The inventory API returns stock on `GET /skus`. Anonymous callers get 401.

Clone [starters/fastify](https://github.com/authdog/samples/tree/main/starters/fastify). SDK reference: [Fastify](/docs/backend/fastify).

`requireAuth` on `GET /skus` is the identity gate. A signed-in session is not a permission grant. Apply [authorization](/docs/concepts/authorization) after the gate.

## What you need

| Requirement | Detail |
| --- | --- |
| Public key | `pk_...` from the [console](https://console.authdog.com) |
| Environment | Copy `.env.example` to `.env` and set `PK_AUTHDOG` |
| Secret key | Never put `sk_...` in the service |
| Request | Hosted sign-in stays in a browser. Call `/skus` with the `authdog-session` cookie or `Authorization: Bearer` |

## Run

```bash
npm install
npm run dev
```

`GET /skus` with no session returns 401. With a valid session it returns `KIT-1` (Field kit, 42 on hand) and `SNS-9` (Spare sensor, 7 on hand), plus the Authdog user.

## Stock

```ts
// src/index.ts
import Fastify from "fastify"
import { authdogPlugin } from "@authdog/fastify"

const app = Fastify({ logger: true })
await app.register(authdogPlugin, { publicKey: process.env.PK_AUTHDOG! })

app.get(
  "/skus",
  { preHandler: app.authdog.requireAuth },
  async (req) => ({
    caller: req.authdog!.user,
    skus: [
      { sku: "KIT-1", name: "Field kit", onHand: 42 },
      { sku: "SNS-9", name: "Spare sensor", onHand: 7 },
    ],
  }),
)
```
