The intake service returns the waiting queue on `GET /intakes`. Anonymous callers are rejected.

Clone [starters/starlette](https://github.com/authdog/samples/tree/main/starters/starlette). SDK reference: [Starlette](/docs/backend/starlette).

`require_auth` is the identity gate. A signed-in session is not a permission grant. Apply [authorization](/docs/concepts/authorization) after the gate.

## What you need

| Requirement | Detail |
| --- | --- |
| Public key | `pk_...` from the [console](https://console.authdog.com) |
| Environment | Copy `.env.example` to `.env` and export `PK_AUTHDOG` |
| Secret key | Never put `sk_...` in the service |
| Package | Starlette extra is source in [authdog/web-sdk](https://github.com/authdog/web-sdk) `packages/python`. It is not the `authdog` package on PyPI. Python 3.10+ |
| Request | Hosted sign-in stays in a browser. Call `/intakes` with the `authdog-session` cookie or `Authorization: Bearer` |

## Run

```bash
python -m venv .venv
source .venv/bin/activate
python -m pip install -r requirements.txt
export PK_AUTHDOG=pk_...
uvicorn main:app --reload --port 3000
```

With a valid session the body includes `in_19` (Referral, waiting) and `in_20` (Follow-up, scheduled).

## Intakes

```python
# main.py
import os

from authdog.starlette import Authdog
from starlette.applications import Starlette
from starlette.responses import JSONResponse
from starlette.routing import Route

authdog = Authdog(public_key=os.environ["PK_AUTHDOG"])

async def intakes(request):
    user = await authdog.require_auth(request)
    return JSONResponse(
        {
            "caller": user,
            "intakes": [
                {"id": "in_19", "queue": "Referral", "status": "waiting"},
                {"id": "in_20", "queue": "Follow-up", "status": "scheduled"},
            ],
        }
    )

app = Starlette(
    routes=[Route("/intakes", intakes)],
    middleware=[authdog.middleware],
)
```

`fetch_user=False` leaves the caller anonymous, so `require_auth` rejects.
