Assertions
Upsert assertions for a model
The WriteAssertions API upserts new assertions for an authorization model id, or overwrite the existing ones. An assertion is an object that contains a tuple key, the expectation of whether a call to the Check API of that tuple key returns true or false, and optionally a list of contextual tuples.
PUT
/
stores
/
{store_id}
/
assertions
/
{authorization_model_id}
Node.js
const { OpenFgaClient, ConsistencyPreference } = require('@openfga/sdk');
const fgaClient = new OpenFgaClient({
apiUrl: process.env.FGA_API_URL,
storeId: process.env.FGA_STORE_ID,
authorizationModelId: process.env.FGA_MODEL_ID, // Set to the authorization model ID for this request.
});
async function main() {
const body = [
{
"user": "user:anne",
"relation": "reader",
"object": "document:budget",
"expectation": true
}
];
await fgaClient.writeAssertions(body);
}
main().catch((error) => {
console.error(error);
process.exitCode = 1;
});package main
import (
"context"
"os"
. "github.com/openfga/go-sdk/client"
)
func main() {
fgaClient, err := NewSdkClient(&ClientConfiguration{
ApiUrl: os.Getenv("FGA_API_URL"),
StoreId: os.Getenv("FGA_STORE_ID"),
AuthorizationModelId: os.Getenv("FGA_MODEL_ID"), // Set to the authorization model ID for this request.
})
if err != nil {
panic(err)
}
body := ClientWriteAssertionsRequest{
{
User: "user:anne",
Relation: "reader",
Object: "document:budget",
Expectation: true,
},
}
_, err = fgaClient.WriteAssertions(context.Background()).Body(body).Execute()
if err != nil {
panic(err)
}
}using System.Collections.Generic;
using OpenFga.Sdk.Client;
using OpenFga.Sdk.Client.Model;
using OpenFga.Sdk.Model;
using Environment = System.Environment;
var fgaClient = new OpenFgaClient(new ClientConfiguration() {
ApiUrl = Environment.GetEnvironmentVariable("FGA_API_URL"),
StoreId = Environment.GetEnvironmentVariable("FGA_STORE_ID"),
AuthorizationModelId = Environment.GetEnvironmentVariable("FGA_MODEL_ID"), // Set to the authorization model ID for this request.
});
var body = new List<ClientAssertion> {
new ClientAssertion {
User = "user:anne",
Relation = "reader",
Object = "document:budget",
Expectation = true,
}
};
await fgaClient.WriteAssertions(body);import asyncio
import os
from openfga_sdk.client import OpenFgaClient, ClientConfiguration
from openfga_sdk.client.models import ClientAssertion
async def main():
configuration = ClientConfiguration(
api_url=os.environ.get("FGA_API_URL"),
store_id=os.environ.get("FGA_STORE_ID"),
authorization_model_id=os.environ.get("FGA_MODEL_ID"), # Set to the authorization model ID for this request.
)
async with OpenFgaClient(configuration) as fga_client:
body = [
ClientAssertion(
user="user:anne",
relation="reader",
object="document:budget",
expectation=True,
),
]
await fga_client.write_assertions(body=body)
asyncio.run(main())import dev.openfga.sdk.api.client.OpenFgaClient;
import dev.openfga.sdk.api.configuration.ClientConfiguration;
import dev.openfga.sdk.api.configuration.*;
import dev.openfga.sdk.api.client.model.*;
import dev.openfga.sdk.api.model.*;
import java.util.List;
import java.util.Map;
import java.util.ArrayList;
public class Example {
public static void main(String[] args) throws Exception {
var config = new ClientConfiguration()
.apiUrl(System.getenv("FGA_API_URL"))
.storeId(System.getenv("FGA_STORE_ID"))
.authorizationModelId(System.getenv("FGA_MODEL_ID")); // Set to the authorization model ID for this request.
var fgaClient = new OpenFgaClient(config);
var body = List.of(
new ClientAssertion()
.user("user:anne")
.relation("reader")
._object("document:budget")
.expectation(true)
);
fgaClient.writeAssertions(body).get();
}
}# Set FGA_API_URL to the URL of your OpenFGA server.
# Set FGA_STORE_ID to your store ID.
# Set FGA_MODEL_ID to your authorization model ID.
# These examples use a server with authentication disabled.
# For authenticated servers, see /docs/getting-started/setup-sdk-client.
curl -X PUT "$FGA_API_URL/stores/$FGA_STORE_ID/assertions/$FGA_MODEL_ID" \
-H "content-type: application/json" \
-d '{
"assertions": [
{
"tuple_key": {
"user": "user:anne",
"relation": "reader",
"object": "document:budget"
},
"expectation": true
}
]
}'{
"code": "validation_error",
"message": "Generic validation error"
}{
"code": "unauthenticated",
"message": "unauthenticated"
}{
"code": "forbidden",
"message": "the principal is not authorized to perform the action"
}{
"code": "undefined_endpoint",
"message": "Endpoint not enabled"
}{
"code": "10",
"message": "transaction conflict"
}{
"code": "throttled_timeout_error",
"message": "timeout due to throttling on complex request"
}{
"code": "internal_error",
"message": "Internal Server Error"
}Last modified on September 28, 2026
Was this page helpful?
