Monday, 14 September 2026

What is the difference between Authentication and Authorization?

Leave a Comment

Two key ideas in application security are permission and authentication. Many people believe they signify the same thing since they are frequently used together. They don't.

The simplest method to comprehend the distinction is:


What authentication entails is: Who are you?
What does authorization mean?
While permission determines what a person may access once their identification has been confirmed, authentication verifies a user's identity.

Let's use some basic examples to comprehend both ideas.

What is Authentication?

Authentication is the process of verifying the identity of a user.

Whenever you log in to a website, mobile application, or online service, authentication is happening.

For example, you enter:

Email: [email protected]
Password: ********

The application checks whether the email and password are correct.

If the credentials are valid, the application confirms your identity.

User enters login details
        ↓
Application checks credentials
        ↓
Credentials are valid
        ↓
User is authenticated

If the credentials are incorrect, authentication fails and access is denied.

So authentication simply answers one question:

Are you really the person you claim to be?

Common Authentication Methods

Applications can authenticate users in several ways.

Username and Password

This is the most common authentication method.

The user provides a username or email address along with a password.

The server checks the credentials and allows access if they are correct.

One-Time Password

Many applications send a temporary code to the user's phone or email.

For example:

OTP: 583921

The user enters the code to verify their identity.

JWT Token

JWT, or JSON Web Token, is commonly used in web APIs.

A user first logs in using valid credentials.

Login
  ↓
Verify user
  ↓
Generate JWT token
  ↓
Return token

The client then sends this token with future API requests.

For example:

Authorization: Bearer eyJhbGciOiJIUzI1Ni...

The server validates the token before processing the request.

Social Login

Applications can also authenticate users using services such as:

Google
Microsoft
GitHub
Apple
Facebook

Instead of creating a separate password, users can sign in using an existing account.

Biometric Authentication

Mobile applications often use:

Fingerprint
Face recognition
Face ID

These methods help verify the identity of the user.

What is Authorization?

Authorization happens after authentication.

Once the application knows who the user is, it needs to decide what that user is allowed to do.

Suppose an application has three types of users:

Admin
Manager
Employee

All three users can successfully log in.

This means they are authenticated.

However, they may have different permissions.

For example:

Admin
  → View users
  → Create users
  → Delete users
  → Manage settings

Manager
  → View users
  → View reports
  → Manage team

Employee
  → View profile
  → View personal dashboard

The process of deciding which features each user can access is called authorization.

A Simple Real-World Example

Imagine you work in a large office.

When you arrive at the entrance, the security guard asks for your employee ID card.

You show the card.

The security system confirms:

Name: John
Employee ID: 1025
Status: Active

You are allowed inside.

This is authentication.

The system has confirmed who you are.

Now suppose you try to enter the server room.

You scan your access card.

The system checks whether you have permission to enter that room.

If you are part of the IT team:

Access Granted

If you do not have permission:

Access Denied

This is authorization.

So the complete idea is:

Who are you?
      ↓
Authentication

What are you allowed to access?
      ↓
Authorization

Authentication vs Authorization

Here is a simple comparison.

Authentication

Authorization

Verifies identity

Verifies permissions

Answers "Who are you?"

Answers "What can you do?"

Happens first

Happens after authentication

Usually happens during login

Happens when accessing protected resources

Uses password, OTP, token, biometrics

Uses roles, permissions, policies, claims

Example: Logging in

Example: Opening an admin page

The easiest way to remember it is:

Authentication = Identity

Authorization = Permission

How Authentication and Authorization Work Together

Consider an application with an admin dashboard.

A user sends a request to:

/admin/users

The application first checks authentication.

Request
   ↓
Authentication
   ↓
Who is this user?

Suppose the user is successfully authenticated.

The application now knows:

User: John
Role: Employee

Next, authorization checks whether John is allowed to access the admin page.

Authentication Successful
        ↓
Authorization
        ↓
Does John have Admin permission?

If not:

Access Denied

If John has the required permission:

Access Granted
      ↓
Admin Dashboard

So the complete process looks like this:

User Request
     ↓
Authentication
     ↓
Identity Verified
     ↓
Authorization
     ↓
Permission Verified
     ↓
Application

Authentication in ASP.NET Core

ASP.NET Core provides built-in authentication support.

For example, an application may configure JWT authentication:

builder.Services.AddAuthentication()
    .AddJwtBearer();

Then authentication middleware is added:

app.UseAuthentication();

This middleware checks authentication information included with incoming requests.

For example, it may validate a JWT token and identify the current user.

Authorization in ASP.NET Core

Authorization is generally configured after authentication.

app.UseAuthentication();

app.UseAuthorization();

The order is important.

First:

Authentication
Who is the user?

Then:

Authorization
What can the user access?

The application needs to know the user's identity before checking permissions.

Using the Authorize Attribute

ASP.NET Core provides the [Authorize] attribute for protecting endpoints.

For example:

[Authorize]
[HttpGet]
public IActionResult GetProfile()
{
    return Ok();
}

This endpoint can only be accessed by authenticated users.

If a user is not authenticated, access will be denied.

Role-Based Authorization

Sometimes simply being authenticated is not enough.

For example, imagine an API that deletes users:

DELETE /api/users/100

Only administrators should be allowed to use this API.

We can restrict the endpoint using a role:

[Authorize(Roles = "Admin")]
[HttpDelete("{id}")]
public IActionResult DeleteUser(int id)
{
    return Ok();
}

The application now performs two checks.

First:

Is the user authenticated?

Then:

Does the user have the Admin role?

Only when both conditions are true will the request be allowed.

Permission-Based Authorization

Roles are useful, but sometimes applications need more control.

Instead of using only roles, an application can use permissions.

For example:

CanViewUsers
CanCreateUsers
CanEditUsers
CanDeleteUsers
CanViewReports
CanManagePayments

A user could have:

Name: John

Role:
Manager

Permissions:
CanViewUsers
CanViewReports
CanEditReports

John can perform only the operations allowed by these permissions.

Permission-based authorization can be useful in large applications where different users require different levels of access.

Authentication with JWT

JWT authentication is very common when building APIs.

Suppose a user sends this request:

POST /api/login

with:

{
  "email": "[email protected]",
  "password": "password"
}

The server checks the credentials.

If they are correct:

Login Request
      ↓
Check Credentials
      ↓
Authentication Successful
      ↓
Generate JWT
      ↓
Return Token

The client receives the token and uses it for future API requests.

For example:

GET /api/profile

Authorization: Bearer <JWT_TOKEN>

The server validates the token.

If the token is valid, the user is authenticated.

Authorization can then check whether the user has permission to access /api/profile.

What is 401 Unauthorized?

HTTP status code 401 Unauthorized usually means the user has not been successfully authenticated.

For example:

GET /api/profile

without a valid authentication token may return:

401 Unauthorized

Common reasons include:

Token is missing
Token is invalid
Token has expired
Credentials are incorrect

Although the status code is called Unauthorized, it is mainly related to authentication.

What is 403 Forbidden?

HTTP status code 403 Forbidden usually means the user has been authenticated but does not have permission to access the requested resource.

For example:

User: John
Role: Employee

John tries to access:

/api/admin/users

The endpoint requires the Admin role.

The application knows who John is, but John does not have permission.

The server returns:

403 Forbidden

A simple way to remember this is:

401 = I cannot verify who you are.

403 = I know who you are, but you cannot access this.

Authentication is Not Authorization

One common security mistake is assuming that a logged-in user should automatically have access to everything.

That is not correct.

Imagine an application with:

5,000 users
50 managers
5 administrators

All 5,000 users may be authenticated.

