Authorization Models
Get all authorization models
The ReadAuthorizationModels API returns all the authorization models for a certain store. OpenFGA’s response contains an array of all authorization models, sorted in descending order of creation.
Example
Assume that a store’s authorization model has been configured twice. To get all the authorization models that have been created in this store, call GET authorization-models. The API returns a response that looks like:
{
"authorization_models": [
{
"id": "01G50QVV17PECNVAHX1GG4Y5NC",
"type_definitions": [...]
},
{
"id": "01G4ZW8F4A07AKQ8RHSVG9RW04",
"type_definitions": [...]
},
],
"continuation_token": "eyJwayI6IkxBVEVTVF9OU0NPTkZJR19hdXRoMHN0b3JlIiwic2siOiIxem1qbXF3MWZLZExTcUoyN01MdTdqTjh0cWgifQ=="
}
If there are no more authorization models available, then continuation_token field returns empty:
{
"authorization_models": [
{
"id": "01G50QVV17PECNVAHX1GG4Y5NC",
"type_definitions": [...]
},
{
"id": "01G4ZW8F4A07AKQ8RHSVG9RW04",
"type_definitions": [...]
},
],
"continuation_token": ""
}
GET
/
stores
/
{store_id}
/
authorization-models
Node.js
const { OpenFgaClient, ConsistencyPreference } = require('@openfga/sdk');
const fgaClient = new OpenFgaClient({
apiUrl: process.env.FGA_API_URL,
storeId: process.env.FGA_STORE_ID,
});
async function main() {
const options = {
"pageSize": 20
};
const response = await fgaClient.readAuthorizationModels(options);
}
main().catch((error) => {
console.error(error);
process.exitCode = 1;
});package main
import (
"context"
"os"
. "github.com/openfga/go-sdk/client"
)
func main() {
fgaClient, err := NewSdkClient(&ClientConfiguration{
ApiUrl: os.Getenv("FGA_API_URL"),
StoreId: os.Getenv("FGA_STORE_ID"),
})
if err != nil {
panic(err)
}
pageSize := int32(20)
options := ClientReadAuthorizationModelsOptions{
PageSize: &pageSize,
}
response, err := fgaClient.ReadAuthorizationModels(context.Background()).Options(options).Execute()
if err != nil {
panic(err)
}
_ = response
}using System.Collections.Generic;
using OpenFga.Sdk.Client;
using OpenFga.Sdk.Client.Model;
using OpenFga.Sdk.Model;
using Environment = System.Environment;
var fgaClient = new OpenFgaClient(new ClientConfiguration() {
ApiUrl = Environment.GetEnvironmentVariable("FGA_API_URL"),
StoreId = Environment.GetEnvironmentVariable("FGA_STORE_ID"),
});
var options = new ClientReadAuthorizationModelsOptions {
PageSize = 20,
};
var response = await fgaClient.ReadAuthorizationModels(options);import asyncio
import os
from openfga_sdk.client import OpenFgaClient, ClientConfiguration
async def main():
configuration = ClientConfiguration(
api_url=os.environ.get("FGA_API_URL"),
store_id=os.environ.get("FGA_STORE_ID"),
)
async with OpenFgaClient(configuration) as fga_client:
options = {"page_size": 20}
response = await fga_client.read_authorization_models(options=options)
asyncio.run(main())import dev.openfga.sdk.api.client.OpenFgaClient;
import dev.openfga.sdk.api.configuration.ClientConfiguration;
import dev.openfga.sdk.api.configuration.*;
import dev.openfga.sdk.api.client.model.*;
import dev.openfga.sdk.api.model.*;
import java.util.List;
import java.util.Map;
import java.util.ArrayList;
import dev.openfga.sdk.api.configuration.ClientReadAuthorizationModelsOptions;
public class Example {
public static void main(String[] args) throws Exception {
var config = new ClientConfiguration()
.apiUrl(System.getenv("FGA_API_URL"))
.storeId(System.getenv("FGA_STORE_ID"));
var fgaClient = new OpenFgaClient(config);
var options = new ClientReadAuthorizationModelsOptions()
.pageSize(20);
var response = fgaClient.readAuthorizationModels(options).get();
}
}# Set FGA_API_URL to the URL of your OpenFGA server.
# Set FGA_STORE_ID to your store ID.
# These examples use a server with authentication disabled.
# For authenticated servers, see /docs/getting-started/setup-sdk-client.
curl -X GET "$FGA_API_URL/stores/$FGA_STORE_ID/authorization-models?page_size=20"{
"authorization_models": [
{
"id": "01G5JAVJ41T49E9TT3SKVS7X1J",
"schema_version": "<string>",
"type_definitions": [
{
"type": "user"
},
{
"metadata": {
"relations": {
"reader": {
"directly_related_user_types": [
{
"type": "user"
}
]
},
"writer": {
"directly_related_user_types": [
{
"type": "user"
}
]
}
}
},
"relations": {
"reader": {
"union": {
"child": [
{
"this": {}
},
{
"computedUserset": {
"object": "",
"relation": "writer"
}
}
]
}
},
"writer": {
"this": {}
}
},
"type": "document"
}
],
"conditions": {}
}
],
"continuation_token": "eyJwayI6IkxBVEVTVF9OU0NPTkZJR19hdXRoMHN0b3JlIiwic2siOiIxem1qbXF3MWZLZExTcUoyN01MdTdqTjh0cWgifQ=="
}{
"code": "validation_error",
"message": "Generic validation error"
}{
"code": "unauthenticated",
"message": "unauthenticated"
}{
"code": "forbidden",
"message": "the principal is not authorized to perform the action"
}{
"code": "undefined_endpoint",
"message": "Endpoint not enabled"
}{
"code": "10",
"message": "transaction conflict"
}{
"code": "throttled_timeout_error",
"message": "timeout due to throttling on complex request"
}{
"code": "internal_error",
"message": "Internal Server Error"
}Path Parameters
Last modified on September 28, 2026
Was this page helpful?
