Skip to main content

Secure features

Some features can be marked as secured in Toggly. For secured features, evaluation is:

  1. normal flag evaluation (filters)
  2. if the flag evaluates to true, the SDK calls your authorization hook

If authorization returns false, the feature is treated as disabled.

Configure an authorization hook​

Implement secure.AuthorizationService:

type MyAuth struct{}

func (a MyAuth) IsAllowed(ctx context.Context, featureKey string, evalCtx toggly.Context) (bool, error) {
// Your RBAC/ABAC checks here
return true, nil
}

Register it:

client, err := toggly.NewClient(toggly.Config{
AppKey: "YOUR_APP_KEY",
Environment: "Production",
AuthorizationService: MyAuth{},
})