Hookfish treats the packaged operator dashboard and your product UI as
separate security surfaces. Neither surface receives a broker credential or a
stored provider credential.
Run the packaged dashboard
Generated projects start the dashboard and backend together:
For an existing backend, provide the backend URL and root credential to the
local server process:
The command binds to loopback by default. It creates an ephemeral operator
session in an HttpOnly, SameSite=Strict cookie. Its backend-for-frontend
injects the broker credential only for explicit connection-management
operations. It does not proxy the raw /api/* surface or expose provider-token
retrieval.
The dashboard can list providers and connections, start authorization, store a
new provider secret, and disconnect a connection. A stored secret is write-only:
the response confirms that it was saved but never returns its value.
The packaged dashboard is a local operator tool. It refuses non-loopback
binding. Use application authentication or SSO for a remotely hosted
operator experience.
Build a product connection screen
Configure an application auth provider on the Hookfish server:
The safe application API exposes:
Connection paths are relative to the authenticated tenant. Hookfish ignores
browser-supplied tenant identifiers and enforces its internal tenant namespace
on every raw API request.
There is no client operation corresponding to connections.access(). The
browser can receive an authorization URL or { stored: true }, but it cannot
retrieve a provider access token, refresh token, API key, OAuth client secret,
or broker credential.
See Application authentication to connect
Better Auth or implement another application auth provider.