Skip to content
aicoolies logo
OpenFGA logo

OpenFGA

Fine-grained authorization engine by Okta

OpenFGA is an open-source authorization engine inspired by Google Zanzibar, built and maintained by Okta (Auth0). It provides relationship-based access control with a flexible modeling language, sub-millisecond permission checks, and SDKs for major languages. OpenFGA is used by companies including Grafana Labs, Canonical, and Docker for fine-grained access control in multi-tenant applications.

About OpenFGA

OpenFGA brings Google Zanzibar's relationship-based access control model to every developer through an open-source engine backed by Okta's Auth0 team. The system models authorization as a graph of relationships between users and objects, evaluating permission queries by traversing these relationships according to rules defined in an authorization model. This approach scales naturally from simple role-based access to complex scenarios involving shared folders, team hierarchies, and cross-organizational permissions.

The authorization modeling language uses a DSL that defines types, their relations, and how permissions compose. Developers write tuples that represent relationships — like 'user:anne is viewer of document:readme' — and the engine resolves whether a user has a specific permission by following the relationship graph. OpenFGA supports conditional relationships based on context, enabling time-based or attribute-based access decisions. The query engine is optimized for sub-millisecond latency even with millions of stored relationship tuples.

With over 5,000 GitHub stars and CNCF sandbox status, OpenFGA has established itself alongside SpiceDB as a leading open-source Zanzibar implementation. Okta provides official SDKs for JavaScript, Python, Go, Java, .NET, and Ruby, along with a visual playground for testing authorization models. The engine runs as a standalone service with PostgreSQL or MySQL backends and integrates with existing identity providers. Production users include Grafana Labs for dashboard permissions, Canonical for Ubuntu Pro access, and Docker for container registry authorization.

Pricing & Platform Specs

Pricing Summary

Free and 100% open source under the Apache-2.0 license as a CNCF incubating project. OpenFGA has no licensing fees, seat restrictions, or query quotas for self-hosted deployments on Docker or Kubernetes. A fully managed commercial SaaS edition is available separately from Okta/Auth0 as Auth0 FGA.

full pricing breakdown →

Supported Platforms

Docker — SDKs for JS, Python, Go, Java, .NET, Ruby

Explore categories, tags & use cases

Google Zanzibar-inspired authorization database

SpiceDB is an open-source authorization database inspired by Google's Zanzibar system, providing relationship-based access control (ReBAC) at scale. It defines permissions through a schema language that models relationships between users, resources, and roles, then evaluates authorization checks in single-digit milliseconds. Used by companies like Netflix and GitHub, SpiceDB handles millions of permission checks per second.

Open Source

Modular open-source identity infrastructure with Kratos, Hydra, and Keto

Ory provides a suite of modular open-source identity components: Kratos for user management and authentication, Hydra for OAuth2 and OIDC, Oathkeeper for API gateway authorization, and Keto for fine-grained permission management. Used by OpenAI and other major organizations. API-first design with Go-based microservices that deploy independently or together as Ory Network cloud.

freemiumOpen Source

Side-by-Side Comparisons

SpiceDB logo
SpiceDB
vs
OpenFGA logo
OpenFGA

SpiceDB vs OpenFGA — Google Zanzibar Authorization Engines Compared

SpiceDB and OpenFGA are the two leading open-source implementations of Google's Zanzibar authorization system. Both provide relationship-based access control at scale, but they differ in backing, ecosystem integration, and operational characteristics. This comparison helps teams choose the right Zanzibar implementation for their authorization infrastructure.

SpiceDBOpenFGA

Community experience

Sources & verification

Sources checked
Content verified

Verification dates are editorial checks. Routine CMS saves and automatic updatedAt timestamps do not advance them.

FAQ

What is OpenFGA?

OpenFGA is an open-source authorization engine inspired by Google Zanzibar, built and maintained by Okta (Auth0). It provides relationship-based access control with a flexible modeling language, sub-millisecond permission checks, and SDKs for major languages. OpenFGA is used by companies including Grafana Labs, Canonical, and Docker for fine-grained access control in multi-tenant applications.

Is OpenFGA free?

Yes — OpenFGA is open source and free to use. Free and 100% open source under the Apache-2.0 license as a CNCF incubating project. OpenFGA has no licensing fees, seat restrictions, or query quotas for self-hosted deployments on Docker or Kubernetes. A fully managed commercial SaaS edition is available separately from Okta/Auth0 as Auth0 FGA.

Is OpenFGA open source?

Yes — OpenFGA is open source.

Is OpenFGA still maintained?

Yes — OpenFGA is active. Its listing was last verified on September 6, 2026.

What are the best OpenFGA alternatives?

The first editor-selected OpenFGA alternatives are SpiceDB, Ory.