---
title: "Cerbos ecosystem"
description: "Every Cerbos integration: 147 identity providers, frameworks, SDKs, gateways, deployment targets and AI tools."
canonical: "https://www.cerbos.dev/ecosystem"
source: "https://www.cerbos.dev/ecosystem"
integrations: 147
---

# Cerbos ecosystem

> 147 integrations across 10 categories, each with a page at `https://www.cerbos.dev/ecosystem/<name>`. This document lists them all, so a lookup takes one fetch rather than one per integration. An integration appears under every category it belongs to.

## Identity providers (32)

Cerbos integrates with any source of user identity, including these common authentication providers, and has native support for JWTs.

- **Auth0** — Map Auth0 Actions, Organizations, and roles to Cerbos policy inputs. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-auth0) · [Vendor site](https://auth0.com/)
- **Authentik** — Authentik property mappings shape token claims for Cerbos policy inputs. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-authentik) · [Vendor site](https://goauthentik.io/)
- **AWS Cognito** — Cognito user pool groups and custom attributes as Cerbos policy inputs. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-aws-cognito) · [Vendor site](https://aws.amazon.com/cognito/)
- **Clerk** — Clerk session claims and Organizations drive Cerbos policy evaluation. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-clerk) · [Vendor site](https://clerk.dev/)
- **Curity Identity Server** — Curity token procedure claims as principal attributes in Cerbos. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-curity) · [Vendor site](https://curity.io/)
- **Descope** — Descope JWT claims, tenant data, and role assignments feed into Cerbos policy evaluation. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-descope) · [Vendor site](https://www.descope.com/)
- **Duende IdentityServer** — Duende IdentityServer claims and scopes evaluated by Cerbos in .NET apps. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-duende) · [Vendor site](https://duendesoftware.com/)
- **EmpowerID** — EmpowerID governance roles and delegated access in Cerbos policies. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-empowerid) · [Vendor site](https://www.empowerid.com/)
- **Firebase** — Firebase custom claims feed into Cerbos for resource-level decisions. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-firebase) · [Vendor site](https://firebase.google.com/)
- **FusionAuth** — FusionAuth per-application roles and custom data fields in Cerbos policies. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-fusionauth)
- **Gluu Server** — Gluu LDAP-backed groups and OIDC claims evaluated by Cerbos policies. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-gluu) · [Vendor site](https://gluu.org/)
- **Google Identity Platform** — Google Identity Platform custom claims and tenant context feed into Cerbos policy evaluation. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-google-identity-platform) · [Vendor site](https://cloud.google.com/identity-platform)
- **JSON Web Tokens** — Cerbos natively decodes JWTs and maps claims to policy attributes. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-jwt) · [Vendor site](https://jwt.io)
- **JumpCloud** — JumpCloud directory groups and OIDC claims drive Cerbos policy evaluation. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-jumpcloud) · [Vendor site](https://jumpcloud.com/)
- **Keycloak** — Keycloak realm roles, client roles, and group hierarchies in Cerbos policies. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-keycloak) · [Vendor site](https://www.keycloak.org)
- **Kinde** — Kinde organizations and feature flags as inputs to Cerbos policies. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-kinde) · [Vendor site](https://kinde.com/)
- **LDAP** — Query any LDAPv3 directory for user attributes and group memberships. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-ldap-enrichment)
- **LDAP** — LDAP group DNs and organizational units as Cerbos principal attributes. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-ldap)
- **Magic** — Magic DID tokens and wallet addresses as Cerbos principal attributes. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-magic) · [Vendor site](https://magic.link/)
- **Microsoft Entra ID** — Entra ID security groups and app roles evaluated by Cerbos policies. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-microsoft-entra-id) · [Vendor site](https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-id)
- **Okta** — Okta groups and Universal Directory attributes as Cerbos policy inputs. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-okta) · [Vendor site](https://www.okta.com/)
- **OneLogin** — OneLogin roles and group memberships from OIDC tokens drive Cerbos policy evaluation. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-onelogin) · [Vendor site](https://www.onelogin.com/)
- **Ory** — Ory Kratos identity traits from JSON schemas feed Cerbos policies. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-ory) · [Vendor site](https://www.ory.sh/)
- **Ping Identity** — PingOne populations and PingFederate attributes in Cerbos policies. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-ping-identity) · [Vendor site](https://www.pingidentity.com/en.html)
- **SecureAuth** — SecureAuth risk signals and identity attributes in Cerbos policy checks. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-secureauth) · [Vendor site](https://www.secureauth.com/)
- **SPIFFE** — SPIFFE IDs authorize service-to-service calls through Cerbos policies. [Integration page](https://www.cerbos.dev/ecosystem/spiffe) · [Vendor site](https://spiffe.io/)
- **Stytch** — Stytch B2B organization memberships and roles in Cerbos policy checks. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-stytch) · [Vendor site](https://stytch.com/?utm_source=cerbos&utm_medium=referral)
- **Supabase** — Supabase app_metadata and JWT claims as policy inputs alongside RLS. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-supabase) · [Vendor site](https://supabase.com/)
- **SuperTokens** — Self-hosted authorization using SuperTokens session claims in Cerbos. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-supertokens) · [Vendor site](https://supertokens.com/)
- **Thales Identity** — Thales SafeNet identity attributes drive resource-level Cerbos policies. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-thales) · [Vendor site](https://cpl.thalesgroup.com/access-management)
- **WorkOS** — WorkOS Directory Sync groups and Organizations in Cerbos B2B policies. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-workos)
- **Zitadel** — Zitadel project roles and organization grants as Cerbos policy inputs. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-zitadel) · [Vendor site](https://zitadel.com/)

