Websitecerbos.dev
CategoryAuthorization / Security
LicenseApache 2.0 (open source)
PricingFree (open source), Enterprise plans available

Overview

Cerbos is an open-source authorization engine. Define access policies in YAML, deploy as a sidecar or service. Decoupled authorization for microservices.

Pros

  • Apache 2.0 license
  • Policy-as-code (YAML)
  • Language-agnostic (gRPC/REST API)
  • Sidecar or standalone deployment
  • Audit logging
  • Playground for testing policies

Cons

  • Authorization-only (no authentication)
  • Learning curve for policy language
  • Smaller community
  • Complex policies can be hard to debug
  • Limited UI for policy management

Verdict

Cerbos solves authorization the right way: policies defined in code, deployed as a service, independent of your application language. The policy-as-code approach means authorization rules are version-controlled, testable, and reviewable. For microservices architectures where authorization logic is scattered across services, Cerbos centralizes it.

Build a security or authorization tool?

Get reviewed and linked from our 27-site network.

See Packages