Oso Cloud website screenshot

Oso Cloud

Oso Cloud is an authorization-as-a-service platform that provides a REST API for defining and enforcing relationship-based access control policies. It enables developers to model RBAC, ReBAC, and ABAC authorization patterns, manage authorization facts, and query permissions at runtime with sub-10ms latency and 99.99% availability.

Oso Cloud publishes 4 APIs on the APIs.io network, including Centralized Authorization Data API, Check API API, Local Check API API, and 1 more. Tagged areas include Authorization, Access Control, RBAC, ReBAC, and ABAC.

The Oso Cloud catalog on APIs.io includes 1 JSON-LD context and 1 Spectral governance ruleset.

Oso Cloud’s developer surface includes authentication, documentation, engineering blog, pricing, changelog, and 11 more developer resources.

49.6/100 developing ▼ -5.5 Agent 31/100 agent aware Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessFreemiumSelf serve⚡ Free to try
4 APIs
AuthorizationAccess ControlRBACReBACABACPermissionsPolicySecurityIdentity

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 49.6/100 · developing
Contract Quality 13.3 / 25
Developer Ergonomics 4.3 / 20
Commercial Clarity 11.6 / 20
Operational Transparency 8.9 / 13
Governance 7.0 / 12
Discoverability 7.4 / 10
Agent readiness — 31/100 · agent aware
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/oso: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 4

Individual APIs this provider publishes, each with its own machine-readable definition.

Oso Cloud Centralized Authorization Data API

The Centralized Authorization Data API from Oso Cloud — 6 operation(s) for centralized authorization data.

Oso Cloud Check API API

The Check API API from Oso Cloud — 6 operation(s) for check api.

Oso Cloud Local Check API API

The Local Check API API from Oso Cloud — 4 operation(s) for local check api.

Oso Cloud Policy API

The Policy API from Oso Cloud — 2 operation(s) for policy.

Pricing Plans 1

Published pricing tiers and plan structures.

Oso Plans Pricing

4 plans

PLANS

Rate Limits 1

Documented rate limits and quota policies.

Oso Rate Limits

3 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Oso Finops

FINOPS

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Oso Context

0 classes · 41 properties

JSON-LD

Spectral Rules 1

Spectral governance rulesets for linting and validating these APIs.

Oso Cloud API Rules

5 rules · 4 warnings 1 info

SPECTRAL

JSON Schema 40

Standalone JSON Schema definitions for this provider's data models.

ActionsQuery

5 properties

JSON SCHEMA

ActionsResult

1 properties

JSON SCHEMA

ApiError

1 properties

JSON SCHEMA

ApiResult

1 properties

JSON SCHEMA

AuthorizeQuery

6 properties

JSON SCHEMA

AuthorizeResourcesQuery

5 properties

JSON SCHEMA

AuthorizeResourcesResult

1 properties

JSON SCHEMA

AuthorizeResult

1 properties

JSON SCHEMA

Bulk

2 properties

JSON SCHEMA

ConcreteFact

2 properties

JSON SCHEMA

Constraint

2 properties

JSON SCHEMA

Fact

2 properties

JSON SCHEMA

FactChangeset

0 properties

JSON SCHEMA

GetPolicyMetadataResult

1 properties

JSON SCHEMA

GetPolicyResult

1 properties

JSON SCHEMA

ListQuery

7 properties

JSON SCHEMA

ListResult

2 properties

JSON SCHEMA

LocalActionsQuery

2 properties

JSON SCHEMA

LocalActionsResult

1 properties

JSON SCHEMA

LocalAuthQuery

2 properties

JSON SCHEMA

LocalAuthResult

1 properties

JSON SCHEMA

LocalListQuery

3 properties

JSON SCHEMA

LocalListResult

1 properties

JSON SCHEMA

LocalQuery

3 properties

JSON SCHEMA

LocalQueryMode

0 properties

JSON SCHEMA

LocalQueryResult

1 properties

JSON SCHEMA

Policy

2 properties

JSON SCHEMA

PolicyError

2 properties

JSON SCHEMA

PolicyFailure

0 properties

JSON SCHEMA

PolicyMetadata

1 properties

JSON SCHEMA

PolicyTestResult

3 properties

JSON SCHEMA

Query

4 properties

JSON SCHEMA

QueryDeprecated

2 properties

JSON SCHEMA

QueryResult

1 properties

JSON SCHEMA

QueryResultDeprecated

1 properties

JSON SCHEMA

ResourceBlockData

3 properties

JSON SCHEMA

SavePolicyError

0 properties

JSON SCHEMA

TestSummary

3 properties

JSON SCHEMA

TypedId

2 properties

JSON SCHEMA

Value

2 properties

JSON SCHEMA

Scroll for all 40

Examples 13

Example request and response payloads for these APIs.

