Aserto website screenshot

Aserto

Aserto is a cloud-native authorization platform providing fine-grained, policy-based access control for applications and APIs. Built on Open Policy Agent (OPA) and a Google Zanzibar-inspired directory, Aserto exposes REST and gRPC APIs for the Authorizer (real-time authorization decisions), Directory (managing users, groups, objects, and relations), and Decision Logs (audit trails of authorization events). The open-source Topaz engine carries the technology forward after the commercial SaaS control plane was wound down in May 2025.

Aserto publishes 7 APIs on the APIs.io network, including Decision Logs API, Authorizer API, authzen API, and 4 more. Tagged areas include Authorization, Fine-Grained Access Control, RBAC, ABAC, and ReBAC.

The Aserto catalog on APIs.io includes 1 JSON-LD context and 1 Spectral governance ruleset.

Aserto’s developer surface includes authentication, documentation, engineering blog, pricing, and 10 more developer resources.

42.1/100 developing ▼ -6.0 Agent 31/100 agent aware Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessFreemiumSelf serve⚡ Free to try
8 APIs
AuthorizationFine-Grained Access ControlRBACABACReBACPolicyOpen Policy AgentOPACloud-NativeSecurity

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 42.1/100 · developing
Contract Quality 13.5 / 25
Developer Ergonomics 4.3 / 20
Commercial Clarity 10.0 / 20
Operational Transparency 2.7 / 13
Governance 7.0 / 12
Discoverability 7.4 / 10
Agent readiness — 31/100 · agent aware
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/aserto: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 8

Individual APIs this provider publishes, each with its own machine-readable definition.

Aserto Decision Logs API

Collects and surfaces a complete audit trail of authorization decisions made by connected Authorizer instances. Supports compliance, debugging, and analytics use cases by record...

Aserto Control Plane API

Management API for the Aserto SaaS control plane (wound down May 2025, succeeded by the open-source Topaz project). Provided lifecycle management of policies, Edge Authorizer in...

Aserto Authorizer API

The Authorizer API from Aserto — 4 operation(s) for authorizer.

Aserto authzen API

The authzen API from Aserto — 5 operation(s) for authzen.

Aserto decision_logs API

The decision_logs API from Aserto — 6 operation(s) for decision_logs.

Aserto directory API

The directory API from Aserto — 14 operation(s) for directory.

Aserto Info API

The Info API from Aserto — 1 operation(s) for info.

Aserto Policy API

The Policy API from Aserto — 2 operation(s) for policy.

Scroll for all 8

Pricing Plans 1

Published pricing tiers and plan structures.

Aserto Plans Pricing

3 plans

PLANS

Rate Limits 1

Documented rate limits and quota policies.

Aserto Rate Limits

0 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Aserto Context

52 classes · 3 properties

JSON-LD

Spectral Rules 1

Spectral governance rulesets for linting and validating these APIs.

Aserto API Rules

5 rules · 4 warnings 1 info

SPECTRAL

JSON Schema 107

Standalone JSON Schema definitions for this provider's data models.

apiIdentityContext

2 properties

JSON SCHEMA

apiIdentityType

0 properties

JSON SCHEMA

apiModule

5 properties

JSON SCHEMA

apiPolicyContext

2 properties

JSON SCHEMA

apiPolicyInstance

2 properties

JSON SCHEMA

authorizerv2Decision

2 properties

JSON SCHEMA

protobufAny

1 properties

JSON SCHEMA

protobufNullValue

0 properties

JSON SCHEMA

rpcStatus

3 properties

JSON SCHEMA

v2CompileRequest

9 properties

JSON SCHEMA

v2CompileResponse

4 properties

JSON SCHEMA

v2DecisionTreeOptions

1 properties

JSON SCHEMA

v2DecisionTreeRequest

5 properties

JSON SCHEMA

v2DecisionTreeResponse

2 properties

JSON SCHEMA

v2GetPolicyResponse

1 properties

JSON SCHEMA

v2InfoResponse

5 properties

JSON SCHEMA

v2IsRequest

4 properties

JSON SCHEMA

v2IsResponse

1 properties

JSON SCHEMA

v2ListPoliciesResponse

1 properties

JSON SCHEMA

v2QueryOptions

4 properties

JSON SCHEMA

v2QueryRequest

7 properties

JSON SCHEMA

v2QueryResponse

4 properties

JSON SCHEMA

protobufAny

2 properties

JSON SCHEMA

protobufNullValue

0 properties

JSON SCHEMA

rpcStatus

3 properties

JSON SCHEMA

v2DecisionLog

1 properties

JSON SCHEMA

v2DecisionLogItem

1 properties

JSON SCHEMA

v2ExecuteQueryRequest

4 properties

JSON SCHEMA

v2ExecuteQueryResponse

2 properties

JSON SCHEMA

v2GetDecisionLogResponse

1 properties

JSON SCHEMA

v2GetDecisionsResponse

1 properties

JSON SCHEMA

v2GetUserResponse

1 properties

JSON SCHEMA

v2IdentityContext

2 properties

JSON SCHEMA

v2IdentityType

0 properties

JSON SCHEMA

v2ListDecisionLogsResponse

2 properties

JSON SCHEMA

v2ListUsersResponse

2 properties

JSON SCHEMA

v2PaginationRequest

2 properties

JSON SCHEMA

v2PaginationResponse

3 properties

JSON SCHEMA

v2PolicyContext

2 properties

JSON SCHEMA

v2PolicyInstance

2 properties

JSON SCHEMA

v2Result

2 properties

JSON SCHEMA

v2User

1 properties

JSON SCHEMA

v2UserItem

2 properties

JSON SCHEMA

protobufAny

1 properties

JSON SCHEMA

protobufNullValue

0 properties

JSON SCHEMA

rpcStatus

3 properties

JSON SCHEMA

v1Page

1 properties

JSON SCHEMA

v3Assert

6 properties

JSON SCHEMA

v3Body

1 properties

JSON SCHEMA

v3CheckPermissionRequest

6 properties

JSON SCHEMA

v3CheckPermissionResponse

2 properties

JSON SCHEMA

v3CheckRelationRequest

6 properties

JSON SCHEMA

v3CheckRelationResponse

2 properties

JSON SCHEMA

v3CheckRequest

6 properties

JSON SCHEMA

v3CheckResponse

3 properties

JSON SCHEMA

EXPERIMENTAL

2 properties

JSON SCHEMA

EXPERIMENTAL

1 properties

JSON SCHEMA

v3DeleteAssertionResponse

1 properties

JSON SCHEMA

v3DeleteManifestResponse

1 properties

JSON SCHEMA

v3DeleteObjectResponse

1 properties

JSON SCHEMA

v3DeleteRelationResponse

1 properties

JSON SCHEMA

v3ExportResponse

3 properties

JSON SCHEMA

v3GetAssertionResponse

1 properties

JSON SCHEMA

v3GetGraphResponse

3 properties

JSON SCHEMA

v3GetManifestResponse

3 properties

JSON SCHEMA

v3GetObjectManyResponse

1 properties

JSON SCHEMA

v3GetObjectResponse

3 properties

JSON SCHEMA

v3GetObjectsResponse

2 properties

JSON SCHEMA

v3GetRelationResponse

2 properties

JSON SCHEMA

v3GetRelationsResponse

3 properties

JSON SCHEMA

v3ImportCounter

5 properties

JSON SCHEMA

v3ImportRequest

3 properties

JSON SCHEMA

v3ImportResponse

4 properties

JSON SCHEMA

v3ImportStatus

3 properties

JSON SCHEMA

v3ListAssertionsResponse

2 properties

