Skip to content
aicoolies logo
SpiceDB logo

SpiceDB

Google Zanzibar-inspired authorization database

SpiceDB is an open-source authorization database inspired by Google's Zanzibar system, providing relationship-based access control (ReBAC) at scale. It defines permissions through a schema language that models relationships between users, resources, and roles, then evaluates authorization checks in single-digit milliseconds. Used by companies like Netflix and GitHub, SpiceDB handles millions of permission checks per second.

About SpiceDB

SpiceDB implements Google's Zanzibar authorization model as an open-source database purpose-built for permission checking at scale. Instead of embedding authorization logic in application code or relying on role-based access control that becomes unmanageable as systems grow, SpiceDB stores relationships between entities and evaluates permission queries against a schema that defines how relationships compose into permissions. This enables complex authorization patterns like hierarchical teams, shared resources, and inherited permissions.

The schema language lets developers model their authorization domain declaratively. A schema defines object types, their relations, and how permissions derive from those relations. For example, a document might have an owner relation and an editor relation, with view permission granted to anyone who is an owner, editor, or member of an organization that owns the document. SpiceDB evaluates these queries through an optimized graph traversal engine that resolves complex permission chains in single-digit milliseconds.

Backed by AuthZed with venture funding and over 6,600 GitHub stars, SpiceDB has been adopted by companies including Netflix, GitHub, and Canva for production authorization. It exposes gRPC and HTTP APIs, supports PostgreSQL, MySQL, CockroachDB, and Spanner as storage backends, and provides client libraries for Go, Python, Java, Ruby, and JavaScript. The distributed architecture handles horizontal scaling for millions of relationships and permission checks, making it suitable for multi-tenant SaaS platforms and complex enterprise applications.

Pricing & Platform Specs

Pricing Summary

Free and 100% open source under the Apache-2.0 license for self-managed Kubernetes and bare-metal deployments. AuthZed Cloud provides a fully managed, usage-based permissions platform with transparent pay-as-you-go billing. AuthZed Dedicated and Enterprise tiers offer single-tenant VPC deployments, multi-region CockroachDB/Spanner clustering, SOC 2 compliance, and dedicated 24/7 SLAs under annual enterprise contracts.

full pricing breakdown →

Supported Platforms

gRPC and HTTP APIs — Go, Python, Java, Ruby, JS clients

Explore categories, tags & use cases

Fine-grained authorization engine by Okta

OpenFGA is an open-source authorization engine inspired by Google Zanzibar, built and maintained by Okta (Auth0). It provides relationship-based access control with a flexible modeling language, sub-millisecond permission checks, and SDKs for major languages. OpenFGA is used by companies including Grafana Labs, Canonical, and Docker for fine-grained access control in multi-tenant applications.

Open Source

Open-source identity provider for self-hosted SSO and access management

Authentik is an open-source Identity Provider supporting SAML, OAuth2/OIDC, LDAP, RADIUS, and SCIM for self-hosted single sign-on. It provides customizable authentication flows, multi-factor authentication, user management, and proxy-based SSO for applications without native support. Positioned as a modern Keycloak alternative with 22K+ GitHub stars, free Open Source use, and paid Enterprise/Enterprise Plus plans.

freemiumOpen Source

Side-by-Side Comparisons

SpiceDB logo
SpiceDB
vs
OpenFGA logo
OpenFGA

SpiceDB vs OpenFGA — Google Zanzibar Authorization Engines Compared

SpiceDB and OpenFGA are the two leading open-source implementations of Google's Zanzibar authorization system. Both provide relationship-based access control at scale, but they differ in backing, ecosystem integration, and operational characteristics. This comparison helps teams choose the right Zanzibar implementation for their authorization infrastructure.

SpiceDBOpenFGA

Community experience

Sources & verification

Sources checked
Content verified

Verification dates are editorial checks. Routine CMS saves and automatic updatedAt timestamps do not advance them.

FAQ

What is SpiceDB?

SpiceDB is an open-source authorization database inspired by Google's Zanzibar system, providing relationship-based access control (ReBAC) at scale. It defines permissions through a schema language that models relationships between users, resources, and roles, then evaluates authorization checks in single-digit milliseconds. Used by companies like Netflix and GitHub, SpiceDB handles millions of permission checks per second.

Is SpiceDB free?

Yes — SpiceDB is open source and free to use. Free and 100% open source under the Apache-2.0 license for self-managed Kubernetes and bare-metal deployments. AuthZed Cloud provides a fully managed, usage-based permissions platform with transparent pay-as-you-go billing. AuthZed Dedicated and Enterprise tiers offer single-tenant VPC deployments, multi-region CockroachDB/Spanner clustering, SOC 2 compliance, and dedicated 24/7 SLAs under annual enterprise contracts.

Is SpiceDB open source?

Yes — SpiceDB is open source.

Is SpiceDB still maintained?

Yes — SpiceDB is active. Its listing was last verified on September 6, 2026.

What are the best SpiceDB alternatives?

The first editor-selected SpiceDB alternatives are OpenFGA, Authentik.