Open Source Authorization Projects
Authorization determines which users, services, or automated agents may access a resource or perform an action. It applies permissions after an identity is established, helping organizations enforce least privilege, separate responsibilities, and protect sensitive data and operations. Rules can be based on roles, attributes, relationships, policies, or contextual conditions, and may be evaluated within an application or by a shared service.
Open source options include policy engines, access-control libraries, identity platforms with permission features, and authorization layers for automated agents. When choosing one, consider its policy model, language and framework support, integration needs, auditability, performance, license, maintenance activity, and operational requirements. These tools are useful to developers, security teams, and organizations that need consistent, reviewable control over access across applications and services.
5 repositories · updated September 19, 2026

APort Agent Guardrails: Deterministic Pre-Action Authorization for AI Agents
APort Agent Guardrails provides deterministic pre-action authorization for AI agents, running security checks before any tool execution. This crucial mechanism prevents prompt injection from bypassing policy, ensuring robust and auditable protection for AI-driven operations.

aport-spec: The Open Agent Passport (OAP) Specification for AI Agent Trust
The aport-spec repository introduces the Open Agent Passport (OAP) specification, a critical framework for establishing trust in AI agents. It defines a lightweight, cryptographically verifiable credential, enabling real-time, pre-action authorization for AI agents across various platforms. OAP provides the essential runtime trust layer for secure and scalable agentic commerce.

OpenWorkProof: Verifiable Work Contracts for AI Agent Systems
OpenWorkProof is an open protocol designed to bring transparency and accountability to AI agent work. It establishes verifiable contracts for multi-agent systems, ensuring that tasks are authorized, executed within agreed scopes, and independently verifiable. This protocol addresses critical questions about authorization, execution evidence, and human acceptance in AI-driven workflows.

Intent-Plane: Fail-Closed Authorization Gate for AI Agent Actions
Intent-Plane is a fail-closed authorization gate designed for AI agents performing irreversible actions, ensuring every decision is deterministic and auditable. It provides a durable record that third parties can re-verify independently, without needing to trust the gate's internal code. This system is crucial for applications in fintech, payments, and treasury, where accountability and security are paramount.

Logto: Open-Source Auth Infrastructure for SaaS and AI Apps
Logto is a modern, open-source authentication and authorization infrastructure designed for SaaS and AI applications. Built on OIDC and OAuth 2.1, it offers robust features like multi-tenancy, enterprise SSO, and RBAC. This platform simplifies secure identity management, providing pre-built sign-in flows and SDKs for various frameworks.