But that does not mean all users should be able to access:

/admin/users
/admin/settings
/admin/payments
/admin/reports

Authentication confirms identity.

Authorization protects sensitive resources.

Secure applications normally need both.

Frontend Authorization Is Not Enough

Applications often hide buttons or pages based on the user's role.

For example, a React application may hide the Delete User button for normal users.

That is useful for the user experience, but it is not enough for security.

A user could still manually call:

DELETE /api/users/100

Therefore, authorization must also be checked on the backend.

The backend should always be the final authority when deciding whether a user is allowed to perform an action.

Authentication and Authorization in an API Request

Let's look at a complete API request.

A client sends:

GET /api/admin/reports

Authorization: Bearer <JWT_TOKEN>

The request may travel through the application like this:

Client
   ↓
HTTP Request
   ↓
Authentication Middleware
   ↓
Validate Token
   ↓
Identify User
   ↓
Authorization Middleware
   ↓
Check Role or Permission
   ↓
Controller
   ↓
Service
   ↓
Database
   ↓
HTTP Response

Authentication establishes the user's identity.

Authorization determines whether that user can access the requested resource.

Why Authentication Comes Before Authorization

Suppose an application needs to answer:

Does this user have Admin permission?

Before answering that question, the application needs to know:

Which user?

That is why authentication comes first.

Step 1

Who are you?
     ↓
Authentication


Step 2

What can you access?
     ↓
Authorization

This is also why ASP.NET Core applications normally use:

app.UseAuthentication();
app.UseAuthorization();

in this order.

Common Authentication and Authorization Mistakes

There are a few common mistakes developers should avoid.

Protecting the Login but Not the APIs

A login page may be secure, but individual APIs must also be protected.

Sensitive endpoints should have proper authorization checks.

Trusting the Frontend

Never rely only on the frontend to decide permissions.

A hidden button is not a security control.

The backend should always verify permissions.

Giving Too Many Permissions

Users should only receive the permissions required to perform their work.

For example, an employee who only needs to view reports should not have permission to delete users.

This follows the principle of least privilege.

Confusing 401 and 403

Remember:

401 → Authentication problem

403 → Authorization problem

Checking Roles Without Checking Identity

Authorization normally depends on authentication.

The application first identifies the user and then checks their roles or permissions.

Another Simple Example

Think about travelling by airplane.

At the airport, you show your passport.

Your passport proves who you are.

That is:

Authentication

Then you show your boarding pass.

Your boarding pass tells you which flight and seat you are allowed to use.

That is:

Authorization

So:

Passport
   ↓
Authentication

Boarding Pass
   ↓
Authorization

The same concept applies to web applications.

Authentication vs Authorization in One Sentence

If you ever forget the difference, just remember:

Authentication verifies the user. Authorization verifies the user's access.

Or even more simply:

Authentication = Who are you?

Authorization = What can you do?

Conclusion

Authentication and authorization are closely related, but they perform different jobs.

Authentication verifies the identity of a user using methods such as passwords, OTPs, JWT tokens, social login, or biometrics.

Authorization happens after authentication and decides which resources and operations the authenticated user can access.

The normal security flow is:

Request
   ↓
Authentication
   ↓
Identity Verified
   ↓
Authorization
   ↓
Permission Verified
   ↓
API / Application

In ASP.NET Core, authentication middleware identifies the user, while authorization middleware checks whether that user has permission to access a protected resource.

Understanding this difference is essential when building secure APIs, websites, mobile applications, and enterprise systems.

The simplest rule to remember is:

Authentication tells the application who you are.
Authorization tells the application what you are allowed to do.

ASP.NET Core 10.0 Hosting Recommendation

One of the most important things when choosing a good ASP.NET Core 9.0 hosting is the feature and reliability. HostForLIFE is the leading provider of Windows hosting and affordable ASP.NET Core, their servers are optimized for PHP web applications. The performance and the uptime of the hosting service are excellent and the features of the web hosting plan are even greater than what many hosting providers ask you to pay for. 

At HostForLIFE.eu, customers can also experience fast ASP.NET Core hosting. The company invested a lot of money to ensure the best and fastest performance of the datacenters, servers, network and other facilities. Its datacenters are equipped with the top equipments like cooling system, fire detection, high speed Internet connection, and so on. That is why HostForLIFEASP.NET guarantees 99.9% uptime for ASP.NET Core. And the engineers do regular maintenance and monitoring works to assure its Orchard hosting are security and always up.

Read More...

Monday, 7 September 2026

C# Access Specifiers: A Comprehensive Guide with Examples

Leave a Comment

In C#, access specifiers are used to specify whether types and their members are visible or accessible.
To put it simply, an access specifier establishes who may access a class, method, property, field, constructor, or other member, as well as from what location.

Let's take an example where a class has several methods. While certain methods may only be accessible inside the same class or within derived classes, others may need to be accessible to all classes in an application.


To manage this visibility and assist developers in implementing encapsulation, C# has access modifiers.

Take a look at this example:

public class Employee
{
    private string employeeName;

    public void SetEmployeeName(string name)
    {
        employeeName = name;
    }

    public string GetEmployeeName()
    {
        return employeeName;
    }
}

Here, employeeName is declared as private, so it cannot be accessed directly from outside the Employee class. The public methods provide controlled access to the value.

This is one of the fundamental concepts of object-oriented programming in C#.

Different Types of Access Specifiers in C#

C# provides six commonly used access modifiers:

  1. private

  2. public

  3. protected

  4. internal

  5. protected internal

  6. private protected

The private protected access modifier was introduced in C# 7.2.

The accessibility provided by these modifiers depends on whether the accessing code is located in the same class, the same assembly, or another assembly, and whether inheritance is involved.

1. Private Access Modifier

The private access modifier restricts access to the containing type.

A private member can be accessed from within the class where it is declared, but it cannot normally be accessed directly from derived classes or unrelated classes.

Example

public class Employee
{
    private string employeeName = "John";

    public void DisplayName()
    {
        Console.WriteLine(employeeName);
    }
}

The employeeName field can be accessed inside the Employee class:

Employee employee = new Employee();
employee.DisplayName();

But the following code is not allowed:

Employee employee = new Employee();

// Compile-time error
// employee.employeeName = "David";

Accessibility of a Private Member

Accessing Code

Accessible?

Containing class

Yes

Derived class in same assembly

No

Non-derived class in same assembly

No

Derived class in another assembly

No

Non-derived class in another assembly

No

private is useful when an implementation detail should be completely hidden from other types.

2. Public Access Modifier

The public access modifier provides the widest accessibility.

A public member can be accessed from code that can access the containing type, including code in other assemblies.

Example

public class Employee
{
    public string EmployeeName = "John";

    public void DisplayName()
    {
        Console.WriteLine(EmployeeName);
    }
}

The member can be accessed from another class:

Employee employee = new Employee();

Console.WriteLine(employee.EmployeeName);
employee.DisplayName();

It can also be accessed from a derived class:

public class Manager : Employee
{
    public void DisplayManagerName()
    {
        Console.WriteLine(EmployeeName);
    }
}

Accessibility of a Public Member

Accessing Code

Accessible?

Containing class

Yes

Derived class in same assembly

Yes

Non-derived class in same assembly

Yes

Derived class in another assembly

Yes

Non-derived class in another assembly

Yes

Public members should generally represent functionality that is intentionally exposed as part of a type's API.

3. Protected Access Modifier

The protected access modifier allows access within the containing type and from derived types.

Unlike public, a protected member cannot normally be accessed through an object from an unrelated class.

