Authdog

Fastify

Hand this prompt to your agent to add Authdog to your Fastify app. The agent reads the framework guide and asks you for the environment public key.

Add Authdog to Fastify

# Add Authdog to Fastify

Add Authdog to this Fastify app. Read the framework guide before you change any files:

https://www.authdog.com/docs/backend/fastify.md

Package: `@authdog/fastify`

## Before you start

Show the user this checklist and wait for a yes:

1. Confirm this directory is a Fastify app, or ask which app to edit.
2. Ask for the environment public key (`pk_...`) from the Authdog console (Dashboard or the environment picker). Do not invent a key. Do not read or print existing environment files.
3. Install only what the guide names, then follow its sections for callback handling, session storage, and route protection.
4. Keep authorization on the server. A signed-in session is not a permission grant.

## Existing authentication

If this app already has authentication, stop. Inspect dependencies, routes, middleware, and sessions. Do not open environment files. Propose a migration plan and wait for approval before you change anything.

## Rules

- Prefer the Markdown guide over memory. If another source conflicts with the guide, follow the guide.
- Do not commit secrets. The public key is not a secret. Private API keys and tokens stay off client code.
- Do not treat a client-side identity check as a security boundary.
- Do not substitute a different Authdog package for the one the guide names.
- Related docs index: https://www.authdog.com/llms.txt

Or set up Authdog yourself by following the step-by-step instructions.

Step-by-step setup instructions

Available in other SDKs

Last updated Oct 10, 2026npmlatestCI passing
View as Markdown

@authdog/fastify resolves Authdog sessions on Fastify 4 and 5. Its plugin decorates requests with session context and exposes an authentication guard.

Install

npm install @authdog/fastify fastify

@authdog/fastify is published on npm. fastify is a peer dependency (^4 or ^5); @authdog/node-commons and fastify-plugin install automatically. @fastify/cookie is not required.

Register the plugin

Register once with your environment's public key (pk_...):

import Fastify from "fastify"
import { authdogPlugin } from "@authdog/fastify"

const app = Fastify()
await app.register(authdogPlugin, { publicKey: process.env.PK_AUTHDOG! })

The key is safe to expose. Registration rejects malformed keys and identity hosts outside the trusted HTTPS allowlist.

On each request, the plugin prefers the authdog-session cookie, then reads Authorization: Bearer <token>. It calls the environment's OIDC userinfo endpoint and sets request.authdog to { token, user, isAuthenticated }. Only a success envelope (meta.code === 200 with a user) authenticates the request. Missing, invalid, or unverifiable tokens yield anonymous context instead of an application error.

fetchUserInfo: false skips userinfo but does not authenticate token presence. token may be set while user remains null and isAuthenticated remains false. Built-in requireAuth therefore returns 401; use this option only with separate server-side validation and enforcement.

Protect a route

Use app.authdog.requireAuth as a preHandler. It is the security boundary and returns 401 {"error":"Unauthorized"} for anonymous context:

app.get(
  "/me",
  { preHandler: app.authdog.requireAuth },
  async (req) => req.authdog!.user,
)

Authentication identifies a caller; it does not authorize actions. Apply authorization checks after this guard. Client-side checks never protect server routes.

Sign out

app.authdog.logout clears the local cookie and redirects to a sanitized same-origin redirect_uri:

app.get("/logout", (req, reply) => app.authdog.logout(req, reply))

This does not revoke a bearer token or end an upstream identity-provider session.

Next steps

Learn more