About Keyring
Keyring is access-control infrastructure for software products. You define the actions a user can take, such as refunding an invoice or inviting a member, bundle them into named roles like Editor, Support or Finance, and grant those roles to your product's users. A single API call then answers whether a given user may perform a given action.
Permission checks are a GET request that takes a subject and a permission and returns an allowed boolean, authenticated with a bearer key. All reads and writes are checked against the grant graph, which lives in the database, so a client cannot talk its way into an action it lacks. Users are referenced by your own IDs, and console accounts stay out of the graph. When someone holds several roles, access is the union of all of them.
A console lets your team manage actions, roles, members, users and settings, and a full activity log records every grant, revocation and policy change. New workspaces start empty, with no seeded roles or demo actions, and membership begins with an approved join request. Keyring is offered as a hosted service with docs and a pricing page.
Key features
- Define custom actions and compose them into roles
- One-call permission check returning allowed or not
- Users keyed by your own IDs
- Union semantics for users holding several roles
- Activity log of grants, revocations and policy edits
- Console for managing actions, roles and members
- Approval-based workspace membership
Good fit for
- SaaS teams adding role-based permissions to their app
- Products needing an audit trail of access changes
Keyring: questions and answers
- What is Keyring used for?
- Keyring is a hosted access-control service where developers define actions, group them into roles, grant them to users and check permissions with one API call. It is a good fit for SaaS teams adding role-based permissions to their app and products needing an audit trail of access changes.
- Is Keyring free?
- Yes. Keyring has a free plan, and paid plans start at $12 per month.
- Is Keyring open source?
- No. Keyring is proprietary (closed-source) software and can't be self-hosted. In the Auth & Identity category, open-source options include SpiceDB, Logto and Authorizer.
- What are some alternatives to Keyring?
- Keyring competes with Oso, Permit.io and Authress.
Open-source alternatives to Keyring
See all
SpiceDB
Auth & Identity
Open Source, Google Zanzibar-inspired database for scalably storing and querying fine-grai
Apache-2.0vs Oso★ 7.1k
Logto
Auth & Identity
🧑🚀 Authentication and authorization infrastructure for SaaS and AI apps, built on OIDC
MPL-2.0vs Auth0★ 15k
Authorizer
Auth & Identity
Your data, your control. Fully open source, authentication and authorization. No lock-ins.
Apache-2.0vs Auth0★ 2.1k
Frontier
Auth & Identity
Frontier is an all-in-one user management platform that provides identity, access and bill
Apache-2.0vs WorkOS★ 345
Ory Hydra
Auth & Identity
Internet-scale OpenID Certified™ OpenID Connect and OAuth2.1 provider that integrates with
Apache-2.0vs Auth0★ 18k
Hexclave
Auth & Identity
Deploy your frontend, backend, and database together with Hexclave Deploy. Automatic scali
OSSvs Auth0★ 6.9k
SaaS alternatives to Keyring
See all
Oso
Auth & Identity
Authorization service for modeling and enforcing app permissions with a policy language
SaaS
Permit.io
Auth & Identity
Authorization-as-a-service with RBAC, ABAC and policy management
SaaS
Authress
Auth & Identity
Hosted login with fine-grained access control for SaaS applications
SaaS
WorkOS
Auth & Identity
Enterprise SSO, directory sync and user management APIs for B2B SaaS
SaaS
Scalekit
Auth & Identity
Auth platform for AI agents and B2B apps with SSO, scoped tokens and connectors
SaaS
Descope
Auth & Identity
Drag-and-drop authentication flows with passwordless login and SSO
SaaS

