1"use strict";(globalThis.webpackChunkauthorizer_docs=globalThis.webpackChunkauthorizer_docs||[]).push([[5899],{1920(e,r,n){n.r(r),n.d(r,{assets:()=>d,contentTitle:()=>a,default:()=>l,frontMatter:()=>o,metadata:()=>i,toc:()=>c});const i=JSON.parse('{"id":"introduction","title":"Introduction","description":"Authorizer is an open-source authentication and authorization solution for your applications. Self-host with your own database.","source":"@site/docs/introduction.md","sourceDirName":".","slug":"/","permalink":"/","draft":false,"unlisted":false,"editUrl":"https://github.com/authorizerdev/authorizer-docs/tree/main/docs/introduction.md","tags":[],"version":"current","sidebarPosition":1,"frontMatter":{"sidebar_position":1,"slug":"/","title":"Introduction","description":"Authorizer is an open-source authentication and authorization solution for your applications. Self-host with your own database."},"sidebar":"docsSidebar","next":{"title":"Getting Started","permalink":"/getting-started/"}}');var t=n(4848),s=n(8453);const o={sidebar_position:1,slug:"/",title:"Introduction",description:"Authorizer is an open-source authentication and authorization solution for your applications. Self-host with your own database."},a="Introduction",d={},c=[{value:"What is Authorizer?",id:"what-is-authorizer",level:2},{value:"Features",id:"features",level:3},{value:"Introduction Video",id:"introduction-video",level:3},{value:"Authorizer v2",id:"authorizer-v2",level:2},{value:"Quick Start",id:"quick-start",level:3},{value:"Where to start",id:"where-to-start",level:3},{value:"Supported Databases",id:"supported-databases",level:2},{value:"Supported SDKs",id:"supported-sdks",level:2},{value:"Frontend SDKs",id:"frontend-sdks",level:3},{value:"Backend SDKs",id:"backend-sdks",level:3},{value:"Roadmap",id:"roadmap",level:2}];function h(e){const r={a:"a",code:"code",h1:"h1",h2:"h2",h3:"h3",header:"header",hr:"hr",img:"img",li:"li",p:"p",pre:"pre",strong:"strong",ul:"ul",...(0,s.R)(),...e.components};return(0,t.jsxs)(t.Fragment,{children:[(0,t.jsx)(r.header,{children:(0,t.jsx)(r.h1,{id:"introduction",children:"Introduction"})}),"\n",(0,t.jsx)(r.h2,{id:"what-is-authorizer",children:"What is Authorizer?"}),"\n",(0,t.jsxs)(r.p,{children:[(0,t.jsx)(r.strong,{children:"Authorizer"})," is an open-source authentication and authorization solution for your applications. Bring your database and have complete control over user information. You can self-host Authorizer instances and connect to any supported database."]}),"\n",(0,t.jsx)(r.p,{children:(0,t.jsx)(r.img,{alt:"Authorizer Architecture",src:n(1734).A+"",width:"4862",height:"2172"})}),"\n",(0,t.jsx)(r.h3,{id:"features",children:"Features"}),"\n",(0,t.jsxs)(r.ul,{children:["\n",(0,t.jsx)(r.li,{children:"Sign-in / Sign-up with email ID and password"}),"\n",(0,t.jsx)(r.li,{children:"Secure session management with HTTP-only cookies"}),"\n",(0,t.jsx)(r.li,{children:"Email verification"}),"\n",(0,t.jsxs)(r.li,{children:[(0,t.jsx)(r.a,{href:"./core/oauth2-oidc",children:"OAuth2 and OpenID Connect"})," compatible APIs"]}),"\n",(0,t.jsx)(r.li,{children:"APIs to update profile securely"}),"\n",(0,t.jsx)(r.li,{children:"Forgot password flow using email"}),"\n",(0,t.jsx)(r.li,{children:"Social logins (Google, GitHub, Facebook, LinkedIn, Apple, Discord, Twitter, Twitch, Roblox, Microsoft)"}),"\n",(0,t.jsxs)(r.li,{children:["Role-based access management and ",(0,t.jsx)(r.a,{href:"./core/authorization",children:"fine-grained authorization (FGA)"})," via an embedded ",(0,t.jsx)(r.a,{href:"https://openfga.dev",children:"OpenFGA"})," (",(0,t.jsx)(r.a,{href:"https://research.google/pubs/pub48190/",children:"Zanzibar"})," ReBAC) engine"]}),"\n",(0,t.jsx)(r.li,{children:"Password-less login with magic link"}),"\n",(0,t.jsxs)(r.li,{children:[(0,t.jsx)(r.a,{href:"https://www.w3.org/TR/webauthn-2/",children:"WebAuthn"})," / ",(0,t.jsx)(r.a,{href:"https://fidoalliance.org/passkeys/",children:"passkey"})," registration and login"]}),"\n",(0,t.jsxs)(r.li,{children:["Multi-factor authentication: ",(0,t.jsx)(r.a,{href:"https://datatracker.ietf.org/doc/html/rfc6238",children:"TOTP"}
1),", email OTP, SMS OTP, and passkey as a second factor"]}),"\n",(0,t.jsxs)(r.li,{children:["SMS OTP via ",(0,t.jsx)(r.a,{href:"https://www.twilio.com",children:"Twilio"})]}),"\n",(0,t.jsxs)(r.li,{children:["Enterprise SSO \u2014 ",(0,t.jsx)(r.a,{href:"https://www.oasis-open.org/standard/saml/",children:"SAML 2.0"})," as Service Provider and Identity Provider, OIDC federation, verified email domains, and home realm discovery (",(0,t.jsx)(r.a,{href:"./core/sso-guide",children:"SSO guide"}),")"]}),"\n",(0,t.jsxs)(r.li,{children:[(0,t.jsx)(r.a,{href:"https://datatracker.ietf.org/doc/html/rfc7644",children:"SCIM 2.0"})," user and group provisioning (",(0,t.jsx)(r.a,{href:"./enterprise/scim",children:"SCIM"}),")"]}),"\n",(0,t.jsxs)(r.li,{children:[(0,t.jsx)(r.a,{href:"./enterprise/organizations",children:"Organizations and multi-tenancy"})," with org-scoped admin roles"]}),"\n",(0,t.jsxs)(r.li,{children:["Machine-to-machine auth (",(0,t.jsx)(r.code,{children:"client_credentials"}),") and secretless workload identity \u2014 ",(0,t.jsx)(r.a,{href:"https://datatracker.ietf.org/doc/html/rfc7523",children:"RFC 7523"})," client assertions, ",(0,t.jsx)(r.a,{href:"https://spiffe.io",children:"SPIFFE"})," JWT-SVIDs, Kubernetes ",(0,t.jsx)(r.a,{href:"https://kubernetes.io/docs/reference/kubernetes-api/authentication-resources/token-review-v1/",children:"TokenReview"})," (",(0,t.jsx)(r.a,{href:"./enterprise/workload-identity",children:"Workload Identity"}),")"]}),"\n",(0,t.jsxs)(r.li,{children:["Agent delegation via ",(0,t.jsx)(r.a,{href:"https://datatracker.ietf.org/doc/html/rfc8693",children:"RFC 8693"})," token exchange (",(0,t.jsx)(r.a,{href:"./enterprise/token-exchange",children:"Token Exchange"}),")"]}),"\n",(0,t.jsx)(r.li,{children:"Email templating and webhooks"}),"\n",(0,t.jsxs)(r.li,{children:["Rate limiting, security hardening, and ",(0,t.jsx)(r.a,{href:"https://prometheus.io",children:"Prometheus"})," metrics (",(0,t.jsx)(r.a,{href:"./core/metrics-monitoring",children:"Metrics & Monitoring"}),")"]}),"\n",(0,t.jsxs)(r.li,{children:[(0,t.jsx)(r.a,{href:"./core/graphql-api",children:"GraphQL"}),", ",(0,t.jsx)(r.a,{href:"./core/rest-api",children:"REST"}),", and ",(0,t.jsx)(r.a,{href:"./core/grpc",children:"gRPC"})," APIs"]}),"\n",(0,t.jsxs)(r.li,{children:[(0,t.jsx)(r.a,{href:"./core/mcp",children:"MCP server"})," for AI agents"]}),"\n"]}),"\n",(0,t.jsx)(r.h3,{id:"introduction-video",children:"Introduction Video"}),"\n",(0,t.jsxs)(r.p,{children:["Watch the introduction video on YouTube: ",(0,t.jsx)(r.a,{href:"https://www.youtube.com/watch?v=DFgo0TuA4c8",children:"Introduction to Authorizer"})]}),"\n",(0,t.jsx)(r.hr,{}),"\n",(0,t.jsx)(r.h2,{id:"authorizer-v2",children:"Authorizer v2"}),"\n",(0,t.jsx)(r.p,{children:"Authorizer