django-prbac
Parameterized Role-Based Access Control for Django
Decision gist · record as of 2026-08-14
Yes, if you need parameterized role-based access control beyond what Django's built-in auth provides. The package is actively maintained, has low install friction, supports current Python and Django versions, and carries no known vulnerabilities. It is marked alpha but has been stable since 2013. The main caveat is that the license treatment is unclear in the metadata, so verify the actual license (described as MIT in the documentation) before use.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Django 4.2 or later and Python 3.9 or later; must be used within a Django project with a configured database.
- Low friction install with three straightforward runtime dependencies (django, jsonfield, simplejson).
- The package is actively maintained with recent commits and marked as alpha-stage, so it is suitable for production use but may see API changes.
License · maintenance · safety
(unclear)
last release 2025-09-24 (324 days) · last repo commit 2026-05-26 · 152 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 77,705 downloads/mo, #14,504 on PyPI
Alternatives
Verify before relying
pip install django-prbac
from django_prbac.models import Role, Privilege
# Define a role with parameters
role = Role.objects.create(name='Analyst')
privilege = Privilege.objects.create(name='Reporting', role=role)- Specific examples of how parameters are passed and evaluated in practice beyond the documentation excerpt.
- Whether the package provides decorators or middleware for enforcing access control in views.
- Performance characteristics when dealing with deeply nested roles or large numbers of parameterized privileges.
What it is and what it does
Django-prbac brings parameterized role-based access control to Django applications. Unlike Django's built-in permission system, which is tied to content types, PRBAC lets you define roles and privileges as abstract concepts and add parameters to them—so you can grant something like 'Reporting(organization="Dimagi", area="Finance")' to a specific role. This is more expressive than traditional RBAC because the parameters can be finite sets or infinite (strings, integers, etc.), making it exponentially or infinitely more powerful depending on how you use it.
The package depends on Django, jsonfield, and simplejson to store and manage these parameterized roles and privileges. It is actively maintained, supports modern Python versions (3.9–3.13) and recent Django releases (4.2 through 5.2), and has no known security vulnerabilities. The library is marked as alpha-stage but has been in development since 2013, so it is reasonably stable for production use.
Use it for
- Multi-tenant SaaS applications where different organizations need different access levels to the same features.
- Complex reporting systems where analysts need access to specific data subsets parameterized by region, department, or time period.
- Enterprise applications with hierarchical role structures where roles inherit privileges conditionally based on parameters.
- Systems requiring fine-grained object-level access control tied to role membership and parameter matching.
- Applications that need to audit and manage who has access to what without hardcoding permissions in code.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need parameterized role-based access control beyond what Django's built-in auth provides.
The package is actively maintained, has low install friction, supports current Python and Django versions, and carries no known vulnerabilities. It is marked alpha but has been stable since 2013. The main caveat is that the license treatment is unclear in the metadata, so verify the actual license (described as MIT in the documentation) before use.
Install
django-prbac on PyPI
Before you install
Low friction install with three straightforward runtime dependencies (django, jsonfield, simplejson). The package is actively maintained with recent commits and marked as alpha-stage, so it is suitable for production use but may see API changes.
Requires Django 4.2 or later and Python 3.9 or later; must be used within a Django project with a configured database.
Quickstart
pip install django-prbac
from django_prbac.models import Role, Privilege
# Define a role with parameters
role = Role.objects.create(name='Analyst')
privilege = Privilege.objects.create(name='Reporting', role=role)
Verify before relying
- Specific examples of how parameters are passed and evaluated in practice beyond the documentation excerpt.
- Whether the package provides decorators or middleware for enforcing access control in views.
- Performance characteristics when dealing with deeply nested roles or large numbers of parameterized privileges.
Package facts
| License | Not declared unclear |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 3 packagesdjangojsonfieldsimplejson |
| Maintenance | Actively maintained 324 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 77,705 / month, #14,504 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 3 - AlphaEnvironment :: Web EnvironmentFramework :: DjangoFramework :: Django :: 4Framework :: Django :: 4.2Framework :: Django :: 5Framework :: Django :: 5.1Framework :: Django :: 5.2Intended Audience :: DevelopersOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.9Topic :: Software Development :: Libraries :: Python Modules |
Evidence: django_prbac-1.1.2-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “django role-based access control”
- django-prbacImplements parameterized role-based access control (PRBAC) for Django…
- djangorestframework-role-filtersAdds role-based access control to Django REST Framework viewsets,…
- drf-access-policyDeclares access control rules for Django REST Framework views using…
Give your agent the search over MCP, or paste the wish link into any chat.
More Python Modules packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
PyYAML parses and emits YAML 1.1 data format, enabling serialization and deserialization of configuration files and Python objects to and from human-readable YAML text.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides reusable metadata objects for use with PEP-593 `typing.Annotated` to express common constraints like bounds, collection sizes, and predicates on types.
Install it if you use or build libraries that need to express type constraints in a standardized, inspectable way—or if you want to annotate your own types with…
Provides runtime tools to inspect and introspect Python type annotations, enabling programmatic examination of type hints at execution time.
See also auth · djangorestframework-role-filters · pycasbin · Flask-Principal · dry-rest-permissions · django-guardian · casbin · django-organizations · AccessControl · elevate