--- title: "Infisical .NET SDK" sidebarTitle: ".NET" icon: "/images/sdks/languages/dotnet.svg" --- If you're working with .NET, the official Infisical .NET SDK package is the easiest way to fetch and work with secrets for your application. ## Installation ```bash dotnet add package Infisical.Sdk ``` ## Getting Started (.NET) ```csharp namespace Example; using Infisical.Sdk; using Infisical.Sdk.Model; public class Program { public static void Main(string[] args) { var settings = new InfisicalSdkSettingsBuilder() .WithHostUri("http://localhost:8080") // Optional. Will default to https://app.infisical.com .Build(); var infisicalClient = new InfisicalClient(settings); var _ = infisicalClient.Auth().UniversalAuth().LoginAsync("", "").Result; var options = new ListSecretsOptions { SetSecretsAsEnvironmentVariables = true, EnvironmentSlug = "", SecretPath = "/", ProjectId = "", }; var secrets = infisicalClient.Secrets().ListAsync(options).Result; if (secrets == null) { throw new Exception("Failed to fetch secrets, returned null response"); } foreach (var secret in secrets) { Console.WriteLine($"{secret.SecretKey}: {secret.SecretValue}"); } } } ``` ## Getting Started (Visual Basic) ```vb Imports Infisical.Sdk Imports Infisical.Sdk.Model Module Program Sub Main(args As String()) Dim settings = New InfisicalSdkSettingsBuilder() _ .WithHostUri("https://app.infisical.com") _ .Build() Dim infisicalClient As New InfisicalClient(settings) Dim authResult = infisicalClient.Auth().UniversalAuth() _ .LoginAsync("", "machine-identity-universal-auth-client-secret").Result Dim options As New ListSecretsOptions With { .SetSecretsAsEnvironmentVariables = True, .EnvironmentSlug = "", .SecretPath = "/", .ProjectId = "" } Dim secrets = infisicalClient.Secrets().ListAsync(options).Result For Each secret In secrets Console.WriteLine(secret.SecretKey) if Environment.GetEnvironmentVariable(secret.SecretKey) IsNot Nothing Then Console.WriteLine("{0} found on environment variables", secret.SecretKey) End If Next End Sub End Module ``` ## Core Methods The SDK methods are organized into the following high-level categories: 1. `Auth()`: Handles authentication methods. 2. `Secrets()`: Manages CRUD operations for secrets. 3. `Pki()`: Programmatically interact with the Infisical PKI. * `Subscribers()`: Manage PKI Subscribers. ### `Auth()` The `Auth()` component provides methods for authentication: ### Universal Auth #### Authenticating ```cs var _ = await sdk.Auth().UniversalAuth().LoginAsync( "CLIENT_ID", "CLIENT_SECRET" ); ``` **Parameters:** - `clientId` (string): The client ID of your Machine Identity. - `clientSecret` (string): The client secret of your Machine Identity. ### LDAP Auth #### Authenticating ```cs var _ = await sdk.Auth().LdapAuth().LoginAsync( "IDENTITY_ID", "USERNAME", "PASSWORD" ); ``` **Parameters:** - `identityId` (string): The ID of your Machine Identity . - `username` (string): The LDAP username for authentication. - `password` (string): The LDAP password for authentication. ### `Secrets()` The `Secrets()` sub-class handles operations related to the Infisical secrets management product. #### List Secrets ```cs Task ListAsync(ListSecretsOptions options); throws InfisicalException ``` ```csharp var options = new ListSecretsOptions { SetSecretsAsEnvironmentVariables = true, EnvironmentSlug = "dev", SecretPath = "/test", Recursive = true, ExpandSecretReferences = true, ProjectId = projectId, ViewSecretValue = true, }; Secret[] secrets = await sdk.Secrets().ListAsync(options); ``` **ListSecretsOptions:** - `ProjectId` (string): The ID of your project. - `EnvironmentSlug` (string): The environment in which to list secrets (e.g., "dev"). - `SecretPath` (string): The path to the secrets. - `ExpandSecretReferences` (boolean): Whether to expand secret references. - `Recursive` (boolean): Whether to list secrets recursively. - `SetSecretsAsEnvironmentVariables` (boolean): Set the retrieved secrets as environment variables. **Returns:** - `Task`: The response containing the list of secrets. #### Create Secret ```cs public Task CreateAsync(CreateSecretOptions options); throws InfisicalException ``` ```cs var options = new CreateSecretOptions { SecretName = "SECRET_NAME", SecretValue = "SECRET_VALUE", EnvironmentSlug = "", SecretPath = "/", ProjectId = "", Metadata = new SecretMetadata[] { new SecretMetadata { Key = "metadata-key", Value = "metadata-value" } } }; Task newSecret = await sdk.Secrets().CreateAsync(options); ``` **Parameters:** - `SecretName` (string): The name of the secret to create - `SecretValue` (string): The value of