Cerbos
Scalable, decoupled authorization service
Cerbos is an open-source, stateless authorization layer that decouples access control logic from application code. It is self-hosted to evaluate context-aware permission policies for any application.
Key features
- Decoupled authorization
- Policy as code
- gRPC and REST APIs
- Stateless and scalable
Strengths
- Released under the Apache-2.0 license
- First-class Docker support for quick deployment
- Kubernetes-ready with Helm charts available
- Active community (4.5k GitHub stars)
Cerbos replaces
Compare Cerbos
27 head-to-head comparisons.
- Cerbos vs Keycloak
- Cerbos vs Casbin
- Cerbos vs Ory Hydra
- Cerbos vs SuperTokens
- Cerbos vs ZITADEL
- Cerbos vs Logto
- Cerbos vs Casdoor
- Cerbos vs Ory Kratos
- Cerbos vs Open Policy Agent
- Cerbos vs Apereo CAS
- Cerbos vs Dex
- Cerbos vs Hanko
- Cerbos vs Pocket ID
- Cerbos vs step-ca
- Cerbos vs SpiceDB
- Cerbos vs LLDAP
- Cerbos vs Permify
- Cerbos vs OpenFGA
- Cerbos vs Ory Keto
- Cerbos vs Kanidm
- Cerbos vs 2FAuth
- Cerbos vs Boundary
- Cerbos vs node-oidc-provider
- Cerbos vs Ory Oathkeeper
- Cerbos vs Vouch Proxy
- Cerbos vs Topaz
- Cerbos vs Warrant
Similar identity & sso apps
Keycloak
Identity & SSOOpen-source identity and access management for modern apps
Replaces Okta, Auth0
Casbin
Identity & SSOAuthorization library supporting many access control models
Replaces Auth0 RBAC
Ory Hydra
Identity & SSOCertified OAuth 2.0 and OpenID Connect server
Replaces Okta, Auth0
SuperTokens
Identity & SSOOpen-source user authentication you can self-host
Replaces Auth0, Firebase Auth
ZITADEL
Identity & SSOCloud-native identity infrastructure with multi-tenancy built in
Replaces Auth0, Okta
Logto
Identity & SSODeveloper-friendly authentication and authorization platform
Replaces Auth0, Firebase Auth