Skip to main content
Hookfish treats the packaged operator dashboard and your product UI as separate security surfaces. Neither surface receives a broker credential or a stored provider credential.

Run the packaged dashboard

Generated projects start the dashboard and backend together:
For an existing backend, provide the backend URL and root credential to the local server process:
The command binds to loopback by default. It creates an ephemeral operator session in an HttpOnly, SameSite=Strict cookie. Its backend-for-frontend injects the broker credential only for explicit connection-management operations. It does not proxy the raw /api/* surface or expose provider-token retrieval. The dashboard can list providers and connections, start authorization, store a new provider secret, and disconnect a connection. A stored secret is write-only: the response confirms that it was saved but never returns its value.
The packaged dashboard is a local operator tool. It refuses non-loopback binding. Use application authentication or SSO for a remotely hosted operator experience.

Build a product connection screen

Configure an application auth provider on the Hookfish server:
The safe application API exposes:
Connection paths are relative to the authenticated tenant. Hookfish ignores browser-supplied tenant identifiers and enforces its internal tenant namespace on every raw API request. There is no client operation corresponding to connections.access(). The browser can receive an authorization URL or { stored: true }, but it cannot retrieve a provider access token, refresh token, API key, OAuth client secret, or broker credential. See Application authentication to connect Better Auth or implement another application auth provider.