Runtime authorization & controls
OpenFGA
Apache-2.0 relationship-based authorization engine whose documentation models agents as first-class principals with narrowly scoped, revocable, optionally time-limited grants, including MCP tool-level checks and permission-filtered retrieval. It answers authorization questions but does not intercept traffic, so an application or gateway must call it.
open_source · generally available · Research snapshot 2026-09-06
Visit the official product source ↗Where it fits
Runtime authorization & controls · Agent identity & access
Useful conversation with: Application security architect, IAM engineer, Platform engineer.
Ask for a demonstration
Show me an OpenFGA model where an agent receives a task-scoped grant to two MCP tools with a turn limit, then revoke the agent without touching the user's permissions.
Capabilities and evidence
Support labels reflect the supplied research. Documentation and vendor claims are not independent product tests. “Not established” means the researcher did not find support; it does not prove a capability is absent.
Documented by provider
OpenFGA documentation models agents as first-class principals that appear in authorization tuples, receive delegated rather than copied permissions, and can be revoked independently of the user they serve.
Limit: Modelling guidance is not an enforcement mechanism; interception must be built by the adopter.
Source s1
Documented by provider
Agents can start with zero permissions and receive narrowly scoped grants per task, with optional expiration, turn limits and agent binding, and MCP tool access can be controlled per user by role, group and temporal grant.
Limit: Documented as modelling patterns; no reference implementation of an MCP interceptor is provided on these pages.
Source s2
Documented by provider
OpenFGA is an Apache-2.0 licensed, high-performance authorization engine inspired by Google Zanzibar with HTTP and gRPC APIs.
Limit: Repository evidence does not establish a vendor support commitment.
Source s3
Limitations to discuss
- Not a gateway or interception point
- No prompt or content inspection
Sources
- AI Agent Authorization with OpenFGA · OpenFGA project · official docs
Access date reported by researcher: 2026-09-06 - Authorization for Agents - OpenFGA · OpenFGA project · official docs
Access date reported by researcher: 2026-09-06 - openfga/openfga · OpenFGA (GitHub) · official repository
Access date reported by researcher: 2026-09-06
Listing does not imply partnership, supplier status, a working DutyGraph integration, or a compliance certification.
Suggest a correction