## Frameworks (17)

Cerbos works with a wide variety of libraries and frameworks. Jumpstart your integration with our pre-built solutions for common frameworks.

- **ASP.NET** — Authorize ASP.NET controllers and endpoints via the Cerbos .NET SDK. [Integration page](https://www.cerbos.dev/ecosystem/aspnet) · [Vendor site](https://dotnet.microsoft.com/en-us/apps/aspnet)
- **Django** — Authorize Django views and middleware via the Cerbos Python SDK. [Integration page](https://www.cerbos.dev/ecosystem/django) · [Vendor site](https://www.djangoproject.com/)
- **Express** — Enforce access control per route via Express middleware hooks. [Integration page](https://www.cerbos.dev/ecosystem/express) · [Vendor site](https://expressjs.com/)
- **FastAPI** — Inject Cerbos checks as FastAPI dependencies in endpoint signatures. [Integration page](https://www.cerbos.dev/ecosystem/fastapi) · [Vendor site](https://fastapi.tiangolo.com/)
- **Flask** — Authorize Flask routes via decorators or before-request hooks with Cerbos. [Integration page](https://www.cerbos.dev/ecosystem/flask) · [Vendor site](https://flask.palletsprojects.com/)
- **Gin** — Cerbos authorization wired into the Gin middleware chain. [Integration page](https://www.cerbos.dev/ecosystem/gin) · [Vendor site](https://gin-gonic.com/)
- **Gorilla** — Cerbos authorization wired into the Gorilla Mux middleware chain. [Integration page](https://www.cerbos.dev/ecosystem/gorilla) · [Vendor site](https://www.gorillatoolkit.org/)
- **GraphQL** — Per-field and per-resolver access control for GraphQL schemas. [Integration page](https://www.cerbos.dev/ecosystem/graphql)
- **Hono** — Authorize Hono routes and middleware via the Cerbos JavaScript SDK. [Integration page](https://www.cerbos.dev/ecosystem/hono) · [Vendor site](https://hono.dev/)
- **NestJS** — Cerbos checks via NestJS guards, decorators, and injectable modules. [Integration page](https://www.cerbos.dev/ecosystem/nestjs) · [Vendor site](https://nestjs.com/)
- **NextJS** — Authorize middleware, server components, and API routes in Next.js. [Integration page](https://www.cerbos.dev/ecosystem/nextjs) · [Vendor site](https://nextjs.org/)
- **Nuxt** — Access control in the Nitro server layer for Nuxt routes and APIs. [Integration page](https://www.cerbos.dev/ecosystem/nuxt) · [Vendor site](https://nuxt.com/)
- **React Router** — Gate data loading and mutations in React Router loaders and actions. [Integration page](https://www.cerbos.dev/ecosystem/react-router) · [Vendor site](https://reactrouter.com/)
- **Ruby on Rails** — Authorize Rails controllers and actions via the Cerbos Ruby SDK. [Integration page](https://www.cerbos.dev/ecosystem/rails) · [Vendor site](https://rubyonrails.org/)
- **Spring Boot** — Wire Cerbos into Spring Boot with annotations and bean injection. [Integration page](https://www.cerbos.dev/ecosystem/spring-boot) · [Vendor site](https://spring.io/projects/spring-boot)
- **SvelteKit** — Authorize load functions, form actions, and hooks in SvelteKit. [Integration page](https://www.cerbos.dev/ecosystem/sveltekit) · [Vendor site](https://kit.svelte.dev/)
- **VueJS** — Server-evaluated permissions surfaced to Vue.js route guards and views. [Integration page](https://www.cerbos.dev/ecosystem/vuejs) · [Vendor site](https://vuejs.org/)

