[Experimental] Check whether one or more users are authorized to access resources
[Experimental] The Evaluations API allows batch authorization checks in a single request. It supports request-level defaults for subject, action, resource, and context that can be overridden per evaluation item.
Evaluation Semantics
The options.evaluations_semantic field controls how evaluations are processed:
execute_all(default): Execute all evaluations and return all resultsdeny_on_first_deny: Stop processing on first deny decisionpermit_on_first_permit: Stop processing on first permit decision
When using deny_on_first_deny or permit_on_first_permit, the response may include fewer items than the request because processing short-circuits when the condition is met.
Authorization Model Selection
To pin evaluations to a specific authorization model version, send the Openfga-Authorization-Model-Id header. If the header is not provided, the latest model is used.
Examples
Basic batch evaluation
Check if a user can perform multiple actions on a document:
{
"subject": {"type": "user", "id": "anne"},
"resource": {"type": "document", "id": "roadmap"},
"evaluations": [
{"action": {"name": "can_read"}},
{"action": {"name": "can_write"}},
{"action": {"name": "can_delete"}}
]
}
Using evaluation semantics
Stop on first permitted action (useful for finding any valid permission):
{
"subject": {"type": "user", "id": "anne"},
"resource": {"type": "document", "id": "roadmap"},
"evaluations": [
{"action": {"name": "can_read"}},
{"action": {"name": "can_write"}}
],
"options": {
"evaluations_semantic": "permit_on_first_permit"
}
}
Overriding defaults per evaluation
Check permissions across multiple resources:
{
"subject": {"type": "user", "id": "anne"},
"action": {"name": "can_read"},
"evaluations": [
{"resource": {"type": "document", "id": "doc1"}},
{"resource": {"type": "document", "id": "doc2"}},
{"resource": {"type": "folder", "id": "folder1"}}
]
}
Path Parameters
Body
Response
A successful response.