JSON SCHEMA

v3Metadata

2 properties

JSON SCHEMA

v3Object

7 properties

JSON SCHEMA

Object identifier

2 properties

JSON SCHEMA

v3Opcode

0 properties

JSON SCHEMA

Pagination request

2 properties

JSON SCHEMA

Pagination response

1 properties

JSON SCHEMA

v3Relation

9 properties

JSON SCHEMA

v3SetAssertionRequest

1 properties

JSON SCHEMA

v3SetAssertionResponse

1 properties

JSON SCHEMA

v3SetManifestResponse

1 properties

JSON SCHEMA

v3SetObjectRequest

1 properties

JSON SCHEMA

v3SetObjectResponse

1 properties

JSON SCHEMA

v3SetRelationRequest

1 properties

JSON SCHEMA

v3SetRelationResponse

1 properties

JSON SCHEMA

Scroll for all 107

Examples 3

Example request and response payloads for these APIs.

Aserto Directory Examples

5 fields

EXAMPLE

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Aserto Authentication

apiKey · 2 schemes

SECURITY

Aserto Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Aserto Agentic Access

36 operations · 21 acting

36 operations · 21 acting

AGENTIC

Resources

Documentation 1

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 2

Authentication, authorization, and security posture

Operate 2

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: aserto
name: Aserto
description: 'Aserto is a cloud-native authorization platform providing fine-grained, policy-based access control for applications
  and APIs. Built on Open Policy Agent (OPA) and a Google Zanzibar-inspired directory, Aserto exposes REST and gRPC APIs for
  the Authorizer (real-time authorization decisions), Directory (managing users, groups, objects, and relations), and Decision
  Logs (audit trails of authorization events). The open-source Topaz engine carries the technology forward after the commercial
  SaaS control plane was wound down in May 2025.

  '
type: Index
accessModel:
  pricing: freemium
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Freemium · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/aserto.png
url: https://raw.githubusercontent.com/api-evangelist/aserto/refs/heads/main/apis.yml
created: '2026-06-13'
modified: '2026-06-13'
specificationVersion: '0.19'
tags:
- Authorization
- Fine-Grained Access Control
- RBAC
- ABAC
- ReBAC
- Policy
- Open Policy Agent
- OPA
- Cloud-Native
- Security
apis:
- name: Aserto Decision Logs API
  description: 'Collects and surfaces a complete audit trail of authorization decisions made by connected Authorizer instances.
    Supports compliance, debugging, and analytics use cases by recording who was authorized (or denied), which policy evaluated
    the decision, and the context at decision time.

    '
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/apis-json-logo.jpg
  humanURL: https://docs.aserto.com/docs/api-reference
  baseURL: https://console.aserto.com
  tags:
  - Decision Logs
  - Audit
  - Compliance
  properties:
  - type: Documentation
    url: https://docs.aserto.com/docs/api-reference
- name: Aserto Control Plane API
  description: 'Management API for the Aserto SaaS control plane (wound down May 2025, succeeded by the open-source Topaz
    project). Provided lifecycle management of policies, Edge Authorizer instances, tenants, and connection configurations.
    Referenced here for historical completeness; the open-source Topaz project at github.com/aserto-dev/topaz carries forward
    the self-hosted control-plane functionality.