⌘I
Node.js
const { OpenFgaClient, ConsistencyPreference } = require('@openfga/sdk');
const fgaClient = new OpenFgaClient({
apiUrl: process.env.FGA_API_URL,
storeId: process.env.FGA_STORE_ID,
});
async function main() {
const options = {
"pageSize": 20
};
const response = await fgaClient.readAuthorizationModels(options);
}
main().catch((error) => {
console.error(error);
process.exitCode = 1;
});package main
import (
"context"
"os"
. "github.com/openfga/go-sdk/client"
)
func main() {
fgaClient, err := NewSdkClient(&ClientConfiguration{
ApiUrl: os.Getenv("FGA_API_URL"),
StoreId: os.Getenv("FGA_STORE_ID"),
})
if err != nil {
panic(err)
}
pageSize := int32(20)
options := ClientReadAuthorizationModelsOptions{
PageSize: &pageSize,
}
response, err := fgaClient.ReadAuthorizationModels(context.Background()).Options(options).Execute()
if err != nil {
panic(err)
}
_ = response
}using System.Collections.Generic;
using OpenFga.Sdk.Client;
using OpenFga.Sdk.Client.Model;
using OpenFga.Sdk.Model;
using Environment = System.Environment;
var fgaClient = new OpenFgaClient(new ClientConfiguration() {
ApiUrl = Environment.GetEnvironmentVariable("FGA_API_URL"),
StoreId = Environment.GetEnvironmentVariable("FGA_STORE_ID"),
});
var options = new ClientReadAuthorizationModelsOptions {
PageSize = 20,
};
var response = await fgaClient.ReadAuthorizationModels(options);import asyncio
import os
from openfga_sdk.client import OpenFgaClient, ClientConfiguration
async def main():
configuration = ClientConfiguration(
api_url=os.environ.get("FGA_API_URL"),
store_id=os.environ.get("FGA_STORE_ID"),
)
async with OpenFgaClient(configuration) as fga_client:
options = {"page_size": 20}
response = await fga_client.read_authorization_models(options=options)
asyncio.run(main())import dev.openfga.sdk.api.client.OpenFgaClient;
import dev.openfga.sdk.api.configuration.ClientConfiguration;
import dev.openfga.sdk.api.configuration.*;
import dev.openfga.sdk.api.client.model.*;
import dev.openfga.sdk.api.model.*;
import java.util.List;
import java.util.Map;
import java.util.ArrayList;
import dev.openfga.sdk.api.configuration.ClientReadAuthorizationModelsOptions;
public class Example {
public static void main(String[] args) throws Exception {
var config = new ClientConfiguration()
.apiUrl(System.getenv("FGA_API_URL"))
.storeId(System.getenv("FGA_STORE_ID"));
var fgaClient = new OpenFgaClient(config);
var options = new ClientReadAuthorizationModelsOptions()
.pageSize(20);
var response = fgaClient.readAuthorizationModels(options).get();
}
}# Set FGA_API_URL to the URL of your OpenFGA server.
# Set FGA_STORE_ID to your store ID.
# These examples use a server with authentication disabled.
# For authenticated servers, see /docs/getting-started/setup-sdk-client.
curl -X GET "$FGA_API_URL/stores/$FGA_STORE_ID/authorization-models?page_size=20"{
"authorization_models": [
{
"id": "01G5JAVJ41T49E9TT3SKVS7X1J",
"schema_version": "<string>",
"type_definitions": [
{
"type": "user"
},
{
"metadata": {
"relations": {
"reader": {
"directly_related_user_types": [
{
"type": "user"
}
]
},
"writer": {
"directly_related_user_types": [
{
"type": "user"
}
]
}
}
},
"relations": {
"reader": {
"union": {
"child": [
{
"this": {}
},
{
"computedUserset": {
"object": "",
"relation": "writer"
}
}
]
}
},
"writer": {
"this": {}
}
},
"type": "document"
}
],
"conditions": {}
}
],
"continuation_token": "eyJwayI6IkxBVEVTVF9OU0NPTkZJR19hdXRoMHN0b3JlIiwic2siOiIxem1qbXF3MWZLZExTcUoyN01MdTdqTjh0cWgifQ=="
}{
"code": "validation_error",
"message": "Generic validation error"
}{
"code": "unauthenticated",
"message": "unauthenticated"
}{
"code": "forbidden",
"message": "the principal is not authorized to perform the action"
}{
"code": "undefined_endpoint",
"message": "Endpoint not enabled"
}{
"code": "10",
"message": "transaction conflict"
}{
"code": "throttled_timeout_error",
"message": "timeout due to throttling on complex request"
}{
"code": "internal_error",
"message": "Internal Server Error"
}