Ross ROSS = Recommend OSS · open-source software intelligence for agents

warrant-dev/warrant

Warrant is a highly scalable, centralized authorization service based on Google Zanzibar. Use it to define, enforce, query, and audit application authorization and access control. observed · 2026-08-28

github.com/warrant-dev/warrant · homepage · Go · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

46/100

  • Activity 55
  • Release rhythm 8
  • Longevity 92
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1296
  • days_rel: n/a
  • days_push: 271
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1336 stars · 53 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Warrant is a highly scalable, centralized fine-grained authorization service inspired by Google Zanzibar, written in Go. It lets applications define, enforce, query, and audit access control rules supporting RBAC, ABAC, and ReBAC paradigms via HTTP APIs and SDKs.

Use cases

  • add role-based access control to a SaaS application
  • check if a user is an editor of a document at runtime
  • implement fine-grained permissions with tenants and pricing tiers
  • self-service role and permission management for customers
  • audit application access rules and entitlements
  • integrate authorization with Auth0 or Firebase identity providers

When to choose

  • you need centralized, low-latency authorization checks across multiple applications
  • you want Zanzibar-style relationship-based access control without building it yourself
  • you need to support RBAC, ABAC, and ReBAC in one service

When to avoid

  • you only need simple authentication (authn), not authorization
  • you want a fully managed service and prefer WorkOS FGA, its successor
  • your stack cannot run a separate Go service or supported database

Facets

service · maturity active

authorization api-framework http-server security backend web-development developer-tools self-hosted windows go zanzibar rebac rbac abac fine-grained-authorization access-control entitlements iam docker linux macos

2 sources

Member repositories

RepositoryRoleHealth v2
warrant-dev/warrantmain46

For agents

markdown · JSON · MCP: product_card(name="warrant-dev/warrant")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem