https://github.com/ory/keto Skip to content Sign up Sign up * Why GitHub? Features - + Mobile - + Actions - + Codespaces - + Packages - + Security - + Code review - + Project management - + Integrations - + GitHub Sponsors - + Customer stories- * Team * Enterprise * Explore + Explore GitHub - Learn and contribute + Topics - + Collections - + Trending - + Learning Lab - + Open source guides - Connect with others + The ReadME Project - + Events - + Community forum - + GitHub Education - + GitHub Stars program - * Marketplace * Pricing Plans - + Compare plans - + Contact Sales - + Education - [ ] [search-key] * # In this repository All GitHub | Jump to | * No suggested jump to results * # In this repository All GitHub | Jump to | * # In this organization All GitHub | Jump to | * # In this repository All GitHub | Jump to | Sign in Sign up Sign up {{ message }} ory / keto * Sponsor Sponsor ory/keto * Notifications * Star 1.3k * Fork 122 Open Source (Go) implementation of "Zanzibar: Google's Consistent, Global Authorization System". Ships gRPC, REST APIs, newSQL, and an easy and granular permission language. Supports ACL, RBAC, and other access models. www.ory.sh/?utm_source=github&utm_medium=banner&utm_campaign=keto Apache-2.0 License 1.3k stars 122 forks Star Notifications * Code * Issues 32 * Pull requests 1 * Discussions * Actions * Projects 1 * Security * Insights More * Code * Issues * Pull requests * Discussions * Actions * Projects * Security * Insights master Switch branches/tags [ ] Branches Tags Nothing to show {{ refName }} default View all branches Nothing to show {{ refName }} default View all tags 4 branches 44 tags Go to file Code Clone HTTPS GitHub CLI [https://github.com/o] Use Git or checkout with SVN using the web URL. [gh repo clone ory/ke] Work fast with our official CLI. Learn more. * Open with GitHub Desktop * Download ZIP Launching GitHub Desktop If nothing happens, download GitHub Desktop and try again. Go back Launching GitHub Desktop If nothing happens, download GitHub Desktop and try again. Go back Launching Xcode If nothing happens, download Xcode and try again. Go back Launching Visual Studio If nothing happens, download the GitHub extension for Visual Studio and try again. Go back Latest commit @aeneasr aeneasr autogen(docs): update milestone document ... aeae024 Apr 8, 2021 autogen(docs): update milestone document aeae024 Git stats * 557 commits Files Permalink Failed to load latest commit information. Type Name Latest commit message Commit time .bin fix: bump deps and replace swagutil (#212) Jun 8, 2020 .circleci ci: fix release pipeline (#528) Apr 6, 2021 .docker fix: resolve goreleaser issues Apr 1, 2021 .github chore: update repository template to c7a2e1f9 (#526) Apr 4, 2021 .releaser docs: update github templates (#195) May 12, 2020 .schema autogen: add v0.6.0-alpha.1 to version.schema.json Apr 7, 2021 cmd feat: add SQA telemetry (#535) Apr 7, 2021 contrib fix: rename /relationtuple endpoint to /relation-tuples (#519) Apr 1, 2021 docs autogen(docs): update milestone document Apr 8, 2021 internal feat: add SQA telemetry (#535) Apr 7, 2021 proto/ory/keto chore: remove is_last_page response field (#531) Apr 7, 2021 scripts test: add dedicated persistence tests (#416) Feb 2, 2021 .dockerignore fix: resolve gitignore build Apr 1, 2021 .gitattributes Tells linguist to ignore SDK files May 10, 2018 .gitignore fix: resolve gitignore build Apr 1, 2021 .golangci.yml fix: secure query building (#442) Feb 10, 2021 .goreleaser.yml fix: resolve goreleaser issues Apr 1, 2021 .nancy-ignore fix: ignore x/net false positives Sep 24, 2020 .npmignore sdk: Update npm package registry Nov 12, 2018 .reference-ignore chore: update repository templates Oct 2, 2020 CHANGELOG.md autogen(docs): regenerate and update changelog Apr 7, 2021 CODE_OF_CONDUCT.md docs: update README (#515) Mar 30, 2021 CONTRIBUTING.md chore: update repository template to f2365e3d (#527) Apr 6, 2021 LICENSE docs: update repository templates May 26, 2020 Makefile fix: strict version enforcement in docker Apr 1, 2021 README.md fix: rename /relationtuple endpoint to /relation-tuples (#519) Apr 1, 2021 SECURITY.md chore: update repository templates Oct 2, 2020 UPGRADE.md docs: update README (#515) Mar 30, 2021 buf.gen.yaml docs: generate gRPC reference page (#488) Mar 16, 2021 buf.yaml chore: (re)move protos and config.Provider (#414) Jan 27, 2021 doc.go Improve documentation (#126) Jul 31, 2019 doc_swagger.go chore: format and linter settings (#274) Oct 23, 2020 docker-compose-mysql.yml fix: strict version enforcement in docker Apr 1, 2021 docker-compose-postgres.yml fix: strict version enforcement in docker Apr 1, 2021 docker-compose-tracing.yml Add tracing support and general improvements (#98) Apr 8, 2019 docker-compose.yml fix: strict version enforcement in docker Apr 1, 2021 go.mod feat: add SQA telemetry (#535) Apr 7, 2021 go.sum feat: add SQA telemetry (#535) Apr 7, 2021 go_mod_indirect_pins.go docs: generate gRPC reference page (#488) Mar 16, 2021 install.sh fix: