Cerbos Ecosystem: Integrations, SDKs and Deployment Options | Cerbos
🔐 New: A CISO’s benchmark for authorization maturity ➔ Download the ebook
Authorize in any language, any framework, any identity
Seamlessly integrate Cerbos into your existing ecosystem.
AllIdentity providersFrameworksSDKsData filteringAIDeploymentContext sourcesAuthorization extensionsAPI gatewaysCI/CD
\ \ Agent2Agent ProtocolPolicy-driven authorization for inter-agent communication via the Agent2Agent protocol\ \ AI](/content/ecosystem/a2a/index.html) \ \ Agent GatewayPolicy-driven authorization for MCP, A2A, and LLM traffic through Agent Gateway\ \ AI](/content/ecosystem/agent-gateway/index.html) \ \ Amazon EC2Standalone binary or container PDP on EC2 with full instance control\ \ Deployment](/content/ecosystem/amazon-ec2/index.html) \ \ Amazon Elastic Container ServiceStateless PDP container running as an ECS task or Fargate sidecar\ \ Deployment](/content/ecosystem/amazon-ecs/index.html) \ \ Amazon Elastic Kubernetes ServiceHelm-managed Cerbos on EKS with IRSA and Fargate support\ \ Deployment](/content/ecosystem/amazon-eks/index.html) \ \ Amazon Elastic BeanstalkMulti-container Cerbos sidecar that auto-scales with Beanstalk instances\ \ Deployment](/content/ecosystem/amazon-elastic-beanstalk/index.html) \ \ AWS LambdaEmbedded in-process PDP for serverless authorization with no network hop\ \ Deployment](/content/ecosystem/amazon-lambda/index.html) \ \ Aperture by TailscaleZero Trust authorization for AI agents routed through Aperture by Tailscale\ \ AI](/content/ecosystem/aperture-by-tailscale/index.html) \ \ ASP.NETAuthorize ASP.NET controllers and endpoints via the Cerbos .NET SDK\ \ Frameworks](/content/ecosystem/aspnet/index.html) \ \ Azure Kubernetes ServiceCerbos on AKS with workload identity and Helm-based lifecycle management\ \ Deployment](/content/ecosystem/azure-aks/index.html) \ \ Azure Container AppsManaged container PDP on Azure Container Apps with scaling and revision control\ \ Deployment](/content/ecosystem/azure-container-apps/index.html) \ \ Azure Virtual MachineBinary or container PDP on Azure VMs with Scale Set auto-scaling\ \ Deployment](/content/ecosystem/azure-virtual-machine/index.html) \ \ ApigeeCerbos policy checks via Apigee service callout policies on API proxy requests\ \ API gateways](/content/ecosystem/cerbos-apigee/index.html) \ \ Auth0Map Auth0 Actions, Organizations, and roles to Cerbos policy inputs\ \ Identity providers](/content/ecosystem/cerbos-auth0/index.html) \ \ AuthentikAuthentik property mappings shape token claims for Cerbos policy inputs\ \ Identity providers](/content/ecosystem/cerbos-authentik/index.html) \ \ AWS API GatewayLambda authorizer that evaluates Cerbos policies for API Gateway\ \ API gateways](/content/ecosystem/cerbos-aws-api-gateway/index.html) \ \ AWS App MeshCerbos authorization via Envoy ext_authz within AWS App Mesh sidecars\ \ Authorization extensions](/content/ecosystem/cerbos-aws-app-mesh/index.html) \ \ AWS CognitoCognito user pool groups and custom attributes as Cerbos policy inputs\ \ Identity providers](/content/ecosystem/cerbos-aws-cognito/index.html) \ \ Azure API ManagementCerbos policy evaluation via Azure API Management inbound policies on each request\ \ API gateways](/content/ecosystem/cerbos-azure-api-management/index.html) \ \ Azure DevOps PipelinesPush Cerbos policies to Cerbos Hub on every merge via Azure DevOps Pipelines\ \ CI/CD](/content/ecosystem/cerbos-azure-devops/index.html) \ \ Bitbucket PipelinesPush Cerbos policies to Cerbos Hub on every merge via Bitbucket Pipelines\ \ CI/CD](/content/ecosystem/cerbos-bitbucket-pipelines/index.html) \ \ BuildkitePush Cerbos policies to Cerbos Hub on every merge via