Skip to main content
Supplying auth mounts the application-facing API at /api/client. Hookfish does not mount that API without an auth provider. The auth provider returns a verified application subject and tenant. Hookfish creates a short-lived, tenant-scoped capability for each request and never sends it to the browser. trustedOrigins, clientOrigins, and rawApiOrigins are separate controls. Redirect trust does not grant raw API access. Origin entries must include the scheme and port, when present. Wildcards are rejected for raw API access. There is no provider-management switch. Provider implementations are trusted deployment code. Providers declare oauth or secret authentication plus a small input schema for connection identity and non-secret configuration.

Runtime options

The second argument to createHookfish or HookfishServer.init accepts runtime, clientOrigins, and rootApiKey. Most deployments should let Hookfish resolve HOOKFISH_API_KEY from server bindings instead of passing rootApiKey directly. Use a provider factory when credentials come from request bindings. Use a lazy ProviderSource for a large application-owned catalog while keeping provider IDs and implementations trusted.