Authdog

RedwoodJS

Hand this prompt to your agent to add Authdog to your RedwoodJS app. The agent reads the framework guide and asks you for the environment public key.

Add Authdog to RedwoodJS

# Add Authdog to RedwoodJS

Add Authdog to this RedwoodJS app. Read the framework guide before you change any files:

https://www.authdog.com/docs/frameworks/redwood.md

Package: `@authdog/redwood`

## Before you start

Show the user this checklist and wait for a yes:

1. Confirm this directory is a RedwoodJS app, or ask which app to edit.
2. Ask for the environment public key (`pk_...`) from the Authdog console (Dashboard or the environment picker). Do not invent a key. Do not read or print existing environment files.
3. Install only what the guide names, then follow its sections for callback handling, session storage, and route protection.
4. Keep authorization on the server. A signed-in session is not a permission grant.

## Existing authentication

If this app already has authentication, stop. Inspect dependencies, routes, middleware, and sessions. Do not open environment files. Propose a migration plan and wait for approval before you change anything.

## Rules

- Prefer the Markdown guide over memory. If another source conflicts with the guide, follow the guide.
- Do not commit secrets. The public key is not a secret. Private API keys and tokens stay off client code.
- Do not treat a client-side identity check as a security boundary.
- Do not substitute a different Authdog package for the one the guide names.
- Related docs index: https://www.authdog.com/llms.txt

Or set up Authdog yourself by following the step-by-step instructions.

Step-by-step setup instructions

Available in other SDKs

Last updated Oct 10, 2026npmlatestCI passing
View as Markdown

The @authdog/redwood SDK provides browser callback utilities and an API-side requireAuth gate for RedwoodJS Functions and services.

Install

yarn workspace web add @authdog/redwood @authdog/react-elements
yarn workspace api add @authdog/redwood

Requires React 18 or 19. The package exposes @authdog/redwood/web and @authdog/redwood/api.

Handle the web callback

// web/src/App.tsx
import { useEffect } from "react"
import { initAuthdog } from "@authdog/redwood/web"
import { RedwoodProvider } from "@redwoodjs/web"
import Routes from "src/Routes"

const App = () => {
  useEffect(() => {
    initAuthdog()
  }, [])

  return (
    <RedwoodProvider titleTemplate="%PageTitle | %AppTitle">
      <Routes />
    </RedwoodProvider>
  )
}

initAuthdog() strips ?token=, stores values that match JWT structure in localStorage, and reloads. This is not cryptographic validation. The exported AuthdogProvider only strips the token and reloads; it does not persist or exchange it, so do not wrap this bootstrap with that provider. Expose browser configuration as REDWOOD_ENV_AUTHDOG_PUBLIC_KEY and add it to includeEnvironmentVariables in redwood.toml.

Protect a Function

On the api side, createAuthdog uses your environment's public key (pk_..., server-only via PK_AUTHDOG). requireAuth accepts either Authorization: Bearer <token> or an authdog-session cookie, validates it through userinfo, returns 401 on failure, and attaches event.authdog on success:

// api/src/functions/me.ts
import { createAuthdog } from "@authdog/redwood/api"
import type { LambdaEvent } from "@authdog/redwood/api"

const authdog = createAuthdog({ publicKey: process.env.PK_AUTHDOG! })

export const handler = authdog.requireAuth(async (event: LambdaEvent) => ({
  statusCode: 200,
  headers: { "Content-Type": "application/json" },
  body: JSON.stringify({ user: event.authdog?.user ?? null }),
}))

Send the stored token when calling the Function:

import { initAuthdog } from "@authdog/redwood/web"

const token = initAuthdog()
const response = await fetch("/.redwood/functions/me", {
  headers: token ? { Authorization: `Bearer ${token}` } : {},
})

The SDK does not create authdog-session; if you prefer an HttpOnly cookie, implement a server callback that validates the token before setting it.

Re-export the logout handler to clear authdog-session:

// api/src/functions/logout.ts
export { logoutHandler as handler } from "@authdog/redwood/api"

In services, resolve the user from the GraphQL context: await authdog.getUser(context.event).

When using the bearer/local-storage flow, also call clearAuthdogToken() in the browser. Treat requireAuth on the api side as the security boundary and pair it with your authorization model.

Next steps

Learn more