⌘I
Node.js
const { OpenFgaClient, ConsistencyPreference } = require('@openfga/sdk');
const fgaClient = new OpenFgaClient({
apiUrl: process.env.FGA_API_URL,
storeId: process.env.FGA_STORE_ID,
authorizationModelId: process.env.FGA_MODEL_ID, // Set to the authorization model ID for this request.
});
async function main() {
const body = [
{
"user": "user:anne",
"relation": "reader",
"object": "document:budget",
"expectation": true
}
];
await fgaClient.writeAssertions(body);
}
main().catch((error) => {
console.error(error);
process.exitCode = 1;
});package main
import (
"context"
"os"
. "github.com/openfga/go-sdk/client"
)
func main() {
fgaClient, err := NewSdkClient(&ClientConfiguration{
ApiUrl: os.Getenv("FGA_API_URL"),
StoreId: os.Getenv("FGA_STORE_ID"),
AuthorizationModelId: os.Getenv("FGA_MODEL_ID"), // Set to the authorization model ID for this request.
})
if err != nil {
panic(err)
}
body := ClientWriteAssertionsRequest{
{
User: "user:anne",
Relation: "reader",
Object: "document:budget",
Expectation: true,
},
}
_, err = fgaClient.WriteAssertions(context.Background()).Body(body).Execute()
if err != nil {
panic(err)
}
}using System.Collections.Generic;
using OpenFga.Sdk.Client;
using OpenFga.Sdk.Client.Model;
using OpenFga.Sdk.Model;
using Environment = System.Environment;
var fgaClient = new OpenFgaClient(new ClientConfiguration() {
ApiUrl = Environment.GetEnvironmentVariable("FGA_API_URL"),
StoreId = Environment.GetEnvironmentVariable("FGA_STORE_ID"),
AuthorizationModelId = Environment.GetEnvironmentVariable("FGA_MODEL_ID"), // Set to the authorization model ID for this request.
});
var body = new List<ClientAssertion> {
new ClientAssertion {
User = "user:anne",
Relation = "reader",
Object = "document:budget",
Expectation = true,
}
};
await fgaClient.WriteAssertions(body);import asyncio
import os
from openfga_sdk.client import OpenFgaClient, ClientConfiguration
from openfga_sdk.client.models import ClientAssertion
async def main():
configuration = ClientConfiguration(
api_url=os.environ.get("FGA_API_URL"),
store_id=os.environ.get("FGA_STORE_ID"),
authorization_model_id=os.environ.get("FGA_MODEL_ID"), # Set to the authorization model ID for this request.
)
async with OpenFgaClient(configuration) as fga_client:
body = [
ClientAssertion(
user="user:anne",
relation="reader",
object="document:budget",
expectation=True,
),
]
await fga_client.write_assertions(body=body)
asyncio.run(main())import dev.openfga.sdk.api.client.OpenFgaClient;
import dev.openfga.sdk.api.configuration.ClientConfiguration;
import dev.openfga.sdk.api.configuration.*;
import dev.openfga.sdk.api.client.model.*;
import dev.openfga.sdk.api.model.*;
import java.util.List;
import java.util.Map;
import java.util.ArrayList;
public class Example {
public static void main(String[] args) throws Exception {
var config = new ClientConfiguration()
.apiUrl(System.getenv("FGA_API_URL"))
.storeId(System.getenv("FGA_STORE_ID"))
.authorizationModelId(System.getenv("FGA_MODEL_ID")); // Set to the authorization model ID for this request.
var fgaClient = new OpenFgaClient(config);
var body = List.of(
new ClientAssertion()
.user("user:anne")
.relation("reader")
._object("document:budget")
.expectation(true)
);
fgaClient.writeAssertions(body).get();
}
}# Set FGA_API_URL to the URL of your OpenFGA server.
# Set FGA_STORE_ID to your store ID.
# Set FGA_MODEL_ID to your authorization model ID.
# These examples use a server with authentication disabled.
# For authenticated servers, see /docs/getting-started/setup-sdk-client.
curl -X PUT "$FGA_API_URL/stores/$FGA_STORE_ID/assertions/$FGA_MODEL_ID" \
-H "content-type: application/json" \
-d '{
"assertions": [
{
"tuple_key": {
"user": "user:anne",
"relation": "reader",
"object": "document:budget"
},
"expectation": true
}
]
}'{
"code": "validation_error",
"message": "Generic validation error"
}{
"code": "unauthenticated",
"message": "unauthenticated"
}{
"code": "forbidden",
"message": "the principal is not authorized to perform the action"
}{
"code": "undefined_endpoint",
"message": "Endpoint not enabled"
}{
"code": "10",
"message": "transaction conflict"
}{
"code": "throttled_timeout_error",
"message": "timeout due to throttling on complex request"
}{
"code": "internal_error",
"message": "Internal Server Error"
}