Authorization Models
Create a new authorization model
The WriteAuthorizationModel API adds a new authorization model to a store.
Each item in the type_definitions array is a type definition as specified in the field type_definition.
The response returns the authorization model’s ID in the id field.
Example
To add an authorization model with user and document type definitions, call POST authorization-models API with the body:
{
"type_definitions":[
{
"type":"user"
},
{
"type":"document",
"relations":{
"reader":{
"union":{
"child":[
{
"this":{}
},
{
"computedUserset":{
"object":"",
"relation":"writer"
}
}
]
}
},
"writer":{
"this":{}
}
}
}
]
}
OpenFGA’s response includes the version id for this authorization model, similar to:
{"authorization_model_id": "01G50QVV17PECNVAHX1GG4Y5NC"}
POST
/
stores
/
{store_id}
/
authorization-models
Node.js
const { OpenFgaClient, ConsistencyPreference } = require('@openfga/sdk');
const fgaClient = new OpenFgaClient({
apiUrl: process.env.FGA_API_URL,
storeId: process.env.FGA_STORE_ID,
});
async function main() {
const body = {
"schema_version": "1.1",
"type_definitions": [
{
"type": "user"
},
{
"type": "document",
"relations": {
"reader": {
"this": {}
}
},
"metadata": {
"relations": {
"reader": {
"directly_related_user_types": [
{
"type": "user"
}
]
}
}
}
}
]
};
const response = await fgaClient.writeAuthorizationModel(body);
}
main().catch((error) => {
console.error(error);
process.exitCode = 1;
});package main
import (
"context"
"os"
"encoding/json"
. "github.com/openfga/go-sdk/client"
)
func main() {
fgaClient, err := NewSdkClient(&ClientConfiguration{
ApiUrl: os.Getenv("FGA_API_URL"),
StoreId: os.Getenv("FGA_STORE_ID"),
})
if err != nil {
panic(err)
}
modelJSON := `{
"schema_version": "1.1",
"type_definitions": [
{
"type": "user"
},
{
"type": "document",
"relations": {
"reader": {
"this": {}
}
},
"metadata": {
"relations": {
"reader": {
"directly_related_user_types": [
{
"type": "user"
}
]
}
}
}
}
]
}`
var body ClientWriteAuthorizationModelRequest
if err := json.Unmarshal([]byte(modelJSON), &body); err != nil {
panic(err)
}
response, err := fgaClient.WriteAuthorizationModel(context.Background()).Body(body).Execute()
if err != nil {
panic(err)
}
_ = response
}using System.Collections.Generic;
using OpenFga.Sdk.Client;
using OpenFga.Sdk.Client.Model;
using OpenFga.Sdk.Model;
using Environment = System.Environment;
using System;
var fgaClient = new OpenFgaClient(new ClientConfiguration() {
ApiUrl = Environment.GetEnvironmentVariable("FGA_API_URL"),
StoreId = Environment.GetEnvironmentVariable("FGA_STORE_ID"),
});
var body = ClientWriteAuthorizationModelRequest.FromJson("{\"schema_version\":\"1.1\",\"type_definitions\":[{\"type\":\"user\"},{\"type\":\"document\",\"relations\":{\"reader\":{\"this\":{}}},\"metadata\":{\"relations\":{\"reader\":{\"directly_related_user_types\":[{\"type\":\"user\"}]}}}}]}")
?? throw new InvalidOperationException("Failed to deserialize the authorization model.");
var response = await fgaClient.WriteAuthorizationModel(body);import asyncio
import os
from openfga_sdk.client import OpenFgaClient, ClientConfiguration
from openfga_sdk import WriteAuthorizationModelRequest, TypeDefinition, Userset, Metadata, RelationMetadata, RelationReference
async def main():
configuration = ClientConfiguration(
api_url=os.environ.get("FGA_API_URL"),
store_id=os.environ.get("FGA_STORE_ID"),
)
async with OpenFgaClient(configuration) as fga_client:
body = WriteAuthorizationModelRequest(
schema_version="1.1",
type_definitions=[
TypeDefinition(
type="user",
),
TypeDefinition(
type="document",
relations={
"reader": Userset(
this={},
),
},
metadata=Metadata(
relations={
"reader": RelationMetadata(
directly_related_user_types=[
RelationReference(
type="user",
),
],
),
},
),
),
],
)
response = await fga_client.write_authorization_model(body=body)
asyncio.run(main())import dev.openfga.sdk.api.client.OpenFgaClient;
import dev.openfga.sdk.api.configuration.ClientConfiguration;
import dev.openfga.sdk.api.configuration.*;
import dev.openfga.sdk.api.client.model.*;
import dev.openfga.sdk.api.model.*;
import java.util.List;
import java.util.Map;
import java.util.ArrayList;
public class Example {
public static void main(String[] args) throws Exception {
var config = new ClientConfiguration()
.apiUrl(System.getenv("FGA_API_URL"))
.storeId(System.getenv("FGA_STORE_ID"));
var fgaClient = new OpenFgaClient(config);
var body = new ApiClient().getObjectMapper()
.readValue("{\"schema_version\":\"1.1\",\"type_definitions\":[{\"type\":\"user\"},{\"type\":\"document\",\"relations\":{\"reader\":{\"this\":{}}},\"metadata\":{\"relations\":{\"reader\":{\"directly_related_user_types\":[{\"type\":\"user\"}]}}}}]}", WriteAuthorizationModelRequest.class);
var response = fgaClient.writeAuthorizationModel(body).get();
}
}# Set FGA_API_URL to the URL of your OpenFGA server.