Example

public class Employee
{
    protected string employeeName = "John";
}

public class Manager : Employee
{
    public void DisplayName()
    {
        Console.WriteLine(employeeName);
    }
}

Manager can access employeeName because Manager derives from Employee.

However, an unrelated class cannot access it directly:

public class Test
{
    public void Display()
    {
        Employee employee = new Employee();

        // Compile-time error
        // Console.WriteLine(employee.employeeName);
    }
}

Accessibility of a Protected Member

Accessing Code

Accessible?

Containing class

Yes

Derived class in same assembly

Yes

Non-derived class in same assembly

No

Derived class in another assembly

Yes

Non-derived class in another assembly

No

protected is commonly used when a base class needs to expose implementation details to derived classes without making those details publicly accessible.

4. Internal Access Modifier

The internal access modifier restricts access to the current assembly.

An assembly is typically the compiled output of a .NET project, such as a .dll or .exe.

An internal member can be accessed by other types within the same assembly but not directly from another assembly.

Example

internal class Employee
{
    internal string EmployeeName = "John";
}

Another class in the same project can access it:

public class Department
{
    public void DisplayEmployee()
    {
        Employee employee = new Employee();

        Console.WriteLine(employee.EmployeeName);
    }
}

However, code in another assembly cannot directly access the internal type or member unless mechanisms such as InternalsVisibleTo are used.

Accessibility of an Internal Member

Accessing Code

Accessible?

Containing class

Yes

Derived class in same assembly

Yes

Non-derived class in same assembly

Yes

Derived class in another assembly

No

Non-derived class in another assembly

No

internal is useful when functionality needs to be shared among types within a project but should not form part of the project's public API.

5. Protected Internal Access Modifier

protected internal combines two accessibility conditions.

A member declared as protected internal can be accessed:

  • From anywhere within the same assembly, or

  • From a derived class, including a derived class in another assembly.

The important point is that this is effectively an OR relationship between protected and internal.

Example

public class Employee
{
    protected internal string EmployeeName = "John";
}

A class in the same assembly can access the member:

public class Department
{
    public void DisplayEmployee()
    {
        Employee employee = new Employee();

        Console.WriteLine(employee.EmployeeName);
    }
}

A derived class in another assembly can also access the member.

Accessibility of a Protected Internal Member

Accessing Code

Accessible?

Containing class

Yes

Derived class in same assembly

Yes

Non-derived class in same assembly

Yes

Derived class in another assembly

Yes

Non-derived class in another assembly

No

Because protected internal provides relatively broad access, it should be used when both same-assembly access and derived-type access are intentionally required.

6. Private Protected Access Modifier

The private protected access modifier provides more restricted access than protected internal.

A private protected member can be accessed only:

  • Within the containing type, or

  • From derived types that are located in the same assembly.

It was introduced in C# 7.2.

Example

public class Employee
{
    private protected string employeeName = "John";
}

public class Manager : Employee
{
    public void DisplayName()
    {
        Console.WriteLine(employeeName);
    }
}

The Manager class can access employeeName because it derives from Employee and is in the same assembly.

A derived class in another assembly cannot access the member.

Accessibility of a Private Protected Member

Accessing Code

Accessible?

Containing class

Yes

Derived class in same assembly

Yes

Non-derived class in same assembly

No

Derived class in another assembly

No

Non-derived class in another assembly

No

This modifier is useful when a base class wants to expose a member only to derived types that are part of the same assembly.

Access Modifier Comparison

The following table provides a quick comparison:

Access Modifier

Same Class

Same Assembly

Derived Type in Other Assembly

Non-Derived Type in Other Assembly

private

Yes

No

No

No

public

Yes

Yes

Yes

Yes

protected

Yes

No for unrelated types

Yes for derived types

No

internal

Yes

Yes

No

No

protected internal

Yes

Yes

Yes for derived types

No

private protected

Yes

Yes for derived types

No

No

The key distinction to remember is:

protected internal = protected OR internal

private protected = protected AND internal

This makes the difference between the two modifiers easier to understand.

Access Modifiers for Types

Access modifiers can also be applied to types such as classes, interfaces, structs, delegates, and enums, subject to the accessibility rules of each type.

For example:

public class Employee
{
}

The Employee class is publicly accessible.

An internal class can be declared as:

internal class Department
{
}

The Department type is accessible only within the same assembly.

For top-level types, private and protected are not valid access modifiers. They are primarily used for members and nested types.

Why Access Modifiers Are Important

Access modifiers are an important part of encapsulation.

They allow developers to decide which parts of a class should be exposed and which implementation details should remain hidden.

For example:

public class BankAccount
{
    private decimal balance;

    public void Deposit(decimal amount)
    {
        if (amount > 0)
        {
            balance += amount;
        }
    }

    public decimal GetBalance()
    {
        return balance;
    }
}

Here, balance is private. External code cannot directly change it:

BankAccount account = new BankAccount();

// Not allowed
// account.balance = -5000;

Instead, the class controls how the balance changes through the public Deposit method.

This helps protect the internal state of the object and keeps business rules inside the class.

Common Mistakes

Making Everything Public

A common beginner mistake is declaring every field and method as public.

For example:

public class Employee
{
    public string name;
    public decimal salary;
}

This exposes the internal state of the class unnecessarily.

A better approach is to expose only what other parts of the application actually need.

Confusing Protected and Internal

protected is primarily related to inheritance, while internal is related to the assembly boundary.

For example:

protected
    -> containing type + derived types

internal
    -> types within the same assembly

Understanding these two boundaries makes the other access modifiers much easier to understand.

Confusing Protected Internal and Private Protected

These two modifiers look similar but provide different levels of access.

protected internal
    = protected OR internal

private protected
    = protected AND internal

Therefore, protected internal is broader, while private protected is more restrictive.

Best Practices

When choosing an access modifier, consider the smallest scope required by the member.

Some general guidelines are:

  • Use private for implementation details that should remain inside the type.

  • Use public only when functionality needs to be exposed to consumers.

  • Use protected when derived classes need access to a member.

  • Use internal for functionality that should remain within the current assembly.

  • Use protected internal when both same-assembly access and derived-type access are required.

  • Use private protected when access should be limited to derived types within the same assembly.

  • Prefer encapsulation instead of exposing internal fields directly.

Conclusion

Access specifiers in C# provide a mechanism for controlling the accessibility and visibility of types and their members.

The six commonly used access modifiers are private, public, protected, internal, protected internal, and private protected.

Understanding the difference between these modifiers is important for designing classes with proper encapsulation and well-defined APIs.

For beginners, the easiest way to remember them is to focus on two boundaries: inheritance and assembly. Once these boundaries are clear, choosing the appropriate access modifier becomes much easier.

Best ASP.NET Core 10.0 Hosting Recommendation

One of the most important things when choosing a good ASP.NET Core 10.0 hosting is the feature and reliability. HostForLIFE is the leading provider of Windows hosting and affordable ASP.NET Core, their servers are optimized for PHP web applications. The performance and the uptime of the hosting service are excellent and the features of the web hosting plan are even greater than what many hosting providers ask you to pay for. 

At HostForLIFEASP.NET, customers can also experience fast ASP.NET Core hosting. The company invested a lot of money to ensure the best and fastest performance of the datacenters, servers, network and other facilities. Its datacenters are equipped with the top equipments like cooling system, fire detection, high speed Internet connection, and so on. That is why HostForLIFEASP.NET guarantees 99.9% uptime for ASP.NET Core. And the engineers do regular maintenance and monitoring works to assure its Orchard hosting are security and always up.
Read More...

Tuesday, 1 September 2026

How to Use WebSockets and Socket to Implement Real-Time Features.IO?

