Authorization Models
Get an authorization model by its ID
The response returns the authorization model for the particular ID. Authorization Models in OpenFGA are immutable, new versions can be created, but existing ones cannot be deleted or modified.
Example
To retrieve the authorization model with ID 01G5JAVJ41T49E9TT3SKVS7X1J for the store, call the GET authorization-models by ID API with 01G5JAVJ41T49E9TT3SKVS7X1J as the id path parameter. The API returns:
{
"authorization_model":{
"id":"01G5JAVJ41T49E9TT3SKVS7X1J",
"type_definitions":[
{
"type":"user"
},
{
"type":"document",
"relations":{
"reader":{
"union":{
"child":[
{
"this":{}
},
{
"computedUserset":{
"object":"",
"relation":"writer"
}
}
]
}
},
"writer":{
"this":{}
}
}
}
]
}
}
In the above example, there are 2 types (user and document). The document type has 2 relations (writer and reader).
GET
/
stores
/
{store_id}
/
authorization-models
/
{id}
Node.js
const { OpenFgaClient, ConsistencyPreference } = require('@openfga/sdk');
const fgaClient = new OpenFgaClient({
apiUrl: process.env.FGA_API_URL,
storeId: process.env.FGA_STORE_ID,
authorizationModelId: process.env.FGA_MODEL_ID, // Set to the authorization model ID for this request.
});
async function main() {
const response = await fgaClient.readAuthorizationModel();
}
main().catch((error) => {
console.error(error);
process.exitCode = 1;
});package main
import (
"context"
"os"
. "github.com/openfga/go-sdk/client"
)
func main() {
fgaClient, err := NewSdkClient(&ClientConfiguration{
ApiUrl: os.Getenv("FGA_API_URL"),
StoreId: os.Getenv("FGA_STORE_ID"),
AuthorizationModelId: os.Getenv("FGA_MODEL_ID"), // Set to the authorization model ID for this request.
})
if err != nil {
panic(err)
}
response, err := fgaClient.ReadAuthorizationModel(context.Background()).Execute()
if err != nil {
panic(err)
}
_ = response
}using System.Collections.Generic;
using OpenFga.Sdk.Client;
using OpenFga.Sdk.Client.Model;
using OpenFga.Sdk.Model;
using Environment = System.Environment;
var fgaClient = new OpenFgaClient(new ClientConfiguration() {
ApiUrl = Environment.GetEnvironmentVariable("FGA_API_URL"),
StoreId = Environment.GetEnvironmentVariable("FGA_STORE_ID"),
AuthorizationModelId = Environment.GetEnvironmentVariable("FGA_MODEL_ID"), // Set to the authorization model ID for this request.
});
var response = await fgaClient.ReadAuthorizationModel();import asyncio
import os
from openfga_sdk.client import OpenFgaClient, ClientConfiguration
async def main():
configuration = ClientConfiguration(
api_url=os.environ.get("FGA_API_URL"),
store_id=os.environ.get("FGA_STORE_ID"),
authorization_model_id=os.environ.get("FGA_MODEL_ID"), # Set to the authorization model ID for this request.
)
async with OpenFgaClient(configuration) as fga_client:
response = await fga_client.read_authorization_model()
asyncio.run(main())import dev.openfga.sdk.api.client.OpenFgaClient;
import dev.openfga.sdk.api.configuration.ClientConfiguration;
import dev.openfga.sdk.api.configuration.*;
import dev.openfga.sdk.api.client.model.*;
import dev.openfga.sdk.api.model.*;
import java.util.List;
import java.util.Map;
import java.util.ArrayList;
public class Example {
public static void main(String[] args) throws Exception {
var config = new ClientConfiguration()
.apiUrl(System.getenv("FGA_API_URL"))
.storeId(System.getenv("FGA_STORE_ID"))
.authorizationModelId(System.getenv("FGA_MODEL_ID")); // Set to the authorization model ID for this request.
var fgaClient = new OpenFgaClient(config);
var response = fgaClient.readAuthorizationModel().get();
}
}# Set FGA_API_URL to the URL of your OpenFGA server.
# Set FGA_STORE_ID to your store ID.
# Set FGA_MODEL_ID to your authorization model ID.
# These examples use a server with authentication disabled.
# For authenticated servers, see /docs/getting-started/setup-sdk-client.
curl -X GET "$FGA_API_URL/stores/$FGA_STORE_ID/authorization-models/$FGA_MODEL_ID"{
"authorization_model": {
"id": "01G5JAVJ41T49E9TT3SKVS7X1J",
"schema_version": "<string>",
"type_definitions": [
{
"type": "user"
},
{
"metadata": {
"relations": {
"reader": {
"directly_related_user_types": [
{
"type": "user"
}
]
},
"writer": {
"directly_related_user_types": [
{
"type": "user"
}
]
}
}
},
"relations": {
"reader": {
"union": {
"child": [
{
"this": {}
},
{
"computedUserset": {
"object": "",
"relation": "writer"
}
}
]
}
},
"writer": {
"this": {}
}
},
"type": "document"
}
],
"conditions": {}
}
}{
"code": "validation_error",
"message": "Generic validation error"
}{
"code": "unauthenticated",
"message": "unauthenticated"
}{
"code": "forbidden",
"message": "the principal is not authorized to perform the action"
}{
"code": "undefined_endpoint",
"message": "Endpoint not enabled"
}{
"code": "10",
"message": "transaction conflict"
}{
"code": "throttled_timeout_error",
"message": "timeout due to throttling on complex request"
}{
"code": "internal_error",
"message": "Internal Server Error"
}Last modified on September 28, 2026
Was this page helpful?