## SDKs (9)

SDKs for the most popular languages and a simple API for everything else. Cerbos works with any software.

- **.NET** — NuGet package with async/await and strongly typed Cerbos models. [Integration page](https://www.cerbos.dev/ecosystem/dotnet) · [Vendor site](https://github.com/cerbos/cerbos-sdk-net)
- **Go** — gRPC-native SDK with strongly typed checks and context.Context support. [Integration page](https://www.cerbos.dev/ecosystem/go) · [Vendor site](https://github.com/cerbos/cerbos-sdk-go)
- **Java** — Maven Central SDK with blocking and CompletableFuture Cerbos clients. [Integration page](https://www.cerbos.dev/ecosystem/java) · [Vendor site](https://github.com/cerbos/cerbos-sdk-java)
- **JavaScript** — Async SDK for Node.js, edge runtimes, and browsers with TypeScript types. [Integration page](https://www.cerbos.dev/ecosystem/javascript) · [Vendor site](https://github.com/cerbos/cerbos-sdk-javascript)
- **Laravel** — Cerbos policies behind Laravel Gate::allows() and @can directives. [Integration page](https://www.cerbos.dev/ecosystem/laravel) · [Vendor site](https://github.com/cerbos/cerbos-sdk-laravel)
- **PHP** — PSR-compatible Composer package for Cerbos authorization in PHP. [Integration page](https://www.cerbos.dev/ecosystem/php) · [Vendor site](https://github.com/cerbos/cerbos-sdk-php)
- **Python** — pip-installable SDK for sync and async Cerbos authorization in Python. [Integration page](https://www.cerbos.dev/ecosystem/python) · [Vendor site](https://github.com/cerbos/cerbos-sdk-python)
- **Ruby** — Idiomatic Ruby gem for authorization checks against the Cerbos PDP. [Integration page](https://www.cerbos.dev/ecosystem/ruby) · [Vendor site](https://github.com/cerbos/cerbos-sdk-ruby)
- **Rust** — Async, type-safe Cerbos client built on tonic and tokio. [Integration page](https://www.cerbos.dev/ecosystem/rust) · [Vendor site](https://github.com/cerbos/cerbos-sdk-rust)

## Deployment (22)

Cerbos is stateless and can run anywhere a container or binary can be launched, including these common deployment targets.

