ServiceCredentialsSecurityTokenManager.CreateSecurityTokenAuthenticator Method

Creates a security token authenticator based on the SecurityTokenRequirement.

Namespace:  System.ServiceModel.Security
Assembly:  System.ServiceModel (in System.ServiceModel.dll)

public override SecurityTokenAuthenticator CreateSecurityTokenAuthenticator(
	SecurityTokenRequirement tokenRequirement,
	out SecurityTokenResolver outOfBandTokenResolver


Type: System.IdentityModel.Selectors.SecurityTokenRequirement

The SecurityTokenRequirement.

Type: System.IdentityModel.Selectors.SecurityTokenResolver%

When this method returns, contains a SecurityTokenResolver. This parameter is passed uninitialized.


tokenRequirement is null.


A security token authenticator cannot be created for the tokenRequirement that was passed in.

An outOfBand token resolver can optionally be returned by the method, which will be used by the WCF security processor to resolve tokens that are not in the SOAP message when processing security. The SecurityTokenAuthenticator that is returned by this method validates tokens and extracts claims. One SecurityTokenAuthenticator is created for each class derived from ServiceModelSecurityTokenRequirement.

The following code is an example of how to override this method.

internal class MyServiceCredentialsSecurityTokenManager : 
    ServiceCredentials credentials;
    public MyServiceCredentialsSecurityTokenManager(ServiceCredentials credentials)
        : base(credentials)
        this.credentials = credentials;

    public override SecurityTokenAuthenticator CreateSecurityTokenAuthenticator
        (SecurityTokenRequirement tokenRequirement, out SecurityTokenResolver outOfBandTokenResolver)
        // Return your implementation of the SecurityTokenProvider based on the  
        // tokenRequirement argument.
        SecurityTokenAuthenticator result;
        if (tokenRequirement.TokenType == SecurityTokenTypes.UserName)
            MessageDirection direction = tokenRequirement.GetProperty<MessageDirection>
            if (direction == MessageDirection.Input)
                outOfBandTokenResolver = null;
                result = new MySecurityTokenAuthenticator();
                result = base.CreateSecurityTokenAuthenticator(tokenRequirement, out outOfBandTokenResolver);
            result = base.CreateSecurityTokenAuthenticator(tokenRequirement, out outOfBandTokenResolver);

        return result;

