{"repo":"authzed/spicedb","free":true,"listed":false,"github":"https://github.com/authzed/spicedb","clone":"git clone https://github.com/authzed/spicedb.git","description":"Open Source, Google Zanzibar-inspired database for scalably storing and querying fine-grained authorization data","language":"Go","stars":6972,"topics":["zanzibar","permissions","database","distributed-systems","security","security-tools","fine-grained-access-control","ciam","kubernetes","acl"],"license":"Apache-2.0","category":"databases-storage","readme_excerpt":"SpiceDB sets the standard for authorization that scales . Scale with Traffic • Dev Velocity • Functionality • Geography &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; What is SpiceDB? SpiceDB is the most mature open source project inspired by Google's internal authorization system: [Zanzibar]. As of 2021, [broken access control became the #1 threat to web security according to OWASP][owasp]. With SpiceDB, platform and product teams can be be protected by answering this question easily: \"can subject X perform action Y on resource Z?\" Similar to a relational database, developers define a schema , write data in the form of relationships , and then use SpiceDB's clients to issue permission checks in their application to determine what actions a user can take on a resource. Other queries are also possible, such as \"What can subject do?\" or \"Who can access resource ?\". SpiceDB is often ran as a centralized service shared across product suites and microservice architectures. SpiceDB is focused purely on authorization and is designed to be fully agnostic to authentication solutions/identity providers. [owasp]: https://owasp.org/Top10/A01 2021-Broken Access Control/ What is Google Zanzibar? In 2019, Google released the paper \"[Zanzibar: Google's Consistent, Global Authorization System][zanzibar]\" providing the original inspiration for SpiceDB. The paper presents the design, implementation, and deployment of, Zanzibar, Google's internal system for storing and evaluating access","default_branch":null,"files":null,"tree":[],"storefront":"/r/authzed","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/authzed/spicedb/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}