- **Amazon EC2** — Standalone binary or container PDP on EC2 with full instance control. [Integration page](https://www.cerbos.dev/ecosystem/amazon-ec2) · [Vendor site](https://aws.amazon.com/ec2/)
- **Amazon Elastic Beanstalk** — Multi-container Cerbos sidecar that auto-scales with Beanstalk instances. [Integration page](https://www.cerbos.dev/ecosystem/amazon-elastic-beanstalk) · [Vendor site](https://aws.amazon.com/elasticbeanstalk/)
- **Amazon Elastic Container Service** — Stateless PDP container running as an ECS task or Fargate sidecar. [Integration page](https://www.cerbos.dev/ecosystem/amazon-ecs) · [Vendor site](https://aws.amazon.com/ecs/)
- **Amazon Elastic Kubernetes Service** — Helm-managed Cerbos on EKS with IRSA and Fargate support. [Integration page](https://www.cerbos.dev/ecosystem/amazon-eks) · [Vendor site](https://aws.amazon.com/eks/)
- **AWS Lambda** — Embedded in-process PDP for serverless authorization with no network hop. [Integration page](https://www.cerbos.dev/ecosystem/amazon-lambda) · [Vendor site](https://aws.amazon.com/lambda/)
- **Azure Container Apps** — Managed container PDP on Azure Container Apps with scaling and revision control. [Integration page](https://www.cerbos.dev/ecosystem/azure-container-apps) · [Vendor site](https://azure.microsoft.com/en-us/products/container-apps)
- **Azure Kubernetes Service** — Cerbos on AKS with workload identity and Helm-based lifecycle management. [Integration page](https://www.cerbos.dev/ecosystem/azure-aks) · [Vendor site](https://azure.microsoft.com/en-gb/products/kubernetes-service)
- **Azure Virtual Machine** — Binary or container PDP on Azure VMs with Scale Set auto-scaling. [Integration page](https://www.cerbos.dev/ecosystem/azure-virtual-machine) · [Vendor site](https://azure.microsoft.com/en-gb/products/virtual-machines)
- **Cloudflare Workers** — Serverless authorization at the network edge via Cerbos inside Cloudflare Workers. [Integration page](https://www.cerbos.dev/ecosystem/cloudflare-workers) · [Vendor site](https://workers.cloudflare.com/)
- **DigitalOcean** — Container or binary PDP on DigitalOcean App Platform, Droplets, or Managed Kubernetes. [Integration page](https://www.cerbos.dev/ecosystem/digitalocean) · [Vendor site](https://www.digitalocean.com/)
- **Docker** — Official multi-arch container image for local dev and production. [Integration page](https://www.cerbos.dev/ecosystem/docker) · [Vendor site](https://www.docker.com/)
- **Fly.io** — Stateless PDP instances placed close to users across Fly.io regions. [Integration page](https://www.cerbos.dev/ecosystem/fly-io) · [Vendor site](https://fly.io/)
- **Google Cloud Compute Engine** — Cerbos binary or container on Compute Engine with Managed Instance Groups. [Integration page](https://www.cerbos.dev/ecosystem/google-cloud-compute) · [Vendor site](https://cloud.google.com/compute)
- **Google Cloud Run** — Serverless container PDP on Cloud Run with automatic scaling and managed infrastructure. [Integration page](https://www.cerbos.dev/ecosystem/google-cloud-run) · [Vendor site](https://cloud.google.com/run)
- **Google Kubernetes Engine** — Helm-managed Cerbos on GKE with Workload Identity and Autopilot support. [Integration page](https://www.cerbos.dev/ecosystem/google-cloud-gke) · [Vendor site](https://cloud.google.com/kubernetes-engine)
- **HashiCorp Nomad** — Container PDP orchestrated by Nomad with Consul service discovery and health checks. [Integration page](https://www.cerbos.dev/ecosystem/nomad) · [Vendor site](https://www.nomadproject.io/)
- **Helm** — Official Helm chart with production-ready defaults for the Cerbos PDP. [Integration page](https://www.cerbos.dev/ecosystem/helm) · [Vendor site](https://helm.sh/)
- **Homebrew** — One-command install of the Cerbos binary on macOS or Linux. [Integration page](https://www.cerbos.dev/ecosystem/homebrew) · [Vendor site](https://brew.sh/)
- **Kubernetes** — Run the PDP as a Deployment, DaemonSet, or sidecar in any K8s cluster. [Integration page](https://www.cerbos.dev/ecosystem/kubernetes) · [Vendor site](https://kubernetes.io)
- **Railway** — Container PDP deployed to Railway with managed networking and automatic restarts. [Integration page](https://www.cerbos.dev/ecosystem/railway) · [Vendor site](https://railway.app/)
- **Render** — Container PDP running as a Render web service with managed TLS and health checks. [Integration page](https://www.cerbos.dev/ecosystem/render) · [Vendor site](https://render.com/)
- **Systemd** — Native binary managed by systemd with journal logging and auto-restarts. [Integration page](https://www.cerbos.dev/ecosystem/systemd) · [Vendor site](https://systemd.io/)