update install script May 28, 2020 main.go fix: bump deps and replace swagutil (#212) Jun 8, 2020 package-lock.json docs: update README (#515) Mar 30, 2021 package.json docs: update README (#515) Mar 30, 2021 View code Chat | Forums | Newsletter Guide | API Docs | Code Docs Support this project! Who's using it? Installation Ecosystem ORY Kratos: Identity and User Infrastructure and Management ORY Hydra: OAuth2 & OpenID Connect Server ORY Oathkeeper: Identity & Access Proxy ORY Keto: Access Control Policies as a Server Security Disclosing vulnerabilities Telemetry Guide HTTP API documentation Upgrading and Changelog Command line documentation Develop Dependencies Install from source Formatting Code Running Tests Short Tests Regular Tests End-to-End Tests Build Docker README.md ORY Keto - Open Source & Cloud Native Access Control Server Chat | Forums | Newsletter Guide | API Docs | Code Docs Support this project! Ory Keto is the first and only open source implementation of "Zanzibar: Google's Consistent, Global Authorization System": Determining whether online users are authorized to access digital objects is central to preserving privacy. This paper presents the design, implementation, and deployment of Zanzibar, a global system for storing and evaluating access control lists. Zanzibar provides a uniform data model and configuration language for expressing a wide range of access control policies from hundreds of client services at Google, including Calendar, Cloud, Drive, Maps, Photos, and YouTube. Its authorization decisions respect causal ordering of user actions and thus provide external consistency amid changes to access control lists and object contents. Zanzibar scales to trillions of access control lists and millions of authorization requests per second to support services used by billions of people. It has maintained 95th-percentile latency of less than 10 milliseconds and availability of greater than 99.999% over 3 years of production use. Source If you need to know if a user (or robot, car, service) is allowed to do something - Ory Keto is the right fit for you. Currently, Ory Keto implements the basic API contracts for managing and checking relations ("permissions") with HTTP and gRPC APIs. Future versions will include features such as userset rewrites (e.g. RBAC-style role-permission models), Zookies, and more. An overview of what is implemented and upcoming can be found at Implemented and Planned Features. Build Status Coverage Status Go Report Card --------------------------------------------------------------------- * Who's using it? + Installation * Ecosystem + ORY Kratos: Identity and User Infrastructure and Management + ORY Hydra: OAuth2 & OpenID Connect Server + ORY Oathkeeper: Identity & Access Proxy + ORY Keto: Access Control Policies as a Server * Security + Disclosing vulnerabilities * Telemetry + Guide + HTTP API documentation + Upgrading and Changelog + Command line documentation + Develop o Dependencies o Install from source o Formatting Code o Running Tests # Short Tests # Regular Tests # End-to-End Tests o Build Docker Who's using it? The ORY community stands on the shoulders of individuals, companies, and maintainers. We thank everyone involved - from submitting bug reports and feature requests, to contributing patches, to sponsoring our work. Our community is 1000+ strong and growing rapidly. The ORY stack protects 16.000.000.000+ API requests every month with over 250.000+ active service nodes. We would have never been able to achieve this without each and everyone of you! The following list represents companies that have accompanied us along the way and that have made outstanding contributions to our ecosystem. If you think that your company deserves a spot here, reach out to office-muc@ory.sh now! Please consider giving back by becoming a sponsor of our open source work on Patreon or Open Collective. Type Name Logo Website Sponsor Raspberry PI Raspberry PI raspberrypi.org Foundation Foundation Contributor Kyma Project Kyma Project kyma-project.io Sponsor ThoughtWorks ThoughtWorks thoughtworks.com Sponsor Tulip Tulip Retail tulip.com Sponsor Cashdeck / All All My Funds cashdeck.com.au My Funds Sponsor 3Rein 3Rein 3rein.com Contributor Hootsuite Hootsuite hootsuite.com Adopter * Segment Segment segment.com Adopter * Arduino Arduino arduino.cc Adopter * DataDetect Datadetect unifiedglobalarchiving.com /data-detect/ Adopter * Sainsbury's Sainsbury's sainsburys.co.uk Sponsor OrderMyGear OrderMyGear ordermygear.com Sponsor Spiri.bo Spiri.bo spiri.bo We also want to thank all individual contributors [6874747073] as well as all of our backers [6874747073] and past & current supporters (in alphabetical order) on Patreon: Alexander Alimovs, Billy, Chancy Kennedy, Drozzy, Edwin Trejos, Howard Edidin, Ken Adler Oz Haven, Stefan Hans, TheCrealm. * Uses one of ORY's major projects in production. Installation Head over to the documentation to learn about ways of installing ORY Keto. Ecosystem We build Ory on several guiding principles