The event ingest service returns recent events on `GET /events`. Handlers without a session are rejected.

Clone [starters/aiohttp](https://github.com/authdog/samples/tree/main/starters/aiohttp). SDK reference: [aiohttp](/docs/backend/aiohttp).

`require_auth` is the identity gate. A signed-in session is not a permission grant. Apply [authorization](/docs/concepts/authorization) after the gate.

## What you need

| Requirement | Detail |
| --- | --- |
| Public key | `pk_...` from the [console](https://console.authdog.com) |
| Environment | Copy `.env.example` to `.env` and export `PK_AUTHDOG` |
| Secret key | Never put `sk_...` in the service |
| Package | aiohttp extra is source in [authdog/web-sdk](https://github.com/authdog/web-sdk) `packages/python`. It is not the `authdog` package on PyPI. Python 3.10+ |
| Request | Hosted sign-in stays in a browser. Call `/events` with the `authdog-session` cookie or `Authorization: Bearer` |

## Run

```bash
python -m venv .venv
source .venv/bin/activate
python -m pip install -r requirements.txt
export PK_AUTHDOG=pk_...
python main.py
```

With a valid session the body includes `evt_3` (`door.opened`) and `evt_4` (`checkin.completed`).

## Events

```python
# main.py
import os

from aiohttp import web
from authdog.aiohttp import Authdog

authdog = Authdog(public_key=os.environ["PK_AUTHDOG"])

@authdog.require_auth
async def events(request):
    ctx = await authdog.session(request)
    return web.json_response(
        {
            "caller": ctx.user,
            "events": [
                {"id": "evt_3", "source": "badge-reader", "name": "door.opened"},
                {"id": "evt_4", "source": "kiosk", "name": "checkin.completed"},
            ],
        }
    )

app = web.Application(middlewares=[authdog.middleware])
app.router.add_get("/events", events)
```
