What Is A Type?
A type is a string. It defines a class of objects with similar characteristics.Examples and details
Examples and details
The following are examples of types:
workspacerepositoryorganizationdocument
What Is A Type Definition?
A type definition defines all possible relations a user or another object can have in relation to this type.Examples and details
Examples and details
Below is an example of a type definition:
What Is An Authorization Model?
An authorization model combines one or more type definitions. This is used to define the permission model of a system.What Is A Store?
A store is an OpenFGA entity used to organize authorization check data.Examples and details
Examples and details
Each store contains one or more versions of an authorization model and can contain various relationship tuples. Store data cannot be shared across stores; we recommended storing all data that may be related or affect your authorization result in a single store.Separate stores can be created for separate authorization needs or isolated environments, e.g. development/prod.
What Is An Object?
An object represents an entity in the system. Users’ relationships to it are defined by relationship tuples and the authorization model.Examples and details
Examples and details
An object is a combination of a type and an identifier.For example:
workspace:fb83c013-3060-41f4-9590-d3233a67938frepository:auth0/express-jwtorganization:org_ajUc9kJdocument:new-roadmap
What Is A User?
A user is an entity in the system that can be related to an object.Examples and details
Examples and details
A user is a combination of a type, an identifier, and an optional relation.For example,
- any identifier: e.g.
user:anneoruser:4179af14-f0c0-4930-88fd-5570c7bf6f59 - any object: e.g.
workspace:fb83c013-3060-41f4-9590-d3233a67938f,repository:auth0/express-jwtororganization:org_ajUc9kJ - a group or a set of users (also called a userset): e.g.
organization:org_ajUc9kJ#members, which represents the set of users related to the objectorganization:org_ajUc9kJasmember - everyone, using the special syntax:
*
What Is A Relation?
A relation is a string defined in the type definition of an authorization model. Relations define a possible relationship between an object (of the same type as the type definition) and a user in the system.Examples and details
Examples and details
Examples of relation:
- User can be a
readerof a document - Team can
administera repo - User can be a
memberof a team
What Is A Relation Definition?
A relation definition lists the conditions or requirements under which a relationship is possible.Examples and details
Examples and details
For example:User, relation and object are the building blocks for relationship tuples.For an example, see Direct Access.
-
editordescribing a possible relationship between a user and an object in thedocumenttype allows the following:-
user identifier to object relationship: the user id
anneof typeuseris related to the objectdocument:roadmapaseditor -
object to object relationship: the object
application:ifftis related to the objectdocument:roadmapaseditor -
userset to object relationship: the userset
organization:auth0.com#memberis related todocument:roadmapaseditor- indicates that the set of users who are related to the object
organization:auth0.comasmemberare related to the objectdocument:roadmapaseditors - allows for potential solutions to use-cases like sharing a document internally with all members of a company or a team
- indicates that the set of users who are related to the object
-
everyone to object relationship: everyone (
*) is related todocument:roadmapaseditor- this is how one could model publicly editable documents
-
user identifier to object relationship: the user id
There are four relations in the document type configuration:
viewer, commenter, editor and owner. The editor relation exists when the report is directly assigned to the user or for any member of an assigned team.What Is A Directly Related User Type?
A directly related user type is an array specified in the type definition to indicate which types of users can be directly related to that relation.What is a Condition?
A condition is a function composed of one or more parameters and an expression. Every condition evaluates to a boolean outcome, and expressions are defined using Google’s Common Expression Language (CEL).Examples and details
Examples and details
In the following snippet
less_than_hundred defines a Condition that evaluates to a boolean outcome. The provided parameter x, defined as an integer type, is used in the boolean expression x < 100. The condition returns a truthy outcome if the expression returns a truthy outcome, but is otherwise false.What Is A Relationship Tuple?
A relationship tuple is a base tuple/triplet consisting of a user, relation, and object. Tuples may add an optional condition, like Conditional Relationship Tuples. Relationship tuples are written and stored in OpenFGA.Examples and details
Examples and details
A relationship tuple consists of:For more information, see Direct Access.
- a user, e.g.
user:anne,user:3f7768e0-4fa7-4e93-8417-4da68ce1846c,workspace:auth0orfolder:planning#editor - a relation, e.g.
editor,memberorparent_workspace - an object, e.g
repo:auth0/express_jwt,domain:auth0.comorchannel:marketing - a condition (optional), e.g.
{"condition": "in_allowed_ip_range", "context": {...}}
What Is A Conditional Relationship Tuple?
A conditional relationship tuple is a relationship tuple that represents a relationship conditioned upon the evaluation of a condition.Examples and details
Examples and details
If a relationship tuple is conditioned, then that condition must to a truthy outcome for the relationship tuple to be permissible.The following relationship tuple is a conditional relationship tuple because it is conditioned on
less_than_hundred. If the expression for less_than_hundred is defined as x < 100, then the relationship is permissible because the expression - 20 < 100 - evaluates to a truthy outcome.What Is A Relationship?
