`com.authdog:authdog-java-sdk` 0.2.0 is the official Java client for the [Authdog REST API](/docs/api). It requires Java 11+. Source is [`java/`](https://github.com/authdog/sdk/tree/main/java) in [authdog/sdk](https://github.com/authdog/sdk). It is a management and userinfo client, not a web-framework session binding.

Maven Central does not host this artifact.

## Install

From a checkout of `java/`, install the artifact into the local Maven repository:

```bash
mvn install
```

Then depend on it:

```xml
<dependency>
  <groupId>com.authdog</groupId>
  <artifactId>authdog-java-sdk</artifactId>
  <version>0.2.0</version>
</dependency>
```

Gradle, after the same local install:

```gradle
implementation "com.authdog:authdog-java-sdk:0.2.0"
```

The client uses OkHttp and Jackson.

## Configure

Construct one client with the public API base URL. Pass a management Bearer credential (`ad_…`) when you call privileged endpoints. `AuthdogClient` implements `AutoCloseable`:

```java
try (AuthdogClient client = new AuthdogClient(
        "https://api.authdog.com",
        System.getenv("AUTHDOG_API_TOKEN"))) {
    Probe probe = client.health();
}
```

Keep the token server-side. `getUserInfo` still uses the caller access token, not the management key.

A third constructor argument is the timeout in milliseconds. Optional credentials `environmentSecret` (`adenv_`), `scimToken` (`adscim_`), and `hrisToken` (`adhris_`) are the AuthZEN/MCP runtime, SCIM, and HRIS Bearers.

`health()` is public and works without an API key.

## Resolve a user from an access token

```java
try (AuthdogClient client = new AuthdogClient("https://api.authdog.com")) {
    UserInfoResponse info = client.getUserInfo(accessToken);
    System.out.println(info.getUser().getDisplayName());
} catch (AuthenticationException e) {
    // 401: missing, invalid, or expired access token
    throw e;
} catch (ApiException e) {
    // transport or non-401 HTTP failure
    throw e;
}
```

`GET /v1/userinfo` always sends `Authorization: Bearer <access-token>`. A constructor API key does not replace that header.

## Call the management API

Methods on the client wrap Waves 1–5 of the public `/v1` surface:

| Method | Resources |
| --- | --- |
| `organizations()` | Organizations, invitations, members, keys |
| `tenants()` | Tenants, domains, seats |
| `projects()` | Applications under a tenant |
| `environments()` | Environment records |
| `users()` | Directory users in a tenant + environment |
| `groups()` | Groups and membership |
| `rbac()` | Roles, permissions, resources, mappings, ABAC |
| `audit()` | Administrative audit logs |
| `events()` | Identity event stream |
| `webhooks()` | Webhook subscriptions |
| `notificationChannels()` | SIEM / notification channels |
| `serviceAccounts()` | Service accounts |
| `personalAccessTokens()` | PATs |
| `apiSecrets()` | Environment API secrets |
| `authzen()` | AuthZEN evaluate, search, and discovery |
| `scim()` | SCIM 2.0 directory |
| `hris()` | HRIS employees and departments |
| `mcp()` | MCP runtime |
| `otel()` | OpenTelemetry exporters |
| `oidcClients()` | OIDC clients |
| `actions()` | Environment actions |
| `addons()` | Add-ons |
| `billing()` | Billing |
| `settings()` | Environment settings |
| `elevate()` | Elevate |
| `emailProviders()` | Email providers |
| `featureFlags()` | Feature flags |
| `forms()` | Forms |
| `provisioningTokens()` | Provisioning tokens |
| `impersonation()` | Impersonation |
| `portal()` | Account portal |
| `security()` | Security settings |
| `threats()` | Threats |
| `vanityDomains()` | Vanity domains |
| `widgets()` | Widgets |
| `smsProviders()` | SMS providers |
| `connectedApps()` | Connected-app grants |

AuthZEN discovery is unauthenticated. Evaluate, search, and the MCP runtime use `environmentSecret`. SCIM uses `scimToken`. HRIS uses `hrisToken`. OpenAPI at [`/v1/openapi`](https://api.authdog.com/v1/openapi) is the field-level contract.

## Errors

| Exception | When |
| --- | --- |
| `AuthenticationException` | HTTP 401 |
| `ApiException` | Other HTTP failures and transport errors |

## Other languages

| Language | Guide |
| --- | --- |
| Python | [Python SDK](/docs/sdks/python) |
| Node.js | [Node.js SDK](/docs/sdks/node) |
| Go | [Go SDK](/docs/sdks/go) |
| Rust | [Rust SDK](/docs/sdks/rust) |
| C# | [C# SDK](/docs/sdks/csharp) |
| Zig | [Zig SDK](/docs/sdks/zig) |

## Next

- [API reference](/docs/api): auth, versioning, and resource families
- [Backend requests](/docs/backend): validate sessions on incoming requests
- [Users](/docs/users): directory model the `users` namespace talks to
