Authorizer is an open-source server that handles sign-in and access control for web and mobile apps. Teams deploy it on their own infrastructure and keep user accounts in a database they choose, with support for 13 or more databases including PostgreSQL, MySQL, MongoDB, and DynamoDB. It covers common login options like email and password, magic links, passkeys, social login through 10 providers, and one-time codes for multifactor authentication, plus SAML 2.0 and OpenID Connect for enterprise single sign-on.

What makes Authorizer notable is its built-in permissions engine and interface for AI agents. The same Go program that logs users in can answer a chatbot's question about whether a user may see a document before the document is fetched. This matters for teams connecting AI assistants to company files: a vector search may return close matches without checking who asked, but Authorizer gives the search a list of documents the user is allowed to see and drops everything else before scoring.

For detailed permissions, Authorizer embeds OpenFGA, an open-source implementation of Google's Zanzibar system, which records access as relationships. The built-in MCP server—the interface tools like Claude Code and Cursor use to call outside services—exposes three read-only functions: profile, check_permissions, and list_permissions. The maintainers say it runs only over local stdio and cannot be reached over a network, and that an agent acting for a user gets only the overlap of its own permissions and that user's. Authorizer is available for free on GitHub.