Delete_Facts

5 fields

EXAMPLE

Get_Policy_Metadata

5 fields

EXAMPLE

Post_Actions

5 fields

EXAMPLE

Post_Actions_Query

5 fields

EXAMPLE

Post_Authorize

5 fields

EXAMPLE

Post_Authorize_Query

5 fields

EXAMPLE

Post_Batch

5 fields

EXAMPLE

Post_Evaluate_Query

5 fields

EXAMPLE

Post_Evaluate_Query_Local

5 fields

EXAMPLE

Post_Facts

5 fields

EXAMPLE

Post_List

5 fields

EXAMPLE

Post_List_Query

5 fields

EXAMPLE

Post_Policy

5 fields

EXAMPLE

Scroll for all 13

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Oso Authentication

http · 1 scheme

SECURITY

Oso Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Oso Trust Center

SOC 2

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Oso Agentic Access

20 operations · 18 acting

20 operations · 18 acting

AGENTIC

Resources

Documentation 1

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 3

Authentication, authorization, and security posture

Operate 3

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: oso
name: Oso Cloud
description: Oso Cloud is an authorization-as-a-service platform that provides a REST API for defining and enforcing relationship-based
  access control policies. It enables developers to model RBAC, ReBAC, and ABAC authorization patterns, manage authorization
  facts, and query permissions at runtime with sub-10ms latency and 99.99% availability.
accessModel:
  pricing: freemium
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Freemium · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/oso.png
url: https://raw.githubusercontent.com/api-evangelist/oso/refs/heads/main/apis.yml
created: '2026-06-13'
modified: '2026-06-13'
specificationVersion: '0.19'
type: Index
tags:
- Authorization
- Access Control
- RBAC
- ReBAC
- ABAC
- Permissions
- Policy
- Security
- Identity
apis:
- aid: oso:oso-centralized-authorization-data-api
  name: Oso Cloud Centralized Authorization Data API
  description: The Centralized Authorization Data API from Oso Cloud — 6 operation(s) for centralized authorization data.
  humanURL: https://www.osohq.com/docs
  baseURL: https://api.osohq.com/api
  tags:
  - Centralized Authorization Data
  properties:
  - type: OpenAPI
    url: openapi/oso-centralized-authorization-data-api-openapi.yml
  - type: Documentation
    url: https://www.osohq.com/docs
  - type: Authentication
    url: https://www.osohq.com/docs/app-integration/oso-cloud-configuration/api-keys
- aid: oso:oso-check-api-api
  name: Oso Cloud Check API API
  description: The Check API API from Oso Cloud — 6 operation(s) for check api.
  humanURL: https://www.osohq.com/docs
  baseURL: https://api.osohq.com/api
  tags:
  - Check API
  properties:
  - type: OpenAPI
    url: openapi/oso-check-api-api-openapi.yml
  - type: Documentation
    url: https://www.osohq.com/docs
  - type: Authentication
    url: https://www.osohq.com/docs/app-integration/oso-cloud-configuration/api-keys
- aid: oso:oso-local-check-api-api
  name: Oso Cloud Local Check API API
  description: The Local Check API API from Oso Cloud — 4 operation(s) for local check api.
  humanURL: https://www.osohq.com/docs
  baseURL: https://api.osohq.com/api
  tags:
  - Local Check API
  properties:
  - type: OpenAPI
    url: openapi/oso-local-check-api-api-openapi.yml
  - type: Documentation
    url: https://www.osohq.com/docs
  - type: Authentication
    url: https://www.osohq.com/docs/app-integration/oso-cloud-configuration/api-keys
- aid: oso:oso-policy-api
  name: Oso Cloud Policy API
  description: The Policy API from Oso Cloud — 2 operation(s) for policy.
  humanURL: https://www.osohq.com/docs
  baseURL: https://api.osohq.com/api
  tags:
  - Policy
  properties:
  - type: OpenAPI
    url: openapi/oso-policy-api-openapi.yml
  - type: Documentation
    url: https://www.osohq.com/docs
  - type: Authentication
    url: https://www.osohq.com/docs/app-integration/oso-cloud-configuration/api-keys
common:
- type: AgenticAccess
  url: agentic-access/oso-agentic-access.yml
- type: TrustCenter
  url: security/oso-trust-center.yml
- type: DomainSecurity
  url: security/oso-domain-security.yml
- type: Authentication
  url: authentication/oso-authentication.yml
- type: Website
  url: https://www.osohq.com
- type: Documentation
  url: https://www.osohq.com/docs
- type: GitHubOrg
  url: https://github.com/osohq
- type: LinkedIn
  url: https://www.linkedin.com/company/osohq
- type: Blog
  url: https://www.osohq.com/blog
- type: Pricing
  url: https://www.osohq.com/pricing
- type: StatusPage
  url: https://oso.statuspage.io/
- type: X
  url: https://x.com/osohq
- type: ChangeLog
  url: https://www.osohq.com/docs/changelog/whats-new
- type: Plans
  url: plans/oso-plans-pricing.yml
- type: RateLimits
  url: rate-limits/oso-rate-limits.yml
- type: FinOps
  url: finops/oso-finops.yml
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com