Skip to main content

Authzed Python Client

PyPI License Build Status Mailing List Discord Server Twitter

This repository houses the Python client library for Authzed.

Authzed is a database and service that stores, computes, and validates your application's permissions.

Developers create a schema that models their permissions requirements and use a client library, such as this one, to apply the schema to the database, insert data into the database, and query the data to efficiently check permissions in their applications.

Supported client API versions:

  • v1 - Core SpiceDB API for permissions checks, schema management, and relationship operations
  • materialize/v0 - Materialize API for building materialized permission views

You can find more info on each API on the Authzed API reference documentation. Additionally, Protobuf API documentation can be found on the Buf Registry Authzed API repository.

See CONTRIBUTING.md for instructions on how to contribute and perform common tasks like building the project and running tests.

Getting Started

We highly recommend following the Protecting Your First App guide to learn the latest best practice to integrate an application with Authzed.

If you're interested in examples of a specific version of the API, they can be found in their respective folders in the examples directory.

Basic Usage

Installation

This project is packaged as the wheel authzed on the Python Package Index.

If you are using pip, the command to install the library is:

pip install authzed

Initializing a client

With the exception of gRPC utility functions found in grpcutil, everything required to connect and make API calls is located in a module respective to API version.

In order to successfully connect, you will have to provide a Bearer Token with your own API Token from the Authzed dashboard in place of t_your_token_here_1234567deadbeef in the following example:

from authzed.api.v1 import Client
from grpcutil import bearer_token_credentials


client = Client(
    "grpc.authzed.com:443",
    bearer_token_credentials("t_your_token_here_1234567deadbeef"),
)

Performing an API call

from authzed.api.v1 import (
    CheckPermissionRequest,
    CheckPermissionResponse,
    ObjectReference,
    SubjectReference,
)


post_one = ObjectReference(object_type="blog/post", object_id="1")
emilia = SubjectReference(object=ObjectReference(
    object_type="blog/user",
    object_id="emilia",
))

# Is Emilia in the set of users that can read post #1?
resp = client.CheckPermission(CheckPermissionRequest(
    resource=post_one,
    permission="reader",
    subject=emilia,
))
assert resp.permissionship == CheckPermissionResponse.PERMISSIONSHIP_HAS_PERMISSION

Insecure Client Usage

When running in a context like docker compose, because of Docker's virtual networking, the gRPC client sees the SpiceDB container as "remote." It has built-in safeguards to prevent calling a remote client in an insecure manner, such as using client credentials without TLS.

However, this is a pain when setting up a development or testing environment, so we provide the InsecureClient as a convenience:

from authzed.api.v1 import InsecureClient

client = InsecureClient(
    "spicedb:50051",
    "my super secret token"
)

Materialize API

The authzed-py supports Authzed Materialize API. The Materialize API allows you to build and maintain materialized views of your permissions data in your own systems for high-performance lookups.

Learn more in the Materialize API Quickstart Guide that can be found the examples directory.

Metadata

Release files for authzed 1.25.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for authzed 1.25.0
File Size Uploaded
authzed-1.25.0.tar.gz 146.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for authzed 1.25.0
File Interpreter ABI Platform
authzed-1.25.0-py3-none-any.whl Python 3 none any Details

Total release size: 333.5 kB

Release files / authzed-1.25.0.tar.gz

Download URL authzed-1.25.0.tar.gz
Size 146.9 kB
Tags Source
SHA-256 checksum
How to use checksums
8a59617f072d64e6b4c450f1379339aa3b9a4251cc2a55d5e6abe4ac6b8b5a4c
BLAKE2b-256 checksum
How to use checksums
18823b8eada7df14079ecdbebccba83b51af3a4a31f14d3ee284038edc5f4eed
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 14, 2026.

Transparency log

Release files / authzed-1.25.0-py3-none-any.whl

Download URL authzed-1.25.0-py3-none-any.whl
Size 186.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
31bf2e4c4c562bdcb7a8b41bcb8812eb84874b70f8c162afce0a03c69655e57d
BLAKE2b-256 checksum
How to use checksums
c8aa1d0c0a825c6b749b647f80b1a8549a6d6a4b2892248f79cee94de8b3a804
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 14, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.25.0 This release

2 release files

1.24.4

2 release files

1.24.3

2 release files

1.24.1

2 release files

1.24.0

2 release files

1.22.1

2 release files

1.21.2

2 release files

1.21.1

2 release files

1.21.0

2 release files

1.20.0

2 release files

1.1.0

2 release files

1.0.0

2 release files

0.19.0

2 release files

0.18.3

2 release files

0.18.2

2 release files

0.17.0

2 release files

0.15.0

2 release files

0.14.1

2 release files

0.14.0

2 release files

0.13.0

2 release files

0.11.0

2 release files

0.10.0

2 release files

0.9.0

2 release files

0.8.0

2 release files

0.7.1

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.2

2 release files

0.4.1

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page