    '
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/apis-json-logo.jpg
  humanURL: https://docs.aserto.com/docs/api-reference
  baseURL: https://console.aserto.com
  tags:
  - Control Plane
  - Management
  - Policies
  properties:
  - type: Documentation
    url: https://docs.aserto.com/docs/api-reference
- aid: aserto:aserto-authorizer-api
  name: Aserto Authorizer API
  description: The Authorizer API from Aserto — 4 operation(s) for authorizer.
  humanURL: https://docs.aserto.com/docs/authorizer-guide/overview
  baseURL: https://authorizer.prod.aserto.com
  tags:
  - Authorizer
  properties:
  - type: OpenAPI
    url: openapi/aserto-authorizer-api-openapi.yml
  - type: Documentation
    url: https://docs.aserto.com/docs/authorizer-guide/overview
  - type: Documentation
    url: https://docs.aserto.com/docs/api-reference
- aid: aserto:aserto-authzen-api
  name: Aserto authzen API
  description: The authzen API from Aserto — 5 operation(s) for authzen.
  humanURL: https://docs.aserto.com/docs/authorizer-guide/overview
  baseURL: https://authorizer.prod.aserto.com
  tags:
  - authzen
  properties:
  - type: OpenAPI
    url: openapi/aserto-authzen-api-openapi.yml
  - type: Documentation
    url: https://docs.aserto.com/docs/authorizer-guide/overview
  - type: Documentation
    url: https://docs.aserto.com/docs/api-reference
- aid: aserto:aserto-decision-logs-api
  name: Aserto decision_logs API
  description: The decision_logs API from Aserto — 6 operation(s) for decision_logs.
  humanURL: https://docs.aserto.com/docs/authorizer-guide/overview
  baseURL: https://authorizer.prod.aserto.com
  tags:
  - decision_logs
  properties:
  - type: OpenAPI
    url: openapi/aserto-decision-logs-api-openapi.yml
  - type: Documentation
    url: https://docs.aserto.com/docs/authorizer-guide/overview
  - type: Documentation
    url: https://docs.aserto.com/docs/api-reference
- aid: aserto:aserto-directory-api
  name: Aserto directory API
  description: The directory API from Aserto — 14 operation(s) for directory.
  humanURL: https://docs.aserto.com/docs/authorizer-guide/overview
  baseURL: https://authorizer.prod.aserto.com
  tags:
  - directory
  properties:
  - type: OpenAPI
    url: openapi/aserto-directory-api-openapi.yml
  - type: Documentation
    url: https://docs.aserto.com/docs/authorizer-guide/overview
  - type: Documentation
    url: https://docs.aserto.com/docs/api-reference
- aid: aserto:aserto-info-api
  name: Aserto Info API
  description: The Info API from Aserto — 1 operation(s) for info.
  humanURL: https://docs.aserto.com/docs/authorizer-guide/overview
  baseURL: https://authorizer.prod.aserto.com
  tags:
  - Info
  properties:
  - type: OpenAPI
    url: openapi/aserto-info-api-openapi.yml
  - type: Documentation
    url: https://docs.aserto.com/docs/authorizer-guide/overview
  - type: Documentation
    url: https://docs.aserto.com/docs/api-reference
- aid: aserto:aserto-policy-api
  name: Aserto Policy API
  description: The Policy API from Aserto — 2 operation(s) for policy.
  humanURL: https://docs.aserto.com/docs/authorizer-guide/overview
  baseURL: https://authorizer.prod.aserto.com
  tags:
  - Policy
  properties:
  - type: OpenAPI
    url: openapi/aserto-policy-api-openapi.yml
  - type: Documentation
    url: https://docs.aserto.com/docs/authorizer-guide/overview
  - type: Documentation
    url: https://docs.aserto.com/docs/api-reference
common:
- type: AgenticAccess
  url: agentic-access/aserto-agentic-access.yml
- type: DomainSecurity
  url: security/aserto-domain-security.yml
- type: Authentication
  url: authentication/aserto-authentication.yml
- type: Website
  url: https://www.aserto.com/
- type: Documentation
  url: https://docs.aserto.com/docs
- type: GitHubOrg
  url: https://github.com/aserto-dev
- type: LinkedIn
  url: https://www.linkedin.com/company/aserto-com
- type: X
  url: https://x.com/aserto_com
- type: Blog
  url: https://www.aserto.com/blog
- type: Pricing
  url: https://www.aserto.com/pricing
- type: StatusPage
  url: https://status.aserto.com
- type: Plans
  url: plans/aserto-plans-pricing.yml
- type: RateLimits
  url: rate-limits/aserto-rate-limits.yml
- type: FinOps
  url: finops/aserto-finops.yml
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com