# Set FGA_STORE_ID to your store ID.
# These examples use a server with authentication disabled.
# For authenticated servers, see /docs/getting-started/setup-sdk-client.
curl -X POST "$FGA_API_URL/stores/$FGA_STORE_ID/authorization-models" \
-H "content-type: application/json" \
-d '{
"schema_version": "1.1",
"type_definitions": [
{
"type": "user"
},
{
"type": "document",
"relations": {
"reader": {
"this": {}
}
},
"metadata": {
"relations": {
"reader": {
"directly_related_user_types": [
{
"type": "user"
}
]
}
}
}
}
]
}'{
"authorization_model_id": "01G5JAVJ41T49E9TT3SKVS7X1J"
}{
"code": "validation_error",
"message": "Generic validation error"
}{
"code": "unauthenticated",
"message": "unauthenticated"
}{
"code": "forbidden",
"message": "the principal is not authorized to perform the action"
}{
"code": "undefined_endpoint",
"message": "Endpoint not enabled"
}{
"code": "10",
"message": "transaction conflict"
}{
"code": "throttled_timeout_error",
"message": "timeout due to throttling on complex request"
}{
"code": "internal_error",
"message": "Internal Server Error"
}Path Parameters
Body
application/json
Response
A successful response.
Example:
"01G5JAVJ41T49E9TT3SKVS7X1J"
Last modified on September 28, 2026
Was this page helpful?
⌘I
Node.js
const { OpenFgaClient, ConsistencyPreference } = require('@openfga/sdk');
const fgaClient = new OpenFgaClient({
apiUrl: process.env.FGA_API_URL,
storeId: process.env.FGA_STORE_ID,
});
async function main() {
const body = {
"schema_version": "1.1",
"type_definitions": [
{
"type": "user"
},
{
"type": "document",
"relations": {
"reader": {
"this": {}
}
},
"metadata": {
"relations": {
"reader": {
"directly_related_user_types": [
{
"type": "user"
}
]
}
}
}
}
]
};
const response = await fgaClient.writeAuthorizationModel(body);
}
main().catch((error) => {
console.error(error);
process.exitCode = 1;
});package main
import (
"context"
"os"
"encoding/json"
. "github.com/openfga/go-sdk/client"
)
func main() {
fgaClient, err := NewSdkClient(&ClientConfiguration{
ApiUrl: os.Getenv("FGA_API_URL"),
StoreId: os.Getenv("FGA_STORE_ID"),
})
if err != nil {
panic(err)
}
modelJSON := `{
"schema_version": "1.1",
"type_definitions": [
{
"type": "user"
},
{
"type": "document",
"relations": {
"reader": {
"this": {}
}
},
"metadata": {
"relations": {
"reader": {
"directly_related_user_types": [
{
"type": "user"
}
]
}
}
}
}
]
}`
var body ClientWriteAuthorizationModelRequest
if err := json.Unmarshal([]byte(modelJSON), &body); err != nil {
panic(err)
}
response, err := fgaClient.WriteAuthorizationModel(context.Background()).Body(body).Execute()
if err != nil {
panic(err)
}
_ = response
}using System.Collections.Generic;
using OpenFga.Sdk.Client;
using OpenFga.Sdk.Client.Model;
using OpenFga.Sdk.Model;
using Environment = System.Environment;
using System;
var fgaClient = new OpenFgaClient(new ClientConfiguration() {
ApiUrl = Environment.GetEnvironmentVariable("FGA_API_URL"),
StoreId = Environment.GetEnvironmentVariable("FGA_STORE_ID"),
});
var body = ClientWriteAuthorizationModelRequest.FromJson("{\"schema_version\":\"1.1\",\"type_definitions\":[{\"type\":\"user\"},{\"type\":\"document\",\"relations\":{\"reader\":{\"this\":{}}},\"metadata\":{\"relations\":{\"reader\":{\"directly_related_user_types\":[{\"type\":\"user\"}]}}}}]}")
