# Example backends

> Working Express, Ktor, Spring Boot and Go backends with the same routes, and the smoke test CI runs.

Four small backends on authbase, with the same routes so one script
(`smoke.sh`) tests them all; CI runs every one against the compose stack.

| | Stack | Port | Uses |
|---|---|---|---|
| [`express`](express) | Node, Express 5 | 3001 | `@authbase/node` |
| [`ktor`](ktor) | Kotlin, Ktor 3 | 3002 | `authbase-ktor` |
| [`spring`](spring) | Kotlin, Spring Boot 4 | 3003 | `authbase-spring-boot-starter` |
| [`go`](go) | Go, net/http | 3004 | no SDK: `lestrrat-go/jwx`, as in the [integration guide](https://authbase.burakmetehan.com.tr/docs/integration.md) |

| Route | |
|---|---|
| `POST /signup` `{email, password}` | creates the user in authbase and logs in → 201 `{user_id, access_token, refresh_token}` |
| `POST /login` `{email, password}` | → `{access_token, refresh_token}` |
| `POST /refresh` `{refresh_token}` | → a new pair; the old refresh token is dead |
| `POST /logout` `{refresh_token}` | → 204 |
| `GET /me` | Bearer token → `{id, email, roles}`; verified locally |
| `GET /admin` | needs the `admin` role → 403 without it |

## Run one

Start authbase and get an API key ([quick start](https://authbase.burakmetehan.com.tr/docs/quickstart.md)),
then, with the key only in your environment:

```sh
export AUTHBASE_URL=http://localhost:8080 AUTHBASE_API_KEY=sk_live_…

# Express: the SDK is used from source, so build it first
(cd sdk/typescript && npm ci && npm run build) && cd examples/express && npm install && npm start
# Go
cd examples/go && go run .
# Ktor / Spring Boot: Gradle builds the Kotlin SDK from source (includeBuild)
cd examples/ktor && ./gradlew run
cd examples/spring && ./gradlew bootRun

# in another shell
examples/smoke.sh http://localhost:3001
```
