`Authdog.Sdk` 0.2.0 is the official C# client for the [Authdog REST API](/docs/api). The project targets `net8.0`. Source is [`csharp/`](https://github.com/authdog/sdk/tree/main/csharp) in [authdog/sdk](https://github.com/authdog/sdk). It is a management and userinfo client, not a web-framework session binding.

NuGet.org does not host this package.

## Install

Reference the project from a checkout of the monorepo:

```xml
<ProjectReference Include="path/to/sdk/csharp/Authdog.Sdk.csproj" />
```

Or pack it locally and add the nupkg:

```bash
dotnet pack sdk/csharp/Authdog.Sdk.csproj
```

The package id is `Authdog.Sdk`. It depends on Newtonsoft.Json and Microsoft.Extensions.Http.

## Configure

Construct one client with the public API base URL. Pass a management Bearer credential (`ad_…`) when you call privileged endpoints. Dispose the client when you are done:

```csharp
using Authdog;

using var client = new AuthdogClient(
    "https://api.authdog.com",
    Environment.GetEnvironmentVariable("AUTHDOG_API_TOKEN"));

var probe = await client.HealthAsync();
```

Keep the token server-side. `GetUserInfoAsync` still uses the caller access token, not the management key.

A third constructor argument is a custom `HttpClient`. Optional credentials `environmentSecret` (`adenv_`), `scimToken` (`adscim_`), and `hrisToken` (`adhris_`) are the AuthZEN/MCP runtime, SCIM, and HRIS Bearers.

`HealthAsync` is public and works without an API key. `Health()` is the synchronous wrapper.

## Resolve a user from an access token

```csharp
using Authdog;
using Authdog.Exceptions;

try
{
    var info = await client.GetUserInfoAsync(accessToken);
    Console.WriteLine(info.User.DisplayName);
}
catch (AuthenticationException)
{
    // 401: missing, invalid, or expired access token
    throw;
}
catch (ApiException)
{
    // transport or non-401 HTTP failure
    throw;
}
```

`GetUserInfo` is the synchronous wrapper. `GET /v1/userinfo` always sends `Authorization: Bearer <access-token>`. A constructor API key does not replace that header.

## Call the management API

Properties on the client wrap Waves 1–5 of the public `/v1` surface:

| Property | Resources |
| --- | --- |
| `Organizations` | Organizations, invitations, members, keys |
| `Tenants` | Tenants, domains, seats |
| `Projects` | Applications under a tenant |
| `Environments` | Environment records |
| `Users` | Directory users in a tenant + environment |
| `Groups` | Groups and membership |
| `Rbac` | Roles, permissions, resources, mappings, ABAC |
| `Audit` | Administrative audit logs |
| `Events` | Identity event stream |
| `Webhooks` | Webhook subscriptions |
| `NotificationChannels` | SIEM / notification channels |
| `ServiceAccounts` | Service accounts |
| `PersonalAccessTokens` | PATs |
| `ApiSecrets` | Environment API secrets |
| `Authzen` | AuthZEN evaluate, search, and discovery |
| `Scim` | SCIM 2.0 directory |
| `Hris` | HRIS employees and departments |
| `Mcp` | MCP runtime |
| `Otel` | OpenTelemetry exporters |
| `OidcClients` | OIDC clients |
| `Actions` | Environment actions |
| `Addons` | Add-ons |
| `Billing` | Billing |
| `Settings` | Environment settings |
| `Elevate` | Elevate |
| `EmailProviders` | Email providers |
| `FeatureFlags` | Feature flags |
| `Forms` | Forms |
| `ProvisioningTokens` | Provisioning tokens |
| `Impersonation` | Impersonation |
| `Portal` | Account portal |
| `Security` | Security settings |
| `Threats` | Threats |
| `VanityDomains` | Vanity domains |
| `Widgets` | Widgets |
| `SmsProviders` | SMS providers |
| `ConnectedApps` | Connected-app grants |

AuthZEN discovery is unauthenticated. Evaluate, search, and the MCP runtime use `environmentSecret`. SCIM uses `scimToken`. HRIS uses `hrisToken`. OpenAPI at [`/v1/openapi`](https://api.authdog.com/v1/openapi) is the field-level contract.

## Errors

| Exception | When |
| --- | --- |
| `AuthenticationException` | HTTP 401 |
| `ApiException` | Other HTTP failures and transport errors |

## Other languages

| Language | Guide |
| --- | --- |
| Python | [Python SDK](/docs/sdks/python) |
| Node.js | [Node.js SDK](/docs/sdks/node) |
| Go | [Go SDK](/docs/sdks/go) |
| Rust | [Rust SDK](/docs/sdks/rust) |
| Java | [Java SDK](/docs/sdks/java) |
| Zig | [Zig SDK](/docs/sdks/zig) |

## Next

- [API reference](/docs/api): auth, versioning, and resource families
- [Backend requests](/docs/backend): validate sessions on incoming requests
- [Users](/docs/users): directory model the `Users` namespace talks to