Leave a Comment

Real-time communication is necessary for contemporary applications including chat apps, live alerts, online gaming, and stock trading platforms. This implies that data should change immediately without requiring a page refresh.



WebSockets and frameworks like Socket.IO make this feasible.

Let's take a step-by-step look at how real-time communication functions and how to put it into practice.

What Are WebSockets?

Simple Explanation

WebSockets provide a persistent connection between client and server.

This means:

  • Data can be sent anytime

  • No need to request again and again

Real-Life Example

In WhatsApp:

  • Messages appear instantly

  • No page refresh needed

This uses WebSockets.

What Is Socket.IO?

Simple Explanation

Socket.IO is a library built on top of WebSockets that makes real-time communication easier.

Why Use Socket.IO

  • Handles connection automatically

  • Supports fallback methods

  • Easy to use for developers

How WebSockets Work

Step 1: Connection Establishment

Client connects to server using WebSocket protocol.

Step 2: Persistent Connection

Connection stays open for continuous communication.

Step 3: Data Exchange

Client and server send data anytime.

Step 4: Real-Time Updates

Data updates instantly on UI.

Step-by-Step Implementation Guide

Step 1: Setup Server

Use Node.js with Socket.IO.

Step 2: Create Client Connection

Connect frontend to server using socket.

Step 3: Listen for Events

Server listens for events like messages.

Step 4: Emit Events

Send data between client and server.

Example:
User sends message → server receives → sends to other users

Step 5: Update UI in Real Time

Display updates instantly on screen.

Real-World Use Cases

Chat Applications

Real-time messaging between users.

Live Notifications

Instant alerts for users.

Online Gaming

Real-time player actions.

Stock Market Apps

Live price updates.

Advantages

  • Real-time communication

  • Faster user experience

  • Reduces server load compared to polling

  • Supports scalable applications

Disadvantages

  • Requires persistent connection management

  • More complex than traditional HTTP

  • Scaling can be challenging

Summary

WebSockets and Socket.IO are essential technologies for building real-time web applications. They allow instant communication between client and server without refreshing the page. For developers in India and globally, mastering real-time features helps build modern applications like chat apps, live dashboards, and gaming platforms with smooth user experience.

Best ASP.NET Core 10.0 Hosting in Europe with 15% OFF Discount!

One of the most important things when choosing a good ASP.NET Core 10.0 hosting in Europe is the feature and reliability. Led by a team with expert who are familiar on ASP.NET technologies, HostForLIFE offers an array of both basic and advanced ASP.NET Core 10.0 features in the package at the same time, such as:


All of their Windows & ASP.NET Core 10.0 Hosting servers are located in state of the art data center facilities that provide 24 hour monitoring and security. You can rest assured that while we do aim to provide cheap Windows and ASP.NET Core 10.0 hosting, we have invested a great deal of time and money to ensure you get excellent uptime and optimal performance. While there are several ASP.NET Core 10.0 Hosting providers many of them do not provide an infrastructure that you would expect to find in a reliable Windows platform.


Read More...

Wednesday, 26 August 2026

Form for ASP.NET Core 11 Testing Static SSR Under Concurrent Requests for Validation

Leave a Comment

One of the components of a web application that appears straightforward until actual users begin submitting them simultaneously is the form. While the program is operating, dozens, hundreds, or thousands of requests may be sent to a registration form, checkout form, help request, or profile editor. Under that load, the server must continue producing replies without needless effort, and the validation logic must stay accurate.


An intriguing paradigm for this situation is provided by ASP.NET Core static server-side rendering. After receiving the request, the server processes the form, verifies the information entered, and returns HTML.

This article looks at form validation in a static SSR application and focuses on a practical question: what happens when multiple users submit forms concurrently?

The goal is not to claim a particular throughput number. Performance depends heavily on the application, hardware, database, network, and validation rules. Instead, we will build a reproducible testing approach and identify the areas worth measuring.

Understanding Static SSR Form Submission

With static SSR, the browser initially receives HTML generated by the server.

A simplified form flow looks like this:

Browser
   |
   | GET /register
   v
ASP.NET Core
   |
   | Render form
   v
HTML response
   |
   v
Browser
   |
   | POST form
   v
ASP.NET Core
   |
   | Validate
   v
Success / Validation response

The server remains responsible for processing the submitted form.

This makes the server-side validation path especially important.

A well-designed application should not depend only on browser-side validation because client-side validation can be bypassed.

Creating a Simple Static SSR Form

Consider a registration model:

using System.ComponentModel.DataAnnotations;

public class RegistrationModel
{
    [Required]
    [StringLength(100)]
    public string Name { get; set; } = string.Empty;

    [Required]
    [EmailAddress]
    public string Email { get; set; } = string.Empty;

    [Required]
    [MinLength(8)]
    public string Password { get; set; } = string.Empty;
}

A Razor component can expose the form:

@page "/register"

<EditForm Model="model" OnValidSubmit="HandleSubmit">
    <DataAnnotationsValidator />

    <ValidationSummary />

    <div>
        <label>Name</label>
        <InputText @bind-Value="model.Name" />
        <ValidationMessage For="@(() => model.Name)" />
    </div>

    <div>
        <label>Email</label>
        <InputText @bind-Value="model.Email" />
        <ValidationMessage For="@(() => model.Email)" />
    </div>

    <div>
        <label>Password</label>
        <InputText type="password"
                   @bind-Value="model.Password" />
        <ValidationMessage For="@(() => model.Password)" />
    </div>

    <button type="submit">Create Account</button>
</EditForm>

@code {
    private RegistrationModel model = new();

    private void HandleSubmit()
    {
        // Process valid form submission.
    }
}
Razor C#

The exact form configuration depends on the Blazor rendering mode and application architecture, but the principle is straightforward: validate the submitted model on the server before performing the business operation.

Why Server-Side Validation Matters

Consider a registration endpoint that performs this sequence:

Receive request
     |
     v
Validate input
     |
     v
Check business rules
     |
     v
Check database
     |
     v
Create account

If validation happens after expensive database operations, invalid requests can consume unnecessary resources.

A better approach is to reject obviously invalid input as early as possible.

For example:

if (string.IsNullOrWhiteSpace(model.Email))
{
    return;
}

if (!new EmailAddressAttribute().IsValid(model.Email))
{
    return;
}

In a real application, use the validation system consistently rather than duplicating validation rules throughout handlers.

Validation and Business Rules Are Different

Data annotations are useful for basic input validation.

For example:

[Required]
[StringLength(100)]
public string Name { get; set; } = string.Empty;

But business validation can be more complicated.

A registration process might require:

  • Email uniqueness

  • Account eligibility

  • Password policy

  • Organization membership

  • Invitation validation

Those checks usually require application or database access.

A useful validation pipeline is:

Input Validation
      |
      v
Business Validation
      |
      v
Database Validation
      |
      v
Business Operation

Keeping these stages separate makes the code easier to test and helps prevent unnecessary database calls.

Handling Concurrent Requests

Suppose 100 users submit the form at approximately the same time.

The server may process requests concurrently:

Request 1  ----\
Request 2  -----\
Request 3  ------> ASP.NET Core
Request 4  -----/
Request 5  ----/

The application should not store request-specific information in shared mutable state.

For example, this is dangerous:

public static RegistrationModel CurrentRegistration { get; set; }

Multiple requests can overwrite the same object.

Instead, keep request data local to the request:

public async Task ProcessRegistration(
    RegistrationModel model)
{
    // Work with this request's model.
}

This allows independent requests to be processed safely.

