Supplying
auth mounts the application-facing API at /api/client. Hookfish
does not mount that API without an auth provider. The auth provider returns a
verified application subject and tenant. Hookfish creates a short-lived,
tenant-scoped capability for each request and never sends it to the browser.
trustedOrigins, clientOrigins, and rawApiOrigins are separate controls.
Redirect trust does not grant raw API access. Origin entries must include the
scheme and port, when present. Wildcards are rejected for raw API access.
There is no provider-management switch. Provider implementations are trusted
deployment code. Providers declare oauth or secret authentication plus a
small input schema for connection identity and non-secret configuration.
Runtime options
The second argument tocreateHookfish or HookfishServer.init accepts
runtime, clientOrigins, and rootApiKey. Most deployments should let
Hookfish resolve HOOKFISH_API_KEY from server bindings instead of passing
rootApiKey directly.
Use a provider factory when credentials come from request bindings. Use a lazy
ProviderSource for a large application-owned catalog while keeping provider
IDs and implementations trusted.