github.com/authdog/go-sdk is the official Go client for the Authdog REST API. The module requires Go 1.21+. Source is `go/` in authdog/sdk. It is a management and userinfo client, not a web-framework session binding.
Need to protect an HTTP route? Use the Go backend SDK.
Install
The module path is github.com/authdog/go-sdk, but there is no authdog/go-sdk repository and the Go module proxy has no tagged version. A bare go get github.com/authdog/go-sdk does not resolve. Check out authdog/sdk and point a replace at the go/ directory:
require github.com/authdog/go-sdk v0.0.0
replace github.com/authdog/go-sdk => ../sdk/goimport "github.com/authdog/go-sdk"Configure
Construct one client with the public API base URL. Pass a management Bearer credential (ad_…) when you call privileged endpoints:
client := authdog.NewClient(authdog.ClientConfig{
BaseURL: "https://api.authdog.com",
APIKey: os.Getenv("AUTHDOG_API_TOKEN"),
})Keep the token server-side. GetUserInfo still uses the caller access token, not the management key.
Optional config fields EnvironmentSecret (adenv_), SCIMToken (adscim_), and HRISToken (adhris_) are the AuthZEN/MCP runtime, SCIM, and HRIS Bearers. Timeout defaults to 10 seconds. HTTPClient overrides the default client.
Health is public and works without an API key:
probe, err := client.Health(ctx)Resolve a user from an access token
userInfo, err := client.GetUserInfo(ctx, accessToken)
if authdog.IsAuthenticationError(err) {
// 401: missing, invalid, or expired access token
return err
}
if authdog.IsAPIError(err) {
// transport or non-401 HTTP failure
return err
}
if err != nil {
return err
}
fmt.Println(userInfo.User.DisplayName)
if len(userInfo.User.Emails) > 0 {
fmt.Println(userInfo.User.Emails[0].Value)
}GET /v1/userinfo always sends Authorization: Bearer <access-token>. A constructor API key does not replace that header.
Call the management API
Exported fields on Client wrap Waves 1–5 of the public /v1 surface:
| Attribute | Resources |
|---|---|
Organizations |
Organizations, invitations, members, keys |
Tenants |
Tenants, domains, seats |
Projects |
Applications under a tenant |
Environments |
Environment records |
Users |
Directory users in a tenant + environment |
Groups |
Groups and membership |
Rbac |
Roles, permissions, resources, mappings, ABAC |
Audit |
Administrative audit logs |
Events |
Identity event stream |
Webhooks |
Webhook subscriptions |
NotificationChannels |
SIEM / notification channels |
ServiceAccounts |
Service accounts |
PersonalAccessTokens |
PATs |
ApiSecrets |
Environment API secrets |
Authzen |
AuthZEN evaluate, search, and discovery |
Scim |
SCIM 2.0 directory |
Hris |
HRIS employees and departments |
Mcp |
MCP runtime |
Otel |
OpenTelemetry exporters |
OidcClients |
OIDC clients |
Actions |
Environment actions |
Addons |
Add-ons |
Billing |
Billing |
Settings |
Environment settings |
Elevate |
Elevate |
EmailProviders |
Email providers |
FeatureFlags |
Feature flags |
Forms |
Forms |
ProvisioningTokens |
Provisioning tokens |
Impersonation |
Impersonation |
Portal |
Account portal |
Security |
Security settings |
Threats |
Threats |
VanityDomains |
Vanity domains |
Widgets |
Widgets |
SmsProviders |
SMS providers |
ConnectedApps |
Connected-app grants |
AuthZEN discovery is unauthenticated. Evaluate, search, and the MCP runtime use EnvironmentSecret. SCIM uses SCIMToken. HRIS uses HRISToken. OpenAPI at `/v1/openapi` is the field-level contract.
Errors
| Check | When |
|---|---|
IsAuthenticationError |
HTTP 401 |
IsAPIError |
Other HTTP failures and transport errors |
IsAuthdogError |
Any error from this module |
Other languages
| Language | Guide |
|---|---|
| Python | Python SDK |
| Node.js | Node.js SDK |
| Rust | Rust SDK |
| Java | Java SDK |
| C# | C# SDK |
| Zig | Zig SDK |
Next
- API reference: auth, versioning, and resource families
- Backend requests: validate sessions on incoming requests
- Go backend: session binding for HTTP handlers
- Users: directory model the
Usersnamespace talks to