Avoiding Shared Mutable State

A common mistake in server-side applications is using a singleton service to hold data that belongs to an individual request.

For example:

builder.Services.AddSingleton<RegistrationState>();

If RegistrationState contains the current user's form data, concurrent requests can interfere with each other.

A better lifetime depends on what the service actually represents.

For request-specific work:

builder.Services.AddScoped<
    RegistrationService>();

The important rule is not simply "always use scoped."

It is:

Choose a service lifetime that matches the lifetime of the data it owns.

Testing Concurrent Form Submissions

A load-testing tool can generate concurrent HTTP requests.

For example, a simple HttpClient test can issue multiple requests:

var tasks = Enumerable.Range(0, 100)
    .Select(async index =>
    {
        var content = new FormUrlEncodedContent(
        [
            new("Name", $"User {index}"),
            new("Email", $"user{index}@example.com"),
            new("Password", "Password123")
        ]);

        return await client.PostAsync(
            "/register",
            content);
    });

var responses = await Task.WhenAll(tasks);

This is useful for a basic concurrency test, but it is not a replacement for a dedicated load-testing tool.

For serious performance testing, tools such as k6, JMeter, or another HTTP load-testing platform provide better control over concurrency, duration, ramp-up, and reporting.

Designing a Useful Load Test

Avoid immediately sending thousands of requests to an application.

Start with a small test and increase concurrency gradually.

For example:

10 concurrent requests
        |
        v
25 concurrent requests
        |
        v
50 concurrent requests
        |
        v
100 concurrent requests
        |
        v
Higher load if required

At each level, observe:

  • Response time

  • Error rate

  • CPU usage

  • Memory usage

  • Database activity

  • Request throughput

This helps identify where the application begins to struggle.

Testing Valid and Invalid Requests

A realistic test should not send only successful forms.

Include different request categories.

Request TypeExample
ValidComplete registration
Missing nameEmpty name
Invalid emailIncorrect format
Weak passwordToo short
Duplicate emailExisting account
Invalid business stateExpired invitation
Malformed requestUnexpected input

This is important because invalid requests should normally be cheaper to process than valid ones that reach database writes.

Testing Database Contention

Form validation frequently involves database queries.

For example:

var existingUser = await db.Users
    .SingleOrDefaultAsync(x => x.Email == model.Email);

if (existingUser is not null)
{
    // Return validation error.
}

Under concurrency, this query can become a bottleneck.

More importantly, checking for an existing email and then inserting a new user can introduce a race condition.

Two requests can perform:

Request A: Email does not exist
Request B: Email does not exist

Request A: Insert
Request B: Insert

Application-level validation alone does not guarantee uniqueness.

The database should enforce the actual invariant with a unique constraint or index.

For example:

CREATE UNIQUE INDEX ux_users_email
ON users (email);

The application can then handle a uniqueness violation gracefully.

Protecting Against Over-Validation

Validation itself can become expensive if every rule requires a database query.

Imagine a form with ten fields where each validator independently queries the database.

Under high concurrency, this can produce unnecessary database traffic.

Instead, group related checks where appropriate:

Request
  |
  +--> Basic validation
  |
  +--> One consolidated business validation stage
  |
  +--> Database operation

The goal is not to avoid database access completely.

The goal is to avoid repeated and unnecessary work.

Measuring Response Time

A load test should track multiple latency measurements.

For example:

Average response time
Median response time
95th percentile
99th percentile
Error rate
Requests per second

Percentiles are particularly useful.

An average response time can look healthy while a smaller group of requests experiences very long delays.

For example:

Most requests: fast
Some requests: very slow

The average can hide that difference.

Do not publish benchmark values unless they come from a controlled test environment.

Memory and CPU Under Load

Concurrent form submissions can increase both CPU and memory usage.

Monitor the application while increasing concurrency.

A simple test table might look like:

ConcurrencyRequestsError RateP95CPUMemory
10MeasureMeasureMeasureMeasureMeasure
25MeasureMeasureMeasureMeasureMeasure
50MeasureMeasureMeasureMeasureMeasure
100MeasureMeasureMeasureMeasureMeasure

The actual values depend entirely on the application and environment.

The purpose of the table is to make the test repeatable and easy to compare.

Common Mistakes

Trusting Client-Side Validation

Client-side validation improves user experience but should not be treated as a security boundary.

Always validate important input on the server.

Storing Request Data Globally

Shared mutable state can cause users' requests to interfere with each other.

Keep request-specific data scoped appropriately.

Relying Only on Application Checks

A "check then insert" operation is not enough to guarantee uniqueness under concurrency.

Use database constraints for database-level invariants.

Testing Only Successful Requests

Invalid requests can exercise completely different application paths.

Include both valid and invalid submissions.

Starting With Extreme Load

A huge concurrency test can make it difficult to understand where the problem started.

Increase load gradually.

Troubleshooting Slow Form Submissions

If response times increase as concurrency grows, investigate the entire request path.

Check:

  1. Validation logic.

  2. Database queries.

  3. Database connection pool usage.

  4. Lock contention.

  5. CPU utilization.

  6. Garbage collection.

  7. External service calls.

  8. Shared application state.

  9. Logging volume.

  10. Response generation.

If database time grows rapidly, inspect the SQL queries and database execution plans.

If CPU reaches saturation while database activity remains low, application-side processing may be the bottleneck.

If memory continually grows during the test, investigate object retention, caching, and resource disposal.

Best Practices

Validate Early

Reject invalid requests before performing expensive work.

Keep Request State Isolated

Do not use shared mutable state for user-specific form data.

Let the Database Enforce Invariants

Use unique constraints and other database constraints for rules that must remain true regardless of application behavior.

Test Realistic Workloads

Use representative form sizes, validation rules, database data, and concurrency levels.

Measure Percentiles

P95 and P99 latency often reveal problems that averages hide.

Monitor the Whole Stack

Application performance cannot be understood by looking only at the ASP.NET Core process.

Monitor the database and external dependencies as well.

Advantages

  • Static SSR provides a straightforward server-side request model.

  • Server-side validation keeps important business rules under application control.

  • Forms can be tested using standard HTTP load-testing tools.

  • Validation logic can be optimized independently from the UI.

  • Database constraints can protect important invariants under concurrent requests.

Disadvantages

  • Every submission requires server-side processing.

  • High concurrency can increase CPU, memory, and database pressure.

  • Expensive validation rules can become a bottleneck.

  • Incorrect service lifetimes can create concurrency problems.

  • Static SSR is not automatically faster simply because rendering happens on the server.

Conclusion

The real test starts when numerous users submit server-rendered forms at once, but static SSR provides ASP.NET Core apps with a simple paradigm for managing such forms.

A dependable solution allows the database to enforce important invariants like uniqueness, verifies input on the server, and isolates request-specific information.

Start with a low concurrency level and progressively raise it for performance testing. Instead of concentrating on just one statistic, measure response-time percentiles, error rates, CPU, memory, and database activities.

 Above all, test the application's real validation process. A form that does several database queries and external service requests behaves considerably differently from one that only has basic annotations.

Creating an impressive request-per-second figure is not the aim of concurrency testing. The goal is to pinpoint the precise area of the request pipeline that requires care and determine where the application begins to deteriorate.

Best ASP.NET Core 10.0 Hosting Recommendation

One of the most important things when choosing a good ASP.NET Core 8.0 hosting is the feature and reliability. HostForLIFE is the leading provider of Windows hosting and affordable ASP.NET Core, their servers are optimized for PHP web applications. The performance and the uptime of the hosting service are excellent and the features of the web hosting plan are even greater than what many hosting providers ask you to pay for. 

