`github.com/authdog/go-sdk` is the official Go client for the [Authdog REST API](/docs/api). The module requires Go 1.21+. Source is [`go/`](https://github.com/authdog/sdk/tree/main/go) in [authdog/sdk](https://github.com/authdog/sdk). It is a management and userinfo client, not a web-framework session binding.

Need to protect an HTTP route? Use the [Go backend SDK](/docs/backend/go).

## Install

The module path is `github.com/authdog/go-sdk`, but there is no `authdog/go-sdk` repository and the Go module proxy has no tagged version. A bare `go get github.com/authdog/go-sdk` does not resolve. Check out [authdog/sdk](https://github.com/authdog/sdk) and point a `replace` at the `go/` directory:

```
require github.com/authdog/go-sdk v0.0.0

replace github.com/authdog/go-sdk => ../sdk/go
```

```go
import "github.com/authdog/go-sdk"
```

## Configure

Construct one client with the public API base URL. Pass a management Bearer credential (`ad_…`) when you call privileged endpoints:

```go
client := authdog.NewClient(authdog.ClientConfig{
    BaseURL: "https://api.authdog.com",
    APIKey:  os.Getenv("AUTHDOG_API_TOKEN"),
})
```

Keep the token server-side. `GetUserInfo` still uses the caller access token, not the management key.

Optional config fields `EnvironmentSecret` (`adenv_`), `SCIMToken` (`adscim_`), and `HRISToken` (`adhris_`) are the AuthZEN/MCP runtime, SCIM, and HRIS Bearers. `Timeout` defaults to 10 seconds. `HTTPClient` overrides the default client.

`Health` is public and works without an API key:

```go
probe, err := client.Health(ctx)
```

## Resolve a user from an access token

```go
userInfo, err := client.GetUserInfo(ctx, accessToken)
if authdog.IsAuthenticationError(err) {
    // 401: missing, invalid, or expired access token
    return err
}
if authdog.IsAPIError(err) {
    // transport or non-401 HTTP failure
    return err
}
if err != nil {
    return err
}

fmt.Println(userInfo.User.DisplayName)
if len(userInfo.User.Emails) > 0 {
    fmt.Println(userInfo.User.Emails[0].Value)
}
```

`GET /v1/userinfo` always sends `Authorization: Bearer <access-token>`. A constructor API key does not replace that header.

## Call the management API

Exported fields on `Client` wrap Waves 1–5 of the public `/v1` surface:

| Attribute | Resources |
| --- | --- |
| `Organizations` | Organizations, invitations, members, keys |
| `Tenants` | Tenants, domains, seats |
| `Projects` | Applications under a tenant |
| `Environments` | Environment records |
| `Users` | Directory users in a tenant + environment |
| `Groups` | Groups and membership |
| `Rbac` | Roles, permissions, resources, mappings, ABAC |
| `Audit` | Administrative audit logs |
| `Events` | Identity event stream |
| `Webhooks` | Webhook subscriptions |
| `NotificationChannels` | SIEM / notification channels |
| `ServiceAccounts` | Service accounts |
| `PersonalAccessTokens` | PATs |
| `ApiSecrets` | Environment API secrets |
| `Authzen` | AuthZEN evaluate, search, and discovery |
| `Scim` | SCIM 2.0 directory |
| `Hris` | HRIS employees and departments |
| `Mcp` | MCP runtime |
| `Otel` | OpenTelemetry exporters |
| `OidcClients` | OIDC clients |
| `Actions` | Environment actions |
| `Addons` | Add-ons |
| `Billing` | Billing |
| `Settings` | Environment settings |
| `Elevate` | Elevate |
| `EmailProviders` | Email providers |
| `FeatureFlags` | Feature flags |
| `Forms` | Forms |
| `ProvisioningTokens` | Provisioning tokens |
| `Impersonation` | Impersonation |
| `Portal` | Account portal |
| `Security` | Security settings |
| `Threats` | Threats |
| `VanityDomains` | Vanity domains |
| `Widgets` | Widgets |
| `SmsProviders` | SMS providers |
| `ConnectedApps` | Connected-app grants |

AuthZEN discovery is unauthenticated. Evaluate, search, and the MCP runtime use `EnvironmentSecret`. SCIM uses `SCIMToken`. HRIS uses `HRISToken`. OpenAPI at [`/v1/openapi`](https://api.authdog.com/v1/openapi) is the field-level contract.

## Errors

| Check | When |
| --- | --- |
| `IsAuthenticationError` | HTTP 401 |
| `IsAPIError` | Other HTTP failures and transport errors |
| `IsAuthdogError` | Any error from this module |

## Other languages

| Language | Guide |
| --- | --- |
| Python | [Python SDK](/docs/sdks/python) |
| Node.js | [Node.js SDK](/docs/sdks/node) |
| Rust | [Rust SDK](/docs/sdks/rust) |
| Java | [Java SDK](/docs/sdks/java) |
| C# | [C# SDK](/docs/sdks/csharp) |
| Zig | [Zig SDK](/docs/sdks/zig) |

## Next

- [API reference](/docs/api): auth, versioning, and resource families
- [Backend requests](/docs/backend): validate sessions on incoming requests
- [Go backend](/docs/backend/go): session binding for HTTP handlers
- [Users](/docs/users): directory model the `Users` namespace talks to
