Authorization

Cerbos

Policy-as-code authorization centered on an open-source policy decision point, with optional managed control-plane and context services.

Editorial verdict

Choose Cerbos when policy should be externalized from application code and evaluated by a PDP near the application, while the team retains meaningful deployment control.13

Best for

  • Teams preferring policy-as-code
  • Services that need local or self-operated authorization decisions
  • Organizations separating policy decisions from application enforcement
1

Not ideal for

  • Products needing only a few inline role checks
  • Teams expecting a product to invent domain policy automatically
  • Organizations unwilling to operate PDP deployment and policy rollout
1
Main trade-off

Cerbos provides a clear PDP boundary and policy workflow, but the application team still owns enforcement, context quality, deployment, and safe failure behavior.1

Product boundary

Decide whether a separately deployed, policy-as-code PDP is the right authorization boundary.

Cerbos PDP returns policy decisions; applications still supply trusted context and enforce them. Hub and Synapse extend, rather than erase, that boundary.13

For: Engineering and platform teams wanting explicit policy separation with local decision control

  • A stable inline role model remains sufficient
  • A managed administration surface becomes more important than local control
  • Relationship graphs dominate the authorization model
  • The team cannot operate PDP availability and policy rollout

Why teams consider Cerbos

  • Open-source PDPRun authorization decisions near application services in team-controlled infrastructure.1
  • Policy as codeVersion, review, test, and deploy policies independently from application logic.1
  • Managed extension pathCerbos Hub and Synapse can add control-plane and context capabilities when needed.1
  • Application-language integrationsSDK and enforcement integrations connect application requests to policy decisions.1

Pricing

Open-source PDP plus self-operated infrastructure, with optional managed services and enterprise contract terms; verify current official documents.3

Self-operated

Open-source Cerbos PDP

Software licensing does not remove infrastructure, storage, availability, observability, upgrade, and staffing costs.34

Managed coordination

Current Cerbos managed offer

Verify current product packages, usage limits, support, and managed-service boundaries on official sources.34

Enterprise

Contracted terms

Review the current service description, security documents, deployment terms, and applicable order form.34

Open-source boundary
The PDP may be self-operated; associated infrastructure and operational work remain real cost.34
Managed boundary
Hub and Synapse are separate managed capabilities with current commercial terms.34
Freshness policy
No numeric amount is stored here; verify pricing and legal documents at decision time.34
Pricing checked View official pricing

Cerbos vs alternatives

Permit.io

Choose when
Prefer a broader managed authorization administration platform.
Compared with Cerbos
Accept more managed control-plane and commercial coupling.68

OpenFGA

Choose when
Permissions are fundamentally relationship-graph shaped.
Compared with Cerbos
Adopt a narrower model and own graph operations.7

Application-owned authorization

Choose when
Policy remains small, local, and stable.
Compared with Cerbos
Application code carries consistency and audit burden.5

Resources and sources

Evaluate

  • Documentation
    Open
  • Pricing
    Open

Governance

  • Legal documents
    Open
  • GitHub
    Open

Related tasks

Starter stacks

  1. 1
    Cerbos documentation

    Cerbos · Accessed Official

  2. 2
    Cerbos Hub documentation

    Cerbos · Accessed Official

  3. 3
    Cerbos pricing

    Cerbos · Accessed Official

  4. 4
    Cerbos legal documents

    Cerbos · Accessed Official

  5. 5
    NIST Role Based Access Control publications

    NIST · Accessed Official

  6. 6
    Permit.io documentation

    Permit.io · Accessed Official

  7. 7
    OpenFGA concepts

    OpenFGA · Accessed Official

  8. 8
    Permit.io pricing

    Permit.io · Accessed Official