At HostForLIFE.eu, customers can also experience fast ASP.NET Core hosting. The company invested a lot of money to ensure the best and fastest performance of the datacenters, servers, network and other facilities. Its datacenters are equipped with the top equipments like cooling system, fire detection, high speed Internet connection, and so on. That is why HostForLIFEASP.NET guarantees 99.9% uptime for ASP.NET Core. And the engineers do regular maintenance and monitoring works to assure its Orchard hosting are security and always up.

 

Read More...

Tuesday, 18 August 2026

Comparing RoutingChatClient with Static Model Selection

Leave a Comment

More and more AI models are being used in contemporary.NET applications.

 

One program could be able to access:

A single application may have access to:

  • A high-capability model for complex reasoning

  • A faster model for simple requests

  • A lower-cost model for routine workloads

  • A specialized model for a particular task

  • A fallback model for availability problems

The engineering challenge is deciding which model should handle each request.

A static model-selection strategy is straightforward:

Application
    |
    v
Selected Model
    |
    v
Response

A routing strategy adds another decision layer:

Application
    |
    v
Routing Layer
    |
    +---- Model A
    +---- Model B
    +---- Model C
    |
    v
Response

The advantage is flexibility, but routing also introduces additional decision logic and potentially additional latency.

Microsoft.Extensions.AI provides the IChatClient abstraction and composable chat-client pipelines, which makes it possible to place routing, logging, retry, configuration, and other behaviors around AI clients. The current API also provides ChatClientBuilder and DelegatingChatClient as mechanisms for composing these pipelines.

This article explains how to benchmark a routing-based chat client against static model selection and determine whether routing actually improves the application's overall performance and economics.

Introduction

Suppose an application supports three request categories:

Simple Question
      |
      v
Fast Model

Complex Reasoning
      |
      v
Advanced Model

Fallback
      |
      v
Backup Model

A static strategy might send every request to the same model:

Every Request
      |
      v
Model A

A routing strategy might inspect the request and select a model:

+--> Model A
                     |
Request --> Router --+--> Model B
                     |
                     +--> Model C

The routing strategy can potentially improve cost, latency, or availability.

However, the router itself has a cost.

It may introduce:

  • Classification latency

  • Additional model calls

  • More complex configuration

  • More difficult debugging

  • Different behavior across workloads

Therefore, routing should be treated as an engineering hypothesis that needs to be benchmarked.

What Is Static Model Selection?

Static model selection means the application chooses the model before processing the request and does not dynamically change that choice.

For example:

IChatClient client = primaryClient;

var response = await client.GetResponseAsync(
    "Explain dependency injection in .NET.",
    cancellationToken: cancellationToken);
C#

The application knows exactly which client will process the request.

This approach is simple and predictable.

The execution path is:

Request
  |
  v
Static Selection
  |
  v
Model
  |
  v
Response

What Is Routing?

Routing introduces a decision mechanism between the application and the underlying model clients.

Request
   |
   v
Router
   |
   +--> Fast Model
   |
   +--> Capable Model
   |
   +--> Fallback Model

The router can use different strategies.

For example:

Request Complexity
      |
      +--> Simple ----> Fast Model
      |
      +--> Moderate -> Balanced Model
      |
      +--> Complex --> Advanced Model

Another strategy could use availability:

Primary Model
     |
     X
Unavailable
     |
     v
Fallback Model

A third strategy could combine both:

Complexity
    +
Cost
    +
Availability
    +
Latency
    |
    v
Model Selection

Microsoft.Extensions.AI and IChatClient

The IChatClient abstraction provides a common interface for chat model interactions. This allows application code to work against an abstraction instead of depending directly on a specific model implementation.

This is important for benchmarking because the application can execute the same workload against different client configurations.

For example:

public interface IModelExecutor
{
    Task<ChatResponse> ExecuteAsync(
        string prompt,
        CancellationToken cancellationToken);
}
C#

A static implementation can wrap one model.

A routing implementation can select among several models.

The benchmark can then compare both using the same test scenarios.

Static Selection Architecture

A simple static architecture looks like this:

Application
        |
        v
IChatClient
        |
        v
   Model A

The advantage is that there is almost no selection overhead.

The main limitation is that every request follows the same model path unless application code explicitly changes the client.

Routing Architecture

A routing architecture looks like this:

Application
             |
             v
       Routing Layer
             |
   +---------+---------+
   |         |         |
   v         v         v
Model A   Model B   Model C

The router becomes responsible for determining the target.

This can be implemented as a custom IChatClient wrapper or as a component in a chat-client pipeline.

DelegatingChatClient is specifically designed as a base type for clients that wrap another IChatClient, and the chat-client pipeline can be composed using ChatClientBuilder.Use(...).

Define the Benchmark Question

Before measuring anything, define what the benchmark is trying to prove.

For example:

Does dynamic routing reduce cost without causing unacceptable latency or quality degradation compared with static model selection?

That question produces several measurable dimensions:

Latency
Cost
Quality
Success Rate
Fallback Rate
Routing Accuracy
Throughput

Without a clear hypothesis, it is easy to produce a benchmark that generates numbers without providing an engineering conclusion.

Benchmark Scenarios

Use multiple workload categories.

Simple Requests

Examples:

What is dependency injection?

Convert this JSON into a C# record.

What does HTTP 404 mean?

Complex Requests

Examples:

Analyze this architecture and identify scalability risks.

Explain the tradeoffs between two distributed-system designs.

Review this code and identify concurrency problems.

Long-Context Requests

These contain larger amounts of input and can expose different model behavior.

Failure Scenarios

Simulate:

Timeout
Rate Limit
Unavailable Model
Invalid Response
Transient Network Failure

Routing should be evaluated not only when everything works but also when the preferred model fails.

Establish a Baseline

The first benchmark should use static selection.

For example:

All Requests
     |
     v
Model A

Measure:

p50 latency
p95 latency
p99 latency
Token usage
Cost
Success rate
Quality score

This becomes the baseline.

Then execute the same workload through the router.

All Requests
     |
     v
Router
     |
     +--> Model A
     +--> Model B
     +--> Model C

The two measurements can then be compared.

Benchmark Harness

Create a common interface.

public interface IBenchmarkClient
{
    string Name { get; }

    Task<BenchmarkResponse> ExecuteAsync(
        BenchmarkRequest request,
        CancellationToken cancellationToken);
}
C#

The request can contain:

public sealed record BenchmarkRequest(
    string Id,
    string Category,
    string Prompt);
C#

The response can contain:

public sealed record BenchmarkResponse(
    string RequestId,
    string Model,
    TimeSpan Latency,
    long InputTokens,
    long OutputTokens,
    bool Success);
C#

This provides a consistent measurement format.

Measure Latency

Use a monotonic timer.

var start = Stopwatch.GetTimestamp();

var response = await client.ExecuteAsync(
    request,
    cancellationToken);

var elapsed =
    Stopwatch.GetElapsedTime(start);
C#

This measures application-observed execution time.

Do not include unrelated operations such as loading the benchmark dataset or writing the final report inside the timed region.

Measure Routing Overhead Separately

Routing latency should not be hidden.

Consider:

Total Routed Latency
=
Routing Decision
+
Model Request
+
Response Processing

If routing itself requires another model call:

Total Latency
=
Router Model Call
+
Target Model Call

That additional call can be significant.

If routing is rule-based:

Total Latency
=
Rule Evaluation
+
Target Model Call

The difference can be substantial.

