Dart & Flutter SDK

neuctra_authix_dart_package is the official Dart SDK for Neuctra Authix. It mirrors the JavaScript SDK — the same class name, method names, routes and security model — expressed with Dart types, null safety and generics, plus Stream-based cursor traversal that suits a ListView.

Dart SDK ^3.0.0Flutter · Android · iOS · Web · DesktopOne dependency: package:http

Quick start

Dart
1import 'dart:io';
2import 'package:neuctra_authix_dart_package/neuctra_authix_dart_package.dart';
3
4// Use only in a trusted Dart server process, never in a shipped Flutter app.
5final authix = NeuctraAuthix(
6  NeuctraAuthixConfig(
7    appId: Platform.environment['AUTHIX_APP_ID']!,
8    apiKey: Platform.environment['AUTHIX_API_KEY']!,
9  ),
10);
11
12await authix.loginUser(
13  const LoginParams(email: '[email protected]', password: 'API'),
14);
15
16final session = await authix.checkUserSession();
17
18// Every list is a bounded Page — 20 records by default, 100 maximum.
19final page = await authix.getUserData(
20  GetUserDataParams(userId: session.userId!, limit: 50),
21);
22
23for (final record in page) {
24  print(record['title']);
25}

What the SDK gives you

AreaCountWhat it covers
Auth & users11Signup, login, logout, session checks, profile, update, delete, email OTP verification.
User security3Forgot-password OTP, password reset, existence check.
User records9Per-user record CRUD, search, bulk delete and atomic batches — every read cursor-paginated.
App data7App-wide record CRUD plus search, scoped by appId. API key only.
Across all users6List and search every user of the app and all their records. API key only.
Escape hatch2rawRequest() for unwrapped endpoints, pages() to walk any cursor-taking method.

One-to-one with the JavaScript SDK

If you already know the JavaScript SDK, you already know this one. Object literals become const parameter classes, and the wire format is identical.

Dart
1// TypeScript
2await authix.addUserData({
3  userId: "u1",
4  dataCategory: "notes",
5  data: { title: "Hello" },
6});
7
8// Dart — same method, same route, same payload
9await authix.addUserData(
10  const AddUserDataParams(
11    userId: 'u1',
12    dataCategory: 'notes',
13    data: {'title': 'Hello'},
14  ),
15);

Package layout

A single import gives you the client, the config, every parameter and response class, the exception type and the session store.

Bash
lib/
├── neuctra_authix_dart_package.dart   # single import — exports everything
└── src/
    ├── client/neuctra_authix_client.dart   # NeuctraAuthix — every method
    ├── models/config.dart                  # NeuctraAuthixConfig
    ├── models/api_key.dart                 # key parsing and masking
    ├── models/pagination.dart              # Page<T>, cursor traversal
    ├── models/params.dart                  # request objects
    ├── models/responses.dart               # DataItem, session, envelopes
    ├── http/session_store.dart             # cookie jar
    └── exceptions/…                        # the typed error hierarchy

Security model

Neuctra Authix uses two independent mechanisms, and each method uses exactly one of them. Every method in these docs is tagged with which.

MechanismUsed byHow it works
Session cookieEnd-user routesThe backend issues an HTTP-only authix_user_session cookie on signup and login. The SDK stores it and replays it on every call.
API keyTrusted serverak_live_… — sent as x-api-key. Grants full account authority; never ship it in a mobile or web build.

Protect user ownership in your backend

API-key calls have full account authority and can target users by id. Your backend must authenticate the end user and derive the user id from its verified session before making a call.

Read this before shipping

A mobile binary can be decompiled, so never ship the account API key. Flutter apps must call your backend for Authix operations.

  • Keep every API-key call on your own backend and expose only the operation and data needed by the Flutter app.
  • Never store an API key in --dart-define, an asset, or source. Defines are compiled into the binary in plain text.

Next steps

  • Install the package and initialise the client.
  • Wire up login, signup and session persistence.
  • Store per-user records with the user data API.

Related