Smallest FastAPI starter for Authdog identity using the source-only
authdog-fastapi extra. It is not on PyPI. Install a pinned
checkout of authdog/web-sdk
packages/python. session records context. require_auth on
GET /me is the identity gate.
Authentication (authn): who the caller is after a validated session.
This is a backend gate. Hosted sign-in still happens in a browser
(Account portal or a frontend SDK). Authentication is not
authorization.
Your authdog public key (pk_...), from the
authdog console → Project settings.
Never ask for or embed the secret key (sk_...).
Copy .env.example to .env and set PK_AUTHDOG. Export it in your
shell (export PK_AUTHDOG=pk_...) before you run the server.
Python 3.10+ is required.
python -m venv .venv
source .venv/bin/activate
python -m pip install -r requirements.txt
export PK_AUTHDOG=pk_...
uvicorn main:app --reload --port 3000requirements.txt installs the FastAPI extra from commit
06bb9cec0eaead7a4ce0a2228473e1ecdf79d0c5. Do not run
pip install authdog-fastapi from PyPI — that package is not
published.
curl -i http://localhost:3000/mewith no session. You should get401 {"detail":"Unauthorized"}(FastAPI'sHTTPExceptionshape).- Complete hosted sign-in, then send the session:
curl -i http://localhost:3000/me \
-H "Authorization: Bearer <token>"A valid authdog-session cookie also works. GET /logout expires the
local cookie and redirects.
- Not on PyPI yet: pin a source checkout with the
fastapiextra. Do not write a productionpip install authdog-fastapi. sessionis informational;require_authis the boundary: the session helper never raises on bad tokens. Userequire_authto gate.fetch_user=Falsemakesrequire_authreject everything: this sample does not use that option.- Logout is local only: it clears the cookie and redirects; it does not revoke a bearer token or end the upstream IdP session.
- Do not log access tokens.
- Bearer tokens go only to a trusted HTTPS identity host.
Authorization for this stack is Present: authz/python.
Apply
authorization
after require_auth. Do not treat /me as a permission check.