## Context sources (13)

Automatically enrich authorization requests with user profiles, group memberships, and directory roles from your identity provider, no application code changes required.

- **AWS Cognito** — Pull Cognito custom attributes and groups into the PDP at decision time. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-cognito-enrichment)
- **Data Source Extensions** — Reusable data connectors with built-in caching for the Cerbos authorization pipeline. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-data-source-extensions)
- **External API** — Call external services to fetch context data for policy evaluation. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-external-api)
- **Keycloak** — Pull realm roles, client roles, and group paths from Keycloak into policies. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-keycloak-enrichment)
- **LDAP** — Query any LDAPv3 directory for user attributes and group memberships. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-ldap-enrichment)
- **Litestream** — Read Litestream-replicated SQLite databases as a policy data source. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-litestream) · [Vendor site](https://litestream.io/)
- **Microsoft Entra ID** — Resolve Entra ID security groups and directory roles for policy evaluation. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-entra-enrichment)
- **MySQL** — Built-in data source that queries MySQL tables at decision time. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-mysql) · [Vendor site](https://www.mysql.com/)
- **Neo4j** — Traverse Neo4j relationship graphs to resolve authorization context. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-neo4j)
- **Okta** — Fetch Okta profiles and group memberships into policy evaluations. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-okta-enrichment)
- **PostgreSQL** — Built-in data source that queries PostgreSQL at decision time. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-postgresql) · [Vendor site](https://www.postgresql.org/)
- **Proxy Extensions** — Transparent request enrichment that fetches context from external systems before policy evaluation. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-proxy-extensions)
- **SQLite** — Embedded SQLite data source for local policy context lookups. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-sqlite) · [Vendor site](https://www.sqlite.org/)

## Authorization extensions (11)

Extend Cerbos authorization beyond your application to service meshes, data platforms, and Kubernetes, with native support and unified policies.

- **Apache Kafka** — Pluggable authorizer for Kafka topic, consumer group, and cluster ops. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-kafka)
- **Apache Trino** — Catalog, schema, and column-level access control via Apache Trino's authorization hook. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-trino)
- **AWS App Mesh** — Cerbos authorization via Envoy ext_authz within AWS App Mesh sidecars. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-aws-app-mesh) · [Vendor site](https://aws.amazon.com/app-mesh/)
- **Consul Connect** — Cerbos authorization via Envoy ext_authz within Consul Connect sidecars. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-consul-connect) · [Vendor site](https://www.consul.io/docs/connect)
- **Contour** — Cerbos authorization via Envoy ext_authz at the Contour ingress controller. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-contour) · [Vendor site](https://projectcontour.io/)
- **Emissary-Ingress (Ambassador)** — Cerbos authorization via Envoy ext_authz at the Emissary-Ingress API gateway. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-emissary-ingress) · [Vendor site](https://www.getambassador.io/products/api-gateway)
- **Envoy External Authorization** — Cerbos as a native ext_authz gRPC service for Envoy proxies. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-envoy)
- **Gloo Gateway** — Cerbos authorization via Envoy ext_authz at the Gloo Gateway edge. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-gloo-gateway) · [Vendor site](https://www.solo.io/products/gloo-gateway/)
- **Istio Service Mesh** — External authorizer for service-to-service calls in Istio meshes. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-istio)
- **Kubernetes Admission Control** — Validating webhook that enforces Cerbos policies on cluster resources. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-k8s-admission)
- **Route Extensions** — Protocol translation layer that lets any infrastructure component delegate authorization to Cerbos. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-route-extensions)

