com.authdog:authdog-java-sdk 0.2.0 is the official Java client for the Authdog REST API. It requires Java 11+. Source is `java/` in authdog/sdk. It is a management and userinfo client, not a web-framework session binding.
Maven Central does not host this artifact.
Install
From a checkout of java/, install the artifact into the local Maven repository:
mvn installThen depend on it:
<dependency>
<groupId>com.authdog</groupId>
<artifactId>authdog-java-sdk</artifactId>
<version>0.2.0</version>
</dependency>Gradle, after the same local install:
implementation "com.authdog:authdog-java-sdk:0.2.0"The client uses OkHttp and Jackson.
Configure
Construct one client with the public API base URL. Pass a management Bearer credential (ad_…) when you call privileged endpoints. AuthdogClient implements AutoCloseable:
try (AuthdogClient client = new AuthdogClient(
"https://api.authdog.com",
System.getenv("AUTHDOG_API_TOKEN"))) {
Probe probe = client.health();
}Keep the token server-side. getUserInfo still uses the caller access token, not the management key.
A third constructor argument is the timeout in milliseconds. Optional credentials environmentSecret (adenv_), scimToken (adscim_), and hrisToken (adhris_) are the AuthZEN/MCP runtime, SCIM, and HRIS Bearers.
health() is public and works without an API key.
Resolve a user from an access token
try (AuthdogClient client = new AuthdogClient("https://api.authdog.com")) {
UserInfoResponse info = client.getUserInfo(accessToken);
System.out.println(info.getUser().getDisplayName());
} catch (AuthenticationException e) {
// 401: missing, invalid, or expired access token
throw e;
} catch (ApiException e) {
// transport or non-401 HTTP failure
throw e;
}GET /v1/userinfo always sends Authorization: Bearer <access-token>. A constructor API key does not replace that header.
Call the management API
Methods on the client wrap Waves 1–5 of the public /v1 surface:
| Method | Resources |
|---|---|
organizations() |
Organizations, invitations, members, keys |
tenants() |
Tenants, domains, seats |
projects() |
Applications under a tenant |
environments() |
Environment records |
users() |
Directory users in a tenant + environment |
groups() |
Groups and membership |
rbac() |
Roles, permissions, resources, mappings, ABAC |
audit() |
Administrative audit logs |
events() |
Identity event stream |
webhooks() |
Webhook subscriptions |
notificationChannels() |
SIEM / notification channels |
serviceAccounts() |
Service accounts |
personalAccessTokens() |
PATs |
apiSecrets() |
Environment API secrets |
authzen() |
AuthZEN evaluate, search, and discovery |
scim() |
SCIM 2.0 directory |
hris() |
HRIS employees and departments |
mcp() |
MCP runtime |
otel() |
OpenTelemetry exporters |
oidcClients() |
OIDC clients |
actions() |
Environment actions |
addons() |
Add-ons |
billing() |
Billing |
settings() |
Environment settings |
elevate() |
Elevate |
emailProviders() |
Email providers |
featureFlags() |
Feature flags |
forms() |
Forms |
provisioningTokens() |
Provisioning tokens |
impersonation() |
Impersonation |
portal() |
Account portal |
security() |
Security settings |
threats() |
Threats |
vanityDomains() |
Vanity domains |
widgets() |
Widgets |
smsProviders() |
SMS providers |
connectedApps() |
Connected-app grants |
AuthZEN discovery is unauthenticated. Evaluate, search, and the MCP runtime use environmentSecret. SCIM uses scimToken. HRIS uses hrisToken. OpenAPI at `/v1/openapi` is the field-level contract.
Errors
| Exception | When |
|---|---|
AuthenticationException |
HTTP 401 |
ApiException |
Other HTTP failures and transport errors |
Other languages
| Language | Guide |
|---|---|
| Python | Python SDK |
| Node.js | Node.js SDK |
| Go | Go SDK |
| Rust | Rust SDK |
| C# | C# SDK |
| Zig | Zig SDK |
Next
- API reference: auth, versioning, and resource families
- Backend requests: validate sessions on incoming requests
- Users: directory model the
usersnamespace talks to