Skip to main content
Version: Next

Public Protobuf APIs

Nauthilus keeps public protobuf contracts below api/<domain>/v1. The directory and protobuf package version describe the wire contract; the generated Go import follows the current Nauthilus major module.

Source directoryProtobuf packagePurpose
api/auth/v1nauthilus.auth.v1Authentication service and messages
api/common/v1nauthilus.common.v1Shared message types
api/identity/v1nauthilus.identity.v1Identity-backend service and messages
api/policy/v1nauthilus.policy.v1Generic Policy decision service and messages

Generated Go clients import these packages below github.com/croessner/nauthilus/v4/api/.../v1. Code generated from the v3 go_package metadata should be regenerated for v4. This source-import change is separate from protobuf wire compatibility.

Compatibility Boundary

The v4 migration preserves protobuf package names, service and method names, field numbers, field wire types, and HTTP paths. Independently generated clients therefore remain wire-compatible when they use those stable identifiers. Do not rely on generated Go package paths or Go type identity remaining compatible across a major module change.

Safe evolution adds new fields with unused numbers and preserves existing meaning. Removing or reusing a field number, changing its wire type, renaming a service or method, or moving an HTTP route is a wire-contract change. Reserve removed field numbers and names rather than recycling them.

The Generic Policy gRPC entry point is /nauthilus.policy.v1.PolicyDecisionService/Evaluate; its typed value, ordered-record, security, status, and decision semantics match the REST contract. See Generic Policy API.

Go Toolchain and Native Plugins

The v4.0.0-alpha.1 source and release build use Go 1.27 with GOEXPERIMENT=runtimesecret. Native Go .so plugins are not protected by protobuf wire compatibility: rebuild them from the exact Nauthilus commit with the same Go version, module graph, experiment, build tags, CGO mode, operating system, and architecture. The public pluginapi/v1 contract does not make mismatched Go binaries load-compatible.