IDSync — identity software buyer platform
Browse toolsRun Stack Finder
Aserto (Topaz) company logo

Aserto (Topaz)

Aserto built a fine-grained authorization platform around Topaz, an Apache 2.0 authorizer that pairs Open Policy Agent (Rego) with a Zanzibar-style relationship directory. The hosted Aserto Control Plane shut down on 31 May 2025; Topaz continues as a self-hosted open-source project.

Visit site

Quick answer

What is Aserto (Topaz)?

Short answer

Aserto was a Redmond, WA authorization start-up founded in 2020 by Omri Gazitt and Gert Drapers and funded with a $5.1M seed round (Costanoa, Heavybit) in 2021. Its architecture split authorization into a hosted Control Plane (policy images from GitHub/GitLab, identity sync from IdPs, decision-log aggregation, tenants) and edge authorizers running next to the application. The authorizer is Topaz, an open-source (Apache 2.0) service that embeds Open Policy Agent as the decision engine and adds a built-in directory implementing Google's Zanzibar data model, so a single policy can mix Rego attribute rules with relationship graph checks (RBAC, ABAC, ReBAC). Topaz exposes gRPC and REST Authorizer and Directory APIs, natively implements the OpenID AuthZEN evaluation API (since v0.32.54), ships a local console UI, and runs as a binary, Docker container, sidecar or Helm release. On 27 April 2025 the founders published "The final chapter for Aserto", stating they could not make the hosted model profitable; the SaaS control plane ceased operation by 31 May 2025 and Aserto wound down as a commercial entity. Topaz remains actively maintained under the aserto-dev GitHub org (v0.33.20 released 9 September 2026; ~1.4k stars), with maintainers saying they may offer paid support independently. No commercial pricing currently exists; the aserto.com pricing page is a legacy artefact of the discontinued service.

Best for
Platform or backend teams that want a self-hosted, OPA-compatible authorizer with a Zanzibar-style relationship store and are comfortable operating it without a vendor behind it.
When to choose
Choose Topaz when you want an Apache 2.0 authorizer that reuses OPA/Rego and adds Zanzibar-style relationships, you can self-host and operate it, and you accept a community-maintained project with no commercial vendor.
When not to choose
Avoid Aserto/Topaz if you need a hosted control plane, vendor support contracts, a horizontally scaled shared relationship store, or assurance that a funded company stands behind the project.

Categories

Common use cases

  • Fine-grained, resource-level permissions in multi-tenant SaaS applications
  • Combining RBAC/ABAC Rego policies with ReBAC relationship checks in one decision
  • Google Drive or GitHub-style document and folder sharing models
  • Replacing hand-rolled permission checks with a sidecar authorization service
  • Standards-based PEP/PDP integration via the OpenID AuthZEN evaluation API
  • Loading users and groups from Auth0, Okta, Entra ID, Cognito or Google into a local directory
  • Audit-grade decision logging for compliance and forensics
  • Low-latency local authorization for APIs where a remote PDP round-trip is unacceptable

Strengths

  • Apache 2.0 licence with no open-core feature gating; everything in Topaz is free to run
  • Uses upstream Open Policy Agent (OPA v1.20.x) so existing Rego skills and tooling carry over
  • Built-in Zanzibar-style directory lets one policy combine attributes and relationship graph queries
  • Native OpenID AuthZEN support and active involvement in the AuthZEN interop programme
  • gRPC and REST APIs plus SDKs for Node.js, Go, Python, Java, .NET and Ruby
  • Policies distributed as signed OCI images, giving a policy-as-code supply-chain story
  • Still actively released after the company wound down (v0.33.20, 9 September 2026)
  • Local console UI, templates and ds-load CLI shorten initial setup

Limitations & considerations

  • Aserto Inc. ceased commercial operations; the hosted Control Plane shut down 31 May 2025, so there is no vendor SLA, sales channel or hosted option
  • Maintenance now depends on a very small maintainer group (public data shows ~2 employees in 2026), a bus-factor risk for long-term adoption
  • Multi-instance policy and data distribution, IdP sync scheduling and decision-log aggregation formerly handled by the Control Plane must now be self-built
  • Directory is an embedded per-instance store (BoltDB-style), not a horizontally scaled shared database like SpiceDB or OpenFGA
  • Website, docs and pricing pages still describe the defunct SaaS, which makes the current offering confusing to evaluate

Pricing model summary

Topaz is free under Apache 2.0 and there is no active commercial price list. Aserto's former hosted tiers (Starter free up to 1,000 users; Essentials $0.20 per user/month up to 5,000 users; Pro and Enterprise by quote) are still shown on aserto.com/pricing but the SaaS was shut down on 31 May 2025 and cannot be purchased (as published September 2026).

Integrations

GoNode.jsJavaScriptPythonJava.NETRubygRPCRESTOIDCDockerKubernetesAuth0OktaMicrosoft Entra IDAWS CognitoOpen Policy AgentOpenID AuthZENGitHubGitLab

Fit

Company size
startup, smb, mid_market
Deployment
self_hosted
Source
open source
Pricing model
free (open source); hosted plans discontinued

Alternatives & comparisons

Open Policy Agent (OPA)

Open Policy Agent is an Apache 2.0, CNCF Graduated policy engine that evaluates Rego policies for application authorization, Kubernetes admission (Gatekeeper), Envoy/Istio, Terraform and CI/CD. It returns decisions; your services enforce them.

Compare Aserto (Topaz) vs Open Policy Agent (OPA) →
Cerbos

Cerbos is an authorization management platform built around an open source policy decision point (PDP). It enforces fine-grained RBAC, ABAC, PBAC, and ReBAC policies for applications, APIs, workloads, and AI agents.

Compare Aserto (Topaz) vs Cerbos →
AuthZed (SpiceDB)

Maker of SpiceDB, the Apache-2.0 "open source permissions database" inspired by Google Zanzibar, offered self-hosted, as usage-priced AuthZed Cloud, as Dedicated cloud, or as a licensed self-hosted enterprise build.

Compare Aserto (Topaz) vs AuthZed (SpiceDB) →
Permit.io

Permit.io provides authorization-as-a-service with a low-code policy management interface, RBAC/ABAC/ReBAC policy support, and a managed policy decision layer — enabling teams to ship fine-grained access control without building it from scratch.

Compare Aserto (Topaz) vs Permit.io →
OpenFGA

OpenFGA is an Apache 2.0 authorization engine, inspired by Google's Zanzibar paper, that stores relationship tuples and answers permission checks via gRPC/HTTP APIs. Originally built by Auth0/Okta, it is now a CNCF Incubating project with a hosted Auth0 FGA option.

Compare Aserto (Topaz) vs OpenFGA →

Key identity & access terms relevant to Aserto (Topaz).

Aserto (Topaz) and its logo are trademarks of their respective owner. IDSync is an independent buyer resource and does not imply endorsement unless explicitly stated.