Cerbos
Cerbos is an open-core, language-agnostic, scalable authorization platform that decouples access control from application code by externalizing fine-grained, context-aware permission decisions into policy-as-code. Authorization is expressed in YAML policies supporting RBAC, ABAC, PBAC, and ReBAC, evaluated by a stateless Policy Decision Point (PDP) that delivers sub-millisecond decisions at scale. The platform consists of the open-source Cerbos PDP (Apache 2.0), Cerbos Hub control plane (PAP), Cerbos Synapse enrichment layer, and PEP SDKs for Go, Java, JavaScript / TypeScript, .NET, PHP, Python, Ruby, and Rust. The PDP exposes both REST (port 3592) and gRPC (port 3593) interfaces, an Admin API, and standards- compliant OpenID AuthZEN endpoints, with query-plan adapters for Prisma and SQLAlchemy.
Cerbos publishes 9 APIs on the APIs.io network, including AuthZEN API, Admin Audit API, Admin Policies API, and 6 more. Tagged areas include ABAC, Access Control, Authorization, AuthZEN, and Open Source.
Cerbos’ developer surface includes authentication, documentation, getting-started guide, GitHub presence, release notes, engineering blog, pricing, and 23 more developer resources.
Kin Score
APIs 13
Individual APIs this provider publishes, each with its own machine-readable definition.
Cerbos PDP gRPC API
The Cerbos PDP gRPC API exposes the cerbos.svc.v1.CerbosService and related management services on port 3593, with server reflection enabled. The gRPC interface is the highest-p...
Cerbos AuthZEN API
Cerbos implements the OpenID AuthZEN authorization API specification, exposing standards-compliant single-evaluation, batch-evaluations, and well-known metadata endpoints so tha...
Cerbos PDP Admin API
The Cerbos Admin API provides management capabilities such as policy add/get/list, schema management, and audit log access on the running PDP. It is intended for administrative ...
Cerbos Hub API
Cerbos Hub is the cloud-hosted Policy Administration Point (PAP) that manages policy authoring, versioning, validation, and distribution to Cerbos PDPs across environments. It a...
Cerbos Synapse
Cerbos Synapse is the enrichment and orchestration component that fetches identity, resource, and relationship attributes from external systems and translates infrastructure pro...
Cerbos Admin Audit API
Audit and decision log access (Admin API).
Cerbos Admin Policies API
Policy management (Admin API).
Cerbos Admin Schemas API
JSON schema management (Admin API).
Cerbos Admin Store API
Policy store administration (Admin API).
Cerbos AuthZEN API
OpenID AuthZEN standards-compliant evaluation endpoints.
Cerbos Check API
Evaluate authorization decisions.
Cerbos Plan API
Generate query plans for resource filtering.
Cerbos Server API
PDP server metadata.
Scroll for all 13
Open Collections 1
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
Cerbos PDP REST API
OPEN COLLECTIONAgent Skills 1
Packaged agent skills for driving this provider's APIs from an AI assistant.
cerbos-policy
AGENT SKILLGraphQL 1
GraphQL schemas published by this provider.
Cerbos GraphQL API
GRAPHQLPricing Plans 1
Published pricing tiers and plan structures.
Cerbos Plans Pricing
PLANSRate Limits 1
Documented rate limits and quota policies.
Cerbos Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Cerbos Finops
FINOPSFeatures 19
Notable capabilities this provider offers.
Policy as Code
YAML Policies
RBAC
ABAC
PBAC
ReBAC
Derived Roles
Sub-Millisecond Decisions
Stateless PDP
REST and gRPC APIs
AuthZEN Standard
Query Plan Generation
Audit Logs
Policy Versioning
Schema Validation
Multiple Storage Backends
Sidecar Deployment
Embedded PDP
Apache 2.0 License
Scroll for all 19
Security Posture 2
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Use Cases 10
What developers build with this provider.
Multi-Tenant SaaS Authorization
API Authorization
AI Agent Access Control
MCP Server Security
RAG Access Control
Non-Human Identity Authorization
Zero Trust Enforcement
Compliance (SOC 2, HIPAA, GDPR, FedRAMP, PCI DSS)
Fintech Permissions
Healthcare Permissions
Scroll for all 10
Resources
Get Started 1
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 3
MCP servers, agent skills, and machine-readable catalogs
Build 4
SDKs, sample code, and the tooling you integrate with
Access & Security 3
Authentication, authorization, and security posture
Learn 1
Tutorials, courses, talks, and written guidance
Operate 3
Status, limits, changes, and where to get help
Commercial 4
Pricing, plans, and the legal terms of use
Company 3
The organization behind the API
Other 7
Properties that don't map to a standard resource type
Scroll for all 7