usage, incidents, audit, and evidence.
Continue into the right detail surface
Concepts and getting started
Security pipeline, authentication schemes, ADA, suspension, source packages, and project templates.
Step-by-step guides
.NET APIs, mobile applications, browser extensions, on-premises APIs, and partner integrations.
Webhooks, releases, and packages
Event verification, release notes, source package grades, and production-promotion evidence.
Take the Developer Hub offline
Download every tutorial, source excerpt, testing harness, configuration example, and operational checklist.
Q4 2026 roadmap extensions
These capabilities are specified and not yet released. Each page carries its status from the Product Truth Registry.
Roslyn Analyzers
Missing protection, invalid permissions and build gates.
Batch Authorization
High-volume mixed resource and action decisions.
Runtime Coverage
gRPC, Functions, workers, queues, Dapr, Orleans, ServiceStack.
Migration Tooling
Discovery and conversion from roles, handlers and custom checks.
Polyglot Protocol
Language-neutral decision, evidence and revocation contracts.
Authorization Testing
Assertions, property tests, replay, mutation and coverage.
Talk to a human.
Get architecture guidance, Test Mode access, integration review, or help choosing the right B5 identity and authorization pattern.