Authdog

Astro

Hand this prompt to your agent to add Authdog to your Astro app. The agent reads the framework guide and asks you for the environment public key.

Add Authdog to Astro

# Add Authdog to Astro

Add Authdog to this Astro app. Read the framework guide before you change any files:

https://www.authdog.com/docs/frameworks/astro.md

Package: `@authdog/astro`

## Before you start

Show the user this checklist and wait for a yes:

1. Confirm this directory is a Astro app, or ask which app to edit.
2. Ask for the environment public key (`pk_...`) from the Authdog console (Dashboard or the environment picker). Do not invent a key. Do not read or print existing environment files.
3. Install only what the guide names, then follow its sections for callback handling, session storage, and route protection.
4. Keep authorization on the server. A signed-in session is not a permission grant.

## Existing authentication

If this app already has authentication, stop. Inspect dependencies, routes, middleware, and sessions. Do not open environment files. Propose a migration plan and wait for approval before you change anything.

## Rules

- Prefer the Markdown guide over memory. If another source conflicts with the guide, follow the guide.
- Do not commit secrets. The public key is not a secret. Private API keys and tokens stay off client code.
- Do not treat a client-side identity check as a security boundary.
- Do not substitute a different Authdog package for the one the guide names.
- Related docs index: https://www.authdog.com/llms.txt

Or set up Authdog yourself by following the step-by-step instructions.

Step-by-step setup instructions

Available in other SDKs

Last updated Oct 10, 2026npmlatestCI passing
View as Markdown

The @authdog/astro SDK provides cookie-reading middleware, userinfo-backed server validation, logout, and a browser token bootstrap for SSR-capable Astro sites.

Install

npm install @authdog/astro

Requires Astro ^5 or ^6 with SSR enabled (output: "server" or "hybrid"). The package ships @authdog/astro/server and @authdog/astro/client.

Add the middleware

authdogMiddleware populates Astro.locals.authdog ({ session, isAuthenticated }) on every request. session is the raw authdog-session cookie, and isAuthenticated means only that this cookie exists:

// src/middleware.ts
import { defineMiddleware } from "astro:middleware"
import { authdogMiddleware } from "@authdog/astro/server"

export const onRequest = defineMiddleware(
  authdogMiddleware({
    publicKey: import.meta.env.PUBLIC_AUTHDOG_PUBLIC_KEY ?? "",
  }),
)

Declare the locals type in src/env.d.ts:

declare namespace App {
  interface Locals {
    authdog: import("@authdog/astro/server").AuthdogLocals
  }
}

Read the user in a page

createAuthdogServer().getUser() validates the cookie through Authdog userinfo. Use that result, not the middleware boolean, as the authentication decision:

---
import { createAuthdogServer } from "@authdog/astro/server"

const authdog = createAuthdogServer({
  publicKey: import.meta.env.PUBLIC_AUTHDOG_PUBLIC_KEY ?? "",
})

const profile = await authdog.getUser(Astro.request).catch(() => null)
if (!profile) {
  return Astro.redirect("/sign-in")
}
---

<p>Signed in as {profile.user.emails?.[0]?.value}</p>

Sign out

Expose an endpoint that calls authdog.logout, which clears the cookie and redirects:

// src/pages/api/logout.ts
import type { APIRoute } from "astro"
import { createAuthdogServer } from "@authdog/astro/server"

const authdog = createAuthdogServer({
  publicKey: import.meta.env.PUBLIC_AUTHDOG_PUBLIC_KEY ?? "",
})

export const GET: APIRoute = ({ request }) => authdog.logout(request)

Client bootstrap

Run initAuthdog() once on the client to shape-check ?token=, store it in localStorage, remove it from the URL, and reload:

<script>
  import { initAuthdog } from "@authdog/astro/client"
  initAuthdog()
</script>

This browser bootstrap does not create the server's authdog-session cookie. Your callback/backend must validate the token and set that cookie as HttpOnly, Secure, and SameSite; the package does not include that exchange. Pair validated identity with authorization.

Next steps

Learn more