---
title: "AuthZed SpiceDB Review 2026: Pricing &amp; Alternatives | IDSync"
description: "AuthZed and SpiceDB review: Apache-2.0 Zanzibar-style permissions database, ReBAC, SDKs, datastores, cloud pricing from $2/hr, limits and alternatives."
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "SoftwareApplication",
      "name": "AuthZed (SpiceDB)",
      "applicationCategory": "SecurityApplication",
      "applicationSubCategory": "Identity & Access Management",
      "url": "https://authzed.com/",
      "description": "AuthZed builds SpiceDB, described as \"the open source permissions database\": a Google Zanzibar-inspired, Apache-2.0 licensed engine for storing and querying fine-grained relationship-based (ReBAC) authorization data, with caveated relationships for ABAC-style conditions, per-request configurable consistency and reverse-index queries (\"Who can access resource?\"). SpiceDB runs on PostgreSQL, CockroachDB, Google Cloud Spanner or MySQL and ships official client libraries for Go, Node, Python, Ruby, Java and .NET. AuthZed sells it as AuthZed Cloud (usage-based, \"Deploy a permissions system for $2/hr\"), AuthZed Dedicated (reserved-vCPU private deployment) and SpiceDB Enterprise (annual per-region, per-vCPU self-hosted licence), plus Materialize for precomputed permissions and MCP servers for AI tooling. Netflix and Turo are named customer stories.",
      "offers": {
        "@type": "Offer",
        "category": "usage-based / enterprise"
      },
      "dateModified": "2026-09-17T14:55:08.010998+00:00"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is AuthZed (SpiceDB)?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "AuthZed builds SpiceDB, described as \"the open source permissions database\": a Google Zanzibar-inspired, Apache-2.0 licensed engine for storing and querying fine-grained relationship-based (ReBAC) authorization data, with caveated relationships for ABAC-style conditions, per-request configurable consistency and reverse-index queries (\"Who can access resource?\"). SpiceDB runs on PostgreSQL, CockroachDB, Google Cloud Spanner or MySQL and ships official client libraries for Go, Node, Python, Ruby, Java and .NET. AuthZed sells it as AuthZed Cloud (usage-based, \"Deploy a permissions system for $2/hr\"), AuthZed Dedicated (reserved-vCPU private deployment) and SpiceDB Enterprise (annual per-region, per-vCPU self-hosted licence), plus Materialize for precomputed permissions and MCP servers for AI tooling. Netflix and Turo are named customer stories."
          }
        },
        {
          "@type": "Question",
          "name": "Who is AuthZed (SpiceDB) best for?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Product engineering teams building fine-grained, relationship-based permissions (sharing, hierarchies, multi-tenant B2B) at scale who want Zanzibar semantics without building them."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://idsync.com/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Directory",
          "item": "https://idsync.com/directory"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "AuthZed (SpiceDB)",
          "item": "https://idsync.com/directory/authzed"
        }
      ]
    }
  ]
---

[![IDSync — identity software buyer platform](/assets/idsync-logo-BKS89EW4.png)](/)

[Directory](/directory)

[Compare](/compare)

[Resources](/resources)

[Browse tools](/directory)[Run Stack Finder](/stack-finder)

1.  [Home](/)
2.  [Directory](/directory)
3.  AuthZed (SpiceDB) 

AS 

# AuthZed (SpiceDB)

Maker of SpiceDB, the Apache-2.0 "open source permissions database" inspired by Google Zanzibar, offered self-hosted, as usage-priced AuthZed Cloud, as Dedicated cloud, or as a licensed self-hosted enterprise build.

Last updated today

[Visit site](https://authzed.com/)

Quick answer

## What is AuthZed (SpiceDB)?

Short answer

AuthZed builds SpiceDB, described as "the open source permissions database": a Google Zanzibar-inspired, Apache-2.0 licensed engine for storing and querying fine-grained relationship-based (ReBAC) authorization data, with caveated relationships for ABAC-style conditions, per-request configurable consistency and reverse-index queries ("Who can access resource?"). SpiceDB runs on PostgreSQL, CockroachDB, Google Cloud Spanner or MySQL and ships official client libraries for Go, Node, Python, Ruby, Java and .NET. AuthZed sells it as AuthZed Cloud (usage-based, "Deploy a permissions system for $2/hr"), AuthZed Dedicated (reserved-vCPU private deployment) and SpiceDB Enterprise (annual per-region, per-vCPU self-hosted licence), plus Materialize for precomputed permissions and MCP servers for AI tooling. Netflix and Turo are named customer stories.