## Data filtering (12)

Authorization-aware query filtering that pushes access control to the data layer, so your database only returns rows users are authorized to see.

- **Apache Kafka** — Pluggable authorizer for Kafka topic, consumer group, and cluster ops. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-kafka)
- **ChromaDB** — Translate Cerbos query plans into ChromaDB metadata filters. [Integration page](https://www.cerbos.dev/ecosystem/chromadb) · [Vendor site](https://www.trychroma.com/)
- **Convex** — Convert Cerbos query plans into native Convex filter expressions. [Integration page](https://www.cerbos.dev/ecosystem/convex) · [Vendor site](https://convex.dev/)
- **Drizzle ORM** — Map Cerbos query plans to Drizzle ORM where-clause conditions. [Integration page](https://www.cerbos.dev/ecosystem/drizzle) · [Vendor site](https://orm.drizzle.team/)
- **Elasticsearch** — Emit Cerbos query plans as Elasticsearch bool query filters. [Integration page](https://www.cerbos.dev/ecosystem/elasticsearch) · [Vendor site](https://www.elastic.co/elasticsearch)
- **Mongoose** — Apply Cerbos query plans as MongoDB filter predicates via Mongoose. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-mongoose) · [Vendor site](https://mongoosejs.com/)
- **Pinecone** — Cerbos policy decisions as Pinecone metadata filters in LangGraph RAG. [Integration page](https://www.cerbos.dev/ecosystem/rag-pinecone) · [Vendor site](https://www.pinecone.io/)
- **Prisma** — Inject Cerbos query plans as Prisma where-clause filters on any model. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-prisma) · [Vendor site](https://www.prisma.io/)
- **RAG (Retrieval-Augmented Generation)** — Enforce document-level access control on vector store retrieval. [Integration page](https://www.cerbos.dev/ecosystem/rag)
- **Spring Data JPA** — Turn Cerbos query plans into JPA Specification predicates for Spring. [Integration page](https://www.cerbos.dev/ecosystem/spring-data-jpa) · [Vendor site](https://spring.io/projects/spring-data-jpa)
- **SQLAlchemy** — Append Cerbos query plans to SQLAlchemy select statements as filters. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-sqlalchemy) · [Vendor site](https://www.sqlalchemy.org/)
- **UCAST (Universal Conditions AST)** — Bridge Cerbos query plans to any data layer via the UCAST AST format. [Integration page](https://www.cerbos.dev/ecosystem/ucast) · [Vendor site](https://github.com/stalniy/ucast)

## AI (18)

Secure AI agents and tool access with fine-grained, policy-driven authorization and full audit trails.

