Warrant

Warrant was a centralized, fine-grained authorization (FGA) and access control service inspired by Google Zanzibar, exposing a real-time REST API to define an authorization model, store relationships (warrants) between objects, and run low-latency access checks and queries. It supported relationship-based (ReBAC), role-based (RBAC), and attribute-based (ABAC) access control, plus entitlements such as pricing tiers and feature gating. The core engine is open source (Apache-2.0, github.com/warrant-dev/warrant) and self-hostable. Warrant was acquired by WorkOS on 2024-04-23 and folded into WorkOS FGA; the standalone hosted Warrant service (api.warrant.dev) and the Warrant-based WorkOS FGA were deprecated and sunset on 2025-11-15. This entry documents Warrant's public API surface historically - the endpoints modeled here reflect the documented api.warrant.dev v1/v2 API and are RETIRED. Current fine-grained authorization is offered through WorkOS; the open-source engine remains self-hostable.

Warrant publishes 5 APIs on the APIs.io network, including Check API, Object Types API, Objects API, and 2 more. Tagged areas include Access Control, Authorization, Fine-Grained Authorization, FGA, and RBAC.

Warrant’s developer surface includes authentication, documentation, engineering blog, and 8 more developer resources.

39.6/100 thin ▬ flat Agent 48/100 agent ready Full breakdown ↓
scored 2026-07-27 · rubric v0.5
AccessFreemiumSelf serve⚡ Free to try
5 APIs
Access ControlAuthorizationFine-Grained AuthorizationFGARBACReBACABACZanzibarPermissionsOpen SourceRetired

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 39.6/100 · thin
Contract Quality 12.6 / 25
Developer Ergonomics 4.3 / 20
Commercial Clarity 7.9 / 20
Operational Transparency 4.8 / 13
Governance 0.0 / 12
Discoverability 10.0 / 10
Agent readiness — 48/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 15 / 15
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/warrant-dev: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 5

Individual APIs this provider publishes, each with its own machine-readable definition.

Warrant Check API

Real-time access checks and relationship queries.

Warrant Object Types API

The authorization model - object types and their relations.

Warrant Objects API

Resources and subjects that participate in the authorization model.

Warrant Roles and Permissions API

RBAC and entitlements convenience surface (roles, permissions, users, tenants, features, pricing tiers).

Warrant Warrants API

Relationship tuples (access rules) between subjects and objects.

Open Collections 1

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

Warrant API (Retired)

OPEN COLLECTION

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Warrant Dev Rate Limits

3 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Warrant Dev Authentication

