`authdog` 0.2.0 is the official Rust client for the [Authdog REST API](/docs/api). Source is [`rust/`](https://github.com/authdog/sdk/tree/main/rust) in [authdog/sdk](https://github.com/authdog/sdk). It is a management and userinfo client, not a web-framework session binding.

crates.io does not host this crate. Need to protect an HTTP route? Use the [Rust backend SDK](/docs/backend/rust).

## Install

Depend on the crate by path from a checkout of the monorepo:

```toml
[dependencies]
authdog = { path = "../sdk/rust" }
```

Client methods are async. The crate uses `tokio` and `reqwest`.

## Configure

Construct one client with the public API base URL. Pass a management Bearer credential (`ad_…`) when you call privileged endpoints:

```rust
use authdog::{AuthdogClient, AuthdogClientConfig};
use std::time::Duration;

let client = AuthdogClient::new(AuthdogClientConfig {
    base_url: "https://api.authdog.com".to_string(),
    api_key: std::env::var("AUTHDOG_API_TOKEN").ok(),
    timeout: Some(Duration::from_secs(10)),
    ..Default::default()
})?;
```

Keep the token server-side. `get_user_info` still uses the caller access token, not the management key.

Optional config fields `environment_secret` (`adenv_`), `scim_token` (`adscim_`), and `hris_token` (`adhris_`) are the AuthZEN/MCP runtime, SCIM, and HRIS Bearers.

`health()` is public and works without an API key:

```rust
let probe = client.health().await?;
```

## Resolve a user from an access token

```rust
match client.get_user_info(access_token).await {
    Ok(info) => {
        println!("{}", info.user.display_name);
        if let Some(email) = info.user.emails.first() {
            println!("{}", email.value);
        }
    }
    Err(err) if err.is_authentication() => {
        // 401: missing, invalid, or expired access token
        return Err(err.into());
    }
    Err(err) if err.is_api() => {
        // transport or non-401 HTTP failure
        return Err(err.into());
    }
    Err(err) => return Err(err.into()),
}
```

`GET /v1/userinfo` always sends `Authorization: Bearer <access-token>`. A constructor API key does not replace that header.

`UserInfoResponse` uses snake_case fields (`user.display_name`, `session.remaining_seconds`).

## Call the management API

Methods on the client wrap Waves 1–5 of the public `/v1` surface:

| Method | Resources |
| --- | --- |
| `organizations()` | Organizations, invitations, members, keys |
| `tenants()` | Tenants, domains, seats |
| `projects()` | Applications under a tenant |
| `environments()` | Environment records |
| `users()` | Directory users in a tenant + environment |
| `groups()` | Groups and membership |
| `rbac()` | Roles, permissions, resources, mappings, ABAC |
| `audit()` | Administrative audit logs |
| `events()` | Identity event stream |
| `webhooks()` | Webhook subscriptions |
| `notification_channels()` | SIEM / notification channels |
| `service_accounts()` | Service accounts |
| `personal_access_tokens()` | PATs |
| `api_secrets()` | Environment API secrets |
| `authzen()` | AuthZEN evaluate, search, and discovery |
| `scim()` | SCIM 2.0 directory |
| `hris()` | HRIS employees and departments |
| `mcp()` | MCP runtime |
| `otel()` | OpenTelemetry exporters |
| `oidc_clients()` | OIDC clients |
| `actions()` | Environment actions |
| `addons()` | Add-ons |
| `billing()` | Billing |
| `settings()` | Environment settings |
| `elevate()` | Elevate |
| `email_providers()` | Email providers |
| `feature_flags()` | Feature flags |
| `forms()` | Forms |
| `provisioning_tokens()` | Provisioning tokens |
| `impersonation()` | Impersonation |
| `portal()` | Account portal |
| `security()` | Security settings |
| `threats()` | Threats |
| `vanity_domains()` | Vanity domains |
| `widgets()` | Widgets |
| `sms_providers()` | SMS providers |
| `connected_apps()` | Connected-app grants |

AuthZEN discovery is unauthenticated. Evaluate, search, and the MCP runtime use `environment_secret`. SCIM uses `scim_token`. HRIS uses `hris_token`. OpenAPI at [`/v1/openapi`](https://api.authdog.com/v1/openapi) is the field-level contract.

## Errors

| Error | When |
| --- | --- |
| `AuthdogError::Authentication` | HTTP 401. `is_authentication()` is true. |
| `AuthdogError::Api` | Other HTTP failures and transport errors. `is_api()` is true. |

## Other languages

| Language | Guide |
| --- | --- |
| Python | [Python SDK](/docs/sdks/python) |
| Node.js | [Node.js SDK](/docs/sdks/node) |
| Go | [Go SDK](/docs/sdks/go) |
| Java | [Java SDK](/docs/sdks/java) |
| C# | [C# SDK](/docs/sdks/csharp) |
| Zig | [Zig SDK](/docs/sdks/zig) |

## Next

- [API reference](/docs/api): auth, versioning, and resource families
- [Backend requests](/docs/backend): validate sessions on incoming requests
- [Rust backend](/docs/backend/rust): session binding for HTTP handlers
- [Users](/docs/users): directory model the `users` namespace talks to