?? throw new InvalidOperationException("Failed to deserialize the authorization model.");
var response = await fgaClient.WriteAuthorizationModel(body);import asyncio
import os
from openfga_sdk.client import OpenFgaClient, ClientConfiguration
from openfga_sdk import WriteAuthorizationModelRequest, TypeDefinition, Userset, Metadata, RelationMetadata, RelationReference
async def main():
configuration = ClientConfiguration(
api_url=os.environ.get("FGA_API_URL"),
store_id=os.environ.get("FGA_STORE_ID"),
)
async with OpenFgaClient(configuration) as fga_client:
body = WriteAuthorizationModelRequest(
schema_version="1.1",
type_definitions=[
TypeDefinition(
type="user",
),
TypeDefinition(
type="document",
relations={
"reader": Userset(
this={},
),
},
metadata=Metadata(
relations={
"reader": RelationMetadata(
directly_related_user_types=[
RelationReference(
type="user",
),
],
),
},
),
),
],
)
response = await fga_client.write_authorization_model(body=body)
asyncio.run(main())import dev.openfga.sdk.api.client.OpenFgaClient;
import dev.openfga.sdk.api.configuration.ClientConfiguration;
import dev.openfga.sdk.api.configuration.*;
import dev.openfga.sdk.api.client.model.*;
import dev.openfga.sdk.api.model.*;
import java.util.List;
import java.util.Map;
import java.util.ArrayList;
public class Example {
public static void main(String[] args) throws Exception {
var config = new ClientConfiguration()
.apiUrl(System.getenv("FGA_API_URL"))
.storeId(System.getenv("FGA_STORE_ID"));
var fgaClient = new OpenFgaClient(config);
var body = new ApiClient().getObjectMapper()
.readValue("{\"schema_version\":\"1.1\",\"type_definitions\":[{\"type\":\"user\"},{\"type\":\"document\",\"relations\":{\"reader\":{\"this\":{}}},\"metadata\":{\"relations\":{\"reader\":{\"directly_related_user_types\":[{\"type\":\"user\"}]}}}}]}", WriteAuthorizationModelRequest.class);
var response = fgaClient.writeAuthorizationModel(body).get();
}
}# Set FGA_API_URL to the URL of your OpenFGA server.
# Set FGA_STORE_ID to your store ID.
# These examples use a server with authentication disabled.
# For authenticated servers, see /docs/getting-started/setup-sdk-client.
curl -X POST "$FGA_API_URL/stores/$FGA_STORE_ID/authorization-models" \
-H "content-type: application/json" \
-d '{
"schema_version": "1.1",
"type_definitions": [
{
"type": "user"
},
{
"type": "document",
"relations": {
"reader": {
"this": {}
}
},
"metadata": {
"relations": {
"reader": {
"directly_related_user_types": [
{
"type": "user"
}
]
}
}
}
}
]
}'{
"authorization_model_id": "01G5JAVJ41T49E9TT3SKVS7X1J"
}{
"code": "validation_error",
"message": "Generic validation error"
}{
"code": "unauthenticated",
"message": "unauthenticated"
}{
"code": "forbidden",
"message": "the principal is not authorized to perform the action"
}{
"code": "undefined_endpoint",
"message": "Endpoint not enabled"
}{
"code": "10",
"message": "transaction conflict"
}{
"code": "throttled_timeout_error",
"message": "timeout due to throttling on complex request"
}{
"code": "internal_error",
"message": "Internal Server Error"
}