← Catalog
Overlap
AuthZ for Go
AuthZ tools that run on Go. The Catch for each, not a winner list.
3 tools · the Catch, not a ranking
- OpenFGAApache-2.0 Zanzibar-style ReBAC with a Check API
Zanzibar-style ReBAC + Check API — not Cerbos YAML ABAC. Vs SpiceDB: CNCF/Okta OpenFGA modeling + Check API lane; SpiceDB is AuthZed production Zanzibar + ZedTokens/Cloud. Distinct from Cerbos.
- TopazApache-2.0 authZ: OPA Rego + embedded Zanzibar in one container
One container = OPA Rego + embedded Zanzibar directory (ABAC+ReBAC) — not Cerbos YAML-only PDP and not OpenFGA ReBAC-only Check API. Distinct from Cerbos and OpenFGA.
- SpiceDBApache-2.0 Google Zanzibar permissions DB; AuthZed Cloud optional
Vs OpenFGA/Cerbos/Topaz: AuthZed production Zanzibar + ZedTokens/Cloud — not OpenFGA CNCF Check API twin, not Cerbos YAML PDP, not Topaz Rego+ReBAC bundle. Free path is self-host; Cloud is paid usage.