# Cerbos

**Canonical:** https://apis.io/providers/cerbos/  
**Website:** https://www.cerbos.dev  
**APIs profiled:** 13

Cerbos is an open-core, language-agnostic, scalable authorization platform that decouples access control from application code by externalizing fine-grained, context-aware permission decisions into policy-as-code. Authorization is expressed in YAML policies supporting RBAC, ABAC, PBAC, and ReBAC, evaluated by a stateless Policy Decision Point (PDP) that delivers sub-millisecond decisions at scale. The platform consists of the open-source Cerbos PDP (Apache 2.0), Cerbos Hub control plane (PAP), Cerbos Synapse enrichment layer, and PEP SDKs for Go, Java, JavaScript / TypeScript, .NET, PHP, Python, Ruby, and Rust. The PDP exposes both REST (port 3592) and gRPC (port 3593) interfaces, an Admin API, and standards- compliant OpenID AuthZEN endpoints, with query-plan adapters for Prisma and SQLAlchemy.

## Kin Score — 40.3 / 100 (developing)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 40.3).

| Facet | Score |
|---|---|
| Discoverability | 72.2 |
| Contract Quality | 48.2 |
| Governance | 0.0 |
| Contract Governance | 0.0 |
| Operational Transparency | 36.8 |
| Developer Ergonomics | 61.9 |
| Commercial Clarity | 26.3 |
| Access Clarity | 26.3 |

Regulatory layer — **Insurance**: 18.2 (matched via tags).

## Agent readiness — 33.3 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | yes |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Freemium · Self-serve signup — onboarding: self-serve, pricing: freemium, trial: no (confidence: high).

## APIs (13)

- **Cerbos PDP gRPC API** — The Cerbos PDP gRPC API exposes the cerbos.svc.v1.CerbosService and related management services on port 3593, with server reflection enabled. The gRPC interface is the highest-p...
- **Cerbos AuthZEN API** — Cerbos implements the OpenID AuthZEN authorization API specification, exposing standards-compliant single-evaluation, batch-evaluations, and well-known metadata endpoints so tha...
- **Cerbos PDP Admin API** — The Cerbos Admin API provides management capabilities such as policy add/get/list, schema management, and audit log access on the running PDP. It is intended for administrative ...
- **Cerbos Hub API** — Cerbos Hub is the cloud-hosted Policy Administration Point (PAP) that manages policy authoring, versioning, validation, and distribution to Cerbos PDPs across environments. It a...
- **Cerbos Synapse** — Cerbos Synapse is the enrichment and orchestration component that fetches identity, resource, and relationship attributes from external systems and translates infrastructure pro...
- **Cerbos Admin Audit API** — Audit and decision log access (Admin API).
- **Cerbos Admin Policies API** — Policy management (Admin API).
- **Cerbos Admin Schemas API** — JSON schema management (Admin API).
- **Cerbos Admin Store API** — Policy store administration (Admin API).
- **Cerbos AuthZEN API** — OpenID AuthZEN standards-compliant evaluation endpoints.
- **Cerbos Check API** — Evaluate authorization decisions.
- **Cerbos Plan API** — Generate query plans for resource filtering.
- **Cerbos Server API** — PDP server metadata.

## Agentic access (1)

- **Cerbos Agentic Access** — 22 operations · 12 acting · 1 human-in-the-loop

## Security (2)

- **Cerbos Authentication** — http · 1 scheme
- **Cerbos Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC

## Plans (1)

- **Cerbos Plans Pricing**

## Use cases (10)

- **Multi-Tenant SaaS Authorization**
- **API Authorization**
- **AI Agent Access Control**
- **MCP Server Security**
- **RAG Access Control**
- **Non-Human Identity Authorization**
- **Zero Trust Enforcement**
- **Compliance (SOC 2, HIPAA, GDPR, FedRAMP, PCI DSS)**
- **Fintech Permissions**
- **Healthcare Permissions**

## Tags

ABAC, Access Control, Authorization, AuthZEN, Open-Source, PBAC, PDP, Permissions, Policy as Code, RBAC, ReBAC, Zero Trust

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/cerbos/). Scores are computed from the provider's own public artifacts under a published rubric.
