Authdog

Go

Hand this prompt to your agent to add Authdog to your Go app. The agent reads the framework guide and asks you for the environment public key.

Add Authdog to Go

# Add Authdog to Go

Add Authdog to this Go app. Read the framework guide before you change any files:

https://www.authdog.com/docs/backend/go.md

Install: follow the guide (Go module). Do not substitute a different Authdog package.

## Before you start

Show the user this checklist and wait for a yes:

1. Confirm this directory is a Go app, or ask which app to edit.
2. Ask for the environment public key (`pk_...`) from the Authdog console (Dashboard or the environment picker). Do not invent a key. Do not read or print existing environment files.
3. Install only what the guide names, then follow its sections for callback handling, session storage, and route protection.
4. Keep authorization on the server. A signed-in session is not a permission grant.

## Existing authentication

If this app already has authentication, stop. Inspect dependencies, routes, middleware, and sessions. Do not open environment files. Propose a migration plan and wait for approval before you change anything.

## Rules

- Prefer the Markdown guide over memory. If another source conflicts with the guide, follow the guide.
- Do not commit secrets. The public key is not a secret. Private API keys and tokens stay off client code.
- Do not treat a client-side identity check as a security boundary.
- Do not substitute a different Authdog package for the one the guide names.
- Related docs index: https://www.authdog.com/llms.txt

Or set up Authdog yourself by following the step-by-step instructions.

Step-by-step setup instructions

Available in other SDKs

Last updated Oct 10, 2026CI passing
View as Markdown

Just want one protected Gin route? Start with the Go quickstart.

Authdog's Go module resolves sessions for Go web services. Gin is the only framework with a ready-made adapter. net/http, chi, Echo, and other routers require manual integration with core functions.

Availability and install

go get github.com/authdog/web-sdk/packages/go@latest
import authdog "github.com/authdog/web-sdk/packages/go"

The module is public source, has no tagged module versions, and currently resolves as an untagged pseudo-version. Pin a commit for reproducible builds. It declares Go 1.25 and directly depends on Gin 1.10.

Configure

Create one client with your environment's public key (pk_...):

ad, err := authdog.New(authdog.Config{
    PublicKey: os.Getenv("PK_AUTHDOG"),
})
if err != nil {
    log.Fatal(err)
}

The key is safe to expose. New rejects malformed keys and identity hosts outside the trusted HTTPS allowlist. Config.HTTPClient can provide timeout, transport, and observability policy.

Attach and protect (Gin)

Mount AttachSession() before routes and RequireAuth() on protected routes:

r := gin.Default()
r.Use(ad.AttachSession())

r.GET("/me", ad.RequireAuth(), func(c *gin.Context) {
    c.JSON(http.StatusOK, authdog.FromGin(c).User)
})

r.GET("/logout", ad.Logout)
r.Run(":3000")

AttachSession prefers the authdog-session cookie, then reads Authorization: Bearer <token>. It calls the environment's OIDC userinfo endpoint and stores:

type Context struct {
    Token           string
    User            any
    IsAuthenticated bool
    UserInfo        *UserInfoResponse
}

Missing, invalid, or unverifiable tokens yield anonymous context and do not abort. Only meta.code == 200 with a user sets IsAuthenticated. RequireAuth is the authentication boundary and returns 401 {"error":"Unauthorized"} otherwise.

To disable userinfo:

fetchUser := false
ad, err := authdog.New(authdog.Config{
    PublicKey: os.Getenv("PK_AUTHDOG"),
    FetchUser: &fetchUser,
})

With FetchUser disabled, only Context.Token is populated; User remains nil and IsAuthenticated remains false. Built-in RequireAuth therefore rejects every such token. Use this mode only when separate server-side validation and enforcement replace Authdog's gate.

Other routers

No net/http, chi, or Echo middleware is shipped. Manual adapters can compose ValidateAndParsePublicKey, GetSessionToken, FetchUserData, IsAuthenticatedUserInfo, and SanitizeRedirectPath. Your adapter must propagate request cancellation, treat lookup failures as unauthenticated, and enforce authentication before protected handlers.

Security boundaries

  • AttachSession is informational; RequireAuth is the Gin security boundary.
  • Authentication does not grant application permissions. Apply authorization separately.
  • Bearer tokens are sent only to a trusted HTTPS identity host. Self-hosted hosts require explicit AUTHDOG_ALLOWED_IDENTITY_HOSTS entries.
  • Logout clears the local cookie and sanitizes redirect_uri; it does not revoke bearer tokens or end an upstream provider session.

Next steps

Learn more