$npx skillfedfor your agent

rules

Awesome Django authorization, without the database

With conditionsPyPI Application FrameworksReleased Sep 2024563.4K downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — rules-3.5-py2.py3-none-any.whl
v3.5 · released 2024-09-02

Yes, if you need lightweight object-level permissions in Django and prefer logic-based rules over database-backed permissions. The package is stable (Production/Stable status), has no known vulnerabilities, and zero runtime dependencies. However, the aging maintenance status (last release 711 days ago) means you should verify compatibility with your target Django version and be prepared to maintain a fork if critical issues arise.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.8 or newer.
  • Optional Django integration requires Django 3.2 or newer.
  • Low install friction with no runtime dependencies.

License · maintenance · safety

MIT (permissive) — MIT license permits commercial and private use with minimal restrictions. You must include a copy of the license and copyright notice, but can modify and distribute freely.

last release 2024-09-02 (711 days) · last repo commit 2025-10-11 · 1,978 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 563,384 downloads/mo, #5,980 on PyPI

Verify before relying

pip install rules

import rules

@rules.predicate
def is_author(user, book):
    return book.author == user

rules.add_rule('can_edit_book', is_author)
rules.test_rule('can_edit_book', user, book)
  • Whether the aging maintenance status (711 days since last release) affects compatibility with current Django versions
  • Performance characteristics when evaluating complex predicate graphs at scale
Same gist for agents: .md · .json

What it is and what it does

rules is a lightweight authorization framework that lets you define object-level permissions using predicates—callable functions that return True or False based on user and object state. Instead of storing permissions in a database, you compose predicates using logical operators to build rule sets that determine what actions a user can perform on specific objects. It integrates seamlessly with Django views, templates, and the admin interface, but can also be used standalone in non-Django contexts.

The core idea is simple: predicates are any callable accepting zero to two arguments (typically user and object), and you combine them with operators to express complex authorization logic. You add rules to a rule set, then test them against a user and object to get a boolean result. This approach avoids database queries for permission checks and keeps authorization logic in code where it's easier to version control and reason about.

Use it for

  • Enforce object-level permissions in Django views—e.g., allow users to edit only their own posts or comments
  • Build custom authorization logic for REST APIs without storing per-object permissions in the database
  • Implement role-based or attribute-based access control using predicates that inspect user roles or object properties
  • Test authorization rules in unit tests by composing predicates without needing fixtures or test data
  • Protect Django admin actions—e.g., allow deletion only if the user is the object's owner

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you need lightweight object-level permissions in Django and prefer logic-based rules over database-backed permissions.

The package is stable (Production/Stable status), has no known vulnerabilities, and zero runtime dependencies. However, the aging maintenance status (last release 711 days ago) means you should verify compatibility with your target Django version and be prepared to maintain a fork if critical issues arise.

Install

rules on PyPI

Before you install

Low install friction with no runtime dependencies. Maintenance status is aging—last release was 711 days ago (2024-09-02), though the repository remains active with recent commits and 1978 stars. Suitable for established projects but check if active maintenance matters for your use case.

Requires Python 3.8 or newer. Optional Django integration requires Django 3.2 or newer.

License in practice

MIT license permits commercial and private use with minimal restrictions. You must include a copy of the license and copyright notice, but can modify and distribute freely.

Quickstart

pip install rules

import rules

@rules.predicate
def is_author(user, book):
    return book.author == user

rules.add_rule('can_edit_book', is_author)
rules.test_rule('can_edit_book', user, book)

Verify before relying

  • Whether the aging maintenance status (711 days since last release) affects compatibility with current Django versions
  • Performance characteristics when evaluating complex predicate graphs at scale

Package facts

LicenseMIT permissive
Python supportNot specified
Install frictionLow. Pure-Python wheel
Runtime dependenciesNone
MaintenanceAging 711 days since the last release
Last repo commit
First released
Downloads563,384 / month, #5,980 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableEnvironment :: Web EnvironmentFramework :: DjangoIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9

Evidence: rules-3.5-py2.py3-none-any.whl

Tags

Capabilities
django object permissionsrule-based authorizationpredicate frameworkdjango access controlpermission decoratorsdecision tree permissionsdjango authorization without database
Topics
django-permissionsauthorizationpredicate-logic

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “rule-based authorization”

  • rulesrules provides object-level permission checking for Django…
  • pysbdDetects sentence boundaries in text using rule-based heuristics,…
  • PyRuSHPyRuSH segments clinical and telegraphic text into sentences using…

Give your agent the search over MCP, or paste the wish link into any chat.

More Application Frameworks packages

fastapi Worth it
PyPI · Software Development · released Jul 2026

FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.

MITpure Python · 3.10+
568.6Mdownloads / mo
annotated-doc With conditions
PyPI · Software Development · released Jul 2026

Provides a way to document function parameters, class attributes, return types, and variables inline using Python's `Annotated` type hint syntax instead of traditional docstrings.

MITpure Python · 3.9+
456.2Mdownloads / mo
textual Worth it
PyPI · Application Frameworks · released Jun 2026

Textual is a Python framework for building cross-platform user interfaces that run in the terminal or web browser using a modern, component-based API.

Install it if you're developing CLI tools, dashboards, or interactive terminal applications.

MITpure Python
443.6Mdownloads / mo
typer Worth it
PyPI · Software Development · released Aug 2026

Typer builds command-line applications from Python functions using type hints, automatically generating help text, argument parsing, and shell completion.

Install it if you are building CLIs in Python.

MITpure Python · 3.10+
369.3Mdownloads / mo
mcp Worth it
PyPI · Application Frameworks · released Jul 2026

Build and connect to Model Context Protocol servers that expose tools, resources, and prompts to LLM applications over stdio, HTTP, or SSE transports.

Install it if you need to build or connect to servers.

MITpure Python · 3.10+
319.3Mdownloads / mo
Werkzeug Worth it
PyPI · Application Frameworks · released Apr 2026

Werkzeug is a WSGI utility library providing request/response objects, URL routing, an interactive debugger, HTTP utilities, and a development server for building web applications.

BSD-3-Clausepure Python · 3.9+
268.1Mdownloads / mo

See also bridgekeeper · skope-rules · dry-rest-permissions · business-rules · zope.security · django-guardian · bddl · django-prbac · djangorestframework-guardian