Therefore, capture routing time independently:

var routingStart = Stopwatch.GetTimestamp();

var target = await router.SelectAsync(
    request,
    cancellationToken);

var routingLatency =
    Stopwatch.GetElapsedTime(routingStart);
C#

Then measure the actual model request separately.

Benchmark Static Selection

A static benchmark might look like:

public async Task<BenchmarkResponse> RunStaticAsync(
    BenchmarkRequest request,
    IChatClient client,
    CancellationToken cancellationToken)
{
    var start = Stopwatch.GetTimestamp();

    var response = await client.GetResponseAsync(
        request.Prompt,
        cancellationToken: cancellationToken);

    var latency =
        Stopwatch.GetElapsedTime(start);

    return new BenchmarkResponse(
        request.Id,
        "static-model",
        latency,
        GetInputTokens(response),
        GetOutputTokens(response),
        true);
}
C#

The exact token-usage extraction depends on the provider and client implementation.

The benchmark should use the actual usage metadata available from the selected client rather than estimating token counts from string length.

Benchmark Routing

A routing benchmark follows the same measurement boundary:

public async Task<BenchmarkResponse> RunRoutedAsync(
    BenchmarkRequest request,
    IRoutingClient client,
    CancellationToken cancellationToken)
{
    var start = Stopwatch.GetTimestamp();

    var response = await client.GetResponseAsync(
        request.Prompt,
        cancellationToken);

    var latency =
        Stopwatch.GetElapsedTime(start);

    return new BenchmarkResponse(
        request.Id,
        response.Model,
        latency,
        response.InputTokens,
        response.OutputTokens,
        true);
}
C#

The important point is that both strategies receive the same benchmark request.

Rule-Based Routing

The simplest routing approach uses deterministic rules.

public string SelectModel(BenchmarkRequest request)
{
    return request.Category switch
    {
        "Simple" => "fast",
        "Complex" => "advanced",
        "LongContext" => "long-context",
        _ => "fast"
    };
}
C#

This has almost no classification overhead.

It is also easy to test.

The disadvantage is that rules can become increasingly complicated as workloads grow.

LLM-Based Routing

A more dynamic strategy can use a model to classify the request.

User Request
     |
     v
Routing Model
     |
     +--> Simple
     +--> Complex
     +--> Specialized
     |
     v
Target Model

This can be flexible but introduces an additional model operation.

For example:

Routing Decision = 80 ms
Target Model = 600 ms

Total = 680 ms

If static selection requires only:

Target Model = 600 ms

the router has made the request slower.

Routing must therefore generate enough savings elsewhere to justify its own overhead.

Benchmark Routing Accuracy

A routing system should also be evaluated for decision quality.

Create an expected model category for each benchmark request:

public sealed record RoutingExpectation(
    string RequestId,
    string ExpectedRoute);
C#

Then compare:

Expected Route
      vs
Selected Route

Calculate:

Routing Accuracy =
Correct Decisions
-----------------
Total Decisions

A router that selects the wrong model frequently may not produce the expected cost or quality benefits.

Measure Model Quality

Latency alone is not sufficient.

Suppose:

Static Model
Latency: 800 ms
Quality: 0.95

Routing
Latency: 650 ms
Quality: 0.86

Routing is faster, but the quality regression may be unacceptable.

Depending on the application, measure:

  • Task success rate

  • Structured-output validity

  • Groundedness

  • Answer relevance

  • Domain-specific correctness

  • Human evaluation

  • Retrieval quality for RAG workloads

The exact evaluation metric should match the application.

Cost Measurement

For each model request, capture:

Input Tokens
Output Tokens
Model
Pricing Version
Calculated Cost

Then aggregate by route.

Static Strategy
--------------
Total Cost
Average Cost
Cost Per Successful Task

Routing Strategy
----------------
Total Cost
Average Cost
Cost Per Successful Task

The most useful comparison is often:

Cost Per Successful Task

rather than simply cost per API request.

Example Cost Comparison

Imagine a benchmark produces:

MetricStatic SelectionRouting
Requests1,0001,000
Success Rate96%97%
p50 LatencyMeasureMeasure
p95 LatencyMeasureMeasure
Total TokensMeasureMeasure
Total CostMeasureMeasure
Cost / Successful TaskMeasureMeasure

The benchmark should populate these values from actual measurements.

Avoid inserting illustrative numbers into a production recommendation unless they come from a reproducible test.

Fallback Routing

Routing can also be used for resilience.

Primary Model
     |
     X
Failure
     |
     v
Fallback Model

A benchmark should measure:

Primary Success Rate
Fallback Rate
Fallback Latency
Final Success Rate

For example:

Request
  |
  v
Primary
  |
  X
  |
  v
Fallback
  |
  v
Response

The latency of the failed primary attempt should remain visible.

Otherwise, the fallback benchmark may appear faster than it actually is.

Routing and Retries

Retries introduce another variable.

Suppose the router sends a request to Model A.

Model A
   |
   X
Retry
   |
   X
Fallback Model

The final request may succeed, but the total cost includes both failed attempts.

Track:

Attempts
Models Used
Retry Count
Total Latency
Total Cost
Final Status

This provides a much more accurate picture of routing behavior.

Warm-Up Strategy

Do not use the first request as the only benchmark measurement.

Warm up each client before collecting steady-state measurements.

foreach (var client in clients)
{
    await client.ExecuteAsync(
        warmupRequest,
        cancellationToken);
}
C#

Then start collecting measurements.

Run cold-start tests separately if cold-start behavior matters to the production workload.

Run the Same Query Set

The static and routed systems should receive exactly the same workload.

Benchmark Dataset
       |
       +------> Static
       |
       +------> Router

Do not allow the router to receive easier questions than the static system.

A fixed dataset also makes regression testing easier.

Query Distribution Matters

Suppose the real application receives:

70% Simple
20% Moderate
10% Complex

but the benchmark contains:

20% Simple
30% Moderate
50% Complex

The resulting cost and latency numbers may not represent production.

Use a representative distribution.

If several workloads are important, benchmark them separately and report the results independently.

Concurrency Testing

A routing strategy can behave differently under load.

Test:

1 concurrent request
5 concurrent requests
10 concurrent requests
25 concurrent requests
50 concurrent requests

depending on service limits and the target workload.

Measure:

p50
p95
p99
Throughput
Error Rate
Route Distribution

A router that performs well at one request at a time may behave differently when multiple requests compete for the same model capacity.

Route Distribution

Record how frequently each model is selected.

For example:

Model A: 60%
Model B: 30%
Model C: 10%

This is important for cost analysis.

If the router unexpectedly sends 80% of requests to the expensive model, the expected savings may disappear.

Static vs Routing Comparison

A useful comparison table is:

DimensionStatic SelectionRouting
Implementation complexityLowMedium/High
Selection overheadMinimalDepends on strategy
Model flexibilityLowHigh
Cost optimizationLimitedPotentially strong
FailoverExplicit application logicCan be centralized
DebuggingSimpleMore complex
Observability requirementsModerateHigher
Workload adaptationLimitedStronger
PredictabilityHighDepends on routing policy

Routing is not automatically better.

It is better when the additional complexity produces measurable value.

Common Benchmarking Mistakes

Comparing Different Prompts

The workload must remain consistent.

Ignoring Router Latency

A routing decision is part of the request path.

Measuring Only Average Latency

Always examine tail latency.

Ignoring Routing Accuracy

A poor route can increase cost or reduce quality.

Using Only Simple Queries

Routing benefits often appear when workloads have meaningful variation.

Ignoring Failure Paths

Fallback behavior should be benchmarked explicitly.

Ignoring Cost of Retries

A successful fallback may still have incurred multiple failed model calls.

