Smallest FastAPI starter for Authdog observability: a signed-webhook receiver and an Events API read path. There is no official Python observability SDK — this sample uses the documented HMAC and REST surface. It does not install the source-only identity extra.
Observability: consuming the identity event stream. Webhooks push signed events to you; the Events API pulls them with cursor pagination. This is not Lidar — Lidar runs detectors inside Authdog and surfaces Signals in the console.
- An API token (
AUTHDOG_API_TOKEN) scoped to read events. - A webhook signing secret (
AUTHDOG_WEBHOOK_SECRET) from the notification channel you create in the console. - Your tenant and environment IDs.
All four are server-only secrets. Copy .env.example to .env.
Export them before you run the server.
Python 3.10+ is required.
python -m venv .venv
source .venv/bin/activate
python -m pip install -r requirements.txt
export AUTHDOG_API_TOKEN=... AUTHDOG_WEBHOOK_SECRET=... \
AUTHDOG_TENANT_ID=... AUTHDOG_ENVIRONMENT_ID=...
uvicorn main:app --reload --port 3000- Create a webhook channel pointing at
https://<your-tunnel>/webhooks/authdog(use a tunnel for local delivery), then send a test event. The server logs the verified event type and delivery ID. curl http://localhost:3000/events→ the first page of events and the opaqueaftercursor.- Send a delivery with a bad signature →
401 Invalid signature.
- Raw body first:
await request.body()keeps the exact bytes. Parsing JSON first breaks verification. - Verification order is fixed: raw body → parse
t/v1→ reject stalet(5-minute tolerance) → HMAC → constant-time compare → only then parse JSON. - Idempotency: this sample dedupes on
X-Authdog-Delivery-Idin memory — use a durable store in production. - The signing secret is sensitive: restrict the API token, never expose it to a browser, and don't log it.
- SIEM forwarding is not Lidar.
Lidar integration for this stack is Present: lidar/python.