Configuration
The CLI is configured to use a specific FGA server in one of three ways:- Using CLI flags.
- Using environment variables.
-
Using a
.fga.yamlconfiguration file, searched in the following order (highest to lowest priority):- Current working directory
-
User-specific config directory
- Unix:
$XDG_CONFIG_HOME(if set), otherwise$HOME/.config - Windows:
%AppData%
- Unix:
-
fgasubdirectory under the user config directory -
User’s home directory
- Unix:
$HOME - Windows:
%USERPROFILE%
- Unix:
If you use pre-shared key authentication, provide the following parameters which appends the pre-shared key in the HTTP request header:
If you use OIDC authentication, configure the following parameters based on the OIDC server that’s used to issue tokens:
A default store Id and authorization model Id can also be configured:
All of the examples in this document assume the CLI is properly configured and that the Store ID is set either in an environment variable or the
~/.fga.yaml file.
Basic operations
The CLI commands below show you how to create a store and run your application’s most common operations, including how to write a model and write/delete/read tuples, and run queries.Work with authorization model versions
OpenFGA models are immutable; each time a model is written to a store, a new version of the model is created. All OpenFGA API endpoints receive an optional authorization model ID that points to a specific version of the model and defaults to the latest model version. Always use a specific model ID and update it each time a new model version is used in production. The following CLI commands lists the model Ids and find the latest one:--model-id parameter or as part of the configuration.
Import tuples
To import tuples, use thefga tuple write command. It has the following parameters:
The CLI returns a detailed JSON response that includes:
successful: List of successfully written tuples (hidden when using--hide-imported-tuples)failed: List of tuples that failed to write, including the error reasontotal_count: Total number of tuples processed in this operationsuccessful_count: Number of tuples successfully writtenfailed_count: Number of tuples that failed to write
--hide-imported-tuples, the successful tuples are not included in the output, making it more practical when importing large datasets. Failed tuples are always shown to help identify and fix any issues. If you specify --max-tuples-per-write greater than one, an error in one of the tuples implies none of the tuples get written.
yaml
JSON
CSV
Delete Tuples
To delete a tuple, specify the user/relation/object you want to delete. To delete a group of tuples, specify a file that contains those tuples. Supported file formats arejson, yaml and csv.
Import stores
The CLI can import an FGA Test file in a store. It writes the model included and imports the tuples in the fga test file. Given the following.fga.yaml file:
fga model get command is used to verify that the model was correctly written, and the fga tuple read command is used to verify that the tuples were properly imported.
Related Sections
Check the following sections for more on how to learn how to write tests.Testing Models
Learn how to test FGA models using the FGA CLI.