OpenFGA
APISelf-hosted relationship-based authorization engine with HTTP and gRPC APIs
- Price
- Free, open source
- Access
- Optional server authentication
About
Open-source authorization engine for relationship, role and conditional attribute permissions. Run your own server with a configured datastore; applications model relationships and ask whether a user can access an object. It provides authorization decisions, not user sign-in.
What you can do with it
- Check whether a user can read or edit a document based on relationships
- Model organization roles, sharing and inherited access outside application code
- List the resources a user can access through an authorization API
Get started
- Run an OpenFGA server and configure its datastore and authentication
- Create a store, authorization model and relationship tuples
- Use the Check API to make an access decision
Example
curl "http://localhost:8080/healthz"Details
- Hosting
- Self-hosted, Runs locally
- Available in
- Worldwide
- Official SDKs
- JavaScript/TypeScript, Python, Go, Java, C#
- MCP server
- None