Buildkite\ \ CI/CD](/content/ecosystem/cerbos-buildkite/index.html) \ \ CircleCIPush Cerbos policies to Cerbos Hub on every merge via CircleCI\ \ CI/CD](/content/ecosystem/cerbos-circleci/index.html) \ \ ClerkClerk session claims and Organizations drive Cerbos policy evaluation\ \ Identity providers](/content/ecosystem/cerbos-clerk/index.html) \ \ CloudflareCerbos policy checks within Cloudflare Workers at the network edge\ \ API gateways](/content/ecosystem/cerbos-cloudflare/index.html) \ \ AWS CognitoPull Cognito custom attributes and groups into the PDP at decision time\ \ Context sources](/content/ecosystem/cerbos-cognito-enrichment/index.html) \ \ Consul ConnectCerbos authorization via Envoy ext_authz within Consul Connect sidecars\ \ Authorization extensions](/content/ecosystem/cerbos-consul-connect/index.html) \ \ ContourCerbos authorization via Envoy ext_authz at the Contour ingress controller\ \ Authorization extensionsAPI gateways](/content/ecosystem/cerbos-contour/index.html) \ \ Curity Identity ServerCurity token procedure claims as principal attributes in Cerbos\ \ Identity providers](/content/ecosystem/cerbos-curity/index.html) \ \ Data Source ExtensionsReusable data connectors with built-in caching for the Cerbos authorization pipeline\ \ Context sources](/content/ecosystem/cerbos-data-source-extensions/index.html) \ \ DescopeDescope JWT claims, tenant data, and role assignments feed into Cerbos policy evaluation\ \ Identity providers](/content/ecosystem/cerbos-descope/index.html) \ \ Duende IdentityServerDuende IdentityServer claims and scopes evaluated by Cerbos in .NET apps\ \ Identity providers](/content/ecosystem/cerbos-duende/index.html) \ \ Emissary-Ingress (Ambassador)Cerbos authorization via Envoy ext_authz at the Emissary-Ingress API gateway\ \ Authorization extensionsAPI gateways](/content/ecosystem/cerbos-emissary-ingress/index.html) \ \ EmpowerIDEmpowerID governance roles and delegated access in Cerbos policies\ \ Identity providers](/content/ecosystem/cerbos-empowerid/index.html) \ \ Microsoft Entra IDResolve Entra ID security groups and directory roles for policy evaluation\ \ Context sources](/content/ecosystem/cerbos-entra-enrichment/index.html) \ \ Envoy External AuthorizationCerbos as a native ext_authz gRPC service for Envoy proxies\ \ Authorization extensionsAPI gateways](/content/ecosystem/cerbos-envoy/index.html) \ \ External APICall external services to fetch context data for policy evaluation\ \ Context sources](/content/ecosystem/cerbos-external-api/index.html) \ \ FirebaseFirebase custom claims feed into Cerbos for resource-level decisions\ \ Identity providers](/content/ecosystem/cerbos-firebase/index.html) \ \ FusionAuthFusionAuth per-application roles and custom data fields in Cerbos policies\ \ Identity providers](/content/ecosystem/cerbos-fusionauth/index.html) \ \ GitHub ActionsPush Cerbos policies to Cerbos Hub on every merge via GitHub Actions\ \ CI/CD](/content/ecosystem/cerbos-github-actions/index.html) \ \ GitLab CI/CDPush Cerbos policies to Cerbos Hub on every merge via GitLab CI/CD\ \ CI/CD](/content/ecosystem/cerbos-gitlab-runners/index.html) \ \ Gloo GatewayCerbos authorization via Envoy ext_authz at the Gloo Gateway edge\ \ Authorization extensionsAPI gateways](/content/ecosystem/cerbos-gloo-gateway/index.html) \ \ Gluu ServerGluu LDAP-backed groups and OIDC claims evaluated by Cerbos policies\ \ Identity providers](/content/ecosystem/cerbos-gluu/index.html) \ \ Google Identity PlatformGoogle Identity Platform custom claims and tenant context feed into Cerbos policy evaluation\ \ Identity providers](/content/ecosystem/cerbos-google-identity-platform/index.html) \ \ Gravitee API GatewayEvaluate Cerbos policies on every