Prototype
Open-source software
Prototype with the official distribution while treating the environment as non-production.23
Authorization
Open-source relationship-based authorization engine for evaluating user, object, and relation tuples against versioned models.
Choose OpenFGA when permissions are naturally expressed as nested ownership, membership, sharing, and inherited relationships and the team can own model and service operations.12
Decide whether relationship tuples are the correct authorization abstraction and whether the team can operate the service.
OpenFGA evaluates relationship models and tuples; it does not supply authentication, general policy administration, application enforcement, or the domain events that keep tuples correct.1
For: Platform teams with relationship-heavy authorization and explicit self-hosting capability
Open-source software with self-operated infrastructure and engineering cost rather than a stored vendor subscription price.3
Prototype
Prototype with the official distribution while treating the environment as non-production.23
Production
Budget for compute, datastore, backups, observability, availability, upgrades, model testing, and on-call ownership.23
OpenFGA · Accessed Official
OpenFGA · Accessed Official
OpenFGA · Accessed Official
NIST · Accessed Official
Cerbos · Accessed Official
Permit.io · Accessed Official
Cerbos · Accessed Official
Permit.io · Accessed Official