⌘I
Node.js
const { OpenFgaClient, ConsistencyPreference } = require('@openfga/sdk');
const fgaClient = new OpenFgaClient({
apiUrl: process.env.FGA_API_URL,
storeId: process.env.FGA_STORE_ID,
authorizationModelId: process.env.FGA_MODEL_ID, // Set to the authorization model ID for this request.
});
async function main() {
const response = await fgaClient.readAuthorizationModel();
}
main().catch((error) => {
console.error(error);
process.exitCode = 1;
});package main
import (
"context"
"os"
. "github.com/openfga/go-sdk/client"
)
func main() {
fgaClient, err := NewSdkClient(&ClientConfiguration{
ApiUrl: os.Getenv("FGA_API_URL"),
StoreId: os.Getenv("FGA_STORE_ID"),
AuthorizationModelId: os.Getenv("FGA_MODEL_ID"), // Set to the authorization model ID for this request.
})
if err != nil {
panic(err)
}
response, err := fgaClient.ReadAuthorizationModel(context.Background()).Execute()
if err != nil {
panic(err)
}
_ = response
}using System.Collections.Generic;
using OpenFga.Sdk.Client;
using OpenFga.Sdk.Client.Model;
using OpenFga.Sdk.Model;
using Environment = System.Environment;
var fgaClient = new OpenFgaClient(new ClientConfiguration() {
ApiUrl = Environment.GetEnvironmentVariable("FGA_API_URL"),
StoreId = Environment.GetEnvironmentVariable("FGA_STORE_ID"),
AuthorizationModelId = Environment.GetEnvironmentVariable("FGA_MODEL_ID"), // Set to the authorization model ID for this request.
});
var response = await fgaClient.ReadAuthorizationModel();import asyncio
import os
from openfga_sdk.client import OpenFgaClient, ClientConfiguration
async def main():
configuration = ClientConfiguration(
api_url=os.environ.get("FGA_API_URL"),
store_id=os.environ.get("FGA_STORE_ID"),
authorization_model_id=os.environ.get("FGA_MODEL_ID"), # Set to the authorization model ID for this request.
)
async with OpenFgaClient(configuration) as fga_client:
response = await fga_client.read_authorization_model()
asyncio.run(main())import dev.openfga.sdk.api.client.OpenFgaClient;
import dev.openfga.sdk.api.configuration.ClientConfiguration;
import dev.openfga.sdk.api.configuration.*;
import dev.openfga.sdk.api.client.model.*;
import dev.openfga.sdk.api.model.*;
import java.util.List;
import java.util.Map;
import java.util.ArrayList;
public class Example {
public static void main(String[] args) throws Exception {
var config = new ClientConfiguration()
.apiUrl(System.getenv("FGA_API_URL"))
.storeId(System.getenv("FGA_STORE_ID"))
.authorizationModelId(System.getenv("FGA_MODEL_ID")); // Set to the authorization model ID for this request.
var fgaClient = new OpenFgaClient(config);
var response = fgaClient.readAuthorizationModel().get();
}
}# Set FGA_API_URL to the URL of your OpenFGA server.
# Set FGA_STORE_ID to your store ID.
# Set FGA_MODEL_ID to your authorization model ID.
# These examples use a server with authentication disabled.
# For authenticated servers, see /docs/getting-started/setup-sdk-client.
curl -X GET "$FGA_API_URL/stores/$FGA_STORE_ID/authorization-models/$FGA_MODEL_ID"{
"authorization_model": {
"id": "01G5JAVJ41T49E9TT3SKVS7X1J",
"schema_version": "<string>",
"type_definitions": [
{
"type": "user"
},
{
"metadata": {
"relations": {
"reader": {
"directly_related_user_types": [
{
"type": "user"
}
]
},
"writer": {
"directly_related_user_types": [
{
"type": "user"
}
]
}
}
},
"relations": {
"reader": {
"union": {
"child": [
{
"this": {}
},
{
"computedUserset": {
"object": "",
"relation": "writer"
}
}
]
}
},
"writer": {
"this": {}
}
},
"type": "document"
}
],
"conditions": {}
}
}{
"code": "validation_error",
"message": "Generic validation error"
}{
"code": "unauthenticated",
"message": "unauthenticated"
}{
"code": "forbidden",
"message": "the principal is not authorized to perform the action"
}{
"code": "undefined_endpoint",
"message": "Endpoint not enabled"
}{
"code": "10",
"message": "transaction conflict"
}{
"code": "throttled_timeout_error",
"message": "timeout due to throttling on complex request"
}{
"code": "internal_error",
"message": "Internal Server Error"
}