~/tools/openfga
OpenFGA
tool

OpenFGA

OpenFGA is an open source authorization engine you can self-host — inspired by Google Zanzibar, it decides who can access what using relationship-based access control (ReBAC), and stands in as an Auth0 FGA or AWS Verified Permissions alternative.

What is OpenFGA?

OpenFGA is an open source authorization engine that decides whether a user can perform an action on a resource — the “can Anne view document X?” question. Written in Go and inspired by Google’s Zanzibar paper, it centralizes fine-grained permissions in a dedicated service with a readable modeling language and millisecond check APIs.

What is OpenFGA best for?

Developers who need application-level authorization more granular than simple roles — per-object sharing, nested groups, “editor vs viewer” on individual resources, or Google Docs-style permission inheritance. It fits teams who want to pull access-control logic out of scattered if statements and app database tables into one auditable, centrally-modeled service.

What can OpenFGA do?

  • Model permissions with relationship-based access control (ReBAC), plus role-based (RBAC) and attribute-based (ABAC) patterns via contextual tuples and conditions
  • Answer authorization questions over HTTP and gRPC APIs — check, list-objects, list-users, and expand
  • Define models in a purpose-built DSL and test them in an interactive Playground before shipping
  • Integrate with official SDKs for Go, Java, Node.js, Python, and .NET, plus a CLI and Terraform provider
  • Persist relationship tuples in PostgreSQL 14+, MySQL 8, or SQLite (beta), with an in-memory store for local dev
  • Scale horizontally — it’s stateless, so you run multiple instances behind a load balancer

Where does OpenFGA fall short?

  • It handles authorization only — not authentication. You still need an identity provider such as Keycloak or Authentik to log users in and tell OpenFGA who they are.
  • Adopting it means rethinking your permission model in Zanzibar terms (types, relations, tuples). The ReBAC mental model is powerful but has a real learning curve, and migrating existing role logic into it is non-trivial.
  • It’s a decision engine, not an admin product — there’s no built-in UI for business users to manage roles day to day, so you build that layer yourself.

Is OpenFGA free?

Yes — OpenFGA is fully free and open source under the Apache-2.0 license, with no paid tier or feature-gated edition. You only pay for the servers and database you run it on. The managed, paid counterpart is Auth0 FGA (Okta), which is built on the same core but hosts and scales it for you.

What does OpenFGA replace?

OpenFGA is a self-hosted alternative to managed authorization services like Auth0 FGA, Okta’s fine-grained authorization, and AWS Verified Permissions. It delivers the same fine-grained, policy-driven access checks without per-request cloud pricing or vendor lock-in. It’s also directly comparable to other open source engines such as SpiceDB, Cerbos, and OPA.

FAQ

Is OpenFGA open source? Yes. It’s Apache-2.0 licensed and a Cloud Native Computing Foundation (CNCF) project, donated by Auth0/Okta and developed in the open via public RFCs.

Can I self-host OpenFGA for free? Yes. The software is free; your only cost is the infrastructure — a server for the OpenFGA service and a PostgreSQL, MySQL, or SQLite database to store relationship tuples.

Is OpenFGA a good Auth0 FGA alternative? For teams comfortable running infrastructure, yes — Auth0 FGA is built on OpenFGA and shares its core, so you get the same model and APIs while avoiding usage-based pricing. Auth0 FGA’s value is handling the hosting and scaling for you.

What do I need to run OpenFGA? The OpenFGA binary or Docker image plus a supported datastore (PostgreSQL 14+, MySQL 8, or SQLite in beta). The in-memory store is for development only, since data is lost on restart.