Agentic Identity, Access Control, Observability.
Website · Docs · Pricing · Console · Status
Quick starters for Authdog on mainstream stacks. Copy one folder, set the public key, run the README.
Authentication is not authorization. A successful sign-in is not a permission grant.
Identity — session, cookie, or bearer. Who the caller is.
| Sample | Stack | What it shows |
|---|---|---|
authn/nextjs |
Next.js | Hosted Account portal, App Router callback, useUser |
authn/remix |
Remix | Hosted sign-in, identityLoader, HttpOnly cookies |
authn/express |
Express | Session attach and requireAuth gate |
authn/sveltekit |
SvelteKit | Handle hook, getUser, hosted sign-in |
authn/vue |
Vue | Browser identity with AuthdogProvider and userinfo |
authn/tanstack-start |
TanStack Start | Hosted sign-in and identityLoader |
authn/angular |
Angular | Standalone browser identity |
authn/astro |
Astro | SSR hosted sign-in |
authn/fastify |
Fastify | Plugin session and requireAuth preHandler |
authn/node |
Node.js | Bearer token validation with @authdog/node-commons |
authn/go |
Go | Gin session attach and RequireAuth gate |
authn/java |
Java | Bearer token validation (authdog-java-sdk, source-only) |
authn/csharp |
C# | Bearer token validation (Authdog.Sdk, source-only) |
authn/python |
Python | FastAPI require_auth gate (source-only extra) |
authn/expo |
Expo | Hosted sign-in, deep link, useUser |
authn/ios-swift |
Swift | REST / redirect bridge (no official SDK) |
authn/android-kotlin |
Kotlin | REST / redirect bridge (no official SDK) |
authn/flutter-dart |
Dart | REST / redirect bridge (no official SDK) |
One environment, one model. The check from your app stays the same. These starters take a validated identity and allow or deny.
| Sample | Stack | What it shows |
|---|---|---|
authz/nextjs |
Next.js | Server allow/deny after session (invoices:read) |
authz/remix |
Remix | Server allow/deny after identity |
authz/express |
Express | Server allow/deny after session |
authz/sveltekit |
SvelteKit | Load-function allow/deny |
authz/vue |
Vue | Browser UI hint only — pair with a server sample |
authz/tanstack-start |
TanStack Start | Server allow/deny after identity |
authz/angular |
Angular | Browser UI hint only — pair with a server sample |
authz/astro |
Astro | SSR page allow/deny |
authz/fastify |
Fastify | preHandler allow/deny |
authz/node |
Node.js | Token plus permission check |
authz/go |
Go | Server allow/deny after session (invoices:read) |
authz/java |
Java | Token plus permission check (source-only) |
authz/csharp |
C# | Token plus permission check (source-only) |
authz/python |
Python | FastAPI allow/deny after session (source-only) |
Do not check permissions in the client as the authorization boundary.
The identity event stream — webhooks push signed events; the Events API pulls them.
| Sample | Stack | What it shows |
|---|---|---|
observability/nextjs |
Next.js | Signed webhook receiver and Events API read |
observability/remix |
Remix | Signed webhook receiver and Events API read |
observability/express |
Express | Signed webhook receiver and Events API read |
observability/sveltekit |
SvelteKit | Signed webhook receiver and Events API read |
observability/vue |
Vue | Companion Node webhook receiver (SPA) |
observability/tanstack-start |
TanStack Start | Signed webhook receiver and Events API read |
observability/angular |
Angular | Companion Node webhook receiver (SPA) |
observability/astro |
Astro | Signed webhook receiver and Events API read |
observability/fastify |
Fastify | Signed webhook receiver and Events API read |
observability/node |
Node.js | Signed webhook receiver on node:http |
observability/go |
Go | Signed webhook receiver and Events API read |
observability/java |
Java | Standalone webhook receiver and Events API read |
observability/csharp |
C# | Standalone webhook receiver and Events API read |
observability/python |
Python | Signed webhook receiver and Events API read |
This is not Lidar. Lidar runs detectors inside Authdog and surfaces Signals in the console.
Identity SIEM — monitors, Signals, and a step-up challenge when a security-relevant event fires. Signals live in the console; there is no public Signals API.
| Sample | Stack | What it shows |
|---|---|---|
lidar/nextjs |
Next.js | React to the event stream with a challenge |
lidar/remix |
Remix | React to the event stream with a challenge |
lidar/express |
Express | React to the event stream with a challenge |
lidar/sveltekit |
SvelteKit | React to the event stream with a challenge |
lidar/vue |
Vue | Companion Node Lidar receiver (SPA) |
lidar/tanstack-start |
TanStack Start | React to the event stream with a challenge |
lidar/angular |
Angular | Companion Node Lidar receiver (SPA) |
lidar/astro |
Astro | React to the event stream with a challenge |
lidar/fastify |
Fastify | React to the event stream with a challenge |
lidar/node |
Node.js | React to the event stream on node:http |
lidar/go |
Go | React to the event stream with a challenge |
lidar/java |
Java | Standalone event-stream step-up |
lidar/csharp |
C# | Standalone event-stream step-up |
lidar/python |
Python | React to the event stream with a challenge |
On a stack that can enforce access on the server:
authn → authz → observability → lidar
| Wave | Stacks | Status |
|---|---|---|
| 3 | go, java, csharp, python |
Present (python extras are source-only) |
| 4 | expo, ios-swift, android-kotlin, flutter-dart |
authn present; observability and lidar planned. No authz/<stack> (pair with a server sample). Native stacks use the REST / redirect bridge until an official SDK ships |
| 5 | gatsby, redwood, react, rust |
Planned — react is UI-only (@authdog/react-elements); rust is source-only until a crate is published |
| Repo | What it is |
|---|---|
| web-sdk | Framework SDKs for web, mobile, and backends |
| sdk | Language SDKs for Authdog APIs |
| cli | Official CLI for management and identity services |
| agent-skills | Skills for agentic onboarding onto Authdog |
Point an agent at /llms.txt — every guide is also available as Markdown.
<concept>/<stack>/
README.md # required standalone quickstart
.env.example # placeholders only
Copy .specify/templates/sample-template.md.
Required README sections, in order: What this sample shows → What you
need first → Run → What to try → Gotchas → Next concept.
New concepts (MCP, agentic identity, and similar) need a Spec Kit feature before they get a top-level folder.
- Confirm the stack's wave may start (previous wave
authnrows are present or deferred). - Confirm
authn/<stack>exists before adding other concepts. - Copy
.specify/templates/sample-template.mdto<concept>/<stack>/README.md. - Keep the required sections in order. Use only real Authdog docs or
SDK surface. Client samples collect the public key (
pk_...) only. - Add
.env.examplewith placeholders if the sample needs env vars. Never commit.envor live keys. - Add a row to the listing above.
For a new kind of sample, a new concept, or a wave-membership
change, run /speckit-specify first.
This repo uses GitHub Spec Kit to govern layout, concepts, and waves.
- Constitution:
.specify/memory/constitution.md - Catalog feature:
specs/001-sample-catalog/ - How to iterate:
specs/README.md