Authdog.Sdk 0.2.0 is the official C# client for the Authdog REST API. The project targets net8.0. Source is `csharp/` in authdog/sdk. It is a management and userinfo client, not a web-framework session binding.
NuGet.org does not host this package.
Install
Reference the project from a checkout of the monorepo:
<ProjectReference Include="path/to/sdk/csharp/Authdog.Sdk.csproj" />Or pack it locally and add the nupkg:
dotnet pack sdk/csharp/Authdog.Sdk.csprojThe package id is Authdog.Sdk. It depends on Newtonsoft.Json and Microsoft.Extensions.Http.
Configure
Construct one client with the public API base URL. Pass a management Bearer credential (ad_…) when you call privileged endpoints. Dispose the client when you are done:
using Authdog;
using var client = new AuthdogClient(
"https://api.authdog.com",
Environment.GetEnvironmentVariable("AUTHDOG_API_TOKEN"));
var probe = await client.HealthAsync();Keep the token server-side. GetUserInfoAsync still uses the caller access token, not the management key.
A third constructor argument is a custom HttpClient. Optional credentials environmentSecret (adenv_), scimToken (adscim_), and hrisToken (adhris_) are the AuthZEN/MCP runtime, SCIM, and HRIS Bearers.
HealthAsync is public and works without an API key. Health() is the synchronous wrapper.
Resolve a user from an access token
using Authdog;
using Authdog.Exceptions;
try
{
var info = await client.GetUserInfoAsync(accessToken);
Console.WriteLine(info.User.DisplayName);
}
catch (AuthenticationException)
{
// 401: missing, invalid, or expired access token
throw;
}
catch (ApiException)
{
// transport or non-401 HTTP failure
throw;
}GetUserInfo is the synchronous wrapper. GET /v1/userinfo always sends Authorization: Bearer <access-token>. A constructor API key does not replace that header.
Call the management API
Properties on the client wrap Waves 1–5 of the public /v1 surface:
| Property | Resources |
|---|---|
Organizations |
Organizations, invitations, members, keys |
Tenants |
Tenants, domains, seats |
Projects |
Applications under a tenant |
Environments |
Environment records |
Users |
Directory users in a tenant + environment |
Groups |
Groups and membership |
Rbac |
Roles, permissions, resources, mappings, ABAC |
Audit |
Administrative audit logs |
Events |
Identity event stream |
Webhooks |
Webhook subscriptions |
NotificationChannels |
SIEM / notification channels |
ServiceAccounts |
Service accounts |
PersonalAccessTokens |
PATs |
ApiSecrets |
Environment API secrets |
Authzen |
AuthZEN evaluate, search, and discovery |
Scim |
SCIM 2.0 directory |
Hris |
HRIS employees and departments |
Mcp |
MCP runtime |
Otel |
OpenTelemetry exporters |
OidcClients |
OIDC clients |
Actions |
Environment actions |
Addons |
Add-ons |
Billing |
Billing |
Settings |
Environment settings |
Elevate |
Elevate |
EmailProviders |
Email providers |
FeatureFlags |
Feature flags |
Forms |
Forms |
ProvisioningTokens |
Provisioning tokens |
Impersonation |
Impersonation |
Portal |
Account portal |
Security |
Security settings |
Threats |
Threats |
VanityDomains |
Vanity domains |
Widgets |
Widgets |
SmsProviders |
SMS providers |
ConnectedApps |
Connected-app grants |
AuthZEN discovery is unauthenticated. Evaluate, search, and the MCP runtime use environmentSecret. SCIM uses scimToken. HRIS uses hrisToken. OpenAPI at `/v1/openapi` is the field-level contract.
Errors
| Exception | When |
|---|---|
AuthenticationException |
HTTP 401 |
ApiException |
Other HTTP failures and transport errors |
Other languages
| Language | Guide |
|---|---|
| Python | Python SDK |
| Node.js | Node.js SDK |
| Go | Go SDK |
| Rust | Rust SDK |
| Java | Java SDK |
| Zig | Zig SDK |
Next
- API reference: auth, versioning, and resource families
- Backend requests: validate sessions on incoming requests
- Users: directory model the
Usersnamespace talks to