Topaz
Topaz is an open-source (Apache-2.0) authorizer for fine-grained, policy-based, real-time access control for applications and APIs, maintained by Aserto (github.com/aserto-dev/topaz). It combines the Open Policy Agent (OPA) decision engine with a built-in Zanzibar-style relationship directory, so you can express authorization as policy-as-code and model RBAC, ReBAC, and ABAC over an object graph of users, groups, resources, and relations. Topaz is self-hosted - you run the authorizer yourself (Docker or binary) and it exposes gRPC plus REST (gRPC-gateway) APIs from your own instance. The Authorizer API answers decisions (is, decisiontree, query); the Directory API reads and writes objects, relations, and permission checks; and a local web Console ships alongside. Aserto is the commercial hosted control plane built on Topaz for centrally managing policies, data, and decision logs across many deployed authorizers.
Topaz publishes 5 APIs on the APIs.io network, including Authorizer API, Directory Checks API, Directory Objects API, and 2 more. Tagged areas include Access Control, Authorization, Fine-Grained Authorization, Open Source, and RBAC.
Topaz’s developer surface includes documentation and 8 more developer resources.
Kin Score
APIs 5
Individual APIs this provider publishes, each with its own machine-readable definition.
Topaz Authorizer API
Policy-driven decisions - is, decisiontree, and query - evaluated by the OPA engine.
Topaz Directory Checks API
Graph-based check and graph-expansion queries over the directory.
Topaz Directory Objects API
Objects in the Zanzibar-style directory - users, groups, resources, and other entities.
Topaz Directory Relations API
Relations (tuples) connecting subjects to objects in the directory graph.
Topaz Policies API
OPA policy modules loaded into the authorizer.
Open Collections 1
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
Topaz Authorizer and Directory API
OPEN COLLECTIONPricing Plans 1
Published pricing tiers and plan structures.
Topaz Plans Pricing
PLANSRate Limits 1
Documented rate limits and quota policies.
Topaz Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Topaz Finops
FINOPSAgentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Resources
Documentation 1
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Build 2
SDKs, sample code, and the tooling you integrate with
Operate 1
Status, limits, changes, and where to get help
Commercial 2
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API