This repository contains sample store models for OpenFGA.
- Authorization Patterns
- OpenFGA Features
- Industry Examples
- OpenFGA Models and Sources in Open Source Projects
- Authoring Models using Coding Assistants
- Testing a sample store
- Modeling Resources
Models for common products and authorization patterns.
| Example | Description |
|---|---|
| Modeling Guide | Step-by-step introduction to OpenFGA modeling |
| Multi-Tenant RBAC | Multi-tenant role-based access control |
| MCP Gateway | Authorization for employee-facing and customer-facing multi-tenant MCP gateways |
| GitHub | Repository, organization, and team permissions |
| Google Drive | File, folder, and shared drive permissions |
| Entitlements | Feature entitlements and plan-based access |
| Slack | Workspace, channel, and messaging permissions |
| Role Assignments | Role assignment patterns for resource-specific roles |
| Temporal Access | Time-limited access grants with expiration |
| Super-Admin | Super-admin override patterns |
Examples focused on specific OpenFGA features.
| Example | Description |
|---|---|
| Modeling ABAC with ReBAC | Combine attribute-based and relationship-based access control |
| Condition Data Types | CEL condition expressions with different data types |
| Custom Roles | User-defined roles with dynamic permission assignment |
| Advanced Entitlements | Complex entitlement and feature-gating patterns |
| Group Resource Attributes | Group-based access with resource attributes |
| IP-Based Access | Network-based access restrictions using conditions |
| Modular Models | Splitting models into modules for team collaboration |
Complete authorization models for industry use cases. Each includes a model, sample tuples, tests, and a README describing the scenario.
| Example | Description |
|---|---|
| Accounting | Charts of accounts, invoices, expenses, payments, journal entries |
| Advertising | Campaigns, ad groups, ads, creatives, reports |
| Applicant Tracking | Jobs, candidates, applications, interviews, offers |
| Banking | Accounts, transactions, and financial operations |
| Calendar | Calendars, events, scheduling links, recordings, webinars |
| Call Center | Calls, contacts, comments, recordings |
| Chat & Messaging | Conversations, messages, groups, membership |
| CRM | Accounts, contacts, leads, opportunities, pipeline |
| Developer Portal | API keys, applications, and developer access |
| E-Commerce | Stores, products, customers, orders, reviews |
| Expenses | Expense reports, approvals, and reimbursements |
| File Storage | Drives, folders, files with hierarchical permissions |
| Healthcare | Patients, encounters, diagnoses, treatments, medications |
| Hospitality | Hotels, rooms, reservations, guest services |
| Human Resources | Employees, teams, payroll, benefits, time-off |
| IoT | Device management and telemetry access |
| Issue Tracking | Collections, tickets, comments, attachments |
| Knowledge Base | Containers, articles, attachments, public content |
| Knowledge Management | Spaces, pages, comments with publishing workflow |
| Learning Management | Courses, classes, content, activities, grading |
| Manufacturing | Production lines, machines, work orders, quality reports |
| Payment | Payments, payouts, refunds, subscriptions |
| Real Estate | Properties, listings, transactions, inspections |
AI coding assistants can help you author OpenFGA models. The modeling guidelines are maintained in the OpenFGA Best Practices Skill.
To install the skill, run:
npx skills add openfga/agent-skillsSome prompts you can try:
- Create an OpenFGA authorization model for an insurance company.
- Create an OpenFGA authorization model for B2B SaaS project management system.
- Create an OpenFGA authorization model for <Product Name> (e.g. create a model for Figma).
With the skill installed, an assistant can help create an .fga model and a .fga.yaml file with tuples and tests. Run the tests with the CLI.
You can also use DeepWiki MCP or Context7 MCP to give AI agents context when implementing OpenFGA models with an SDK.
To run a sample store's tests locally, install the following tools:
- The
fgaCLI, follow the installation instructions here to get it git
- Clone this repository
git clone https://github.com/openfga/sample-stores.git openfga-sample-stores
cd openfga-sample-stores- Run the tests for a sample store, for example
github:
SAMPLE_STORE=github
fga model test --tests "stores/${SAMPLE_STORE}/store.fga.yaml"- Linux Foundation
- agent-substrate
- canonical/lxd
- canonical/identity-platform-login-ui
- canonical/jimm
- canonical/lx4dmaas
- grafana/grafana (modular schema directory)
- SigNoz
- Community AI Platform Engineering ReBAC model for AgentGateway + OpenFGA
- lxc/incus
- zeroroot-ai/gibson
- mindersec/minder
- theopenlane/core
- instill-ai/mgmt-backend
- virtool/virtool
- concrete-utopia/utopia
- Cross-Lab-Project/crosslab
- klothoplatform/infracopilot
- ZEISS/knox
- Lakekeeper (OpenFGA model versions)
- bex-co/bex
- edgehog-device-manager/edgehog
- cloudoperators/heureka
- saga-ed/soa
If you are using OpenFGA in your open source project, please let us know by opening a PR to add your model to this list.