v2 focuses on simpler, more secure configuration and a cleaner operational model:"}),"\n",(0,t.jsxs)(r.ul,{children:["\n",(0,t.jsxs)(r.li,{children:[(0,t.jsx)(r.strong,{children:"Configuration via CLI flags only"})," -- no persisted env in the database or cache"]}),"\n",(0,t.jsxs)(r.li,{children:[(0,t.jsx)(r.strong,{children:"More secure secret handling"})," -- secrets are passed at process start, not stored in Authorizer-managed storage"]}),"\n",(0,t.jsxs)(r.li,{children:[(0,t.jsx)(r.strong,{children:"Stronger defaults and hardening flags"})," -- better control over GraphQL introspection, admin access, and cookies"]}),"\n",(0,t.jsxs)(r.li,{children:[(0,t.jsx)(r.strong,{children:"Updated SDKs"})," -- ",(0,t.jsx)(r.code,{children:"@authorizerdev/authorizer-js"})," v3 and ",(0,t.jsx)(r.code,{children:"@authorizerdev/authorizer-react"})," v2"]}),"\n"]}),"\n",(0,t.jsx)(r.h3,{id:"quick-start",children:"Quick Start"}),"\n",(0,t.jsx)(r.pre,{children:(0,t.jsx)(r.code,{className:"language-bash",children:"./authorizer \\\n --database-type=sqlite \\\n --database-url=test.db \\\n --url=http://localhost:8080 \\\n --jwt-type=HS256 \\\n --jwt-secret=test \\\n --encryption-key=test-encryption-key \\\n --admin-secret=admin \\\n --client-id=123456 \\\n --client-secret=secret\n"})}),"\n",(0,t.jsx)(r.p,{children:"Or with Docker:"}),"\n",(0,t.jsx)(r.pre,{children:(0,t.jsx)(r.code,{className:"language-bash",children:"docker run -p 8080:8080 quay.io/authorizer/authorizer:latest \\\n --database-type=sqlite \\\n --database-url=test.db \\\n --url=http://localhost:8080 \\\n --jwt-type=HS256 \\\n --jwt-secret=test \\\n --encryption-key=test-encryption-key \\\n --admin-secret=admin \\\n --client-id=123456 \\\n --client-secret=secret\n"})}),"\n",(0,t.jsx)(r.h3,{id:"where-to-start",children:"Where to start"}),"\n",(0,t.jsxs)(r.ul,{children:["\n",(0,t.jsxs)(r.li,{children:[(0,t.jsx)(r.strong,{children:"New projects:"})," Start with the ",(0,t.jsx)(r.a,{href:"./getting-started",children:"Getting Started"})," guide"]}),"\n",(0,t.jsxs)(r.li,{children:[(0,t.jsx)(r.strong,{children:"Migrating from v1:"})," See ",(0,t.jsx)(r.a,{href:"./migration/v1-to-v2",children:"Migration v1 to v2"})," for a complete guide"]}),"\n",(0,t.jsxs)(r.li,{children:[(0,t.jsx)(r.strong,{children:"Deployment:"})," Choose from ",(0,t.jsx)(r.a,{href:"./deployment/docker",children:"Docker"}),", ",(0,t.jsx)(r.a,{href:"./deployment/kubernetes",children:"Kubernetes"}),", ",(0,t.jsx)(r.a,{href:"./deployment/helm-chart",children:"Helm Chart"}),", or ",(0,t.jsx)(r.a,{href:"./deployment",children:"one-click deploys"})]}),"\n",(0,t.jsxs)(r.li,{children:[(0,t.jsx)(r.strong,{children:"SDK integration:"})," See ",(0,t.jsx)(r.a,{href:"./sdks/authorizer-js",children:"authorizer-js"}),", ",(0,t.jsx)(r.a,{href:"./sdks/authorizer-react",children:"authorizer-react"}),", or ",(0,t.jsx)(r.a,{href:"./sdks/authorizer-go",children:"authorizer-go"})]}),"\n"]}),"\n",(0,t.jsx)(r.hr,{}),"\n",(0,t.jsx)(r.h2,{id:"supported-databases",children:"Supported Databases"}),"\n",(0,t.jsx)(r.p,{children:"Authorizer supports a wide range of databases:"}),"\n",(0,t.jsxs)(r.ul,{children:["\n",(0,t.jsx)(r.li,{children:"PostgreSQL, MySQL, MariaDB, SQLite, libSQL / Turso, SQL Server"}),"\n",(0,t.jsx)(r.li,{children:"MongoDB, ArangoDB, Couchbase"}),"\n",(0,t.jsx)(r.li,{children:"CassandraDB, ScyllaDB, DynamoDB"}),"\n",(0,t.jsx)(r.li,{children:"Yugabyte, PlanetScale, CockroachDB"}),"\n"]}),"\n",(0,t.jsxs)(r.p,{children:["See ",(0,t.jsx)(r.a,{href:"./core/databases",children:"Databases"})," for connection string formats."]