Cerbos is an open-core authorization management platform for authorizing every identity and governing every action across applications, gateways, workloads, and AI agents.
-
Updated
Oct 2, 2026 - Go
Cerbos is an open-core authorization management platform for authorizing every identity and governing every action across applications, gateways, workloads, and AI agents.
Purpose-bound authorization reference: RBAC + ABAC + ReBAC, row/field controls, fidelity gates, lifecycle governance, and a tested 100K synthetic-data path.
Keycloak integration with OpenFGA and Apache APISIX for multi-tenancy authentication and authorization at Scale
Authorization and access control tools, frameworks, standards, and resources.
Frank!Gateway is an API gateway built for the specific needs of Dutch municipalities
This repository contains an extended version of OPA (OPA-AuthZEN) that implements the OpenID AuthZEN Authorization API 1.0.
AuthZEN NL Gov is een standaard voor autorisatie. Het beschrijft de wijze waarop toegangsvragen en -beslissingen uitgewisseld worden tussen applicaties/API's en autorisatiesoftware
SPIFFE-compatible workload identity + OpenID AuthZEN 1.0 authorization in a single Apache-2.0 binary. Cedar PDP, SPIFFE federation, tamper-evident audit log, Kubernetes operator.
De publieke website van het project Federatieve Toegangsverlening (FTV). FTV stelt standaarden voor in het kader van autorisatie, in het bijzonder in federatieve datastelsels.
A token procedure plugin enabling callout to an AuthZEN compliant authorizations service (PDP)
Agent Trust — open profile + reference implementation for proving what an autonomous AI agent is authorized to do: identity, delegation with attenuation, proof-of-possession, attestations, tamper-evident provenance. Built on JWS, OAuth/OIDC, SPIFFE/WIMSE, AuthZEN, OpenID Federation, MCP and A2A.
OpenID AuthZEN Authorization API for Policy Decision and Enforcement
Verifiable delegation for AI agents — signed chains rooted in a human sponsor, attenuating at every hop, revocable per link, and evaluated across whole action sequences.
Pointer to kanywst/opa-authzen-plugin — the OPA plugin implementing the OpenID AuthZEN Authorization API 1.0.
A proxy that converts from AuthZEN into XACML requests and back
Open interoperability and conformance kit for progressive autonomy across evidence, PAA and AuthZEN
Go implementation of the OpenID AuthZEN Authorization API 1.0 — PEP and PDP wire protocol
AuthZEN approval for Docker Sandbox Kit permission widenings in headless CI
To associate your repository with the authzen topic, visit your repo's landing page and select "manage topics."