The member site keeps the home page public and loads the member library only after userinfo accepts the session.

Clone [starters/sveltekit](https://github.com/authdog/samples/tree/main/starters/sveltekit). SDK reference: [SvelteKit](/docs/frameworks/sveltekit).

The library answers who the member is. It does not grant a permission. Apply [authorization](/docs/concepts/authorization) after `getUser`.

## What you need

| Requirement | Detail |
| --- | --- |
| Public key | `pk_...` from the [console](https://console.authdog.com) |
| Environment | Copy `.env.example` to `.env` and set `PUBLIC_AUTHDOG_PUBLIC_KEY` |
| Secret key | Never put `sk_...` in client code |
| Return URL | Account portal back to this app. Local: `http://localhost:5173/library` |
| Cookie | The server sets the HttpOnly `authdog-session` cookie after validating the token. Client bootstrap does not create it |

## Run

```bash
npm install
npm run dev
```

Open http://localhost:5173. Sign in, then open `/library`. You should see Benefits enrollment and Office map. Without a session, `/library` redirects home.

## Hook

`createAuthdogHandle` reads the cookie and sets `event.locals.authdog` on every request. `locals.authdog.isAuthenticated` means the cookie exists. It does not validate the token.

```ts
// src/hooks.server.ts
import { createAuthdogHandle } from "@authdog/sveltekit/server"

export const handle = createAuthdogHandle({
  publicKey: import.meta.env.PUBLIC_AUTHDOG_PUBLIC_KEY,
})
```

## Member library

`getUser` validates the cookie through userinfo. `getSession` returns the raw cookie and is not an authorization check.

```ts
// src/routes/library/+page.server.ts
import { createAuthdogServer } from "@authdog/sveltekit/server"
import { redirect } from "@sveltejs/kit"
import type { PageServerLoad } from "./$types"

const GUIDES = [
  { title: "Benefits enrollment", updated: "March" },
  { title: "Office map", updated: "January" },
]

const authdog = createAuthdogServer({
  publicKey: import.meta.env.PUBLIC_AUTHDOG_PUBLIC_KEY,
})

export const load: PageServerLoad = async ({ request }) => {
  const identity = await authdog.getUser(request).catch(() => null)
  if (!identity) throw redirect(302, "/")
  return { user: identity.user, guides: GUIDES }
}
```
