OpenFGA
OpenFGA is an Apache 2.0 authorization engine, inspired by Google's Zanzibar paper, that stores relationship tuples and answers permission checks via gRPC/HTTP APIs. Originally built by Auth0/Okta, it is now a CNCF Incubating project with a hosted Auth0 FGA option.
Quick answer
What is OpenFGA?
Short answer
OpenFGA is an open-source authorization engine that implements relationship-based access control (ReBAC) in the style described by Google's Zanzibar paper. Applications write relationship tuples (user, relation, object) into OpenFGA and call its Check, ListObjects, ListUsers and Expand APIs over gRPC or HTTP to answer permission questions. The permission graph is declared in a modeling language (DSL or JSON, schema 1.1) with union, intersection, exclusion and tuple-to-userset operators, and Conditions written in Google CEL add attribute-based rules on top of the relationship model. The server is a single Go binary backed by PostgreSQL, MySQL or SQLite (beta), with Prometheus metrics and OTLP tracing built in and an official Helm chart, CLI, Terraform provider and Spring Boot starter alongside it. Originally developed by Auth0/Okta, OpenFGA was open sourced in June 2022 under Apache 2.0, accepted into the CNCF Sandbox that September, and promoted to Incubating on 28 October 2025; maintainers are Okta and Grafana Labs employees working under a public RFC process. Okta sells a hosted version, Auth0 FGA, with a time-unlimited free trial (50,000 tuples, 20 checks/second) and an enterprise contract tier adding multi-region active-active deployment, an SLA and a logging API. Verify current pricing at auth0.com.
- Best for
- Product engineering teams building multi-tenant SaaS with document-sharing, folder-hierarchy or org/team permission models who want a self-hostable Zanzibar-style engine with a vendor-neutral foundation home.
- When to choose
- Choose OpenFGA when you want a self-hostable, foundation-governed Zanzibar-style engine for hierarchical or sharing-heavy permission models and are willing to run a database-backed service.
- When not to choose
- Avoid OpenFGA if your rules are primarily attribute or policy expressions over request data rather than relationships, or if you need a hosted service with a published per-check price list rather than an enterprise contract.
Categories
Common use cases
- Google-Docs-style sharing where users, groups and folders inherit view/edit/owner rights
- Multi-tenant B2B SaaS with organisation, team and project hierarchies
- Replacing hand-rolled permission tables with a central Check API called from every service
- Listing every document a user can see (ListObjects) or every user who can see a document (ListUsers) for UI filtering
- Time-boxed, IP-restricted or quota-based access using CEL Conditions on top of relationships
- Platform and infrastructure permissions (adopters include Canonical LXD/Juju, Grafana, Docker, SigNoz)
- Authorization for AI-agent and RAG pipelines where retrieved data must respect end-user permissions
Strengths
- Apache 2.0 licence with the project owned by the CNCF, not a single vendor; promoted to Incubating on 28 October 2025
- Faithful Zanzibar model: relationship tuples, computed usersets, tuple-to-userset, plus reverse queries (ListObjects, ListUsers, Expand)
- Readable DSL with a CLI, VS Code and JetBrains extensions, model tests and a browser playground for iterating on models
- Conditions (Google CEL) and contextual tuples cover many ABAC cases without leaving the ReBAC model
- Runs as one Go binary on PostgreSQL, MySQL or SQLite; official Helm chart, Terraform provider and Docker images
- Official SDKs for Node.js/JavaScript, Go, Python, Java and .NET, plus a Spring Boot starter
- Prometheus metrics, OTLP tracing and gRPC health checks built in; API auth via pre-shared key or OIDC
- Active release cadence (v1.21.0 on 20 September 2026) and 46 organisations listed as production adopters
Limitations & considerations
- Self-hosting means you own the database, migrations (openfga migrate on every upgrade), scaling, backups and HA; the open-source server has no built-in dashboard, audit log API or multi-region replication, which are reserved for the paid Auth0 FGA tier
- Relationship data must be synced into OpenFGA and kept consistent with your application database; there is no native policy-as-code evaluation over arbitrary attributes like OPA or Cedar
- Conditions are capped (32 KB context, 512 KB request, CEL cost 100 by default) and some features such as dynamic conditions, access control and weighted-graph checks are still marked experimental
- No official Ruby, Rust or PHP SDKs yet (listed as roadmap items in the CNCF incubation announcement); the Envoy integration repository is archived
- Auth0 FGA enterprise pricing is contract-only with no published rate card, so hosted total cost of ownership requires a sales conversation
Pricing model summary
OpenFGA itself is free under Apache 2.0 with no paid tier. The hosted Auth0 FGA service publishes a time-unlimited free trial (50,000 tuples, 20 requests/second, 100 monthly active users, 10 stores, no SLA) and an Enterprise subscription priced by contract (10 million tuples expandable, 500 requests/second, SLA, 20 stores), plus a separately sold Permissions Index add-on and an AWS Private Cloud option (as published September 2026).
View vendor pricing page ↗Integrations
Fit
Alternatives & comparisons
Aserto built a fine-grained authorization platform around Topaz, an Apache 2.0 authorizer that pairs Open Policy Agent (Rego) with a Zanzibar-style relationship directory. The hosted Aserto Control Plane shut down on 31 May 2025; Topaz continues as a self-hosted open-source project.
Compare OpenFGA vs Aserto (Topaz) →Maker of SpiceDB, the Apache-2.0 "open source permissions database" inspired by Google Zanzibar, offered self-hosted, as usage-priced AuthZed Cloud, as Dedicated cloud, or as a licensed self-hosted enterprise build.
Compare OpenFGA vs AuthZed (SpiceDB) →Cerbos is an authorization management platform built around an open source policy decision point (PDP). It enforces fine-grained RBAC, ABAC, PBAC, and ReBAC policies for applications, APIs, workloads, and AI agents.
Compare OpenFGA vs Cerbos →Oso Cloud is a managed authorization service where teams model RBAC, ReBAC and ABAC in the Polar language and query it from Node.js, Python, Go, Java, Ruby or .NET SDKs. In 2026 Oso added Oso for Agents, a control product for AI coding agents.
Compare OpenFGA vs Oso →Permit.io provides authorization-as-a-service with a low-code policy management interface, RBAC/ABAC/ReBAC policy support, and a managed policy decision layer — enabling teams to ship fine-grained access control without building it from scratch.
Compare OpenFGA vs Permit.io →Related glossary terms
Key identity & access terms relevant to OpenFGA.
OpenFGA and its logo are trademarks of their respective owner. IDSync is an independent buyer resource and does not imply endorsement unless explicitly stated.
