Runnable example

Protect an internal API

Run Identity and Policy against disposable PostgreSQL, then exercise an API route that allows or denies access based on the signed-in user's current identity and configured policy.

Requirements

1. Create local-only credentials and start PostgreSQL

node examples/internal-api/setup-local-policy.js
set -a
. examples/internal-api/.local/quickstart.env
set +a
docker compose -f examples/internal-api/compose.postgres.yml up -d --wait
npm run migrate

The setup command creates private credentials under the ignored .local/ directory and refuses to overwrite existing files.

2. Verify Identity, Policy, and Diesel

TEST_DATABASE_URL="$DATABASE_URL" npm test --prefix Aarchon_Identity
npm test --prefix aarchon_backend
TEST_DATABASE_URL="$DATABASE_URL" npm test --prefix examples/internal-api
cargo run --manifest-path examples/diesel-postgres/Cargo.toml

The database-backed test creates a throwaway test account, signs in through Identity, then exercises an allowed and a denied API request through Policy. Diesel runs a read-only role-count query against the same schema; it does not create accounts or handle credentials.

3. Exercise the complete HTTP flow

Keep each service in its own terminal. Start Identity:

set -a
. examples/internal-api/.local/quickstart.env
set +a
LEDGER_SIGNING_KEY="$IDENTITY_LEDGER_SIGNING_KEY" npm start

Start Policy in another terminal:

cd aarchon_backend
set -a
. ../examples/internal-api/.local/quickstart.env
. ../examples/internal-api/.local/policy.env
set +a
npm run validate-policy -- ../examples/internal-api/.local/policy.json
PORT=4000 GOVERNANCE_POLICY_FILE=../examples/internal-api/.local/policy.json \
LEDGER_SIGNING_KEY="$POLICY_LEDGER_SIGNING_KEY" npm start

Start the example API in a third terminal:

set -a
. examples/internal-api/.local/policy.env
set +a
npm --prefix examples/internal-api start

Register or sign in at http://127.0.0.1:3000, then use the returned access token:

curl -i -H "Authorization: Bearer $ACCESS_TOKEN" \
  http://127.0.0.1:5000/api/reports/team-a
curl -i -H "Authorization: Bearer $ACCESS_TOKEN" \
  http://127.0.0.1:5000/api/reports/team-b

The sample policy permits the configured user role to read team A and denies team B. Do not use demo data or local credentials in production.

Stop and clean up

docker compose -f examples/internal-api/compose.postgres.yml down
rm -f examples/internal-api/.local/policy.json \
  examples/internal-api/.local/policy.env \
  examples/internal-api/.local/quickstart.env
rmdir examples/internal-api/.local

For the policy schema and failure behavior, see the policy guide and trust boundaries.