OSS TanbouSign in with GitHub

separate ACL, RBAC, and ABAC authorization policies from Go application code

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
20,433
Primary language
Go
License
Apache-2.0
Repository last updated
Oct 5, 2026
On this page

Overview

Apache Casbin is an access-control library for Go applications. It models ACL, RBAC, ABAC, domain-aware RBAC, RESTful paths, deny-override, priorities, and related authorization rules as models and policies evaluated by an enforcer.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Use one enforcer across ACL, RBAC, ABAC, and other access-control models

Model configuration defines requests, policies, roles, effects, and matchers, allowing applications to express ACL, RBAC, ABAC, and tenant or domain-aware roles.

Sources: [2]

Keep policy persistence and role management behind adapters

Policies can be persisted through file or database adapters, while role hierarchy and multi-node policy consistency can be extended through surrounding components, reducing authorization logic embedded in business code.

Sources: [2]

Best fit

Fits APIs and business systems that want permission policy outside conditional application code

It is useful when roles, resources, actions, tenants, or attributes need a consistent policy model that can change independently of handlers and services.

Sources: [2]

Before adoption

v3.11.0 declares Go 1.13; the repository moved to apache/casbin while the module path remains casbin/casbin/v3

The v3.11.0 go.mod declares github.com/casbin/casbin/v3 and Go 1.13 even though the GitHub repository has moved to Apache. The release fixes policy ordering, conditional-role behavior, and non-ASCII literal handling, so policy serialization and role evaluation should be regression-tested.

Sources: [3][4][2]

Official sources

  1. [1]apache/casbin — GitHub repository(2026-10-06)
  2. [2]Apache Casbin v3.11.0 — README(2026-10-06)
  3. [3]Apache Casbin v3.11.0 — go.mod(2026-10-06)
  4. [4]Apache Casbin v3.11.0 release(2026-10-06)
  5. [5]Apache Casbin Apache-2.0 license(2026-10-06)
Supplemental curator note

Casbin separates authorization policy—who may do what—from authentication. The GitHub repository is now apache/casbin, while the v3.11.0 Go module path remains github.com/casbin/casbin/v3; do not confuse the repository URL with the import path.

Try it in 3 steps

  1. 1

    Get the source

    git clone --depth 1 https://github.com/apache/casbin.git
  2. 2

    Enter the repository

    cd casbin
  3. 3

    Check the official steps

    Continue with the commands in the README Installation, Quick Start, or Getting Started section.

    find . -maxdepth 1 -iname 'README*' -exec sed -n '1,220p' {} \; -quit
Check the official README

Growth

Growth trends · Last 30 days

20,433 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
6
Open PRs
2

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • casbin
  • access-control
  • authorization
  • rbac
  • abac
  • acl
  • auth
  • authz
  • permission
  • authentication
  • authn
  • iam
Stars
20,433
Forks
1,761
Watchers
238
Open issues
37
Contributors
155
Owner type
Organization
Primary language
Go
License
Apache-2.0
Repository last updated
Oct 5, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?