AuthZed (SpiceDB)
Maker of SpiceDB, the Apache-2.0 "open source permissions database" inspired by Google Zanzibar, offered self-hosted, as usage-priced AuthZed Cloud, as Dedicated cloud, or as a licensed self-hosted enterprise build.
Quick answer
What is AuthZed (SpiceDB)?
Short answer
AuthZed builds SpiceDB, described as "the open source permissions database": a Google Zanzibar-inspired, Apache-2.0 licensed engine for storing and querying fine-grained relationship-based (ReBAC) authorization data, with caveated relationships for ABAC-style conditions, per-request configurable consistency and reverse-index queries ("Who can access resource?"). SpiceDB runs on PostgreSQL, CockroachDB, Google Cloud Spanner or MySQL and ships official client libraries for Go, Node, Python, Ruby, Java and .NET. AuthZed sells it as AuthZed Cloud (usage-based, "Deploy a permissions system for $2/hr"), AuthZed Dedicated (reserved-vCPU private deployment) and SpiceDB Enterprise (annual per-region, per-vCPU self-hosted licence), plus Materialize for precomputed permissions and MCP servers for AI tooling. Netflix and Turo are named customer stories.
- Best for
- Product engineering teams building fine-grained, relationship-based permissions (sharing, hierarchies, multi-tenant B2B) at scale who want Zanzibar semantics without building them.
- When to choose
- Your permission model is relationship-heavy and must scale, and you want a proven open-source engine with a managed option.
- When not to choose
- You only need coarse roles inside one app, or you prefer a policy-language approach (OPA or Cedar style) over a relationship graph.
- Related tools & categories
- OryCerbosRun the IAM Stack FinderReport: The State of AI Agent Identity 2026
Categories
Common use cases
- Fine-grained application authorization (document sharing, folders, org hierarchies)
- Multi-tenant B2B permission models
- Externalising authorization from microservices via gRPC or HTTP API
- Permission-aware RAG and AI-agent access (LangChain, Pinecone, Weaviate integrations)
- Answering "who can access X" via reverse-index queries
Strengths
- Apache-2.0 open-source engine with a faithful Zanzibar design and a stated 5 ms p95 in production
- Official SDKs for Go, Node, Python, Ruby, Java and .NET plus an HTTP/OpenAPI API
- Runs on PostgreSQL, CockroachDB, Spanner or MySQL, with a Kubernetes operator for self-hosting
- Choice of free self-host, usage-based cloud, dedicated or licensed enterprise builds
Limitations & considerations
- ReBAC/Zanzibar modelling has a learning curve compared with simple RBAC libraries
- Self-hosted enterprise and Dedicated pricing are quote-only
- Operating SpiceDB yourself means running a datastore and tuning consistency and caching
- Focused on authorization data; no authentication, user directory or IdP features
Pricing model summary
Published (as published September 2026): SpiceDB open source free (Apache-2.0); AuthZed Cloud usage-based, resource-priced from "$2/hr"; Self-Hosted enterprise on an annual per-region, per-vCPU licence (contact sales); Dedicated Cloud priced on reserved-vCPU capacity (contact sales).
View vendor pricing page ↗Integrations
Fit
Alternatives & comparisons
Open source identity, authorization and zero trust stack (Kratos, Hydra, Keto, Oathkeeper) available self-hosted or as Ory Network SaaS.
Compare AuthZed (SpiceDB) vs Ory →Cerbos is an authorization management platform built around an open source policy decision point (PDP). It enforces fine-grained RBAC, ABAC, PBAC, and ReBAC policies for applications, APIs, workloads, and AI agents.
Compare AuthZed (SpiceDB) vs Cerbos →Permit.io provides authorization-as-a-service with a low-code policy management interface, RBAC/ABAC/ReBAC policy support, and a managed policy decision layer — enabling teams to ship fine-grained access control without building it from scratch.
Compare AuthZed (SpiceDB) vs Permit.io →Related glossary terms
Key identity & access terms relevant to AuthZed (SpiceDB).
AuthZed (SpiceDB) and its logo are trademarks of their respective owner. IDSync is an independent buyer resource and does not imply endorsement unless explicitly stated.