}),"\n",(0,t.jsx)(r.hr,{}),"\n",(0,t.jsx)(r.h2,{id:"supported-sdks",children:"Supported SDKs"}),"\n",(0,t.jsx)(r.h3,{id:"frontend-sdks",children:"Frontend SDKs"}),"\n",(0,t.jsxs)(r.ul,{children:["\n",(0,t.jsxs)(r.li,{children:[(0,t.jsx)(r.a,{href:"https://github.com/authorizerdev/authorizer-js",children:"JavaScript / TypeScript"})," \u2014 v4.0.0; user + admin client; GraphQL + REST protocols"]}),"\n",(0,t.jsxs)(r.li,{children:[(0,t.jsx)(r.a,{href:"https://github.com/authorizerdev/authorizer-react",children:"React"})," \u2014 v2.2.0; ",(0,t.jsx)(r.code,{children:"protocol"})," prop; pre-built login/signup/MFA components"]}),"\n",(0,t.jsxs)(r.li,{children:[(0,t.jsx)(r.a,{href:"https://github.com/authorizerdev/authorizer-vue",children:"Vue"})," \u2014 v2.1.0; no admin client or protocol selection yet"]}),"\n",(0,t.jsxs)(r.li,{children:[(0,t.jsx)(r.a,{href:"https://github.com/authorizerdev/authorizer-svelte",children:"Svelte"})," \u2014 v1.1.0; no admin client or protocol selection yet"]}),"\n",(0,t.jsxs)(r.li,{children:[(0,t.jsx)(r.a,{href:"https://github.com/authorizerdev/authorizer-flutter-sdk",children:"Flutter"})," \u2014 not released yet; no package on pub.dev"]}),"\n"]}),"\n",(0,t.jsx)(r.h3,{id:"backend-sdks",children:"Backend SDKs"}),"\n",(0,t.jsxs)(r.ul,{children:["\n",(0,t.jsxs)(r.li,{children:[(0,t.jsx)(r.a,{href:"https://github.com/authorizerdev/authorizer-go",children:"Go"})," \u2014 v2.2.0; user + admin client; protocol selection (gRPC / REST / GraphQL); FGA helpers"]}),"\n",(0,t.jsxs)(r.li,{children:[(0,t.jsx)(r.a,{href:"https://github.com/authorizerdev/authorizer-py",children:"Python"})," \u2014 v0.3.0; sync + async; admin API (",(0,t.jsx)(r.code,{children:"pip install authorizer-py"}),")"]}),"\n",(0,t.jsxs)(r.li,{children:[(0,t.jsx)(r.a,{href:"https://github.com/authorizerdev/authorizer-js",children:"Node.js"})," \u2014 same package as the frontend SDK, works server-side"]}),"\n"]}),"\n",(0,t.jsxs)(r.p,{children:["See the ",(0,t.jsx)(r.a,{href:"./sdks/authorizer-js",children:"SDK reference"})," for usage docs."]}),"\n",(0,t.jsx)(r.hr,{}),"\n",(0,t.jsx)(r.h2,{id:"roadmap",children:"Roadmap"}),"\n",(0,t.jsxs)(r.ul,{children:["\n",(0,t.jsx)(r.li,{children:"React Native SDK"}),"\n",(0,t.jsx)(r.li,{children:"Android Native SDK"}),"\n",(0,t.jsx)(r.li,{children:"iOS Native SDK"}),"\n",(0,t.jsx)(r.li,{children:"PHP SDK"}),"\n",(0,t.jsx)(r.li,{children:"WordPress plugin"}),"\n",(0,t.jsx)(r.li,{children:"AMI / Digital Ocean Droplet"}),"\n",(0,t.jsx)(r.li,{children:"Azure deployment"}),"\n",(0,t.jsx)(r.li,{children:"Vue / Svelte admin client and protocol parity with authorizer-js"}),"\n"]})]})}function l(e={}){const{wrapper:r}={...(0,s.R)(),...e.components};return r?(0,t.jsx)(r,{...e,children:(0,t.jsx)(h,{...e})}):h(e)}},1734(e,r,n){n.d(r,{A:()=>i});const i=n.p+"assets/images/authorizer-arch-cc556559860ca2574081397b7a72b466.png"},8453(e,r,n){n.d(r,{R:()=>o,x:()=>a});var i=n(6540);const t={},s=i.createContext(t);function o(e){const r=i.useContext(s);return i.useMemo(function(){return"function"==typeof e?e(r):{...r,...e}},[r,e])}function a(e){let r;return r=e.disableParentContext?"function"==typeof e.components?e.components(t):e.components||t:o(e.components),i.createElement(s.Provider,{value:r},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.