apiKey · 1 scheme

SECURITY

Warrant Dev Domain Security

DNSSEC · DMARC

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Warrant Dev Agentic Access

29 operations · 17 acting

29 operations · 17 acting

AGENTIC

Resources

Documentation 1

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 2

Authentication, authorization, and security posture

Operate 1

Status, limits, changes, and where to get help

Commercial 2

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: warrant-dev
url: https://raw.githubusercontent.com/api-evangelist/warrant-dev/refs/heads/main/apis.yml
name: Warrant
kind: company
description: Warrant was a centralized, fine-grained authorization (FGA) and access control service inspired by Google Zanzibar,
  exposing a real-time REST API to define an authorization model, store relationships (warrants) between objects, and run
  low-latency access checks and queries. It supported relationship-based (ReBAC), role-based (RBAC), and attribute-based (ABAC)
  access control, plus entitlements such as pricing tiers and feature gating. The core engine is open source (Apache-2.0,
  github.com/warrant-dev/warrant) and self-hostable. Warrant was acquired by WorkOS on 2024-04-23 and folded into WorkOS FGA;
  the standalone hosted Warrant service (api.warrant.dev) and the Warrant-based WorkOS FGA were deprecated and sunset on 2025-11-15.
  This entry documents Warrant's public API surface historically - the endpoints modeled here reflect the documented api.warrant.dev
  v1/v2 API and are RETIRED. Current fine-grained authorization is offered through WorkOS; the open-source engine remains
  self-hostable.
accessModel:
  pricing: freemium
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Freemium · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/warrant-dev.png
tags:
- Access Control
- Authorization
- Fine-Grained Authorization
- FGA
- RBAC
- ReBAC
- ABAC
- Zanzibar
- Permissions
- Open Source
- Retired
created: '2026-07-11'
modified: '2026-07-11'
specificationVersion: '0.19'
apis:
- aid: warrant-dev:warrant-dev-check-api
  name: Warrant Check API
  description: Real-time access checks and relationship queries.
  humanURL: https://github.com/warrant-dev/warrant
  baseURL: https://api.warrant.dev/v1
  tags:
  - Check
  properties:
  - type: OpenAPI
    url: openapi/warrant-dev-check-api-openapi.yml
  - type: Documentation
    url: https://github.com/warrant-dev/warrant
  - type: APIReference
    url: https://workos.com/docs/fga
  - type: Documentation
    url: https://workos.com/docs/fga/warrants
  - type: Documentation
    url: https://workos.com/docs/fga
  - type: Documentation
    url: https://workos.com/docs/fga/resource-types
- aid: warrant-dev:warrant-dev-object-types-api
  name: Warrant Object Types API
  description: The authorization model - object types and their relations.
  humanURL: https://github.com/warrant-dev/warrant
  baseURL: https://api.warrant.dev/v1
  tags:
  - Object Types
  properties:
  - type: OpenAPI
    url: openapi/warrant-dev-object-types-api-openapi.yml
  - type: Documentation
    url: https://github.com/warrant-dev/warrant
  - type: APIReference
    url: https://workos.com/docs/fga
  - type: Documentation
    url: https://workos.com/docs/fga/warrants
  - type: Documentation
    url: https://workos.com/docs/fga
  - type: Documentation
    url: https://workos.com/docs/fga/resource-types
- aid: warrant-dev:warrant-dev-objects-api
  name: Warrant Objects API
  description: Resources and subjects that participate in the authorization model.
  humanURL: https://github.com/warrant-dev/warrant
  baseURL: https://api.warrant.dev/v1
  tags:
  - Objects
  properties:
  - type: OpenAPI
    url: openapi/warrant-dev-objects-api-openapi.yml
  - type: Documentation
    url: https://github.com/warrant-dev/warrant
  - type: APIReference
    url: https://workos.com/docs/fga
  - type: Documentation
    url: https://workos.com/docs/fga/warrants
  - type: Documentation
    url: https://workos.com/docs/fga
  - type: Documentation
    url: https://workos.com/docs/fga/resource-types
- aid: warrant-dev:warrant-dev-roles-and-permissions-api
  name: Warrant Roles and Permissions API
  description: RBAC and entitlements convenience surface (roles, permissions, users, tenants, features, pricing tiers).
  humanURL: https://github.com/warrant-dev/warrant
  baseURL: https://api.warrant.dev/v1
  tags:
  - Roles and Permissions
  properties:
  - type: OpenAPI
    url: openapi/warrant-dev-roles-and-permissions-api-openapi.yml
  - type: Documentation
    url: https://github.com/warrant-dev/warrant
  - type: APIReference
    url: https://workos.com/docs/fga
  - type: Documentation
    url: https://workos.com/docs/fga/warrants
  - type: Documentation
    url: https://workos.com/docs/fga
  - type: Documentation
    url: https://workos.com/docs/fga/resource-types
- aid: warrant-dev:warrant-dev-warrants-api
  name: Warrant Warrants API
  description: Relationship tuples (access rules) between subjects and objects.
  humanURL: https://github.com/warrant-dev/warrant
  baseURL: https://api.warrant.dev/v1
  tags:
  - Warrants
  properties:
  - type: OpenAPI
    url: openapi/warrant-dev-warrants-api-openapi.yml
  - type: Documentation
    url: https://github.com/warrant-dev/warrant
  - type: APIReference
    url: https://workos.com/docs/fga
  - type: Documentation
    url: https://workos.com/docs/fga/warrants
  - type: Documentation
    url: https://workos.com/docs/fga
  - type: Documentation
    url: https://workos.com/docs/fga/resource-types
common:
- type: AgenticAccess
  url: agentic-access/warrant-dev-agentic-access.yml
- type: Authentication
  url: authentication/warrant-dev-authentication.yml
- type: DomainSecurity
  url: security/warrant-dev-domain-security.yml
- type: GitHubOrganization
  url: https://github.com/warrant-dev
- type: LinkedIn
  url: https://www.linkedin.com/company/warrant-dev
- type: Website
  url: https://warrant.dev
- type: Documentation
  url: https://workos.com/docs/fga
- type: Plans
  url: plans/warrant-dev-plans-pricing.yml
- type: RateLimits
  url: rate-limits/warrant-dev-rate-limits.yml
- type: FinOps
  url: finops/warrant-dev-finops.yml
- url: https://blog.warrant.dev
  type: Blog
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com