On this page
Overview
CanCanCan is an authorization library for Ruby and Ruby on Rails. It defines which actions a user may perform on resources through Ability rules and reuses those rules across controllers, views, and database queries. Rails helpers can also combine resource loading with authorization checks.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Centralize authorization rules in Ability objects
Include CanCan::Ability in an Ability class and define can rules so controllers and views do not duplicate the same permission conditions.
Sources: [1]
Check access with can? and enforce it with authorize!
Views and controllers can use can? or cannot?, while authorize! raises when the current user is not allowed to perform the requested action.
Sources: [1]
Filter records with accessible_by
accessible_by(current_ability) applies Ability rules to model queries so the returned records are limited to objects the user is allowed to access.
Sources: [1]
Best fit
Fits Rails applications that need consistent authorization across layers
It is useful when role, ownership, or resource attributes should drive the same authorization policy in UI rendering, controller actions, and database access.
Sources: [1]
Before adoption
Keep authentication separate from authorization
CanCanCan manages permissions on resources. Login and identity verification belong to a separate authentication mechanism whose user context is then passed into Ability rules.
Sources: [1]
Test automatic loading and authorization for custom controllers
load_and_authorize_resource automates loading and checks for RESTful controllers. Custom actions and complex associations should be tested to ensure the intended record and rule are selected.
Sources: [1]
Official sources
- [1]CanCanCan 3.5.0 README(2026-10-03)
- [2]CanCanCan 3.5.0 gemspec(2026-10-03)
- [3]CanCanCan 3.5.0 release(2026-10-03)
- [4]CanCanCommunity/cancancan repository(2026-10-03)
- [5]CanCanCan MIT license(2026-10-03)
Supplemental curator note
CanCanCan fits Rails applications that need a single place to decide what an authenticated user may do. As policies grow, split Ability responsibilities by domain and add focused authorization tests to keep rule interactions maintainable.
Try it in 3 steps
- 1
Add CanCanCan 3.5.0 to the Gemfile
Pin the stable release in the Rails application's Gemfile and run
bundle install.gem 'cancancan', '3.5.0' - 2
Generate the Ability class
Create the
Abilityclass that will hold authorization rules.bin/rails generate cancan:ability - 3
Check permission in a view or controller
Define rules such as
can :read, Post, ...in Ability, then reuse the same policy throughcan?,authorize!, and related helpers.can? :read, @post
Growth
Growth trends · Last 30 days
5,681 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 1
- Open PRs
- 31
Development activity is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- authorization
- cancancan
- rails
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- Chatwoot37,488 Stars
1 shared tag(s) · Same language
Unify web chat, email, WhatsApp, and social channels into shared inboxes, automation, and AI support
Ruby - Vagrant27,211 Stars
1 shared tag(s) · Same language
define portable development environments across providers with a Vagrantfile
Ruby - GitLab CE/EE Mirror24,554 Stars
1 shared tag(s) · Same language
inspect GitLab's large DevOps codebase through its GitHub mirror
Ruby - Ruby23,771 Stars
1 shared tag(s) · Same language
one upstream for web scripting, the CRuby VM, GC, and YJIT/ZJIT
Ruby - OpenProject16,299 Stars
1 shared tag(s) · Same language
self-host Gantt, agile planning, time tracking, wikis, and meetings in one project platform
Ruby - Draper5,277 Stars
2 shared tag(s) · 1 shared category(s) · Same language
wrap Rails models with decorators and view models so presentation logic stays out of models and global helpers
Ruby
Report incorrect information
Tell us if any listing information is incorrect or outdated.