A relationship is the realization of a relation between a user and an object.Examples and details
Examples and details
An authorization model, together with relationship tuples, determine whether a relationship exists between a user and an object. Relationships may be direct or implied.
What Are Direct And Implied Relationships?
A direct relationship (R) between user X and object Y means the relationship tuple (user=X, relation=R, object=Y) exists, and the OpenFGA authorization model for that relation allows the direct relationship because of direct relationship type restrictions. An implied (or computed) relationship (R) exists between user X and object Y if user X is related to an object Z that is in a direct or implied relationship with object Y, and the OpenFGA authorization model allows it.Examples and details
Examples and details
-
user:annehas a direct relationship withdocument:new-roadmapasviewerif the type definition allows it with direct relationship type restrictions, and one of the following relationship tuples exist:-
Anne of type user is directly related to the document
-
Everyone (
*) of type user is directly related to the document -
The userset is directly related to this document
AND Anne of type user is a member of the userset team:product#member
-
Anne of type user is directly related to the document
-
user:annehas an implied relationship withdocument:new-roadmapasviewerif the type definition allows it, and the presence of relationship tuples satisfying the relationship exist. For example, assume the following type definition: And assume the following relationship tuple exists in the system:In this case, the relationship betweenuser:anneanddocument:new-roadmapas avieweris implied from the directeditorrelationshipuser:annehas with that same document. Thus, the following request to check whether a viewer relationship exists betweenuser:anneanddocument:new-roadmapwill returntrue.
What Is A Check Request?
A check request is a call to the OpenFGA check endpoint, returning whether the user has a certain relationship with an object.Examples and details
Examples and details
Check requests use the
check methods in the OpenFGA SDKs (JavaScript SDK/Go SDK/.NET SDK) by manually calling the check endpoint using curl or in your code. The check endpoint responds with { "allowed": true } if a relationship exists, and with { "allowed": false } if the relationship does not.For example, the following will check whether anne of type user has a viewer relation to document:new-roadmap:For more information, see the Relationship Queries page and the official Check API Reference.What Is A List Objects Request?
A list objects request is a call to the OpenFGA list objects endpoint that returns all objects of a given type that a user has a specified relationship with.Examples and details
Examples and details
List objects requests are completed using the
listobjects methods in the OpenFGA SDKs (JavaScript SDK/Go SDK/.NET SDK) by manually calling the list objects endpoint using curl or in your code.The list objects endpoint responds with a list of objects for a given type that the user has the specified relationship with.For example, the following returns all the objects with document type for which anne of type user has a viewer relation with:For more information, see the Relationship Queries page and the List Objects API Reference.What Is A List Users Request?
A list users request is a call to the OpenFGA list users endpoint that returns all users of a given type that have a specified relationship with an object.Examples and details
Examples and details
List users requests are completed using the relevant
ListUsers method in SDKs, the fga query list-users command in the CLI, or by manually calling the ListUsers endpoint using curl or in your code.The list users endpoint responds with a list of users for a given type that have the specificed relationship with an object.For example, the following returns all the users of type user that have the viewer relationship for document:planning:For more information, see the ListUsers API Reference.What Are Contextual Tuples?
Contextual tuples are tuples that can be added to a Check request, a ListObjects request, a ListUsers request, or an Expand request. They only exist within the context of that particular request and are not persisted in the datastore.Examples and details
Examples and details
Similar to relationship tuples, contextual tuples are composed of a user, relation and object. Unlike relationship tuples, they are not written to the store. However, if contextual tuples are sent alongside a check request in the context of a particular check request, they are treated if they had been written in the store.For more information, see Contextual and Time-Based Authorization, Authorization Through Organization Context and Check API Request Documentation.
What Is Type Bound Public Access?
In OpenFGA, type bound public access (represented by<type>:*) is a special OpenFGA syntax meaning “every object of [type]” when invoked as a user within a relationship tuple. For example, user:* represents every object of type user , including those not currently present in the system.
Examples and details
Examples and details
For example, to indicate Note:
document:new-roadmap is publicly writable (in other words, has everyone of type user as an editor, add the following relationship tuple:<type>:* cannot be used in the relation or object properties. In addition, <type>:* cannot be used as part of a userset in the tuple’s user field. For more information, see Modeling Public Access and Advanced Modeling: Modeling Google Drive.Related Sections
Check the following sections for more on how object-to-object relationships can be used.Authorization Concepts
Learn about Authorization.
Configuration Language
Learning about the FGA configuration language
Direct access
Get started with modeling your permission system in OpenFGA