the secret. - `ProjectId` (string): The ID of your project. - `EnvironmentSlug` (string): The environment in which to create the secret. - `SecretPath` (string, optional): The path to the secret. - `Metadata` (object, optional): Attach metadata to the secret. - `SecretComment` (string, optional): Attach a secret comment to the secret. - `SecretReminderNote` (string, optional): Attach a secret reminder note to the secret. - `SecretReminderRepeatDays` (int, optional): Set the reminder repeat days on the secret. - `SkipMultilineEncoding` (bool, optional): Whether or not to skip multiline encoding for the secret's value. Defaults to `false`. **Returns:** - `Task`: The created secret. #### Update Secret ```cs public Task UpdateAsync(UpdateSecretOptions options); throws InfisicalException ``` ```cs var updateSecretOptions = new UpdateSecretOptions { SecretName = "EXISTING_SECRET_NAME", EnvironmentSlug = "", SecretPath = "/", NewSecretName = "NEW_SECRET_NAME", NewSecretValue = "new-secret-value", ProjectId = "", }; Task updatedSecret = await sdk.Secrets().UpdateAsync(updateSecretOptions); ``` **Parameters:** - `SecretName` (string): The name of the secret to update.` - `ProjectId` (string): The ID of your project. - `EnvironmentSlug` (string): The environment in which to update the secret. - `SecretPath` (string): The path to the secret. - `NewSecretValue` (string, optional): The new value of the secret. - `NewSecretName` (string, optional): A new name for the secret. - `NewMetadata` (object, optional): New metadata to attach to the secret. **Returns:** - `Task`: The updated secret. #### Get Secret by Name ```cs public Task GetAsync(GetSecretOptions options); throws InfisicalException ``` ```cs var getSecretOptions = new GetSecretOptions { SecretName = "SECRET_NAME", EnvironmentSlug = "", SecretPath = "/", ProjectId = "", }; Secret secret = await sdk.Secrets().GetAsync(getSecretOptions); ``` **Parameters:** - `SecretName` (string): The name of the secret to get` - `ProjectId` (string): The ID of your project. - `EnvironmentSlug` (string): The environment in which to retrieve the secret. - `SecretPath` (string): The path to the secret. - `ExpandSecretReferences` (boolean, optional): Whether to expand secret references. - `Type` (SecretType, optional): The type of secret to fetch. Defaults to `Shared`. **Returns:** - `Task`: The fetched secret. #### Delete Secret by Name ```cs public Secret DeleteAsync(DeleteSecretOptions options); throws InfisicalException ``` ```cs var options = new DeleteSecretOptions { SecretName = "SECRET_TO_DELETE", EnvironmentSlug = "", SecretPath = "/", ProjectId = "", }; Secret deletedSecret = await sdk.Secrets().DeleteAsync(options); ``` **Parameters:** - `SecretName` (string): The name of the secret to delete. - `ProjectId` (string): The ID of your project. - `EnvironmentSlug` (string): The environment in which to delete the secret. - `SecretPath` (string, optional): The path to the secret. **Returns:** - `Task`: The deleted secret. ### `Pki().Subscribers()` The `Pki().Subscribers()` sub-class is used to programmatically interact with the Infisical PKI product line. Currently only issuing new certificates and retrieving the latest certificate bundle from a subscriber is supported. More widespread support for the PKI product is coming to the .NET SDK in the near future. #### Issue a new certificate ```cs public async Task IssueCertificateAsync(IssueCertificateOptions options); throws InfisicalException ``` ```cs var options = new IssueCertificateOptions { SubscriberName = "", ProjectId = "", }; SubscriberIssuedCertificate newCertificate = await sdk.Pki().Subscribers().IssueCertificateAsync(options); ``` **Parameters:** - `SubscriberName` (string): The name of the subscriber to create a certificate for. - `ProjectId` (string): The ID of PKI project. **Returns:** - `Task`: The newly issued certificate along with it's credentials for the specified subscriber. #### Retrieve latest certificate bundle ```cs public async Task RetrieveLatestCertificateBundleAsync(RetrieveLatestCertificateBundleOptions options) throws InfisicalException ``` ```cs var options = new RetrieveLatestCertificateBundleOptions { SubscriberName = "", ProjectId = "", }; CertificateBundle latestCertificate = await sdk.Pki().Subscribers().RetrieveLatestCertificateBundleAsync(options); ``` **Parameters:** - `SubscriberName` (string): The name of the subscriber to retrieve the latest certificate bundle for - `ProjectId` (string): The ID of PKI project. **Returns:** - `Task`: The latest certificate bundle for the specified subscriber.