overview
What is Authorizer?
Authorizer is an open-source authentication and authorization tool developed by Authorizer that enables developers and teams to manage user data in their own database. It provides a comprehensive suite of authentication and authorization functionalities, acting as an enforcement decision point for access control.
Authorizer allows developers to integrate robust authentication and fine-grained authorization without building it from scratch, maintaining full control over user data by connecting to existing databases. It supports various authentication methods, including email/password, social logins (Google, GitHub, Facebook, LinkedIn, Apple, Discord, Twitter, Twitch, Roblox, Microsoft), passwordless login with magic links, and WebAuthn/passkey registration. Multi-factor authentication (TOTP, email OTP, SMS OTP via Twilio, and passkey as a second factor) is also supported. For authorization, it offers role-based access management and fine-grained authorization (FGA) through an embedded OpenFGA (Zanzibar ReBAC) engine. Enterprise SSO capabilities include SAML 2.0 (as Service Provider and Identity Provider), OIDC federation, SCIM 2.0 provisioning, verified email domains, and home-realm discovery. Machine-to-machine authentication is facilitated via client_credentials flow, secretless workload identity (RFC 7523 client assertions), SPIFFE JWT-SVIDs, and Kubernetes TokenReview. A notable feature is its integration with AI assistants via a built-in Model Context Protocol (MCP) server, enabling permission-aware AI agents to check user permissions before data retrieval, thus supporting secure Retrieval Augmented Generation (RAG) systems. Multi-tenancy is supported with organizations, org-scoped admins, and verified email domains.