when it comes to our architecture design: * Minimal dependencies * Runs everywhere * Scales without effort * Minimize room for human and network errors ORY's architecture designed to run best on a Container Orchestration Systems such as Kubernetes, CloudFoundry, OpenShift, and similar projects. Binaries are small (5-15MB) and available for all popular processor types (ARM, AMD64, i386) and operating systems (FreeBSD, Linux, macOS, Windows) without system dependencies (Java, Node, Ruby, libxml, ...). ORY Kratos: Identity and User Infrastructure and Management ORY Kratos is an API-first Identity and User Management system that is built according to cloud architecture best practices. It implements core use cases that almost every software application needs to deal with: Self-service Login and Registration, Multi-Factor Authentication (MFA/2FA), Account Recovery and Verification, Profile and Account Management. ORY Hydra: OAuth2 & OpenID Connect Server ORY Hydra is an OpenID Certified(tm) OAuth2 and OpenID Connect Provider which easily connects to any existing identity system by writing a tiny "bridge" application. Gives absolute control over user interface and user experience flows. ORY Oathkeeper: Identity & Access Proxy ORY Oathkeeper is a BeyondCorp/Zero Trust Identity & Access Proxy (IAP) with configurable authentication, authorization, and request mutation rules for your web services: Authenticate JWT, Access Tokens, API Keys, mTLS; Check if the contained subject is allowed to perform the request; Encode resulting content into custom headers (X-User-ID), JSON Web Tokens and more! ORY Keto: Access Control Policies as a Server ORY Keto is a policy decision point. It uses a set of access control policies, similar to AWS IAM Policies, in order to determine whether a subject (user, application, service, car, ...) is authorized to perform a certain action on a resource. Security Disclosing vulnerabilities If you think you found a security vulnerability, please refrain from posting it publicly on the forums, the chat, or GitHub and send us an email to hi@ory.am instead. Telemetry Our services collect summarized, anonymized data which can optionally be turned off. Click here to learn more. Guide The Guide is available here. HTTP API documentation The HTTP API is documented here. Upgrading and Changelog New releases might introduce breaking changes. To help you identify and incorporate those changes, we document these changes in UPGRADE.md and CHANGELOG.md. Command line documentation Run keto -h or keto help. Develop We encourage all contributions and encourage you to read our contribution guidelines Dependencies You need Go 1.16+ and (for the test suites): * Docker and Docker Compose * GNU Make 4.3 * NodeJS / npm@v7 It is possible to develop ORY Keto on Windows, but please be aware that all guides assume a Unix shell like bash or zsh. Install from source make install Formatting Code You can format all code using make format. Our CI checks if your code is properly formatted. Running Tests There are two types of tests you can run: * Short tests (do not require a SQL database like PostgreSQL) * Regular tests (do require PostgreSQL, MySQL, CockroachDB) Short Tests Short tests run fairly quickly. You can either test all of the code at once go test -short -tags sqlite ./... or test just a specific module: go test -tags sqlite -short ./internal/check/... Regular Tests Regular tests require a database set up. Our test suite is able to work with docker directly (using ory/dockertest) but we encourage to use the script instead. Using dockertest can bloat the number of Docker Images on your system and starting them on each run is quite slow. Instead we recommend doing: source ./scripts/test-resetdb.sh go test -tags sqlite ./... End-to-End Tests The e2e tests are part of the normal go test. To only run the e2e test, use source ./scripts/test-resetdb.sh go test -tags sqlite ./internal/e2e/... or add the -short tag to only test against sqlite in-memory. Build Docker You can build a development Docker Image using: make docker About Open Source (Go) implementation of "Zanzibar: Google's Consistent, Global Authorization System". Ships gRPC, REST APIs, newSQL, and an easy and granular permission language. Supports ACL, RBAC, and other access models. www.ory.sh/?utm_source=github&utm_medium=banner&utm_campaign=keto Topics hacktoberfest Resources Readme License Apache-2.0 License Releases 44 tags Sponsor this project * patreon patreon.com/_ory * open_collective opencollective.com/ory Packages 0 No packages published Contributors 24 * @aeneasr * @zepatrik * @rliebz * @minchao * @vinckr * @RomanMinkin * @robinbraemer * @xlanor * @sum2000 * @tacurran * @jfcurran + 13 contributors Languages * Go 60.0% * JavaScript 34.2% * Shell 5.1% * Other 0.7% * (c) 2021 GitHub, Inc. * Terms * Privacy * Security * Status * Docs * Contact GitHub * Pricing * API * Training * Blog * About You can't perform that action at this time. You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session.