Authdog

Express

Hand this prompt to your agent to add Authdog to your Express app. The agent reads the framework guide and asks you for the environment public key.

Add Authdog to Express

# Add Authdog to Express

Add Authdog to this Express app. Read the framework guide before you change any files:

https://www.authdog.com/docs/backend/express.md

Package: `@authdog/express`

## Before you start

Show the user this checklist and wait for a yes:

1. Confirm this directory is a Express app, or ask which app to edit.
2. Ask for the environment public key (`pk_...`) from the Authdog console (Dashboard or the environment picker). Do not invent a key. Do not read or print existing environment files.
3. Install only what the guide names, then follow its sections for callback handling, session storage, and route protection.
4. Keep authorization on the server. A signed-in session is not a permission grant.

## Existing authentication

If this app already has authentication, stop. Inspect dependencies, routes, middleware, and sessions. Do not open environment files. Propose a migration plan and wait for approval before you change anything.

## Rules

- Prefer the Markdown guide over memory. If another source conflicts with the guide, follow the guide.
- Do not commit secrets. The public key is not a secret. Private API keys and tokens stay off client code.
- Do not treat a client-side identity check as a security boundary.
- Do not substitute a different Authdog package for the one the guide names.
- Related docs index: https://www.authdog.com/llms.txt

Or set up Authdog yourself by following the step-by-step instructions.

Step-by-step setup instructions

Available in other SDKs

Last updated Oct 10, 2026npmlatestCI passing
View as Markdown

Just want one protected route? Start with the Express quickstart.

@authdog/express resolves Authdog sessions for Express 4 and 5. It reads a cookie or bearer token, checks it through the environment's OIDC userinfo endpoint, and exposes the result to route handlers.

Install

npm install @authdog/express express

@authdog/express is published on npm. express is a peer dependency (^4.18 or ^5); @authdog/node-commons installs automatically.

Configure

Create one client with your environment's public key (pk_...):

import express from "express"
import { createAuthdog } from "@authdog/express"

const app = express()
const authdog = createAuthdog({ publicKey: process.env.PK_AUTHDOG! })

The key is safe to expose. It is parsed at startup; malformed keys and identity hosts outside the trusted HTTPS allowlist fail immediately.

Attach the session

Mount attachSession() before routes:

app.use(authdog.attachSession())

It prefers the authdog-session cookie, then reads Authorization: Bearer <token>. A valid token requires a successful userinfo response (meta.code === 200 with a user). Missing, expired, malformed, or unverifiable tokens do not fail the request; they produce:

{
  token: string | null,
  user: unknown | null,
  isAuthenticated: boolean,
  userInfo?: UserInfoResponse | null,
}

attachSession({ fetchUser: false }) only surfaces the unverified token. It deliberately leaves user null and isAuthenticated false, so the built-in requireAuth rejects the request with 401. Use this option only when separate server-side validation and enforcement replace Authdog's gate.

Protect a route

attachSession only records context. requireAuth is the security boundary and returns 401 {"error":"Unauthorized"} unless isAuthenticated is true:

app.get("/me", authdog.requireAuth, (req, res) => {
  res.json(req.authdog!.user)
})

Authentication identifies a caller; it does not authorize actions. Apply your authorization checks after requireAuth. Client-side checks never protect server routes.

Sign out

logout expires the local cookie and redirects to a sanitized same-origin redirect_uri:

app.get("/logout", authdog.logout)

This does not revoke a bearer token or end an upstream identity-provider session.

Next steps

Learn more