Best for

Product engineering teams building fine-grained, relationship-based permissions (sharing, hierarchies, multi-tenant B2B) at scale who want Zanzibar semantics without building them.

When to choose

Your permission model is relationship-heavy and must scale, and you want a proven open-source engine with a managed option.

When not to choose

You only need coarse roles inside one app, or you prefer a policy-language approach (OPA or Cedar style) over a relationship graph.

Related tools & categories

[Ory](/directory/ory)[Cerbos](/directory/cerbos)[Run the IAM Stack Finder](/stack-finder)[Report: The State of AI Agent Identity 2026](/reports/state-of-ai-agent-identity-2026)

## Categories

## Common use cases

-   Fine-grained application authorization (document sharing, folders, org hierarchies) 
-   Multi-tenant B2B permission models 
-   Externalising authorization from microservices via gRPC or HTTP API 
-   Permission-aware RAG and AI-agent access (LangChain, Pinecone, Weaviate integrations) 
-   Answering "who can access X" via reverse-index queries 

## Strengths

-   Apache-2.0 open-source engine with a faithful Zanzibar design and a stated 5 ms p95 in production 
-   Official SDKs for Go, Node, Python, Ruby, Java and .NET plus an HTTP/OpenAPI API 
-   Runs on PostgreSQL, CockroachDB, Spanner or MySQL, with a Kubernetes operator for self-hosting 
-   Choice of free self-host, usage-based cloud, dedicated or licensed enterprise builds 

## Limitations & considerations

-   ReBAC/Zanzibar modelling has a learning curve compared with simple RBAC libraries 
-   Self-hosted enterprise and Dedicated pricing are quote-only 
-   Operating SpiceDB yourself means running a datastore and tuning consistency and caching 
-   Focused on authorization data; no authentication, user directory or IdP features 

## Pricing model summary

Published (as published September 2026): SpiceDB open source free (Apache-2.0); AuthZed Cloud usage-based, resource-priced from "$2/hr"; Self-Hosted enterprise on an annual per-region, per-vCPU licence (contact sales); Dedicated Cloud priced on reserved-vCPU capacity (contact sales).

[View vendor pricing page ↗](https://authzed.com/pricing)

## Integrations

PostgreSQL CockroachDB Google Cloud Spanner MySQL Kubernetes gRPC Go Node.js Python Ruby Java .NET LangChain LangGraph Pinecone Weaviate Testcontainers 

## Fit

Company size

startup, smb, mid\_market, enterprise

Deployment

saas, self\_hosted

Source

open core

Pricing model

usage-based / enterprise

## Alternatives & comparisons

[Ory](/directory/ory)

Open source identity, authorization and zero trust stack (Kratos, Hydra, Keto, Oathkeeper) available self-hosted or as Ory Network SaaS.

[Compare AuthZed (SpiceDB) vs Ory →](/compare/authzed-vs-ory)

[Cerbos](/directory/cerbos)

Cerbos is an authorization management platform built around an open source policy decision point (PDP). It enforces fine-grained RBAC, ABAC, PBAC, and ReBAC policies for applications, APIs, workloads, and AI agents.

[Compare AuthZed (SpiceDB) vs Cerbos →](/compare/authzed-vs-cerbos)

[Permit.io](/directory/permit-io)

Permit.io provides authorization-as-a-service with a low-code policy management interface, RBAC/ABAC/ReBAC policy support, and a managed policy decision layer — enabling teams to ship fine-grained access control without building it from scratch.

[Compare AuthZed (SpiceDB) vs Permit.io →](/compare/authzed-vs-permit-io)

## Related glossary terms

Key identity & access terms relevant to AuthZed (SpiceDB).

