cedarpy
Decision gist · record as of 2026-08-14
Yes, if you need Cedar's policy language and evaluation engine in Python. The package is actively maintained, has no known vulnerabilities, covers modern Python versions and common platforms with pre-built wheels, and offers both single-request and batch authorization with performance optimizations for static policies. License treatment is unclear, so verify licensing terms before use in commercial projects.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.9 or later; pre-built wheels available for Linux, macOS, and Windows on common architectures.
- Medium install friction due to platform-specific wheels (compiled Rust bindings), but pre-built wheels cover Linux x86_64/aarch64, macOS x86_64/arm64, and Windows x86_64 for Python 3.10–3.14.
- Active maintenance with a release 35 days ago.
License · maintenance · safety
(unclear)
last release 2026-07-10 (35 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 669,604 downloads/mo, #5,412 on PyPI
Alternatives
Verify before relying
pip install cedarpy
from cedarpy import is_authorized, Decision
policies = "permit(principal, action, resource);"
entities = [{"uid": {"__entity": {"type": "User", "id": "alice"}}, "attrs": {}, "parents": []}]
request = {"principal": 'User::"alice"', "action": 'Action::"read"', "resource": 'Photo::"1"', "context": {}}
result = is_authorized(request, policies, entities)
if result.decision == Decision.Allow:
print("Access granted")- Whether the package is officially supported by AWS or the Cedar Policy team (description states it is not, but maintainer affiliation is unclear)
- Exact performance characteristics of batch authorization relative to single-request calls in real-world scenarios
What it is and what it does
cedarpy is a Python wrapper around the Cedar Policy authorization engine, a Rust-based policy evaluator developed by AWS. It lets you define fine-grained access-control policies in Cedar's domain-specific language, then evaluate authorization requests against those policies and a schema from Python. The package supports three main workflows: checking whether a single request is authorized, validating policies against a schema, and formatting policies.
The library is designed for performance in long-running services and serverless functions. It offers batch authorization (evaluating many requests against shared policies in one call, often 10x faster than individual calls), reusable PolicySet handles to avoid re-parsing static policies on every request, and optional per-request policy fragments layered on top of a static base. It has no runtime dependencies and is available as pre-built wheels for modern Python versions and common platforms.
Use it for
- Enforce fine-grained access control in a web service by evaluating Cedar policies against incoming requests before granting access to resources.
- Batch-authorize a set of user actions in a single call to avoid the overhead of parsing policies and entities repeatedly.
- Validate a policy file against a schema at deployment time to catch syntax and type errors before policies go live.
- Reuse a static policy set across many authorization requests in a long-running service or Lambda function, avoiding repeated parsing.
- Add dynamic per-request policies to a static base policy set without re-parsing the entire base each time.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need Cedar's policy language and evaluation engine in Python.
The package is actively maintained, has no known vulnerabilities, covers modern Python versions and common platforms with pre-built wheels, and offers both single-request and batch authorization with performance optimizations for static policies. License treatment is unclear, so verify licensing terms before use in commercial projects.
Install
cedarpy on PyPI
Before you install
Medium install friction due to platform-specific wheels (compiled Rust bindings), but pre-built wheels cover Linux x86_64/aarch64, macOS x86_64/arm64, and Windows x86_64 for Python 3.10–3.14. Active maintenance with a release 35 days ago.
Requires Python 3.9 or later; pre-built wheels available for Linux, macOS, and Windows on common architectures.
Quickstart
pip install cedarpy
from cedarpy import is_authorized, Decision
policies = "permit(principal, action, resource);"
entities = [{"uid": {"__entity": {"type": "User", "id": "alice"}}, "attrs": {}, "parents": []}]
request = {"principal": 'User::"alice"', "action": 'Action::"read"', "resource": 'Photo::"1"', "context": {}}
result = is_authorized(request, policies, entities)
if result.decision == Decision.Allow:
print("Access granted")
Verify before relying
- Whether the package is officially supported by AWS or the Cedar Policy team (description states it is not, but maintainer affiliation is unclear)
- Exact performance characteristics of batch authorization relative to single-request calls in real-world scenarios
Package facts
| License | Not declared unclear |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Medium. Platform-specific wheel |
| Runtime dependencies | None |
| Maintenance | Actively maintained 35 days since the last release |
| First released | |
| Downloads | 669,604 / month, #5,412 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPyProgramming Language :: Rust |
Evidence: cedarpy-4.8.7-cp310-cp310-manylinux_2_17_aarch64.manylinux2014_aarch64.whl; cedarpy-4.8.7-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl; cedarpy-4.8.7-cp310-cp310-win_amd64.whl; cedarpy-4.8.7-cp311-cp311-macosx_10_12_x86_64.whl; cedarpy-4.8.7-cp311-cp311-macosx_11_0_arm64.whl; cedarpy-4.8.7-cp311-cp311-manylinux_2_17_aarch64.manylinux2014_aarch64.whl; cedarpy-4.8.7-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl; cedarpy-4.8.7-cp311-cp311-win_amd64.whl; cedarpy-4.8.7-cp312-cp312-macosx_10_12_x86_64.whl; cedarpy-4.8.7-cp312-cp312-macosx_11_0_arm64.whl; cedarpy-4.8.7-cp312-cp312-manylinux_2_17_aarch64.manylinux2014_aarch64.whl; cedarpy-4.8.7-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl; cedarpy-4.8.7-cp312-cp312-win_amd64.whl; cedarpy-4.8.7-cp313-cp313-macosx_10_12_x86_64.whl; cedarpy-4.8.7-cp313-cp313-macosx_11_0_arm64.whl; cedarpy-4.8.7-cp313-cp313-manylinux_2_17_aarch64.manylinux2014_aarch64.whl; cedarpy-4.8.7-cp313-cp313-manylinux_2_17_x86_64.manylinux2014_x86_64.whl; cedarpy-4.8.7-cp313-cp313-win_amd64.whl; cedarpy-4.8.7-cp314-cp314-macosx_10_12_x86_64.whl; cedarpy-4.8.7-cp314-cp314-macosx_11_0_arm64.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “cedar policy authorization python”
- cedarpycedarpy binds the Cedar Policy authorization engine to Python,…
- cerbosPython client library for querying and managing authorization…
- casbinCasbin enforces access control policies (ACL, RBAC, ABAC) by…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also zope.security · casbin · oslo.policy · policy-sentry · drf-access-policy · awacs · pycasbin · biscuit-python · casbin-async-sqlalchemy-adapter · cerbos