Open-source authorization engine

Fast. Simple. Access control.

Externalize fine-grained authorization with a human-readable policy language, centralized management and millisecond decisions across polyglot systems.

The original Speedle project continues as Speedle+, maintained by its founding members.
Explore Speedle+
About Speedle

Authorization that stays out of your application code.

Speedle is a general-purpose authorization engine for cloud-native and legacy applications. It evaluates RBAC and ABAC policies for users, services and delegated processes.

One engine, many stacks

Define policy once, manage it centrally and ask Speedle for a consistent authorization decision from any service or language.

Open source and built for extension. Speedle+ carries the project forward under the Universal Permissive License.

Read the project story

Speedle consists of

  • SPDL policy definition language
  • Policy Management Service
  • Authorization Decision Service
  • Command-line tool (spctl)

Use the complete stack or integrate only the components your system needs.

Features

Fine-grained control without the friction.

Preserve the policies your team can reason about while keeping enforcement fast, centralized and adaptable.

Simple Policy Language

Express authorization intent in the human-readable Secure Policy Definition Language.

Learn more

Cloud Native

Run across clouds and connect to modern infrastructure through pluggable interfaces.

Learn more

Real-time Policy Discovery

Observe runtime interactions and turn real access patterns into enforceable policies.

Learn more

RBAC / ABAC

Combine roles and attributes for precise access decisions.

Learn more

Centralized Management

Manage policy for disparate services from one place.

Learn more

Pluggable Identity

Connect GitHub, Okta or your own identity provider.

Learn more

Bring Your Own Store

Use etcd or implement the persistence interface for your storage layer.

Learn more
SPDL

Policies humans can read.

Describe who can perform an action on a resource, add conditions when needed, and keep authorization rules separate from business logic.

Explore SPDL
library.spdl
// Employees can read books
grant read on book
  if principal in group:employee;

// Explicit deny always wins
deny delete on book
  if principal == user:bob;
Integrations

Built for the infrastructure you already run.

View all integrations
Kubernetes Istio Docker
Open source contributors

Help move Speedle+ forward.

Speedle+ is maintained in the open. Review the code, report an issue or contribute an improvement.

Contribute to Speedle+