IDSync — identity software buyer platform
Browse toolsRun Stack Finder
Oso company logo

Oso

Oso Cloud is a managed authorization service where teams model RBAC, ReBAC and ABAC in the Polar language and query it from Node.js, Python, Go, Java, Ruby or .NET SDKs. In 2026 Oso added Oso for Agents, a control product for AI coding agents.

Visit site

Quick answer

What is Oso?

Short answer

Oso is a New York-based, venture-backed authorization company (Sequoia, Felicis; roughly $25M raised as of its June 2023 round). Its core product, Oso Cloud, is a hosted authorization service: you write permission logic in Polar, a declarative logic language, load 'facts' (roles, relationships, attributes) into Oso, and call authorize/list APIs from official SDKs for Node.js, Python, Go, Java, Ruby and .NET or over HTTP. Local Authorization lets Oso emit SQL fragments so decisions can be evaluated against data that stays in your own PostgreSQL or MySQL database. Deployment options are managed cloud, hybrid (read-only Fallback nodes run as Docker containers in your infrastructure, syncing every 30 minutes) and an AWS-only Self-Hosted mode that Oso describes as limited GA. A free Oso Dev Server binary/Docker image runs policies locally for development and CI only. The original open-source Oso library (Apache 2.0) was formally deprecated on 18 December 2023; Oso Cloud itself is proprietary, though SDKs and the SQLAlchemy integration are Apache 2.0 on GitHub. Since January 2026 the company's marketing centres on Oso for Agents, which inventories, monitors and controls AI coding agents via an edge proxy, Tailscale Aperture, EDR and browser integrations. Verify current pricing at osohq.com.

Best for
Product engineering teams at SaaS companies that need fine-grained, multi-model (RBAC/ReBAC/ABAC) authorization across services without building and operating their own policy engine.
When to choose
Choose Oso when you want a managed, SDK-first authorization service that can express roles, relationships and attributes together and can evaluate against your existing SQL data without replicating it.
When not to choose
Avoid Oso if you require an open-source or fully self-hostable engine on non-AWS infrastructure, or if you need published, predictable pricing before engaging sales.

Common use cases

  • Centralised fine-grained authorization for multi-tenant SaaS applications
  • Combining RBAC, relationship-based (ReBAC) and attribute-based rules in one Polar policy
  • Filtering large result lists by permission using SQL pushed down to PostgreSQL or MySQL
  • Sharing one authorization model across microservices written in different languages
  • Migrating from a home-grown permissions system using Oso Migrate parity checks
  • Syncing users and groups from Okta into authorization policies
  • Discovering, monitoring and controlling AI coding agents (Claude Code, Cursor, Codex) with Oso for Agents
  • Meeting availability targets with read-only Fallback nodes in your own infrastructure

Strengths

  • Polar language expresses RBAC, ReBAC and ABAC in one model with built-in patterns for roles, hierarchies and custom roles
  • Local Authorization generates SQL so authorization can run against data that never leaves your database (PostgreSQL, MySQL; document stores in beta)
  • Official SDKs for Node.js, Python, Go, Java, Ruby and .NET plus a CLI, VS Code and Zed extensions and an MCP server for policy debugging
  • Multiple deployment models: managed cloud, hybrid with Fallback nodes, and AWS Self-Hosted
  • Free Dev Server (Docker or native binary) runs the engine locally with no account for tests and CI
  • Published service limits and a 99.99% uptime claim backed by a public status page; SOC 2 certified
  • Named enterprise customers include Duolingo, Wayfair, Webflow, Brex, Verizon and PagerDuty
  • Available through AWS Marketplace (ISV Accelerate) for procurement

Limitations & considerations

  • The open-source Oso library is deprecated (since December 2023); the Oso Cloud engine is proprietary, so there is no open-source path to run production authorization
  • No public price list for the authorization product; the /pricing page now covers only Oso for Agents, so budgeting requires a sales conversation
  • Self-Hosted is AWS-only and Fallback nodes are read-only with a 30-minute sync interval, so hybrid deployments still depend on Oso Cloud for writes
  • Polar is a proprietary logic language with a learning curve, and Local Authorization has documented constraints (no recursive mixed logic, no cross-source inequality comparisons)
  • Company focus has shifted toward AI agent security in 2026, which buyers of the authorization product should weigh when assessing roadmap priorities

Pricing model summary

Oso Cloud (Oso for Apps) has no public price list as of September 2026: the docs describe a Free plan (4 concurrent connections, 1,000 read requests/s, 1,000 fact writes/min) and Startup/Growth plans, and Oso's own comparison content cites a Startup tier from $149/month, but osohq.com/pricing only lists Oso for Agents at $0 (up to 3 users), $15/user/month (up to 25 users) and custom Enterprise (as published September 2026). An AWS Marketplace listing shows a 12-month Growth contract at $300,000/year for up to 10,000 monthly active users (as published September 2026).

View vendor pricing page ↗

Integrations

Node.jsJavaScriptPythonGoJavaRuby.NETRESTDockerKubernetesAWSTerraformOktaPostgreSQLMySQLSQLAlchemySlackTailscaleCrowdStrikeSentinelOne

Fit

Company size
startup, mid_market, enterprise
Deployment
saas, hybrid, self_hosted
Source
commercial
Pricing model
free tier + usage-based; enterprise quote

Alternatives & comparisons

Aserto (Topaz)

Aserto built a fine-grained authorization platform around Topaz, an Apache 2.0 authorizer that pairs Open Policy Agent (Rego) with a Zanzibar-style relationship directory. The hosted Aserto Control Plane shut down on 31 May 2025; Topaz continues as a self-hosted open-source project.

Compare Oso vs Aserto (Topaz) →
AuthZed (SpiceDB)

Maker of SpiceDB, the Apache-2.0 "open source permissions database" inspired by Google Zanzibar, offered self-hosted, as usage-priced AuthZed Cloud, as Dedicated cloud, or as a licensed self-hosted enterprise build.

Compare Oso vs AuthZed (SpiceDB) →
Cerbos

Cerbos is an authorization management platform built around an open source policy decision point (PDP). It enforces fine-grained RBAC, ABAC, PBAC, and ReBAC policies for applications, APIs, workloads, and AI agents.

Compare Oso vs Cerbos →
OpenFGA

OpenFGA is an Apache 2.0 authorization engine, inspired by Google's Zanzibar paper, that stores relationship tuples and answers permission checks via gRPC/HTTP APIs. Originally built by Auth0/Okta, it is now a CNCF Incubating project with a hosted Auth0 FGA option.

Compare Oso vs OpenFGA →
Permit.io

Permit.io provides authorization-as-a-service with a low-code policy management interface, RBAC/ABAC/ReBAC policy support, and a managed policy decision layer — enabling teams to ship fine-grained access control without building it from scratch.

Compare Oso vs Permit.io →

Key identity & access terms relevant to Oso.

Oso and its logo are trademarks of their respective owner. IDSync is an independent buyer resource and does not imply endorsement unless explicitly stated.