On this page
Overview
Apache Casbin is an access-control library for Go applications. It models ACL, RBAC, ABAC, domain-aware RBAC, RESTful paths, deny-override, priorities, and related authorization rules as models and policies evaluated by an enforcer.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Use one enforcer across ACL, RBAC, ABAC, and other access-control models
Model configuration defines requests, policies, roles, effects, and matchers, allowing applications to express ACL, RBAC, ABAC, and tenant or domain-aware roles.
Sources: [2]
Keep policy persistence and role management behind adapters
Policies can be persisted through file or database adapters, while role hierarchy and multi-node policy consistency can be extended through surrounding components, reducing authorization logic embedded in business code.
Sources: [2]
Best fit
Fits APIs and business systems that want permission policy outside conditional application code
It is useful when roles, resources, actions, tenants, or attributes need a consistent policy model that can change independently of handlers and services.
Sources: [2]
Before adoption
v3.11.0 declares Go 1.13; the repository moved to apache/casbin while the module path remains casbin/casbin/v3
The v3.11.0 go.mod declares github.com/casbin/casbin/v3 and Go 1.13 even though the GitHub repository has moved to Apache. The release fixes policy ordering, conditional-role behavior, and non-ASCII literal handling, so policy serialization and role evaluation should be regression-tested.
Official sources
- [1]apache/casbin — GitHub repository(2026-10-06)
- [2]Apache Casbin v3.11.0 — README(2026-10-06)
- [3]Apache Casbin v3.11.0 — go.mod(2026-10-06)
- [4]Apache Casbin v3.11.0 release(2026-10-06)
- [5]Apache Casbin Apache-2.0 license(2026-10-06)
Supplemental curator note
Casbin separates authorization policy—who may do what—from authentication. The GitHub repository is now apache/casbin, while the v3.11.0 Go module path remains github.com/casbin/casbin/v3; do not confuse the repository URL with the import path.
Try it in 3 steps
- 1
Get the source
git clone --depth 1 https://github.com/apache/casbin.git - 2
Enter the repository
cd casbin - 3
Check the official steps
Continue with the commands in the README Installation, Quick Start, or Getting Started section.
find . -maxdepth 1 -iname 'README*' -exec sed -n '1,220p' {} \; -quit
Growth
Growth trends · Last 30 days
20,433 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 6
- Open PRs
- 2
Development activity is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- casbin
- access-control
- authorization
- rbac
- abac
- acl
- auth
- authz
- permission
- authentication
- authn
- iam
- Stars
- 20,433
- Forks
- 1,761
- Watchers
- 238
- Open issues
- 37
- Contributors
- 155
- Owner type
- Organization
- Primary language
- Go
- License
- Apache-2.0
- Repository last updated
- Oct 5, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- golang-jwt9,229 Stars
3 shared tag(s) · 1 shared category(s) · Same language
create, sign, parse, and validate JSON Web Tokens in Go
Go - imgproxy11,109 Stars
3 shared tag(s) · Same language
offload application image processing to a standalone HTTP service
Go - Hanko9,034 Stars
3 shared tag(s) · Same language
API-first authentication from passkeys to SSO with native multi-tenancy
Go - mkcert59,718 Stars
2 shared tag(s) · 2 shared category(s) · Same language
create a local CA and easily issue browser-trusted TLS certificates for localhost and development domains
Go - Gitleaks29,723 Stars
2 shared tag(s) · 2 shared category(s) · Same language
detect passwords, API keys, tokens, and other secrets in Git history, files, directories, and stdin
Go - Grype12,979 Stars
2 shared tag(s) · 2 shared category(s) · Same language
scan container images, filesystems, and SBOMs against vulnerability data and prioritize findings with EPSS, KEV, and VEX
Go
Report incorrect information
Tell us if any listing information is incorrect or outdated.