Authdog

Rust

Hand this prompt to your agent to add Authdog to your Rust app. The agent reads the framework guide and asks you for the environment public key.

Add Authdog to Rust

# Add Authdog to Rust

Add Authdog to this Rust app. Read the framework guide before you change any files:

https://www.authdog.com/docs/backend/rust.md

Install: follow the guide (Source available · crates.io release pending). Do not substitute a different Authdog package.

## Before you start

Show the user this checklist and wait for a yes:

1. Confirm this directory is a Rust app, or ask which app to edit.
2. Ask for the environment public key (`pk_...`) from the Authdog console (Dashboard or the environment picker). Do not invent a key. Do not read or print existing environment files.
3. Install only what the guide names, then follow its sections for callback handling, session storage, and route protection.
4. Keep authorization on the server. A signed-in session is not a permission grant.

## Existing authentication

If this app already has authentication, stop. Inspect dependencies, routes, middleware, and sessions. Do not open environment files. Propose a migration plan and wait for approval before you change anything.

## Rules

- Prefer the Markdown guide over memory. If another source conflicts with the guide, follow the guide.
- Do not commit secrets. The public key is not a secret. Private API keys and tokens stay off client code.
- Do not treat a client-side identity check as a security boundary.
- Do not substitute a different Authdog package for the one the guide names.
- Related docs index: https://www.authdog.com/llms.txt

Or set up Authdog yourself by following the step-by-step instructions.

Step-by-step setup instructions

Available in other SDKs

Last updated Oct 10, 2026CI passing
View as Markdown

Authdog's Rust source provides a shared session core and adapters for axum, actix-web, Rocket, warp, and Poem.

Availability

Unreleased: authdog-core, authdog-axum, authdog-actix, authdog-rocket, authdog-warp, and authdog-poem are not available on crates.io. Commands such as cargo add authdog-axum will fail.

Current code is source-only in the `packages/rust` workspace, versioned 0.1.0. Vendor or pin a repository commit and use Cargo path dependencies from that checkout. Do not rely on the unshipped crates.io version declarations in its manifests.

The workspace targets Rust 1.75+ and edition 2021. Current manifests integrate axum 0.8, actix-web 4, Rocket 0.5, warp 0.3, and Poem 3. Published compatibility and semver stability are not yet guaranteed.

Configure

Every adapter exports Authdog. Create one instance from your environment's public key (pk_...):

let authdog = Authdog::new(&std::env::var("PK_AUTHDOG")?)?;

The key is safe to expose. Construction rejects malformed keys and identity hosts outside the trusted HTTPS allowlist. A custom reqwest::Client can supply timeout, transport, and observability policy:

let authdog = Authdog::builder(&pk).http_client(client).build()?;

Each adapter resolves:

AuthContext {
    token: Option<String>,
    user: Option<serde_json::Value>,
    is_authenticated: bool,
    user_info: Option<UserInfoResponse>,
}

Resolution prefers the authdog-session cookie, then reads Authorization: Bearer <token>. Missing, invalid, or failed OIDC userinfo requests produce anonymous context. Only meta.code == 200 with a user sets is_authenticated.

Authdog::builder(&pk).fetch_user(false).build() only exposes the unverified token. user and user_info remain None, and is_authenticated remains false. Every built-in guard therefore rejects it; use this mode only when separate server-side validation and enforcement replace Authdog's gate.

Framework integration

Framework Optional session Authentication boundary Setup
axum AuthContext extractor after attach_session require_auth middleware Add state and from_fn_with_state(..., attach_session); layer guard on protected routes
actix-web AuthContext extractor RequireAuth extractor Register web::Data<Authdog>
Rocket AuthContext request guard RequireAuth guard Manage Authdog; register unauthorized catcher for JSON 401
warp with_session(authdog) filter require_auth(authdog) filter Recover Unauthorized with recover_unauthorized
Poem AuthContext extractor RequireAuth extractor Attach Authdog with .data(authdog)

Example axum wiring:

use authdog_axum::{attach_session, require_auth, AuthContext, Authdog};
use axum::{middleware, routing::get, Router};

let authdog = Authdog::new(&std::env::var("PK_AUTHDOG")?)?;
let app = Router::new()
    .route("/me", get(|ctx: AuthContext| async move { format!("{:?}", ctx.user) })
        .layer(middleware::from_fn(require_auth)))
    .layer(middleware::from_fn_with_state(authdog.clone(), attach_session))
    .with_state(authdog);

Security boundaries

  • Optional context is informational; each framework's guard above is the authentication boundary.
  • Authentication does not grant application permissions. Apply authorization separately.
  • Bearer tokens are sent only to a trusted HTTPS identity host. Self-hosted hosts require explicit AUTHDOG_ALLOWED_IDENTITY_HOSTS entries.
  • Logout handlers clear the local cookie and sanitize redirect_uri; they do not revoke bearer tokens or end an upstream provider session.

Next steps

Learn more