Casbin
Casbin is an Apache 2.0 open-source authorization library, embedded in-process, that evaluates ACL, RBAC, ABAC and other models defined in a model.conf file against policy rules loaded from CSV or a database adapter. It entered the Apache Incubator in February 2026.
Quick answer
What is Casbin?
Short answer
Casbin is an open-source, in-process authorization library rather than a hosted service. Created by Yang Luo at Peking University in April 2017, it entered the Apache Software Foundation Incubator on 7 February 2026; the code and language ports now live under the apache/ GitHub organisation and casbin.org redirects to casbin.apache.org. Code is Apache 2.0 licensed. Casbin separates the access-control model from policy data: a model.conf file written in the PERM metamodel (Policy, Effect, Request, Matchers, plus an optional role_definition) declares how requests are matched, and a policy.csv or a storage adapter supplies the rules. One engine covers ACL, RBAC with role hierarchies and domains/tenants, ABAC via attribute expressions, RESTful path matching, deny-override and priority effects, plus BLP, Biba and UCON. Production-ready implementations exist for Go, Java, Node.js, PHP, Python, .NET, C++ and Rust, with experimental ports for Lua, Dart, Elixir and Delphi. Roughly 80 adapters (GORM, Xorm, MongoDB, Redis, DynamoDB, etcd, Firestore), watchers for multi-instance policy sync, a Raft-based dispatcher, an optional gRPC casbin-server, a Kubernetes admission webhook and dozens of web-framework middlewares surround the core. There is no commercial edition or paid tier; funding is via Open Collective donations, and Casbin does not handle authentication or user storage. Casdoor, a sibling IAM project from the same founder, is a separate product and was not part of the Apache donation.
- Best for
- Backend teams that want to embed a fast, model-driven RBAC/ABAC engine directly inside their own services in Go, Java, Node.js, Python, .NET, PHP or Rust without running a separate authorization server.
- When to choose
- Choose Casbin when you want a permissively licensed, in-process authorization engine that speaks RBAC, RBAC-with-tenants and ABAC through one config format across several languages, and you are comfortable owning policy storage and distribution.
- When not to choose
- Avoid Casbin if you need a turnkey managed authorization service with UI, audit and SLA, or Google Zanzibar-style relationship graphs at very large scale, where OpenFGA, SpiceDB (AuthZed) or Permit.io are a closer fit.
- Related tools & categories
- AuthorizationOpen Policy Agent (OPA)OsoRun the IAM Stack FinderReport: The State of AI Agent Identity 2026
Categories
Common use cases
- Embedding RBAC with role hierarchies inside a Go, Java, Node.js or Python monolith or microservice
- Multi-tenant SaaS authorization using RBAC with domains (per-tenant roles for the same user)
- Attribute-based checks such as resource ownership or age/region rules via ABAC matchers and eval()
- RESTful API authorization matching HTTP method plus path patterns (keyMatch, regexMatch)
- Kubernetes admission control policies via the Casbin K8s-Gatekeeper validating webhook
- API-gateway and reverse-proxy authorization plugins (Kong, Apache APISIX, OpenResty, Traefik, Caddy, Nginx)
- Keeping policies consistent across horizontally scaled instances with watchers or a Raft dispatcher
- Centralising enforcement behind a gRPC endpoint with the optional casbin-server when embedding is impractical
Strengths
- Apache 2.0 licence with Apache Software Foundation governance since February 2026 (Incubating), reducing single-vendor risk
- Single PERM model.conf format shared across eight production-ready language ports (Go, Java, Node.js, PHP, Python, .NET, C++, Rust)
- Broad model coverage in one engine: ACL, RBAC, RBAC with domains, ABAC, RESTful, deny-override, priority, BLP/Biba/LBAC, UCON
- In-process evaluation with sub-millisecond latency for small policy sets in Go (published benchmarks: ACL ~0.015 ms/op, RBAC ~0.022 ms/op)
- Roughly 80 storage adapters plus watchers for etcd, Redis, Kafka, NATS, RabbitMQ, PostgreSQL, ZooKeeper and cloud pub/sub
- Named adopters include VMware Harbor, Argo CD, Intel RMD and the Docker authz plugin
- Rich Management and RBAC APIs (AddPolicy, GetImplicitPermissionsForUser, EnforceEx with explanation) and an online model editor
- Long-running project (2017) with a 20k+ star Go repository and active 2026 releases (3.11.0, August 2026)
Limitations & considerations
- It is a library, not a platform: no bundled admin UI, audit log, policy versioning, or hosted control plane; you build or assemble those yourself
- Multi-instance consistency depends on wiring adapters, watchers or a dispatcher correctly; the docs warn dispatchers only sync changes made after all nodes start identical
- ABAC attributes can only be read from request elements, not policy elements, and JSON request parsing adds roughly 1.1-1.5x overhead
- Large policy sets are evaluated in memory (published Go benchmark ~24 ms/op at 110,000 RBAC rules) and there is no native relationship-graph engine of the Zanzibar type
- Apache Incubator status means governance and release processes are still maturing; feature parity and maintenance cadence vary across language ports, and there is no commercial support contract
Pricing model summary
Casbin is free under the Apache 2.0 licence with no paid edition, hosted tier or public price list. The project accepts voluntary donations via Open Collective (Backer USD 5/month, Sponsor USD 100/month, as published September 2026); these are contributions, not a commercial support contract.
Integrations
Fit
Alternatives & comparisons
Open Policy Agent is an Apache 2.0, CNCF Graduated policy engine that evaluates Rego policies for application authorization, Kubernetes admission (Gatekeeper), Envoy/Istio, Terraform and CI/CD. It returns decisions; your services enforce them.
Compare Casbin vs Open Policy Agent (OPA) →Oso Cloud is a managed authorization service where teams model RBAC, ReBAC and ABAC in the Polar language and query it from Node.js, Python, Go, Java, Ruby or .NET SDKs. In 2026 Oso added Oso for Agents, a control product for AI coding agents.
Compare Casbin vs Oso →Cerbos is an authorization management platform built around an open source policy decision point (PDP). It enforces fine-grained RBAC, ABAC, PBAC, and ReBAC policies for applications, APIs, workloads, and AI agents.
Compare Casbin vs Cerbos →Maker of SpiceDB, the Apache-2.0 "open source permissions database" inspired by Google Zanzibar, offered self-hosted, as usage-priced AuthZed Cloud, as Dedicated cloud, or as a licensed self-hosted enterprise build.
Compare Casbin vs AuthZed (SpiceDB) →OpenFGA is an Apache 2.0 authorization engine, inspired by Google's Zanzibar paper, that stores relationship tuples and answers permission checks via gRPC/HTTP APIs. Originally built by Auth0/Okta, it is now a CNCF Incubating project with a hosted Auth0 FGA option.
Compare Casbin vs OpenFGA →Related glossary terms
Key identity & access terms relevant to Casbin.
Casbin and its logo are trademarks of their respective owner. IDSync is an independent buyer resource and does not imply endorsement unless explicitly stated.
