OpenFGA

API

Self-hosted relationship-based authorization engine with HTTP and gRPC APIs

Price
Free, open source
Access
Optional server authentication

About

Open-source authorization engine for relationship, role and conditional attribute permissions. Run your own server with a configured datastore; applications model relationships and ask whether a user can access an object. It provides authorization decisions, not user sign-in.

What you can do with it

  • Check whether a user can read or edit a document based on relationships
  • Model organization roles, sharing and inherited access outside application code
  • List the resources a user can access through an authorization API

Get started

  1. Run an OpenFGA server and configure its datastore and authentication
  2. Create a store, authorization model and relationship tuples
  3. Use the Check API to make an access decision

Example

curl "http://localhost:8080/healthz"

Details

Hosting
Self-hosted, Runs locally
Available in
Worldwide
Official SDKs
JavaScript/TypeScript, Python, Go, Java, C#
MCP server
None

Tasks

Alternatives

Other tools for the same tasks.

Last checked on .