[Relationship-Based Access Control](/glossary/relationship-based-access-control)[Attribute-Based Access Control](/glossary/attribute-based-access-control)[Role-Based Access Control](/glossary/rbac)[Policy as Code](/glossary/policy-as-code)[Principle of Least Privilege](/glossary/least-privilege)[OAuth Scopes](/glossary/oauth-scopes)

IDSync provides educational buyer guidance based on publicly available information, editorial review, and user-submitted data. Vendor information should be verified before purchase. [Who we are, our methodology & disclosure policy](/about).

AuthZed (SpiceDB) and its logo are trademarks of their respective owner. IDSync is an independent buyer resource and does not imply endorsement unless explicitly stated.

### Take action

[Request vendor shortlist](/request-shortlist)[Run the IAM Stack Finder](/stack-finder)[Request vendor intro](/contact)[Docs ↗](https://authzed.com/docs)[Pricing ↗](https://authzed.com/pricing)

### Work at AuthZed (SpiceDB)?

Claim this profile to keep it current.

Claim this profile

[![IDSync home](/assets/idsync-logo-BKS89EW4.png)](/)

The buyer-focused platform for identity, access, and authentication software.

### Platform

-   [Home](/)
-   [IAM Stack Finder](/stack-finder)
-   [Directory](/directory)
-   [Resources](/resources)
-   [State of AI Agent Identity 2026](/reports/state-of-ai-agent-identity-2026)
-   [Buyer Guides](/guides)
-   [Glossary](/glossary)
-   [Newsletter](/newsletter)
-   [Newsletter Archive](/newsletter/archive)

### Best of guides

-   [All comparisons](/compare)
-   [All vendor alternatives](/alternatives)
-   [Best SSO tools](/compare/best-sso-tools)
-   [Best MFA tools](/compare/best-mfa-tools)
-   [Best PAM tools](/compare/best-pam-tools)
-   [Best IGA tools](/compare/best-iga-tools)
-   [Best CIAM tools](/compare/best-ciam-tools)
-   [Best passwordless auth](/compare/best-passwordless-authentication-tools)
-   [Best identity security](/compare/best-identity-security-tools)
-   [Best machine identity](/compare/best-machine-identity-tools)
-   [Best SaaS access governance](/compare/best-saas-access-governance-tools)
-   [Best developer auth](/compare/best-developer-authentication-tools)
-   [Best for startups](/compare/best-iam-tools-for-startups)
-   [Best for enterprises](/compare/best-iam-tools-for-enterprises)
-   [Best SCIM tools](/compare/best-scim-provisioning-tools)
-   [Best for AI agents](/compare/best-ai-agent-identity-tools)
-   [Best NHI tools](/compare/best-nhi-management-tools)
-   [Okta pricing explained](/guides/okta-pricing)
-   [Auth0 pricing explained](/guides/auth0-pricing)
-   [Okta alternatives](/alternatives/okta)
-   [Auth0 alternatives](/alternatives/auth0)

### For Vendors

-   [Sponsor](/sponsor)
-   [Badges](/badges)
-   [Submit Product](/submit-product)
-   [Claim Profile](/claim-profile)
-   [Partner](/partner)

### Company

-   [About & Methodology](/about)
-   [Contact](/contact)
-   [Privacy](/privacy)

Vendor names, logos, and trademarks are the property of their respective owners. IDSync is an independent buyer resource and does not imply endorsement unless explicitly stated. Logos are displayed for identification purposes only.

IDSYNC® is a registered trademark of TRZ Holdings, Inc. and InnerApps, LLC (U.S. Trademark Registration No. 4,263,864). IDSync (idsync.com) is operated by TetraCore, Bowling Green, Ohio, part of the TRZ Holdings family. The IDSync® Active Directory synchronizer is a distinct product, now at [identitysyncronizer.com](https://identitysyncronizer.com) — [learn more](/about#idsync-disambiguation).

© 2026 IDSync. All rights reserved.

Editorial independence. Sponsored placements are clearly disclosed.