ory/keto

The most scalable and customizable permission server on the market. Fix your slow or broken permission system with Google's proven "Zanzibar" approach....

View on GitHub ↗Jump to charts ↓Open shareable report

Summary Information

Updated 31 minutes ago
Added to GitGenius on September 12th, 2026
Created on March 17th, 2018
Open Issues & Pull Requests: 74 (+0)
GitHub issues: Enabled
Number of forks: 388
Total Stargazers: 5,397 (+0)
Total Subscribers: 55 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 11.3 hours
Mean response time: 109.3 days
90th percentile: 261.2 days
Tracked items: 27

How this project is maintained

Around half of the issues opened in the past year never receive a reply. 76% of open issues come from outside the core team, so the backlog reflects real-world use rather than internal planning. Only 2% of issues opened in the past year have been closed.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 25
New in 7 days: 0
Closed in 7 days: 0
Avg open age: 860 days
Stale 30+ days: 24
Stale 90+ days: 19

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

  • feat (18)
  • bug (17)
  • stale (14)
  • help wanted (10)
  • good first issue (9)
  • upstream (8)
  • rfc (7)
  • corp/m6 (3)

Most active issues this week

No issue events were indexed in the last 7 days.

Detailed Description

Ory Keto is an open source authorization server that implements Google's Zanzibar model for managing permissions at scale.

The tool addresses the problem of slow or broken permission systems by providing a scalable, low-latency authorization platform based on Google's proven Zanzibar approach. It uses relationship-based access control to handle billions of relationships while maintaining sub-10ms permission checks. The system supports multiple access control models including ACL, RBAC, and more flexible relationship-based patterns through the Ory Permission Language.

Keto suits organizations that need to scale permission checks across large datasets or complex authorization requirements. It works as either a managed service on the Ory Network or as a self-hosted deployment, making it adaptable to different operational preferences. The tool is cloud native and designed for Kubernetes environments, with an API-first, headless architecture that integrates with any identity provider. Teams evaluating authorization solutions should consider Keto if their current systems struggle with latency or scalability, or if they need the flexibility of relationship-based access control rather than simpler permission models.

The project maintains active development with regular engagement through discussions and documentation updates. The codebase receives consistent attention to performance optimization and feature expansion around the Zanzibar model. Security is treated as a priority with a documented vulnerability disclosure process. The project includes telemetry capabilities for monitoring deployments in production environments.