authdog 0.2.0 is the official Rust client for the Authdog REST API. Source is `rust/` in authdog/sdk. It is a management and userinfo client, not a web-framework session binding.
crates.io does not host this crate. Need to protect an HTTP route? Use the Rust backend SDK.
Install
Depend on the crate by path from a checkout of the monorepo:
[dependencies]
authdog = { path = "../sdk/rust" }Client methods are async. The crate uses tokio and reqwest.
Configure
Construct one client with the public API base URL. Pass a management Bearer credential (ad_…) when you call privileged endpoints:
use authdog::{AuthdogClient, AuthdogClientConfig};
use std::time::Duration;
let client = AuthdogClient::new(AuthdogClientConfig {
base_url: "https://api.authdog.com".to_string(),
api_key: std::env::var("AUTHDOG_API_TOKEN").ok(),
timeout: Some(Duration::from_secs(10)),
..Default::default()
})?;Keep the token server-side. get_user_info still uses the caller access token, not the management key.
Optional config fields environment_secret (adenv_), scim_token (adscim_), and hris_token (adhris_) are the AuthZEN/MCP runtime, SCIM, and HRIS Bearers.
health() is public and works without an API key:
let probe = client.health().await?;Resolve a user from an access token
match client.get_user_info(access_token).await {
Ok(info) => {
println!("{}", info.user.display_name);
if let Some(email) = info.user.emails.first() {
println!("{}", email.value);
}
}
Err(err) if err.is_authentication() => {
// 401: missing, invalid, or expired access token
return Err(err.into());
}
Err(err) if err.is_api() => {
// transport or non-401 HTTP failure
return Err(err.into());
}
Err(err) => return Err(err.into()),
}GET /v1/userinfo always sends Authorization: Bearer <access-token>. A constructor API key does not replace that header.
UserInfoResponse uses snake_case fields (user.display_name, session.remaining_seconds).
Call the management API
Methods on the client wrap Waves 1–5 of the public /v1 surface:
| Method | Resources |
|---|---|
organizations() |
Organizations, invitations, members, keys |
tenants() |
Tenants, domains, seats |
projects() |
Applications under a tenant |
environments() |
Environment records |
users() |
Directory users in a tenant + environment |
groups() |
Groups and membership |
rbac() |
Roles, permissions, resources, mappings, ABAC |
audit() |
Administrative audit logs |
events() |
Identity event stream |
webhooks() |
Webhook subscriptions |
notification_channels() |
SIEM / notification channels |
service_accounts() |
Service accounts |
personal_access_tokens() |
PATs |
api_secrets() |
Environment API secrets |
authzen() |
AuthZEN evaluate, search, and discovery |
scim() |
SCIM 2.0 directory |
hris() |
HRIS employees and departments |
mcp() |
MCP runtime |
otel() |
OpenTelemetry exporters |
oidc_clients() |
OIDC clients |
actions() |
Environment actions |
addons() |
Add-ons |
billing() |
Billing |
settings() |
Environment settings |
elevate() |
Elevate |
email_providers() |
Email providers |
feature_flags() |
Feature flags |
forms() |
Forms |
provisioning_tokens() |
Provisioning tokens |
impersonation() |
Impersonation |
portal() |
Account portal |
security() |
Security settings |
threats() |
Threats |
vanity_domains() |
Vanity domains |
widgets() |
Widgets |
sms_providers() |
SMS providers |
connected_apps() |
Connected-app grants |
AuthZEN discovery is unauthenticated. Evaluate, search, and the MCP runtime use environment_secret. SCIM uses scim_token. HRIS uses hris_token. OpenAPI at `/v1/openapi` is the field-level contract.
Errors
| Error | When |
|---|---|
AuthdogError::Authentication |
HTTP 401. is_authentication() is true. |
AuthdogError::Api |
Other HTTP failures and transport errors. is_api() is true. |
Other languages
| Language | Guide |
|---|---|
| Python | Python SDK |
| Node.js | Node.js SDK |
| Go | Go SDK |
| Java | Java SDK |
| C# | C# SDK |
| Zig | Zig SDK |
Next
- API reference: auth, versioning, and resource families
- Backend requests: validate sessions on incoming requests
- Rust backend: session binding for HTTP handlers
- Users: directory model the
usersnamespace talks to