Tech blog
Demos, implementation guides, product updates and broader takes on authorization, identity and security.

Not every authorization decision is allow or deny
Not every authorization decision is allow or deny. Some denials are conditional, and the policy can return what would unblock them. Covers Cerbos policy outputs, the conditionNotMet trigger, the AuthZEN ARAP draft profile for requestable denials, and why an approval is an input to a new decision.

What is authorization? Types, examples and definitions
Learn what authorization is all about! Explore several key authorization design patterns, how they work, and possible scenarios where they may be implemented. This guide covers RBAC, ABAC, PBAC, DAC, MAC, and ReBAC, how authorization differs from authentication, how it works with tokens and OAuth scopes, real-world examples, and best practices for getting it right.

Istio authorization stops at identity, not at what a workload may do
Istio proves which workload is calling with mTLS and SPIFFE, and stops there. This guide covers where AuthorizationPolicy runs out, handing the decision to an external authorizer through the CUSTOM action, running one policy set across north south and east west traffic, and what the extra network hops cost.

Stale JWT claims in authorization, and how to look up identity attributes at decision time
How to resolve identity attributes at decision time rather than reading stale JWT claims. Covers Envoy verifying the token while a Synapse data source fetches current profile and group data, policies that read attributes rather than claims, per source cache expiry, and failure behavior when the provider is unreachable.

Policy-driven MCP routing: enforcing tool gates outside the agent
Telling an agent which tools not to use is a request, not a control. Here is how to gate MCP tool calls with policy enforced outside the agent, at the execution boundary.

Full guide to Next.js authorization & authentication
Next.js has two main patterns of authentication. Meanwhile when it comes to authorization, nothing is as simple as adding Cerbos. Read our full guide.

Open source Cerbos vs paid Cerbos
Open source vs paid Cerbos explained. The Apache 2.0 engine is complete and free, running over 2 billion checks a month. See what the commercial platform adds around it, policy distribution, compliance audit, and data enrichment, plus the roughly 19 engineer months it takes to build the equivalent yourself.

Delegated authorization: Why acting on behalf of someone else is not a role
Delegated authorization explained. Why modeling on-behalf-of access as a role loses the subject, the approver and the expiry. Covers the RFC 8693 act claim, delegation versus impersonation, AuthZEN and COAZ, multi-party policy conditions, revocation before expiry, and audit lineage for delegated actions.

MCP server vetting checklist for enterprises
Every MCP server you connect is a third party you have handed an agent a door to. Here is a practical checklist for vetting MCP servers and governing the ones you cannot fully trust.

Authorizing MCP tool calls at the gateway or inside the proxy, and what each one stops
Two ways to authorize MCP tool calls, in the request path or inside the proxy, and they stop different things. Covers in-path gateway enforcement against a pre-call hook, why denying a tool and hiding a tool are different security properties, fail closed behavior, and where both shapes stop working.

Envoy ext_authz: enforcing one authorization policy at the gateway and in the service
Envoy external authorization with the ext_authz filter lets the gateway and the service run checks against one policy set. This guide covers the CheckRequest to Cerbos mapping in CEL, policy outputs as request headers, embedded versus external PDP, bypass paths, caching trade offs and what AuthZEN leaves undefined.

Cerbos PDP v0.55.0: Strict evaluation mode, multiple JWTs, and faster conditions
Cerbos PDP v0.55.0 adds strict evaluation mode, which turns runtime errors in policy conditions into explicit denials instead of silent skips. This release also lets auxData carry multiple named JWTs, folds constant expressions at compile time, and upgrades CEL with 21 new expression functions for networking, regex, and sets.
Recommended content

Mapping business requirements to authorization policy
eBook: Zero Trust for AI, securing MCP servers

Experiment, learn, and prototype with Cerbos Playground
eBook: How to adopt externalized authorization

Framework for evaluating authorization providers and solutions
