Aserto
Aserto is a cloud-native authorization platform providing fine-grained, policy-based access control for applications and APIs. Built on Open Policy Agent (OPA) and a Google Zanzibar-inspired directory, Aserto exposes REST and gRPC APIs for the Authorizer (real-time authorization decisions), Directory (managing users, groups, objects, and relations), and Decision Logs (audit trails of authorization events). The open-source Topaz engine carries the technology forward after the commercial SaaS control plane was wound down in May 2025.
Aserto publishes 7 APIs on the APIs.io network, including Decision Logs API, Authorizer API, authzen API, and 4 more. Tagged areas include Authorization, Fine-Grained Access Control, RBAC, ABAC, and ReBAC.
The Aserto catalog on APIs.io includes 1 JSON-LD context and 1 Spectral governance ruleset.
Aserto’s developer surface includes authentication, documentation, engineering blog, pricing, and 10 more developer resources.
Kin Score
APIs 8
Individual APIs this provider publishes, each with its own machine-readable definition.
Aserto Decision Logs API
Collects and surfaces a complete audit trail of authorization decisions made by connected Authorizer instances. Supports compliance, debugging, and analytics use cases by record...
Aserto Control Plane API
Management API for the Aserto SaaS control plane (wound down May 2025, succeeded by the open-source Topaz project). Provided lifecycle management of policies, Edge Authorizer in...
Aserto Authorizer API
The Authorizer API from Aserto — 4 operation(s) for authorizer.
Aserto authzen API
The authzen API from Aserto — 5 operation(s) for authzen.
Aserto decision_logs API
The decision_logs API from Aserto — 6 operation(s) for decision_logs.
Aserto directory API
The directory API from Aserto — 14 operation(s) for directory.
Aserto Info API
The Info API from Aserto — 1 operation(s) for info.
Aserto Policy API
The Policy API from Aserto — 2 operation(s) for policy.
Scroll for all 8
Pricing Plans 1
Published pricing tiers and plan structures.
Aserto Plans Pricing
PLANSRate Limits 1
Documented rate limits and quota policies.
Aserto Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Aserto Finops
FINOPSSemantic Vocabularies 1
JSON-LD contexts and semantic vocabularies used across these APIs.
Aserto Context
JSON-LDSpectral Rules 1
Spectral governance rulesets for linting and validating these APIs.
Aserto API Rules
SPECTRALJSON Schema 107
Standalone JSON Schema definitions for this provider's data models.
apiIdentityContext
JSON SCHEMAapiIdentityType
JSON SCHEMAapiModule
JSON SCHEMAapiPolicyContext
JSON SCHEMAapiPolicyInstance
JSON SCHEMAauthorizerv2Decision
JSON SCHEMAprotobufAny
JSON SCHEMAprotobufNullValue
JSON SCHEMArpcStatus
JSON SCHEMAv2CompileRequest
JSON SCHEMAv2CompileResponse
JSON SCHEMAv2DecisionTreeOptions
JSON SCHEMAv2DecisionTreeRequest
JSON SCHEMAv2DecisionTreeResponse
JSON SCHEMAv2GetPolicyResponse
JSON SCHEMAv2InfoResponse
JSON SCHEMAv2IsRequest
JSON SCHEMAv2IsResponse
JSON SCHEMAv2ListPoliciesResponse
JSON SCHEMAv2QueryOptions
JSON SCHEMAv2QueryRequest
JSON SCHEMAv2QueryResponse
JSON SCHEMAprotobufAny
JSON SCHEMAprotobufNullValue
JSON SCHEMArpcStatus
JSON SCHEMAv2DecisionLog
JSON SCHEMAv2DecisionLogItem
JSON SCHEMAv2ExecuteQueryRequest
JSON SCHEMAv2ExecuteQueryResponse
JSON SCHEMAv2GetDecisionLogResponse
JSON SCHEMAv2GetDecisionsResponse
JSON SCHEMAv2GetUserResponse
JSON SCHEMAv2IdentityContext
JSON SCHEMAv2IdentityType
JSON SCHEMAv2ListDecisionLogsResponse
JSON SCHEMAv2ListUsersResponse
JSON SCHEMAv2PaginationRequest
JSON SCHEMAv2PaginationResponse
JSON SCHEMAv2PolicyContext
JSON SCHEMAv2PolicyInstance
JSON SCHEMAv2Result
JSON SCHEMAv2User
JSON SCHEMAv2UserItem
JSON SCHEMAprotobufAny
JSON SCHEMAprotobufNullValue
JSON SCHEMArpcStatus
JSON SCHEMAv1Page
JSON SCHEMAv3Assert
JSON SCHEMAv3Body
JSON SCHEMAv3CheckPermissionRequest
JSON SCHEMAv3CheckPermissionResponse
JSON SCHEMAv3CheckRelationRequest
JSON SCHEMAv3CheckRelationResponse
JSON SCHEMAv3CheckRequest
JSON SCHEMAv3CheckResponse
JSON SCHEMAEXPERIMENTAL
JSON SCHEMAEXPERIMENTAL
JSON SCHEMAv3DeleteAssertionResponse
JSON SCHEMAv3DeleteManifestResponse
JSON SCHEMAv3DeleteObjectResponse
JSON SCHEMAv3DeleteRelationResponse
JSON SCHEMAv3ExportResponse
JSON SCHEMAv3GetAssertionResponse
JSON SCHEMAv3GetGraphResponse
JSON SCHEMAv3GetManifestResponse
JSON SCHEMAv3GetObjectManyResponse
JSON SCHEMAv3GetObjectResponse
JSON SCHEMAv3GetObjectsResponse
JSON SCHEMAv3GetRelationResponse
JSON SCHEMAv3GetRelationsResponse
JSON SCHEMAv3ImportCounter
JSON SCHEMAv3ImportRequest
JSON SCHEMAv3ImportResponse
JSON SCHEMAv3ImportStatus
JSON SCHEMAv3ListAssertionsResponse
JSON SCHEMAv3Metadata
JSON SCHEMAv3Object
JSON SCHEMAObject identifier
JSON SCHEMAv3Opcode
JSON SCHEMAPagination request
JSON SCHEMAPagination response
JSON SCHEMAv3Relation
JSON SCHEMAv3SetAssertionRequest
JSON SCHEMAv3SetAssertionResponse
JSON SCHEMAv3SetManifestResponse
JSON SCHEMAv3SetObjectRequest
JSON SCHEMAv3SetObjectResponse
JSON SCHEMAv3SetRelationRequest
JSON SCHEMAv3SetRelationResponse
JSON SCHEMAScroll for all 107
Examples 3
Example request and response payloads for these APIs.
Aserto Authorizer Examples
EXAMPLEAserto Directory Examples
EXAMPLESecurity Posture 2
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Resources
Documentation 1
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Build 1
SDKs, sample code, and the tooling you integrate with
Access & Security 2
Authentication, authorization, and security posture
Operate 2
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use
Company 3
The organization behind the API
Other 1
Properties that don't map to a standard resource type