# AthenZ/athenz

Open source platform for X.509 certificate based service authentication and fine grained access control in dynamic infrastructures. Athenz supports provisioning and configuration (centralized authorization) use cases as well as serving/runtime (decentralized authorization) use cases.

Repository: https://github.com/AthenZ/athenz
Canonical: https://ross.abutalabs.com/products/athenz
Homepage: https://www.athenz.io
Language: Java
License: Apache-2.0
License Family: permissive
Topics: rbac, role-based-access-control, authorization, containers, cloud, service-identity, tls, spiffe, access-token, dynamic-infrastructures
Last push: 2026-09-03T00:15:42+00:00

## Health v2 (maintenance only)
Score: 100/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 100, release rhythm 99, longevity 100
- inputs: {"age_days": 3577, "days_push": 0, "days_rel": 9, "gap_med": 14.0, "n_releases_24m": 49}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1006, forks 313 (observed 2026-09-03T02:15:05.017657+00:00)

## What it is
Athenz is an open source platform for X.509 certificate-based service authentication and fine-grained role-based access control (RBAC) in dynamic infrastructures. It issues short-lived service identity certificates to workloads in private or public clouds and supports both centralized authorization management and decentralized runtime authorization using mTLS-bound OAuth2 access tokens.

## Use cases
- issue short-lived x509 certificates to cloud workloads for service identity
- implement role-based access control (rbac) for microservices
- enable mutual tls authentication between services
- provide workload identity for kubernetes pods
- manage centralized authorization policies for dynamic infrastructure
- issue mtls-bound oauth2 access tokens for service authorization
- implement zero trust security in hybrid cloud environments

## When to choose
- you need workload/service identity via short-lived X.509 certificates across hybrid or multi-cloud environments
- you want fine-grained RBAC with centralized management and decentralized runtime enforcement
- you need mTLS-bound OAuth2 access tokens and zero trust principles for service-to-service communication
- you want an open source alternative to SPIRE/SPIFFE-style identity with integrated authorization

## When to avoid
- you only need simple user-facing authentication like social login or SSO for web apps
- your infrastructure is small and static where built-in cloud IAM suffices
- you cannot operate the operational overhead of running certificate authorities and identity agents
- you need only coarse-grained access control without role or policy management

## Facets
- artifact type: service
- maturity: active
- function: auth, authorization, security, cryptography, microservices, api-gateway
- domain: security, cloud-computing, microservices, infrastructure-as-code, developer-tools
- platform: cloud, self-hosted, jvm, go, cross-platform
- tags: rbac, x509, mtls, zero-trust, service-identity, oauth2, spiffe, access-control, identity-provider, workload-identity, containers, kubernetes, docker, linux

## Member repositories
- AthenZ/athenz (main) score 100

## Provenance
- Observed fields: from GitHub, fetched 2026-09-03T02:15:05.017657+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T07:13:05.180866+00:00, confidence not recorded.
  - readme: https://github.com/AthenZ/athenz (fetched 2026-09-03T02:15:05.017657+00:00, sha 0248eaa4364e)
  - homepage: https://www.athenz.io (fetched 2026-08-29T13:12:54.692870+00:00, sha ca6ec703f514)
- Data as of 2026-08-30T08:39:29.467469+00:00.
