Skip to main content
Every OpenFGA model should be tested before deployment to ensure your authorization model is correctly designed. The .fga.yaml contains tests for OpenFGA authorization models. If you are using Visual Studio Code as your IDE, install the OpenFGA extension to enable syntax coloring and validation. For complete details on the .fga.yaml store file format, see Store File Format.

Define the model and tuples

.fga.yaml files have the following top level items: The example below defines a model and tuples:

Write tests

Always write tests to verify that the calls your application will make return the results you expect. A good test covers scenarios that verify every relation. Tests have the following structure:

Write Check tests

Check tests verify the results of the check API calls to validate access requirements for a user. Each check verification has the following structure: The following example adds multiple check verifications in every test:

Write List Objects tests

A good test covers scenarios that specify every relation for every object type that your application will need to call the list-objects API for. The following verifies the expected results using the list_objects option in OpenFGA tests:
The example above checks that user:anne has access to the organization:acme as a member and is not an admin of any organization. It also checks that user:peter, given the current time is February 1st 2024, 0:10 AM, is not related to any organization as a member, but is related to organization:acme as an admin.

Write List Users tests

List users tests verify the results of the list-users API to validate the users who or do not have access to an object Each list users verification has the following structure: In order to simplify test writing, the following syntax is supported for the various object types included in users from the API response:
  • <type>:<id> to represent a userset that is a user
  • <type>:<id>#<relation> to represent a userset that is a relation on a type
  • <type>:* to represent a userset that is a type bound public access for a type
The following is an example of using the list_users option in OpenFGA tests:
The example above checks that the organization:acme, given the current time is February 2nd 2024, it has ‘user:anne’ as a member, nobody as an admin. If we tried with current time being February 1st 2024, then user:peter would be listed as an admin

Testing with Modular Models

If you are using Modular Models, you need to use the fga.mod as the model_file. You can define tests for each model in separate .fga.yaml files, all of which should reference the common fga.mod model. Shared relationship tuples can be placed in a separate file and included using the tuple_file option. If needed, you can split tuples across multiple shared files and include them with the tuple_files option. Additionally, each .fga.yaml file can include module-specific tuples inline.

Running tests

Tests are run using the model test CLI command. For instructions on installing the OpenFGA CLI, visit the OpenFGA CLI Github repository.
When all tests pass, a summary with the number of tests passed is displayed. When a test fails, a line for every test is displayed.

Running tests using GitHub Actions

Use the OpenFGA Model Testing Action to run tests from CI/CD flows in GitHub. Set the path to the .fga.yaml file as the store-file-path parameter when configuring the action:
Check the following sections for more on how to learn how to write tests.

Use the FGA CLI

Learn how to use the FGA CLI.

Super Admin Example

Define a model and tests for modeling a super-admin role.

Banking Example

Define a model and tests for banking application.

Entitlements Example

Define a model and tests for B2B application entitlements.
Last modified on September 28, 2026