cerbos
SDK for working with Cerbos: an open core, language-agnostic, scalable authorization solution
Decision gist · record as of 2026-08-14
Yes, if you are already running a Cerbos authorization service or planning to adopt one. The SDK is actively maintained, has no known vulnerabilities, and low install friction. It is purpose-built for Cerbos integration and not a general-purpose authorization library—install it only when Cerbos is your chosen policy engine.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires a running Cerbos authorization service accessible at the specified host and port; Python 3.10 or later.
- Low friction install with a pure-Python wheel.
- Active maintenance with a release 1 day old.
License · maintenance · safety
Apache-2.0 (permissive) — Apache-2.0 permissive license allows commercial and private use with minimal restrictions; suitable for most projects.
last release 2026-08-13 (1 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 264,512 downloads/mo, #8,337 on PyPI
Alternatives
Verify before relying
pip install cerbos
from cerbos.sdk.grpc.client import CerbosClient
from cerbos.engine.v1 import engine_pb2
principal = engine_pb2.Principal(id="john", roles={"employee"})
resource = engine_pb2.Resource(id="XX125", kind="leave_request")
with CerbosClient("localhost:3593", tls_verify=False) as c:
if c.is_allowed("view", principal, resource):
print("Access allowed")- Performance characteristics and latency impact of gRPC vs HTTP client modes under typical load.
- Completeness of async API coverage relative to sync client.
- Admin API feature parity and stability guarantees.
What it is and what it does
Cerbos is a Python SDK that connects your application to a Cerbos authorization service—a separate, language-agnostic policy engine that evaluates access control decisions. Instead of embedding authorization logic in your code, you define context-aware policies in Cerbos and query them via this client. The SDK provides two transport options (gRPC recommended for new projects, HTTP for backwards compatibility), both with sync and async support, plus an Admin API for policy management.
The library handles the protocol details: it serializes principals (users with roles and attributes), resources (the objects being accessed), and actions into protobuf messages, sends them to the Cerbos service, and returns whether an action is allowed or a query plan for filtering resources. It also supports Cerbos Hub for managed policy storage, Unix domain sockets, TLS configuration, and custom gRPC channel options.
Use it for
- Check if a user can perform an action on a resource before executing application logic.
- Generate query plans to filter database results based on user permissions without fetching all records.
- Manage authorization policies centrally in Cerbos Hub and sync them via the Admin API.
- Build multi-tenant applications where permissions depend on department, geography, or team attributes.
- Implement async authorization checks in high-concurrency services using AsyncCerbosClient.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are already running a Cerbos authorization service or planning to adopt one.
The SDK is actively maintained, has no known vulnerabilities, and low install friction. It is purpose-built for Cerbos integration and not a general-purpose authorization library—install it only when Cerbos is your chosen policy engine.
Install
cerbos on PyPI
Before you install
Low friction install with a pure-Python wheel. Active maintenance with a release 1 day old. Requires Python 3.10 or later and 12 runtime dependencies including gRPC, protobuf, and HTTP tooling.
Requires a running Cerbos authorization service accessible at the specified host and port; Python 3.10 or later.
License in practice
Apache-2.0 permissive license allows commercial and private use with minimal restrictions; suitable for most projects.
Quickstart
pip install cerbos
from cerbos.sdk.grpc.client import CerbosClient
from cerbos.engine.v1 import engine_pb2
principal = engine_pb2.Principal(id="john", roles={"employee"})
resource = engine_pb2.Resource(id="XX125", kind="leave_request")
with CerbosClient("localhost:3593", tls_verify=False) as c:
if c.is_allowed("view", principal, resource):
print("Access allowed")
Verify before relying
- Performance characteristics and latency impact of gRPC vs HTTP client modes under typical load.
- Completeness of async API coverage relative to sync client.
- Admin API feature parity and stability guarantees.
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 12 packagesdataclasses-jsonrequests-toolbelthttpxanyiotenacitygrpcio-toolstypes-protobufprotoc-gen-openapiv2googleapis-common-protosprotobufgrpcio-statuscircuitbreaker |
| Maintenance | Actively maintained 1 days since the last release |
| First released | |
| Downloads | 264,512 / month, #8,337 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaIntended Audience :: DevelopersTopic :: SecurityTopic :: Software Development :: Libraries |
Evidence: cerbos-0.16.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “authorization policy client”
- cerbosPython client library for querying and managing authorization…
- oso-cloudOso Cloud client provides a Python wrapper for…
- cedarpycedarpy binds the Cedar Policy authorization engine to Python,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Libraries packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.
Install it if you're building an extensible application or framework.
Provides parsing, arithmetic, and recurrence rule computation for dates and times, with timezone support and iCalendar RFC compliance.
Install it if you need to parse flexible date strings, compute relative dates, handle timezones, or work with recurrence rules—it's the de facto choice for these tasks.
Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.
pytest is a testing framework that lets you write test functions using plain assert statements and automatically discovers and runs them, with detailed failure reporting.
See also authzed · cerbos-sqlalchemy · zope.security · oauth2-client · oslo.policy · invenio-records-permissions · cedarpy · grpclib · propelauth-py · grpcio-admin