Skip to main content

atlas-fga

The Atlas FGA (fine-grained, relationship-based authorization — Zanzibar / OpenFGA) client for Python. Native, standard-library-only, preconfigured for Atlas.

pip install atlas-fga

Quickstart

from atlas_fga import AtlasFga

fga = AtlasFga(secret_key="sk_live_...", store_id="store_123")

# write a relationship tuple
fga.write_tuples([{"user": "user:alice", "relation": "viewer", "object": "doc:readme"}])

# ask an access question
fga.check(user="user:alice", relation="viewer", object="doc:readme").allowed  # True

# list the objects a user can reach
fga.list_objects(user="user:alice", relation="viewer", type="doc").objects  # ['doc:readme']

Configuration falls back to the environment when not passed: ATLAS_SECRET_KEY, ATLAS_FGA_STORE_ID, ATLAS_FGA_MODEL_ID, and ATLAS_FGA_URL (base URL, default https://api.atlasauth.net). So AtlasFga() works when those are set.

Operations

Method Atlas route
check(user=, relation=, object=) POST /v1/fga/stores/:store/check
batch_check(checks) POST /v1/fga/stores/:store/batch-check
write(writes=, deletes=) / write_tuples(...) / delete_tuples(...) POST /v1/fga/stores/:store/write
read(user=, relation=, object=) POST /v1/fga/stores/:store/read
list_objects(user=, relation=, type=) POST /v1/fga/stores/:store/list-objects
expand(object=, relation=) POST /v1/fga/stores/:store/expand
list_stores / create_store / get_store / delete_store /v1/fga/stores
list_models / create_model / get_model /v1/fga/stores/:store/authorization-models

fga.store("store_id") returns a BoundStore with the store id fixed, for the common single-store case.

Errors

Non-2xx responses raise AtlasFgaError carrying Atlas's {"errors": [...]} envelope:

from atlas_fga import AtlasFgaError
try:
    fga.check(user="user:a", relation="viewer", object="doc:1")
except AtlasFgaError as e:
    if e.code == "store_id_not_found":
        ...

Relationship to OpenFGA

Atlas's engine is OpenFGA-shaped (same model DSL/JSON, same tuple vocabulary, same operations) and also exposes an OpenFGA wire-compatible mirror at /v1/openfga that the stock openfga-sdk can drive for check / write / stores / models (configure its api_url to https://<host>/v1/openfga and the credential as the Atlas secret key).

This client targets the native /v1/fga surface because list-objects, read, and expand live only there (not on /v1/openfga), and /v1/fga wraps responses in Atlas's {"object": ...} envelope — read returns a ListPage ({"object":"list", "data", "has_more"}) with each tuple's object named target, rather than OpenFGA's {"tuples", "continuation_token"}. Auth is an Atlas secret key (Authorization: Bearer sk_…, scopes fga:read/fga:write), not an OpenFGA store-scoped token. Model format and tuple semantics are identical to OpenFGA.

Development

python -m unittest discover -s tests -v   # no third-party deps required

Metadata

Release files for atlas-fga 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for atlas-fga 0.1.0
File Size Uploaded
atlas_fga-0.1.0.tar.gz 7.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for atlas-fga 0.1.0
File Interpreter ABI Platform
atlas_fga-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 15.2 kB

Release files / atlas_fga-0.1.0.tar.gz

Download URL atlas_fga-0.1.0.tar.gz
Size 7.9 kB
Tags Source
SHA-256 checksum
How to use checksums
18bb208ea9b864cd5d514003e27f796f356a665659567416361de9f18637e8d5
BLAKE2b-256 checksum
How to use checksums
1e7b962dcf790aa924feb2859bd89cecf842eb83c45ed71d147a7d438c10828d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.6

Release files / atlas_fga-0.1.0-py3-none-any.whl

Download URL atlas_fga-0.1.0-py3-none-any.whl
Size 7.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b3e61594cb254eeebf0d867609187e4039afc6f37c61270cfcbda054d0c264d7
BLAKE2b-256 checksum
How to use checksums
a573f0e8b2ce24d1ed5d5ee8e672a713323a333a73dc0a1008e99b0eac5eccc4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.6

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page