Topaz
Topaz is an open-source (Apache-2.0) authorizer for fine-grained, policy-based, real-time access control for applications and APIs, maintained by Aserto (github.com/aserto-dev/topaz). It combines the Open Policy Agent (OPA) decision engine with a built-in Zanzibar-style relationship directory, so you can express authorization as policy-as-code and model RBAC, ReBAC, and ABAC over an object graph of users, groups, resources, and relations. Topaz is self-hosted - you run the authorizer yourself (Docker or binary) and it exposes gRPC plus REST (gRPC-gateway) APIs from your own instance. The Authorizer API answers decisions (is, decisiontree, query); the Directory API reads and writes objects, relations, and permission checks; and a local web Console ships alongside. Aserto is the commercial hosted control plane built on Topaz for centrally managing policies, data, and decision logs across many deployed authorizers.
Topaz publishes 5 APIs on the APIs.io network, including Authorizer API, Directory Checks API, Directory Objects API, and 2 more. Tagged areas include Access Control, Authorization, Fine-Grained Authorization, Open-Source, and RBAC.
Topaz’s developer surface includes documentation and 9 more developer resources.
Kin Score
APIs 5
Individual APIs this provider publishes, each with its own machine-readable definition.
Topaz Authorizer API
Policy-driven decisions - is, decisiontree, and query - evaluated by the OPA engine.
Topaz Directory Checks API
Graph-based check and graph-expansion queries over the directory.
Topaz Directory Objects API
Objects in the Zanzibar-style directory - users, groups, resources, and other entities.
Topaz Directory Relations API
Relations (tuples) connecting subjects to objects in the directory graph.
Topaz Policies API
OPA policy modules loaded into the authorizer.
Open Collections 7
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
API Collection
OPEN COLLECTIONTopaz and Directory Authorizer API
OPEN COLLECTIONTopaz and Directory Authorizer Directory Checks API
OPEN COLLECTIONTopaz and Directory Authorizer Directory Objects API
OPEN COLLECTIONTopaz and Directory Authorizer Directory Relations API
OPEN COLLECTIONTopaz and Directory Authorizer Policies API
OPEN COLLECTIONTopaz Authorizer and Directory API
OPEN COLLECTIONScroll for all 7
Pricing Plans 1
Published pricing tiers and plan structures.
Topaz Plans Pricing
PLANSRate Limits 1
Documented rate limits and quota policies.
Topaz Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Topaz Finops
FINOPSAgentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Resources
Documentation 1
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Build 2
SDKs, sample code, and the tooling you integrate with
Operate 1
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API