# ory/keto

The most scalable and customizable permission server on the market. Fix your slow or broken permission system with Google's proven "Zanzibar" approach. Supports ACL, RBAC, and more. Written in Go, cloud native, headless, API-first. Available as a service on Ory Network and for self-hosters.

Repository: https://github.com/ory/keto
Canonical: https://ross.abutalabs.com/products/keto
Homepage: https://www.ory.com/?utm_source=github&utm_medium=banner&utm_campaign=keto
Language: Go
License: Apache-2.0
License Family: permissive
Topics: hacktoberfest, abac, access-control, acl, authorization, fine-grained-permissions, iam, permission-management, permissions, policy-management, rbac, rebac, zanzibar, relation-tuples
Last push: 2026-08-24T03:44:49+00:00

## Health v2 (maintenance only)
Score: 80/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 99, release rhythm 43, longevity 100
- inputs: {"age_days": 3091, "days_push": 9, "days_rel": 166, "gap_med": 189.0, "n_releases_24m": 3}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 5390, forks 386 (observed 2026-08-28T04:09:17.257940+00:00)

## What it is
Ory Keto is an open-source authorization server implementing Google's Zanzibar model for scalable, low-latency permission checks. It supports ReBAC, RBAC, and ABAC via the Ory Permission Language and can be self-hosted or used through the Ory Network.

## Use cases
- implement google zanzibar style authorization
- manage fine-grained permissions for billions of relationships
- replace a slow or broken permission system
- check user permissions with sub-10ms latency
- define access control policies with a permission language
- self-host a permission server for microservices
- implement relationship-based access control (rebac)

## When to choose
- you need scalable, consistent permission checks modeled on Google's Zanzibar
- you want a headless, API-first authorization server you can self-host
- your app needs ReBAC/RBAC/ABAC with horizontal scaling
- you want to integrate with the broader Ory IAM ecosystem

## When to avoid
- you only need simple role checks that a library can handle in-process
- you don't want to operate a separate authorization service or database
- you need a full policy engine with complex rule evaluation rather than relationship tuples

## Facets
- artifact type: service
- maturity: active
- function: authorization, api-framework, http-server, security
- domain: security, backend, apis, developer-tools
- platform: go, self-hosted, cloud, windows
- tags: zanzibar, rebac, rbac, abac, acl, fine-grained-permissions, permission-server, iam, cloud-native, ory, docker, kubernetes, linux, macos

## Member repositories
- ory/keto (main) score 80

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:17.257940+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:58:23.945895+00:00, confidence not recorded.
  - readme: https://github.com/ory/keto (fetched 2026-08-28T04:09:17.257940+00:00, sha 01bcc186dec5)
  - homepage: https://www.ory.com/?utm_source=github&utm_medium=banner&utm_campaign=keto (fetched 2026-08-29T08:52:44.277180+00:00, sha 9cd75b156cd4)
  - site_page: https://www.ory.com/docs/welcome (fetched 2026-08-29T08:52:44.288896+00:00, sha e6f2747eb4d2)
  - site_page: https://www.ory.com/about (fetched 2026-08-29T08:52:44.292618+00:00, sha e44652fde9f9)
  - site_page: https://www.ory.com/pricing (fetched 2026-08-29T08:52:44.286324+00:00, sha 35c1d920fc8d)
  - site_page: https://changelog.ory.com/ (fetched 2026-08-29T08:52:44.290816+00:00, sha c8e6b35f30bb)
  - site_page: https://www.ory.com/integrations (fetched 2026-08-29T08:52:44.294199+00:00, sha 966475eed325)
- Data as of 2026-08-30T08:39:29.467469+00:00.
