# Warrant

**Canonical:** https://apis.io/providers/warrant-dev/  
**Website:** https://warrant.dev  
**APIs profiled:** 5

Warrant was a centralized, fine-grained authorization (FGA) and access control service inspired by Google Zanzibar, exposing a real-time REST API to define an authorization model, store relationships (warrants) between objects, and run low-latency access checks and queries. It supported relationship-based (ReBAC), role-based (RBAC), and attribute-based (ABAC) access control, plus entitlements such as pricing tiers and feature gating. The core engine is open source (Apache-2.0, github.com/warrant-dev/warrant) and self-hostable. Warrant was acquired by WorkOS on 2024-04-23 and folded into WorkOS FGA; the standalone hosted Warrant service (api.warrant.dev) and the Warrant-based WorkOS FGA were deprecated and sunset on 2025-11-15. This entry documents Warrant's public API surface historically - the endpoints modeled here reflect the documented api.warrant.dev v1/v2 API and are RETIRED. Current fine-grained authorization is offered through WorkOS; the open-source engine remains self-hostable.

## Kin Score — 38.0 / 100 (thin)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 38.0).

| Facet | Score |
|---|---|
| Discoverability | 74.1 |
| Contract Quality | 54.0 |
| Governance | 0.0 |
| Contract Governance | 0.0 |
| Operational Transparency | 34.2 |
| Developer Ergonomics | 23.8 |
| Commercial Clarity | 39.5 |
| Access Clarity | 39.5 |

## Agent readiness — 29.1 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Freemium · Self-serve signup — onboarding: self-serve, pricing: freemium, trial: no (confidence: high).

## APIs (5)

- **Warrant Check API** — Real-time access checks and relationship queries.
- **Warrant Object Types API** — The authorization model - object types and their relations.
- **Warrant Objects API** — Resources and subjects that participate in the authorization model.
- **Warrant Roles and Permissions API** — RBAC and entitlements convenience surface (roles, permissions, users, tenants, features, pricing tiers).
- **Warrant Warrants API** — Relationship tuples (access rules) between subjects and objects.

## Agentic access (1)

- **Warrant Dev Agentic Access** — 29 operations · 17 acting

## Security (2)

- **Warrant Dev Authentication** — apiKey · 1 scheme
- **Warrant Dev Domain Security** — DNSSEC · DMARC

## Plans (1)

- **Warrant Dev Plans Pricing**

## Tags

Access Control, Authorization, Fine-Grained Authorization, FGA, RBAC, ReBAC, ABAC, Zanzibar, Permissions, Open-Source, Retired

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/warrant-dev/). Scores are computed from the provider's own public artifacts under a published rubric.
