7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

SpiceDB

Open source

SpiceDB from Authzed is an open-source, Google Zanzibar-inspired database for storing and querying fine-grained authorization data, answering whether a subject can perform an action on a resource.

Open-source alternative to

authzed.com
SpiceDB homepage screenshot
GitHub stars
7.1k
Last commit
yesterday
Repository age
5 years
Version
v1.56.2
Licence
Apache-2.0
Self-hosted
Yes

About SpiceDB

This entry covers SpiceDB, the open-source authorization database from Authzed. It is inspired by Google's Zanzibar paper and lets platform and product teams answer questions such as whether a given subject can perform an action on a given resource, which addresses broken access control, a major web security risk.

Like a relational database, you define a schema, write data as relationships and then use client libraries to issue permission checks from your application. Other queries are possible too, such as what a subject can do or who can access a resource. SpiceDB typically runs as one central service used by several products and microservices, and it focuses purely on authorization, staying agnostic to authentication and identity providers. Topics mention RBAC, ABAC, ReBAC and fine-grained access control.

SpiceDB is written in Go, runs on Kubernetes and elsewhere, and is licensed under Apache-2.0. Authzed also offers commercial products around it. It suits engineering teams that need consistent, scalable permissions for multi-tenant or collaborative applications.

Key features

  • Zanzibar-style relationship-based permissions
  • Schema language for authorization models
  • Permission check and lookup queries
  • Centralized authorization service
  • Independent of identity providers
  • Distributed, cloud-native design

Good fit for

  • →Fine-grained permissions in SaaS apps
  • →Sharing and access control for documents
  • →Centralized authorization across microservices
Built with
Go
Kubernetes
Tags
authorization
zanzibar
rebac
rbac
permissions
access-control
distributed-systems
golang
security

SpiceDB: questions and answers

What is SpiceDB used for?
SpiceDB from Authzed is an open-source, Google Zanzibar-inspired database for storing and querying fine-grained authorization data, answering whether a subject can perform an action on a resource. It is a good fit for fine-grained permissions in SaaS apps, sharing and access control for documents, and centralized authorization across microservices.
Is SpiceDB open source?
Yes. SpiceDB is open source under the Apache-2.0 licence. Its source code is on GitHub at authzed/spicedb and is written mainly in Go.
Is SpiceDB free?
Yes. SpiceDB is open source, so the software itself is free to use.
Can I self-host SpiceDB?
Yes. SpiceDB can be self-hosted on your own server or infrastructure.
What is SpiceDB an alternative to?
SpiceDB is an open-source alternative to Oso, Permit.io and Authress. Other open-source alternatives to Authress include Logto, ZITADEL and Hexclave.
Is SpiceDB actively maintained?
Yes. The most recent commit to SpiceDB was on 1 October 2026, and the latest release is v1.56.2, published on 11 September 2026. The project has 7.1k stars on GitHub.

Open-source alternatives to SpiceDB

See all

SaaS alternatives to SpiceDB

See all