Skip to main content
This section will illustrate how to integrate OpenFGA within a framework, such as Fastify or Fiber.

Before you start

  1. Deploy an instance of the OpenFGA server, and have ready the values for your setup: FGA_STORE_ID, FGA_API_URL and, if needed, FGA_API_TOKEN.
  2. You have installed the OpenFGA SDK.
  3. You have configured the authorization model and updated the relationship tuples.
  4. You know how to perform a Check.
  5. You have loaded FGA_API_URL and FGA_STORE_ID as environment variables.

Step by step

Assume that you want to have a web service for documents using one of the frameworks mentioned above. The service will authenticate users via JWT tokens, which contain the user ID.
The reader should set up their own login method based on their OpenID connect provider’s documentation.
Assume that you want to provide a route GET /read/{document} to return documents depending on whether the authenticated user has access to it.

01. Install and setup framework

The first step is to install the framework.
For the context of this example, we will use the Fastify framework. For that we need to install the following packages:
  • the fastify package that provides the framework itself
  • the fastify-plugin package that allows integrating plugins with Fastify
  • the fastify-jwt package for processing JWT tokens
Using npm:
Using yarn:
Next, we setup the web service with the GET /read/{document} route in file app.js.

02. Authenticate and get user ID

Before we can call OpenFGA to protect the /read/{document} route, we need to validate the user’s JWT.
The fastify-jwt package allows validation of JWT tokens, as well as providing access to the user’s identity.In jwt-authenticate.js:
Then, use the preValidation hook of a route to protect it and access the user information inside the JWT:In route-read.js:
Finally, update app.js to register the newly added hooks.

03. Integrate the OpenFGA check API into the service

First, we will create a decorator preauthorize to parse the incoming HTTP method as well as name of the document, and set the appropriate relation and object that we will call Check on.In preauthorize.js:
Next, we will create a decorator called authorize. This decorator will invoke the Check API to see if the user has a relationship with the specified document.In authorize.js:
We can now update the GET /read/{document} route to check for user permissions.In route-read.js:
Finally, we will register the new hooks in app.js:
Take a look at the following sections for examples that you can try when integrating with SDK.

Entitlements

Modeling Entitlements for a System in OpenFGA.

IoT

Modeling Fine-Grained Authorization for an IoT Security Camera System with OpenFGA.

Slack

Modeling Authorization for Slack with OpenFGA.
Last modified on September 28, 2026