Ross ROSS = Recommend OSS · open-source software intelligence for agents

ory/keto

The most scalable and customizable permission server on the market. Fix your slow or broken permission system with Google's proven "Zanzibar" approach. Supports ACL, RBAC, and more. Written in Go, cloud native, headless, API-first. Available as a service on Ory Network and for self-hosters. observed · 2026-08-28

github.com/ory/keto · homepage · Go · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

80/100

  • Activity 99
  • Release rhythm 43
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 189.0
  • age_days: 3091
  • days_rel: 166
  • days_push: 9
  • n_releases_24m: 3

Full methodology

Adoption not part of the score

5390 stars · 386 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Ory Keto is an open-source authorization server implementing Google's Zanzibar model for scalable, low-latency permission checks. It supports ReBAC, RBAC, and ABAC via the Ory Permission Language and can be self-hosted or used through the Ory Network.

Use cases

  • implement google zanzibar style authorization
  • manage fine-grained permissions for billions of relationships
  • replace a slow or broken permission system
  • check user permissions with sub-10ms latency
  • define access control policies with a permission language
  • self-host a permission server for microservices
  • implement relationship-based access control (rebac)

When to choose

  • you need scalable, consistent permission checks modeled on Google's Zanzibar
  • you want a headless, API-first authorization server you can self-host
  • your app needs ReBAC/RBAC/ABAC with horizontal scaling
  • you want to integrate with the broader Ory IAM ecosystem

When to avoid

  • you only need simple role checks that a library can handle in-process
  • you don't want to operate a separate authorization service or database
  • you need a full policy engine with complex rule evaluation rather than relationship tuples

Facets

service · maturity active

authorization api-framework http-server security security backend apis developer-tools go self-hosted cloud windows zanzibar rebac rbac abac acl fine-grained-permissions permission-server iam cloud-native ory docker kubernetes linux macos

7 sources

Member repositories

RepositoryRoleHealth v2
ory/ketomain80

For agents

markdown · JSON · MCP: product_card(name="ory/keto")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem