Software Alternatives & Reviews

Oso VS Topaz.sh

Compare Oso VS Topaz.sh and see what are their differences

Oso logo Oso

A batteries-included system for authorization.

Topaz.sh logo Topaz.sh

Cloud-native authorization. Combining the best of OPA and Zanzibar
  • Oso Landing page
    Landing page //
    2023-10-16

Drop Oso Cloud into your apps to quickly add roles, sharing, fine-grained access, or any other access model you can think of.

  • Topaz.sh Landing page
    Landing page //
    2023-07-25

Topaz is an open-source authorization service providing fine grained, real-time, policy based access control for applications and APIs.

It comes with built in support for every major programming language as well as every popular authorization model (RBAC, ABAC, PBAM, ReBAC, and combinations).

Oso

Website
osohq.com
$ Details
free
Platforms
Python Rust JavaScript Node JS Ruby Go
Release Date
-

Topaz.sh

Website
topaz.sh
Pricing URL
-
$ Details
free
Platforms
Azure AWS GCP Node JS Java JavaScript Ruby Python Go .Net
Release Date
2022 October

Oso features and specs

No features have been listed yet.

Topaz.sh features and specs

  • Graph directory: Yes
  • OPA decision engine: Yes
  • ReBAC: Yes
  • ABAC: Yes
  • RBAC: Yes

Oso videos

OSO Vintage Style Chronograph 70's Style Watch Review

More videos:

  • Review - $300 For A Super Functional Retro Chronograph! (OSO Orbit Chronograph Review)
  • Review - The 70s With A Twist! - OSO Orbit Hybrid Chronograph Review

Topaz.sh videos

No Topaz.sh videos yet. You could help us improve this page by suggesting one.

+ Add video

Category Popularity

0-100% (relative to Oso and Topaz.sh)
Developer Tools
94 94%
6% 6
Developer Tool
0 0%
100% 100
Security
100 100%
0% 0
Open Source
0 0%
100% 100

Questions and Answers

As answered by people managing Oso and Topaz.sh.

What makes your product unique?

Topaz.sh's answer:

It is the only open-source authorization project to support every authorization model and combinations

How would you describe your primary audience?

Topaz.sh's answer:

Applications developers charged with implementing access controls for their applications/APIs

Which are the primary technologies used for building your product?

Topaz.sh's answer:

Golang based and uses Open Policy Agent as the decision engine

User comments

Share your experience with using Oso and Topaz.sh. For example, how are they different and which one is better?
Log in or Post with

Social recommendations and mentions

Based on our record, Oso should be more popular than Topaz.sh. It has been mentiond 6 times since March 2021. We are tracking product recommendations and mentions on various public social media platforms and blogs. They can help you identify which product is more popular and what people think of it.

Oso mentions (6)

  • Solution for ReBAC authz using attributes?
    I know of warrant.dev, osohq.com, and Ory Keto but I don't see that these evaluate based on attributes. Source: over 1 year ago
  • Authorization Framework + Data Filtering
    Oso supports applying authorization logic at the ORM layer so that you can efficiently authorize entire data sets. For example, suppose you have millions of posts in a social media application created by thousands of users, and regular users are only authorized to view posts from their friends. It would be inefficient to fetch all of the posts and authorize them one by one. It would be much more efficient to... Source: almost 3 years ago
  • Node Authorization Framework
    Oso's Node library now provides a configuration-based approach to adding role-based access control (RBAC) to your application. This new library speeds up the time it takes to build fine-grained permissions using roles and related patterns. Here are the docs + quickstart. Source: almost 3 years ago
  • AuthZ: Carta’s highly scalable permissions system
    > It's crazy this still is part of the stack where there are no great solutions. Seems like a few others have come to the same conclusion :) We're working on this at Oso (https://osohq.com) - I'm the CTO. Oso is an open source framework for authorization. Policies can reference application directly, so any authorization decisions can be made dynamically based on the data. And your data doesn't need to leave your... - Source: Hacker News / almost 3 years ago
  • The basics of role-based access control (RBAC) in SQLAlchemy
    To celebrate a new release of Oso, our open-source authorization library, this blog post demonstrates a few ways of modeling role-based access control in Python and SQLAlchemy. It has complex examples to provide you with the building blocks for adding RBAC to your app and are written in a multi-tenant production system. - Source: dev.to / about 3 years ago
View more

Topaz.sh mentions (1)

  • Authorization is still a nightmare for engineers
    Congrats on the launch! [Disclosure: I'm one of the co-founders of Aserto, the creators of Topaz]. The problem of data filtering is indeed a huge part of building an effective authorization system. Partial evaluation is one way of doing it, although with systems like OPA [0] it requires a lot of heavy lifting (parsing the returned AST and converting it into a WHERE clause). Looking forward to seeing how turnkey... - Source: Hacker News / 18 days ago

What are some alternatives?

When comparing Oso and Topaz.sh, you can also consider the following products

authzed - The platform to store, compute, and validate app permissions

Cerbos - Cerbos helps teams separate their authorization process from their core application code, making their authorization system more scalable, more secure and easier to change as the application evolves.

Aserto - Fine-grained, scalable authorization in minutes

Permit.io - Fullstack Authorization as a Service for cloud native applications

Warrant - Authorization and access control infrastructure for developers

Ory - Developer-first Access Management