request at the Gravitee API Gateway edge\ \ API gateways](/content/ecosystem/cerbos-gravitee/index.html) \ \ Istio Service MeshExternal authorizer for service-to-service calls in Istio meshes\ \ Authorization extensions](/content/ecosystem/cerbos-istio/index.html) \ \ JumpCloudJumpCloud directory groups and OIDC claims drive Cerbos policy evaluation\ \ Identity providers](/content/ecosystem/cerbos-jumpcloud/index.html) \ \ JSON Web TokensCerbos natively decodes JWTs and maps claims to policy attributes\ \ Identity providers](/content/ecosystem/cerbos-jwt/index.html) \ \ Kubernetes Admission ControlValidating webhook that enforces Cerbos policies on cluster resources\ \ Authorization extensions](/content/ecosystem/cerbos-k8s-admission/index.html) \ \ Apache KafkaPluggable authorizer for Kafka topic, consumer group, and cluster ops\ \ Authorization extensionsData filtering](/content/ecosystem/cerbos-kafka/index.html) \ \ KeycloakPull realm roles, client roles, and group paths from Keycloak into policies\ \ Context sources](/content/ecosystem/cerbos-keycloak-enrichment/index.html) \ \ KeycloakKeycloak realm roles, client roles, and group hierarchies in Cerbos policies\ \ Identity providers](/content/ecosystem/cerbos-keycloak/index.html) \ \ KindeKinde organizations and feature flags as inputs to Cerbos policies\ \ Identity providers](/content/ecosystem/cerbos-kinde/index.html) \ \ Kong GatewayEvaluate Cerbos policies on every request at the Kong gateway edge\ \ API gateways](/content/ecosystem/cerbos-kong/index.html) \ \ Broadcom Layer7 API GatewayCerbos policy enforcement at the Broadcom Layer7 gateway edge\ \ API gateways](/content/ecosystem/cerbos-layer7/index.html) \ \ LDAPQuery any LDAPv3 directory for user attributes and group memberships\ \ Context sourcesIdentity providers](/content/ecosystem/cerbos-ldap-enrichment/index.html) \ \ LDAPLDAP group DNs and organizational units as Cerbos principal attributes\ \ Identity providers](/content/ecosystem/cerbos-ldap/index.html) \ \ LitestreamRead Litestream-replicated SQLite databases as a policy data source\ \ Context sources](/content/ecosystem/cerbos-litestream/index.html) \ \ MagicMagic DID tokens and wallet addresses as Cerbos principal attributes\ \ Identity providers](/content/ecosystem/cerbos-magic/index.html) \ \ Microsoft Entra IDEntra ID security groups and app roles evaluated by Cerbos policies\ \ Identity providers](/content/ecosystem/cerbos-microsoft-entra-id/index.html) \ \ MongooseApply Cerbos query plans as MongoDB filter predicates via Mongoose\ \ Data filtering](/content/ecosystem/cerbos-mongoose/index.html) \ \ MySQLBuilt-in data source that queries MySQL tables at decision time\ \ Context sources](/content/ecosystem/cerbos-mysql/index.html) \ \ Neo4jTraverse Neo4j relationship graphs to resolve authorization context\ \ Context sources](/content/ecosystem/cerbos-neo4j/index.html) \ \ NGINXCerbos policy checks via the NGINX auth_request module at the reverse proxy edge\ \ API gateways](/content/ecosystem/cerbos-nginx/index.html) \ \ OktaFetch Okta profiles and group memberships into policy evaluations\ \ Context sources](/content/ecosystem/cerbos-okta-enrichment/index.html) \ \ OktaOkta groups and Universal Directory attributes as Cerbos policy inputs\ \ Identity providers](/content/ecosystem/cerbos-okta/index.html) \ \ OneLoginOneLogin roles and group memberships from OIDC tokens drive Cerbos policy evaluation\ \ Identity providers](/content/ecosystem/cerbos-onelogin/index.html) \ \ OryOry Kratos identity traits from JSON schemas feed Cerbos policies\ \ Identity providers](/content/ecosystem/cerbos-ory/index.html) \ \ Ping IdentityPingOne populations and PingFederate attributes in Cerbos policies\ \ Identity providers](/content/ecosystem/cerbos-ping-identity/index.html) \ \ PostgreSQLBuilt-in data source that queries PostgreSQL at decision time\ \ Context sources](/content/ecosystem/cerbos-postgresql/index.html) \ \ PrismaInject Cerbos query plans as Prisma where-clause filters on any model\ \ Data filtering](/content/ecosystem/cerbos-prisma/index.html) \ \ Proxy ExtensionsTransparent request enrichment that fetches context from external systems before policy evaluation\ \ Context sources](/content/ecosystem/cerbos-proxy-extensions/index.html) \ \ Route ExtensionsProtocol translation layer that lets any infrastructure component delegate authorization to Cerbos\ \ Authorization extensions](/content/ecosystem/cerbos-route-extensions/index.html) \ \ SecureAuthSecureAuth risk signals and identity attributes in Cerbos policy checks\ \ Identity providers](/content/ecosystem/cerbos-secureauth/index.html) \ \ SQLAlchemyAppend Cerbos query plans to SQLAlchemy select statements as filters\ \ Data filtering](/content/ecosystem/cerbos-sqlalchemy/index.html) \ \ SQLiteEmbedded SQLite data source for local policy context lookups\ \ Context sources](/content/ecosystem/cerbos-sqlite/index.html) \ \ StytchStytch B2B organization memberships and roles in Cerbos policy checks\ \ Identity providers](/content/ecosystem/cerbos-stytch/index.html) \ \ SupabaseSupabase app_metadata and JWT claims as policy inputs alongside RLS\ \ Identity providers](/content/ecosystem/cerbos-supabase/index.html) \ \ SuperTokensSelf-hosted authorization using SuperTokens session claims in Cerbos\ \ Identity providers](/content/ecosystem/cerbos-supertokens/index.html) \ \ Thales IdentityThales SafeNet identity attributes drive resource-level Cerbos policies\ \ Identity providers](/content/ecosystem/cerbos-thales/index.html) \ \ Traefik ProxyCerbos policy evaluation via Traefik's ForwardAuth middleware on each request\ \ API gateways](/content/ecosystem/cerbos-traefik/index.html) \ \ Apache TrinoCatalog, schema, and column-level access control via Apache Trino's authorization hook\ \ Authorization extensions](/content/ecosystem/cerbos-trino/index.html) \ \ Tyk GatewayCerbos policy evaluation as a Tyk gateway middleware plugin\ \ API gateways](/content/ecosystem/cerbos-tyk/index.html) \ \ WorkOSWorkOS Directory Sync groups and Organizations in Cerbos B2B policies\ \ Identity providers](/content/ecosystem/cerbos-workos/index.html) \ \ WSO2 API ManagerAttach Cerbos policy checks to WSO2 API Manager request flows\ \ API gateways](/content/ecosystem/cerbos-wso2/index.html) \ \ ZitadelZitadel project roles and organization grants as Cerbos policy inputs\ \ Identity providers](/content/ecosystem/cerbos-zitadel/index.html) \ \ Zuplo API GatewayInline Cerbos authorization checks within Zuplo request pipelines\ \ API gateways](/content/ecosystem/cerbos-zuplo/index.html) \ \ ChromaDBTranslate Cerbos query plans into ChromaDB metadata filters\ \ Data filteringAI](/content/ecosystem/chromadb/index.html) \ \ Claude Agent SDKGate Claude agent tool calls and data access through Cerbos policies\ \ AI](/content/ecosystem/claude-agent-sdk/index.html) \ \ Claude CodeCentralized policy enforcement and audit logging for Claude Code agent tool calls\ \ AI](/content/ecosystem/claude-code/index.html) \ \ Cloudflare WorkersServerless authorization at the network edge via Cerbos inside Cloudflare Workers\ \ Deployment](/content/ecosystem/cloudflare-workers/index.html) \ \ ConvexConvert Cerbos query plans into native Convex filter expressions\ \ Data filtering](/content/ecosystem/convex/index.html) \ \ CrewAIPer-agent and per-tool authorization for CrewAI multi-agent workflows through Cerbos policies\ \ AI](/content/ecosystem/crewai/index.html) \ \ DigitalOceanContainer or binary PDP on DigitalOcean App Platform, Droplets, or Managed Kubernetes\ \ Deployment](/content/ecosystem/digitalocean/index.html) \ \ DjangoAuthorize Django views and middleware via the Cerbos Python SDK\ \ Frameworks](/content/ecosystem/django/index.html) \ \ DockerOfficial multi-arch container image for local dev and production\ \ Deployment](/content/ecosystem/docker/index.html) \ \ .NETNuGet package with async/await and strongly typed Cerbos models\ \ SDKs](/content/ecosystem/dotnet/index.html) \ \ Drizzle ORMMap Cerbos query plans to Drizzle ORM where-clause conditions\ \ Data filtering](/content/ecosystem/drizzle/index.html) \ \ ElasticsearchEmit Cerbos query plans as Elasticsearch bool query filters\ \ Data filtering](/content/ecosystem/elasticsearch/index.html) \ \ ExpressEnforce access control per route via Express middleware hooks\ \ Frameworks](/content/ecosystem/express/index.html) \ \ FastAPIInject Cerbos checks as FastAPI dependencies in endpoint signatures\ \ Frameworks](/content/ecosystem/fastapi/index.html) \ \ FastMCPDrop-in Cerbos middleware for FastMCP tool and resource authorization\ \ AI](/content/ecosystem/fastmcp/index.html) \ \ FlaskAuthorize Flask routes via decorators or before-request hooks with Cerbos\ \ Frameworks](/content/ecosystem/flask/index.html) \ \ Fly.ioStateless PDP instances placed close to users across Fly.io regions\ \ Deployment](/content/ecosystem/fly-io/index.html) \ \ GinCerbos authorization wired into the Gin middleware chain\ \ Frameworks](/content/ecosystem/gin/index.html) \ \ GogRPC-native SDK with strongly typed checks and context.Context support\ \ SDKs](/content/ecosystem/go/index.html) \ \ Google Agent Development KitGate Google ADK agent tool calls and data access through Cerbos policies\ \ AI](/content/ecosystem/google-adk/index.html) \ \ Google Cloud Compute EngineCerbos binary or container on Compute Engine with Managed Instance Groups\ \ Deployment](/content/ecosystem/google-cloud-compute/index.html) \ \ Google Kubernetes EngineHelm-managed Cerbos on GKE with Workload Identity and Autopilot support\ \ Deployment](/content/ecosystem/google-cloud-gke/index.html) \ \ Google Cloud RunServerless container PDP on Cloud Run with automatic scaling and managed infrastructure\ \ Deployment](/content/ecosystem/google-cloud-run/index.html) \ \ GorillaCerbos authorization wired into the Gorilla Mux middleware chain\ \ Frameworks](/content/ecosystem/gorilla/index.html) \ \ GraphQLPer-field and per-resolver access control for GraphQL schemas\ \ Frameworks](/content/ecosystem/graphql/index.html) \ \ HelmOfficial Helm chart with production-ready defaults for the Cerbos PDP\ \ Deployment](/content/ecosystem/helm/index.html) \ \ HomebrewOne-command install of the Cerbos binary on macOS or Linux\ \ Deployment](/content/ecosystem/homebrew/index.html) \ \ HonoAuthorize Hono routes and middleware via the Cerbos JavaScript SDK\ \ Frameworks](/content/ecosystem/hono/index.html) \ \ JavaMaven Central SDK with blocking and CompletableFuture Cerbos clients\ \ SDKs](/content/ecosystem/java/index.html) \ \ JavaScriptAsync SDK for Node.js, edge runtimes, and browsers with TypeScript types\ \ SDKs](/content/ecosystem/javascript/index.html) \ \ KubernetesRun the PDP as a Deployment, DaemonSet, or sidecar in any K8s cluster\ \ Deployment](/content/ecosystem/kubernetes/index.html) \ \ LangChainGate LangChain and LangGraph tool calls through Cerbos policies\ \ AI](/content/ecosystem/langchain/index.html) \ \ LangGraphPer-node and per-tool authorization for LangGraph multi-step agent workflows\ \ AI](/content/ecosystem/langgraph/index.html) \ \ LaravelCerbos policies behind Laravel Gate::allows() and @can directives\ \ SDKs](/content/ecosystem/laravel/index.html) \ \ LlamaIndexEnforce authorization on LlamaIndex agent tool calls and data connector access through Cerbos policies\ \ AI](/content/ecosystem/llamaindex/index.html) \ \ Model Context ProtocolPer-tool and per-resource authorization for Model Context Protocol servers\ \ AI](/content/ecosystem/mcp/index.html) \ \ NestJSCerbos checks via NestJS guards, decorators, and injectable modules\ \ Frameworks](/content/ecosystem/nestjs/index.html) \ \ NextJSAuthorize middleware, server components, and API routes in Next.js\ \ Frameworks](/content/ecosystem/nextjs/index.html) \ \ HashiCorp NomadContainer PDP orchestrated by Nomad with Consul service discovery and health checks\ \ Deployment](/content/ecosystem/nomad/index.html) \ \ NuxtAccess control in the Nitro server layer for Nuxt routes and APIs\ \ Frameworks](/content/ecosystem/nuxt/index.html) \ \ OpenAI Agents SDKGate OpenAI Agents SDK tool invocations through Cerbos policy evaluation\ \ AI](/content/ecosystem/openai-agents-sdk/index.html) \ \ PHPPSR-compatible Composer package for Cerbos authorization in PHP\ \ SDKs](/content/ecosystem/php/index.html) \ \ Pythonpip-installable SDK for sync and async Cerbos authorization in Python\ \ SDKs](/content/ecosystem/python/index.html) \ \ PineconeCerbos policy decisions as Pinecone metadata filters in LangGraph RAG\ \ AIData filtering](/content/ecosystem/rag-pinecone/index.html) \ \ RAG (Retrieval-Augmented Generation)Enforce document-level access control on vector store retrieval\ \ AIData filtering](/content/ecosystem/rag/index.html) \ \ Ruby on RailsAuthorize Rails controllers and actions via the Cerbos Ruby SDK\ \ Frameworks](/content/ecosystem/rails/index.html) \ \ RailwayContainer PDP deployed to Railway with managed networking and automatic restarts\ \ Deployment](/content/ecosystem/railway/index.html) \ \ React RouterGate data loading and mutations in React Router loaders and actions\ \ Frameworks](/content/ecosystem/react-router/index.html) \ \ RenderContainer PDP running as a Render web service with managed TLS and health checks\ \ Deployment](/content/ecosystem/render/index.html) \ \ RubyIdiomatic Ruby gem for authorization checks against the Cerbos PDP\ \ SDKs](/content/ecosystem/ruby/index.html) \ \ RustAsync, type-safe Cerbos client built on tonic and tokio\ \ SDKs](/content/ecosystem/rust/index.html) \ \ Semantic KernelGate Semantic Kernel plugin and function invocations through Cerbos policy evaluation\ \ AI](/content/ecosystem/semantic-kernel/index.html) \ \ SPIFFESPIFFE IDs authorize service-to-service calls through Cerbos policies\ \ Identity providers](/content/ecosystem/spiffe/index.html) \ \ Spring BootWire Cerbos into Spring Boot with annotations and bean injection\ \ Frameworks](/content/ecosystem/spring-boot/index.html) \ \ Spring Data JPATurn Cerbos query plans into JPA Specification predicates for Spring\ \ Data filtering](/content/ecosystem/spring-data-jpa/index.html) \ \ SvelteKitAuthorize load functions, form actions, and hooks in SvelteKit\ \ Frameworks](/content/ecosystem/sveltekit/index.html) \ \ SystemdNative binary managed by systemd with journal logging and auto-restarts\ \ Deployment](/content/ecosystem/systemd/index.html) \ \ UCAST (Universal Conditions AST)Bridge Cerbos query plans to any data layer via the UCAST AST format\ \ Data filtering](/content/ecosystem/ucast/index.html) \ \ Vercel AI SDKGate AI tool invocations in Vercel AI SDK applications through Cerbos policy evaluation\ \ AI](/content/ecosystem/vercel-ai-sdk/index.html) \ \ VueJSServer-evaluated permissions surfaced to Vue.js route guards and views\ \ Frameworks](/content/ecosystem/vuejs/index.html)
Trusted by hundreds of companies