Comparing Different Model Configurations

Keep relevant settings consistent where the benchmark is intended to isolate routing behavior.

Treating Quality as Secondary

A cheaper or faster response is not necessarily a better response.

Observability

A routing system should record enough telemetry to explain every decision.

Useful attributes include:

TraceId
RequestId
SelectedModel
RoutingReason
RoutingLatency
ModelLatency
InputTokens
OutputTokens
RetryCount
FallbackUsed
EstimatedCost
Success

This allows engineers to answer:

Why did this request use Model B?
How long did routing take?
How much did the request cost?
Did fallback occur?
Was the response successful?

These questions become essential when debugging production behavior.

Building a Routing Wrapper

Because DelegatingChatClient is designed for wrapping an inner IChatClient, a custom routing abstraction can follow the same compositional pattern. The important design choice is to keep routing policy separate from model execution.

A simplified conceptual implementation could look like:

public sealed class RoutingChatClient
{
    private readonly IReadOnlyDictionary<string, IChatClient> _clients;
    private readonly IRoutingPolicy _policy;

    public RoutingChatClient(
        IReadOnlyDictionary<string, IChatClient> clients,
        IRoutingPolicy policy)
    {
        _clients = clients;
        _policy = policy;
    }

    public async Task<ChatResponse> GetResponseAsync(
        string prompt,
        CancellationToken cancellationToken)
    {
        var route = await _policy.SelectAsync(
            prompt,
            cancellationToken);

        var client = _clients[route.Model];

        return await client.GetResponseAsync(
            prompt,
            cancellationToken: cancellationToken);
    }
}
C#

This is a simplified example rather than a complete implementation of a production routing client.

In a real application, the routing layer should also handle:

  • Cancellation

  • Resilience

  • Telemetry

  • Model availability

  • Policy validation

  • Error classification

  • Fallback

  • Cost tracking

Composing the Client Pipeline

The ChatClientBuilder API supports composing intermediate chat-client stages. This allows routing-related behavior to coexist with logging, retries, options configuration, function invocation, and other middleware-like components.

A conceptual pipeline can look like:

Application
    |
    v
Routing
    |
    v
Logging
    |
    v
Retry
    |
    v
Model Client

The exact ordering should be chosen deliberately.

For example, placing telemetry around the routing layer can help measure routing decisions separately from downstream model latency.

Release Regression Testing

Once the benchmark works, run it automatically.

Code Change
    |
    v
Build
    |
    v
Benchmark Dataset
    |
    +--> Static Baseline
    |
    +--> Routing Strategy
    |
    v
Compare
    |
    +--> Latency
    +--> Cost
    +--> Quality
    +--> Reliability
    |
    v
Release Decision

For example:

Routing must satisfy:

p95 latency <= baseline + 20%
Quality >= baseline - 5%
Cost per successful task < baseline
Error rate <= baseline

The exact thresholds should be based on application requirements.

When Static Selection Is Better

Static model selection is often preferable when:

  • The workload is highly predictable.

  • One model already satisfies quality requirements.

  • Routing logic does not produce meaningful savings.

  • Simplicity is a major requirement.

  • The additional routing latency is unacceptable.

  • There are few model options.

A simpler architecture can be the better architecture.

When Routing Is Better

Routing becomes more attractive when:

  • Requests vary significantly in complexity.

  • Different models have different strengths.

  • Cost optimization is important.

  • Availability requirements justify fallback paths.

  • The application handles multiple workload classes.

  • The routing decision can be made reliably.

  • The operational team can observe and debug the routing behavior.

Advantages

Better Model Utilization

Different workloads can use different models.

Potential Cost Reduction

Simple requests can avoid unnecessarily expensive models.

Better Resilience

Fallback routing can improve availability when a preferred model fails.

Centralized Policy

Model-selection rules can be managed in one place.

Easier Model Evolution

New models can be introduced without rewriting every application workflow.

Disadvantages

Additional Complexity

Routing adds another component to the request path.

Routing Latency

A model-based router can add another AI operation.

Debugging Complexity

A response can depend on both the routing decision and the selected model.

More Telemetry

Engineers need visibility into route decisions, fallback, retries, and model usage.

Potential Quality Regression

An incorrect route can select a model that is cheaper or faster but less capable for the task.

Best Practices

  1. Establish a static-model baseline before evaluating routing.

  2. Use the same benchmark dataset for both strategies.

  3. Measure routing latency independently.

  4. Track p50, p95, and p99 latency.

  5. Measure routing accuracy.

  6. Track route distribution.

  7. Measure token consumption and cost.

  8. Include model quality in the benchmark.

  9. Test fallback and retry behavior separately.

  10. Run concurrency tests.

  11. Use realistic production query distributions.

  12. Keep model configuration consistent during controlled comparisons.

  13. Record routing decisions in telemetry.

  14. Compare cost per successful task rather than raw request cost alone.

  15. Automate benchmark execution as part of regression testing.

Frequently Asked Questions

Is RoutingChatClient always better than static model selection?

No. Routing introduces additional complexity and potentially additional latency. It should be used when dynamic model selection provides measurable value.

Does routing always reduce AI costs?

No. A router can increase costs if it adds another model call, selects expensive models too frequently, or causes additional retries.

Should routing be rule-based or AI-based?

Start with deterministic rules when they are sufficient. AI-based classification can provide more flexibility, but it introduces additional latency and evaluation complexity.

What should I measure when benchmarking routing?

At minimum, measure latency, cost, quality, routing accuracy, success rate, fallback rate, token usage, and route distribution.

Should the router itself be included in latency?

Yes. If the goal is to measure user-visible request latency, the routing decision is part of the request path and should be included in total latency. It should also be measured separately so its overhead is visible.

How can I prove that routing is worthwhile?

Compare routing with a static baseline using the same workload and evaluate whether it produces an acceptable improvement in cost, latency, reliability, or quality after accounting for routing overhead.

Conclusion

Dynamic model routing is an attractive architecture for applications that work with multiple AI models, but it should not be adopted simply because multiple models are available.

The right question is whether routing produces measurable value compared with a well-defined static baseline.

A useful benchmark evaluates the complete picture:

Routing Overhead
      +
Model Latency
      +
Cost
      +
Quality
      +
Reliability
      +
Fallback Behavior

A routing strategy may reduce cost for simple workloads, improve resilience during model failures, and select more capable models for complex requests. At the same time, it can introduce classification latency, additional operational complexity, and incorrect model selections.

The most reliable approach is therefore empirical: establish a static baseline, run the same workload through the routing strategy, measure p50/p95/p99 latency, cost, quality, route accuracy, and failure behavior, and then make the architecture decision from those results.

In production AI systems, model routing should be treated as a measurable optimization layer rather than an assumption that dynamic selection is automatically better.

Best ASP.NET Core 10.0 Hosting Recommendation

One of the most important things when choosing a good ASP.NET Core 8.0 hosting is the feature and reliability. HostForLIFE is the leading provider of Windows hosting and affordable ASP.NET Core, their servers are optimized for PHP web applications. The performance and the uptime of the hosting service are excellent and the features of the web hosting plan are even greater than what many hosting providers ask you to pay for. 

At HostForLIFE.eu, customers can also experience fast ASP.NET Core hosting. The company invested a lot of money to ensure the best and fastest performance of the datacenters, servers, network and other facilities. Its datacenters are equipped with the top equipments like cooling system, fire detection, high speed Internet connection, and so on. That is why HostForLIFEASP.NET guarantees 99.9% uptime for ASP.NET Core. And the engineers do regular maintenance and monitoring works to assure its Orchard hosting are security and always up.

Read More...