Each app below is a small product with Authdog on the private surface. Open one to see the screen or route the sample actually serves, then clone the same folder from authdog/samples under starters/.
A signed-in session is not a permission grant. Apply authorization after the identity check.
Frontend
- Team dashboard — Next.js. Project status for the signed-in member. Billing, Mobile, and Docs render only after userinfo accepts the session.
- Customer navbar — React Elements. Shop catalog under a navbar that opens hosted sign-in. Orders stay on a server app that holds the session.
- Support inbox — Remix. Customer tickets on
/inbox. The loader redirects anonymous agents before the list renders. - Field companion — React Native / Expo. Today's site visits after a deep-link return. The job list renders only after userinfo accepts the token in secure storage.
- Member site — SvelteKit. Public home, member library on
/library.getUserredirects anonymous readers before the guides load. - Ops console — TanStack Start. Open incidents for the on-call operator. Anonymous visitors see the sign-in link and no incident rows.
- Workspace settings — Vue. Workspace name, timezone, and join notification after hosted sign-in. The fields stay hidden until userinfo returns a user.
- Admin console — Angular. Team directory on
/directory. The route guard keeps the list off screen untilfetchUserreturns a user. - Handbook — Astro. Public chapters on the home page. Member chapters on
/handbookload only aftergetUseraccepts the session. - Resource library — Gatsby. Titles on the public page.
GET /api/filesreturns the board pack and runbook only afterrequireAuth. - Job board — RedwoodJS. Listings stay public. The applications function returns candidates only after
requireAuth.
Backend
- Orders API — Express.
GET /ordersreturns open orders for the signed-in clerk and 401 for everyone else. - Inventory API — Fastify.
GET /skusreturns on-hand stock for the signed-in clerk and 401 for everyone else. - Booking API — FastAPI.
GET /bookingsreturns room reservations. Routes without a session return 401. - Clinic portal — Django.
GET /appointmentsreturns today's clinic slots. Anonymous callers are rejected. - Status board — Flask.
GET /publishes component state.GET /notesreturns the internal timeline only with a session. - Intake service — Starlette.
GET /intakesreturns the waiting queue. Anonymous callers are rejected. - Event ingest — aiohttp.
GET /eventsreturns recent door and check-in events. Handlers without a session are rejected. - Billing service — Go.
GET /invoicesreturns open and paid invoices. Gin returns 401 unless Authdog authenticates the caller. - Policy service — Rust.
GET /policiesreturns shipping and refund rules. The Axum gate returns 401 without a session.