Skip to main content
Self-hosted Dograh ships with a built-in local authentication provider (email + password, backed by a signed JWT). This is the default and needs no external service. To offer social logins (Google, GitHub, and others), you can delegate sign-in to Stack Auth. Enabling it is a runtime configuration change β€” set a few environment variables and restart. The prebuilt dograhai/dograh-api and dograhai/dograh-ui images work as-is; you do not need to rebuild or build from source.
The active provider is controlled by the backend AUTH_PROVIDER variable (local by default). The frontend discovers the provider β€” and, for Stack, its public client config β€” at runtime from the backend’s /api/v1/health response, so the browser bundle never needs Stack values baked in at build time.

How it works

  1. The backend reads AUTH_PROVIDER and the Stack settings from its environment.
  2. When AUTH_PROVIDER=stack, /api/v1/health returns the public Stack client config (project id + publishable client key).
  3. The UI fetches that at runtime and initializes the Stack SDK in the browser.
  4. The secret server key is used only server-side (by the backend and the UI’s server runtime) and is never sent to the browser.

Prerequisites

A Stack Auth project. Create one in the Stack Auth dashboard and configure the social login providers you want to offer.

Step 1 β€” Collect your Stack credentials

From your project in the Stack Auth dashboard, gather:

Step 2 β€” Configure the backend (api)

Set these on the api service. Add them to the environment: block of the api service in your docker-compose.yaml:
docker-compose.yaml

Step 3 β€” Configure the UI (ui)

The UI runs server-side code (SSR pages and the /handler/* auth routes) that calls Stack with the secret server key, so the ui service needs that one value too:
docker-compose.yaml
The ui service does not need the project id or publishable client key β€” it receives those from the backend at runtime via /api/v1/health. Only the secret server key (used server-side) is set here.

Step 4 β€” Restart and verify

Recreate the containers so they pick up the new environment:
Confirm the backend reports the active provider and the public client config:
Then open the UI. The sign-in page should now present your configured Stack Auth social login options instead of the local email/password form.

Environment variable reference

STACK_SECRET_SERVER_KEY is the only secret here. Keep it out of any client-visible config and never bake it into an image. The project ID and publishable client key are public by design β€” the backend deliberately serves them to the browser so Stack can initialize at runtime.

Reverting to local auth

Remove the variables above (or set AUTH_PROVIDER=local) and restart. The UI detects local from the backend at runtime and falls back to the built-in email/password flow β€” no rebuild required.