- **Agent Gateway** — Policy-driven authorization for MCP, A2A, and LLM traffic through Agent Gateway. [Integration page](https://www.cerbos.dev/ecosystem/agent-gateway) · [Vendor site](https://agentgateway.dev/)
- **Agent2Agent Protocol** — Policy-driven authorization for inter-agent communication via the Agent2Agent protocol. [Integration page](https://www.cerbos.dev/ecosystem/a2a) · [Vendor site](https://google.github.io/A2A/)
- **Aperture by Tailscale** — Zero Trust authorization for AI agents routed through Aperture by Tailscale. [Integration page](https://www.cerbos.dev/ecosystem/aperture-by-tailscale) · [Vendor site](https://tailscale.com/aperture)
- **ChromaDB** — Translate Cerbos query plans into ChromaDB metadata filters. [Integration page](https://www.cerbos.dev/ecosystem/chromadb) · [Vendor site](https://www.trychroma.com/)
- **Claude Agent SDK** — Gate Claude agent tool calls and data access through Cerbos policies. [Integration page](https://www.cerbos.dev/ecosystem/claude-agent-sdk) · [Vendor site](https://docs.anthropic.com/en/docs/agents-and-tools/claude-agent-sdk)
- **Claude Code** — Centralized policy enforcement and audit logging for Claude Code agent tool calls. [Integration page](https://www.cerbos.dev/ecosystem/claude-code) · [Vendor site](https://code.claude.com)
- **CrewAI** — Per-agent and per-tool authorization for CrewAI multi-agent workflows through Cerbos policies. [Integration page](https://www.cerbos.dev/ecosystem/crewai)
- **FastMCP** — Drop-in Cerbos middleware for FastMCP tool and resource authorization. [Integration page](https://www.cerbos.dev/ecosystem/fastmcp) · [Vendor site](https://github.com/jlowin/fastmcp)
- **Google Agent Development Kit** — Gate Google ADK agent tool calls and data access through Cerbos policies. [Integration page](https://www.cerbos.dev/ecosystem/google-adk) · [Vendor site](https://google.github.io/adk-docs/)
- **LangChain** — Gate LangChain and LangGraph tool calls through Cerbos policies. [Integration page](https://www.cerbos.dev/ecosystem/langchain) · [Vendor site](https://www.langchain.com/)
- **LangGraph** — Per-node and per-tool authorization for LangGraph multi-step agent workflows. [Integration page](https://www.cerbos.dev/ecosystem/langgraph) · [Vendor site](https://langchain-ai.github.io/langgraph/)
- **LlamaIndex** — Enforce authorization on LlamaIndex agent tool calls and data connector access through Cerbos policies. [Integration page](https://www.cerbos.dev/ecosystem/llamaindex)
- **Model Context Protocol** — Per-tool and per-resource authorization for Model Context Protocol servers. [Integration page](https://www.cerbos.dev/ecosystem/mcp) · [Vendor site](https://modelcontextprotocol.io/)
- **OpenAI Agents SDK** — Gate OpenAI Agents SDK tool invocations through Cerbos policy evaluation. [Integration page](https://www.cerbos.dev/ecosystem/openai-agents-sdk)
- **Pinecone** — Cerbos policy decisions as Pinecone metadata filters in LangGraph RAG. [Integration page](https://www.cerbos.dev/ecosystem/rag-pinecone) · [Vendor site](https://www.pinecone.io/)
- **RAG (Retrieval-Augmented Generation)** — Enforce document-level access control on vector store retrieval. [Integration page](https://www.cerbos.dev/ecosystem/rag)
- **Semantic Kernel** — Gate Semantic Kernel plugin and function invocations through Cerbos policy evaluation. [Integration page](https://www.cerbos.dev/ecosystem/semantic-kernel)
- **Vercel AI SDK** — Gate AI tool invocations in Vercel AI SDK applications through Cerbos policy evaluation. [Integration page](https://www.cerbos.dev/ecosystem/vercel-ai-sdk)

## API gateways (16)

Enforce fine-grained authorization at the edge, rejecting unauthorized requests before they reach your services.

