Authdog

SvelteKit

Hand this prompt to your agent to add Authdog to your SvelteKit app. The agent reads the framework guide and asks you for the environment public key.

Add Authdog to SvelteKit

# Add Authdog to SvelteKit

Add Authdog to this SvelteKit app. Read the framework guide before you change any files:

https://www.authdog.com/docs/frameworks/sveltekit.md

Package: `@authdog/sveltekit`

## Before you start

Show the user this checklist and wait for a yes:

1. Confirm this directory is a SvelteKit app, or ask which app to edit.
2. Ask for the environment public key (`pk_...`) from the Authdog console (Dashboard or the environment picker). Do not invent a key. Do not read or print existing environment files.
3. Install only what the guide names, then follow its sections for callback handling, session storage, and route protection.
4. Keep authorization on the server. A signed-in session is not a permission grant.

## Existing authentication

If this app already has authentication, stop. Inspect dependencies, routes, middleware, and sessions. Do not open environment files. Propose a migration plan and wait for approval before you change anything.

## Rules

- Prefer the Markdown guide over memory. If another source conflicts with the guide, follow the guide.
- Do not commit secrets. The public key is not a secret. Private API keys and tokens stay off client code.
- Do not treat a client-side identity check as a security boundary.
- Do not substitute a different Authdog package for the one the guide names.
- Related docs index: https://www.authdog.com/llms.txt

Or set up Authdog yourself by following the step-by-step instructions.

Step-by-step setup instructions

Available in other SDKs

Last updated Oct 10, 2026npmlatestCI passing
View as Markdown

The @authdog/sveltekit SDK provides a cookie-reading handle hook, server helpers, and a browser token bootstrap for SvelteKit.

Install

npm install @authdog/sveltekit

Requires @sveltejs/kit ^2. Expose your environment's public key (pk_...) as PUBLIC_AUTHDOG_PUBLIC_KEY (SvelteKit's PUBLIC_ prefix makes it readable via import.meta.env).

Add the handle hook

createAuthdogHandle reads the authdog-session cookie and populates event.locals.authdog on every request:

// src/hooks.server.ts
import { createAuthdogHandle } from "@authdog/sveltekit/server"

export const handle = createAuthdogHandle({
  publicKey: import.meta.env.PUBLIC_AUTHDOG_PUBLIC_KEY,
})

locals.authdog.isAuthenticated means only that the cookie exists. It does not validate the token.

Read the user in a load function

Call getUser(request) to validate the cookie through Authdog userinfo before granting access. getSession(request) returns the raw cookie value and performs no validation:

// src/routes/profile/+page.server.ts
import { createAuthdogServer } from "@authdog/sveltekit/server"

const authdog = createAuthdogServer({
  publicKey: import.meta.env.PUBLIC_AUTHDOG_PUBLIC_KEY,
})

export const load = async ({ request }) => {
  const identity = await authdog.getUser(request).catch(() => null)
  if (!identity) {
    return { user: null }
  }
  return { user: identity.user }
}

The server instance also exposes logout(request). Pair validated identity with authorization.

Client bootstrap

Run initAuthdog() once on mount to shape-check ?token=, store it in browser localStorage, strip the URL, and reload:

<!-- src/routes/+layout.svelte -->
<script>
  import { onMount } from "svelte"
  import { initAuthdog } from "@authdog/sveltekit/client"
  onMount(() => initAuthdog())
</script>

This bootstrap does not create the server's authdog-session cookie. For server-side authentication, your callback/backend must set that cookie as HttpOnly, Secure, and SameSite after validating the token. clearAuthdogToken() clears only browser storage; authdog.logout(request) clears the server cookie.

Next steps

Learn more