IDSync — identity software buyer platform
Browse toolsRun Stack Finder
Open Policy Agent (OPA) company logo

Open Policy Agent (OPA)

Open Policy Agent is an Apache 2.0, CNCF Graduated policy engine that evaluates Rego policies for application authorization, Kubernetes admission (Gatekeeper), Envoy/Istio, Terraform and CI/CD. It returns decisions; your services enforce them.

Visit site

Quick answer

What is Open Policy Agent (OPA)?

Short answer

Open Policy Agent (OPA) is an open source, general-purpose policy engine that decouples policy decisions from the services that enforce them. Policies are written in Rego, a declarative language derived from Datalog and built for querying JSON-like structured data; services send OPA a query plus input and receive a JSON decision, which the caller enforces. OPA runs as a sidecar or daemon over REST, as an embedded Go library, or as policies compiled to WebAssembly, and it ships management APIs (bundles, decision logs, status, discovery) for fleet control, though no control plane is included by default. Its scope is wider than application authorization: Gatekeeper handles Kubernetes admission control, opa-envoy-plugin implements Envoy's external authorization API for Envoy and Istio meshes, and Conftest and Terraform integrations cover infrastructure and CI/CD policy. OPA is Apache 2.0 licensed and has been a CNCF Graduated project since January 2021; version 1.0 (December 2024) made the Rego v1 syntax the default. In August 2025 the project's creators and much of the Styra team joined Apple, and Styra's commercial pieces (EOPA, OPA Control Plane, Regal, SDKs) were donated to the CNCF OPA organization; the EOPA repository has since been archived. No first-party paid tier exists; third parties such as Permit.io and Aserto sell OPA-based platforms.

Best for
Platform and security engineering teams that want one policy-as-code engine spanning application authorization, Kubernetes admission, service-mesh and infrastructure checks, and are prepared to operate it themselves.
When to choose
Choose OPA when you want a single, vendor-neutral policy-as-code engine you can run anywhere, especially if Kubernetes admission, Envoy/Istio authorization or IaC checks sit alongside application authorization.
When not to choose
Avoid OPA if you need a hosted authorization service with a policy UI and vendor support out of the box, or if your team will not invest in learning Rego and operating a policy distribution pipeline.

Categories

Common use cases

  • Fine-grained API and microservice authorization via REST sidecar or embedded library
  • Kubernetes admission control and audit with OPA Gatekeeper ConstraintTemplates
  • Envoy and Istio external authorization (ext_authz) without changing service code
  • Terraform plan and infrastructure-as-code policy checks in CI/CD (Conftest, AWS CloudFormation Hooks)
  • Data filtering: compiling Rego to SQL or UCAST filters via the Compile API for list endpoints
  • Kafka topic authorization and Docker daemon authorization plugins
  • SSH and sudo host access policy
  • Guardrails for AI agents and internal tooling that need policy decisions over JSON context

Strengths

  • Apache 2.0 licence with CNCF Graduated status (since 29 January 2021) and vendor-neutral governance; maintainer list unchanged after the Apple hires
  • General-purpose: the same engine and language cover app authz, Kubernetes, service mesh, IaC and CI/CD
  • Multiple runtime modes with clear latency trade-offs: REST daemon/sidecar, Go library, and Rego compiled to WebAssembly
  • Built-in management APIs (bundles, decision logs, status, discovery) plus Prometheus metrics, OpenTelemetry tracing and a /health endpoint
  • Large ecosystem: Gatekeeper, opa-envoy-plugin, Conftest, Regal linter/language server, SDKs for Go, Java, Python, JavaScript, Rust, C#, PHP and more
  • Active release cadence (v1.21.0 shipped 24 September 2026) with OPA 1.0 having stabilised Rego v1 syntax
  • Broad production adoption cited on the project site (Atlassian, Bloomberg, Capital One, Goldman Sachs, Pinterest, and Apple as a major user)

Limitations & considerations

  • Rego has a real learning curve: Datalog-style semantics, undefined-versus-false results and the OPA 1.0 syntax break (mandatory if/contains) trip up new authors
  • No control plane, UI or policy-authoring workflow out of the box; OPA Control Plane is a pre-1.0 (v0.x) donated project and the previous commercial option, Styra DAS, has an uncertain future
  • OPA makes decisions only; enforcement, identity resolution, audit UI and policy lifecycle tooling are yours to assemble
  • Data used in decisions must be pushed in (bundles/data API) and kept in memory; very large or fast-changing datasets need external design work, and EOPA's data-source connectors were archived in June 2026
  • No first-party commercial support; the support page lists only unvetted third-party consultancies

Pricing model summary

There is no price list: OPA, Gatekeeper, opa-envoy-plugin, Regal and OPA Control Plane are all Apache 2.0 and free to self-host (as published September 2026). Styra DAS, the former commercial control plane, is in an uncertain state after Styra's founders and team joined Apple in August 2025; styra.com was unreachable at research time, so verify its status directly. Third-party commercial support vendors are listed on openpolicyagent.org/support.

Integrations

KubernetesEnvoyIstioTerraformKafkaDockerAWSKonggRPCRESTGoJavaPythonJavaScriptNode.js.NETRustPHPOpenTelemetryPrometheus

Fit

Company size
startup, smb, mid_market, enterprise
Deployment
self_hosted
Source
open source
Pricing model
free (open source)

Alternatives & comparisons

Casbin

Casbin is an Apache 2.0 open-source authorization library, embedded in-process, that evaluates ACL, RBAC, ABAC and other models defined in a model.conf file against policy rules loaded from CSV or a database adapter. It entered the Apache Incubator in February 2026.

Compare Open Policy Agent (OPA) vs Casbin →
Cerbos

Cerbos is an authorization management platform built around an open source policy decision point (PDP). It enforces fine-grained RBAC, ABAC, PBAC, and ReBAC policies for applications, APIs, workloads, and AI agents.

Compare Open Policy Agent (OPA) vs Cerbos →
OpenFGA

OpenFGA is an Apache 2.0 authorization engine, inspired by Google's Zanzibar paper, that stores relationship tuples and answers permission checks via gRPC/HTTP APIs. Originally built by Auth0/Okta, it is now a CNCF Incubating project with a hosted Auth0 FGA option.

Compare Open Policy Agent (OPA) vs OpenFGA →
Oso

Oso Cloud is a managed authorization service where teams model RBAC, ReBAC and ABAC in the Polar language and query it from Node.js, Python, Go, Java, Ruby or .NET SDKs. In 2026 Oso added Oso for Agents, a control product for AI coding agents.

Compare Open Policy Agent (OPA) vs Oso →
Permit.io

Permit.io provides authorization-as-a-service with a low-code policy management interface, RBAC/ABAC/ReBAC policy support, and a managed policy decision layer — enabling teams to ship fine-grained access control without building it from scratch.

Compare Open Policy Agent (OPA) vs Permit.io →

Key identity & access terms relevant to Open Policy Agent (OPA).

Open Policy Agent (OPA) and its logo are trademarks of their respective owner. IDSync is an independent buyer resource and does not imply endorsement unless explicitly stated.