- **Apigee** — Cerbos policy checks via Apigee service callout policies on API proxy requests. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-apigee) · [Vendor site](https://cloud.google.com/apigee)
- **AWS API Gateway** — Lambda authorizer that evaluates Cerbos policies for API Gateway. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-aws-api-gateway) · [Vendor site](https://aws.amazon.com/api-gateway/)
- **Azure API Management** — Cerbos policy evaluation via Azure API Management inbound policies on each request. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-azure-api-management) · [Vendor site](https://azure.microsoft.com/en-us/products/api-management)
- **Broadcom Layer7 API Gateway** — Cerbos policy enforcement at the Broadcom Layer7 gateway edge. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-layer7) · [Vendor site](https://www.broadcom.com/products/software/api-management)
- **Cloudflare** — Cerbos policy checks within Cloudflare Workers at the network edge. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-cloudflare) · [Vendor site](https://www.cloudflare.com/)
- **Contour** — Cerbos authorization via Envoy ext_authz at the Contour ingress controller. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-contour) · [Vendor site](https://projectcontour.io/)
- **Emissary-Ingress (Ambassador)** — Cerbos authorization via Envoy ext_authz at the Emissary-Ingress API gateway. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-emissary-ingress) · [Vendor site](https://www.getambassador.io/products/api-gateway)
- **Envoy External Authorization** — Cerbos as a native ext_authz gRPC service for Envoy proxies. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-envoy)
- **Gloo Gateway** — Cerbos authorization via Envoy ext_authz at the Gloo Gateway edge. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-gloo-gateway) · [Vendor site](https://www.solo.io/products/gloo-gateway/)
- **Gravitee API Gateway** — Evaluate Cerbos policies on every request at the Gravitee API Gateway edge. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-gravitee) · [Vendor site](https://gravitee.io/)
- **Kong Gateway** — Evaluate Cerbos policies on every request at the Kong gateway edge. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-kong) · [Vendor site](https://konghq.com/)
- **NGINX** — Cerbos policy checks via the NGINX auth_request module at the reverse proxy edge. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-nginx) · [Vendor site](https://nginx.org/)
- **Traefik Proxy** — Cerbos policy evaluation via Traefik's ForwardAuth middleware on each request. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-traefik) · [Vendor site](https://traefik.io/)
- **Tyk Gateway** — Cerbos policy evaluation as a Tyk gateway middleware plugin. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-tyk) · [Vendor site](https://tyk.io/)
- **WSO2 API Manager** — Attach Cerbos policy checks to WSO2 API Manager request flows. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-wso2) · [Vendor site](https://wso2.com/api-manager/)
- **Zuplo API Gateway** — Inline Cerbos authorization checks within Zuplo request pipelines. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-zuplo) · [Vendor site](https://zuplo.com/)

## CI/CD (6)

Automate Cerbos policy testing and deployment as part of your CI/CD pipeline, so every policy change is validated and pushed to Cerbos Hub on merge.

- **Azure DevOps Pipelines** — Push Cerbos policies to Cerbos Hub on every merge via Azure DevOps Pipelines. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-azure-devops) · [Vendor site](https://azure.microsoft.com/en-us/products/devops/pipelines)
- **Bitbucket Pipelines** — Push Cerbos policies to Cerbos Hub on every merge via Bitbucket Pipelines. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-bitbucket-pipelines) · [Vendor site](https://bitbucket.org/product/features/pipelines)
- **Buildkite** — Push Cerbos policies to Cerbos Hub on every merge via Buildkite. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-buildkite) · [Vendor site](https://buildkite.com)
- **CircleCI** — Push Cerbos policies to Cerbos Hub on every merge via CircleCI. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-circleci) · [Vendor site](https://circleci.com)
- **GitHub Actions** — Push Cerbos policies to Cerbos Hub on every merge via GitHub Actions. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-github-actions) · [Vendor site](https://github.com/features/actions)
- **GitLab CI/CD** — Push Cerbos policies to Cerbos Hub on every merge via GitLab CI/CD. [Integration page](https://www.cerbos.dev/ecosystem/cerbos-gitlab-runners) · [Vendor site](https://docs.gitlab.com/ee/ci/)
