authorizerdev
Authorizer is an open-source, Apache-2.0, self-hosted authentication and authorization platform. It lets application teams keep identity data in their own database and infrastructure while providing authentication, fine-grained authorization, enterprise identity, and permission-aware AI capabilities.
At a Glance
- Developers and engineering teams
- Startups and SaaS companies
- Enterprise and regulated organizations
- Teams needing self-hosted or data-sovereign identity infrastructure
- +1 more
AI Tools by authorizerdev
(1)Authorizer
Open Source Auth Server for AI
Discussions
No discussions yet
Be the first to start a discussion about authorizerdev
Latest News
Authorizer 2.4.1 security release fixes admin lockout bypass and machine-identity/delegation authorization issues
Authorizer 2.4: open-source auth for AI agents and modern enterprise apps
Authorizer 2.4.0 release adds OAuth 2.1/MCP, service accounts, agent delegation, SSO, SCIM, organizations, and OpenFGA authorization
Permission-aware self-hosted RAG demo using Authorizer, OpenFGA, and Qdrant
Products & Services
Self-hosted open-source authentication and authorization server, distributed as a Go binary/container and usable with the customer's database.
Enterprise-oriented release adding OAuth 2.1 and remote MCP, service accounts, machine-to-machine authentication, agent delegation/token exchange, workload identity, passkeys, SAML/OIDC federation, SCIM, organizations, embedded OpenFGA, and multiple API transports.
User and admin client for browser or Node.js integrations, with GraphQL and REST protocol support.
React provider and pre-built login, signup, and MFA components for embedding Authorizer in React applications.
Market Position
Authorizer positions itself as a free, self-hosted, database-independent alternative to hosted identity platforms such as Auth0 and similar per-seat or usage-priced services. Its differentiators are keeping the user directory in the customer's database, deployment on the customer's cloud/VPC, broad database support, embedded OpenFGA fine-grained authorization, and a combined identity/authorization/AI-agent stack. Relevant open-source or self-hosted alternatives include Keycloak, Ory, FusionAuth, and Stack Auth; hosted alternatives include Auth0 and Clerk.
Leadership
Founders
Lakhan Samani
Creator and maintainer of Authorizer; an indie/freelance software engineer from India. He previously worked as a cloud software engineer at ArangoDB and has also described himself as a developer-tools/product builder; LinkedIn search results identify him as a senior software engineer at Qdrant from May 2026.
Executive Team
Lakhan Samani
Creator and maintainer
Indie/freelance software engineer from India; previously a cloud software engineer at ArangoDB and later identified on LinkedIn as a senior software engineer at Qdrant.
Founding Story
Lakhan Samani started Authorizer to avoid repeatedly implementing authentication logic, keep application and user data in one place rather than splitting it across third-party services, and avoid per-user pricing such as Auth0's as applications scale. He also wanted an always-running authorization service with a graphical, linked representation of user data for GraphQL-oriented applications.
Business Model
Revenue Model
Authorizer is free and open source under Apache-2.0 and is self-hosted, so users pay their own infrastructure costs rather than per-seat auth fees. The project accepts GitHub Sponsors and donations; the sponsor page says sponsorship supports development and infrastructure costs.
Pricing Tiers
Apache-2.0 software; deploy on your own infrastructure and database.
Community sponsorship to fund project development and infrastructure; the sponsor page states a $5,000 MRR goal for full-time work on Authorizer.
Target Markets
- Developers and engineering teams
- Startups and SaaS companies
- Enterprise and regulated organizations
- Teams needing self-hosted or data-sovereign identity infrastructure
- Teams building AI agents, MCP servers, or permission-aware RAG systems
- SaaS and multi-tenant applications
- Developer tools and API products
- E-commerce and consumer applications
- Enterprise applications requiring SAML/OIDC SSO and SCIM
- Applications needing self-hosted identity, data residency, or compliance control
- AI assistants and RAG systems that must enforce document permissions before retrieval