Open Policy Agent
General-purpose policy engine for cloud-native stacks
Open Policy Agent (OPA) is an open-source, CNCF graduated policy engine that decouples policy decisions from applications. It is self-hosted to enforce authorization and admission control across systems.
Key features
- Declarative Rego policies
- Decoupled decision making
- Kubernetes admission control
- REST decision API
Strengths
- Released under the Apache-2.0 license
- First-class Docker support for quick deployment
- Kubernetes-ready with Helm charts available
- Mature project with 12.3k GitHub stars
Open Policy Agent replaces
Similar identity & sso apps
Keycloak
Identity & SSOOpen-source identity and access management for modern apps
Replaces Okta, Auth0
Casbin
Identity & SSOAuthorization library supporting many access control models
Replaces Auth0 RBAC
Ory Hydra
Identity & SSOCertified OAuth 2.0 and OpenID Connect server
Replaces Okta, Auth0
SuperTokens
Identity & SSOOpen-source user authentication you can self-host
Replaces Auth0, Firebase Auth
ZITADEL
Identity & SSOCloud-native identity infrastructure with multi-tenancy built
Replaces Auth0, Okta
Logto
Identity & SSODeveloper-friendly authentication and authorization platform
Replaces Auth0, Firebase Auth