Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

A valid ZITADEL access token tells your API who is calling; it does not automatically authorize that caller to edit every document or enter every customer’s tenant. ZITADEL provides useful building blocks—project roles, organization context, project grants, and custom claims—but your API must enforce permissions against the requested resource. For access rules involving ownership, sharing, teams, or inheritance, pair ZITADEL with application logic or a dedicated authorization engine.

Authentication is not authorization

Authentication answers who is the caller? Authorization answers may this caller perform this action on this resource in this context? A token can be correctly signed, unexpired, and intended for your API while the requested document belongs to another organization. Token validation and permission checks are separate responsibilities. ZITADEL documents its API and identity concepts at its API introduction.

It helps to distinguish four levels:

  • Application access: May the user use this application?
  • Role-based access (RBAC): Does the user have a role such as project.editor?
  • Tenant-scoped access: Does that role apply within the organization that owns the resource?
  • Resource- or relationship-based access: May this user edit this particular document because they own it, belong to its team, or have been granted access?

A long list of global roles is still coarse RBAC. “Fine-grained” is most useful when decisions account for a specific subject, action, resource, and possibly context.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose the permission model first

Model Example Good fit
RBAC admin, editor, viewer A small application with a stable set of roles.
Tenant-scoped RBAC project.write for tenant A, but not tenant B B2B SaaS where organizations have their own members and roles.
ABAC Allow export only when the tenant’s plan permits it Rules depend on user or organization attributes.
ReBAC A user can edit a document because their team owns its project Sharing, teams, nested resources, and inheritance.
Hybrid ZITADEL role plus a resource ownership or policy check Many production SaaS applications.

Start with an action matrix, not a claim list. For example:

#1 Best Overall
XYBkey WiFi TUYA Complete Security Access System Kit with Waterproof RFID Touch Keypad Door Lock, Smart Remote Door Opener, App,600-Pound Electric Magnetic Lock + ZL, Metal Sensor Switch, Doorbel
  • All-in-one kit: Your full access control kit is a complete access control system that provides everything you need in one kit (including WiFi access control host, power supply, 280kg magnetic lock + ZL bracket, sensor switch, doorbell, remote control, IC keychain)
  • The wiring is super simple and the installation is more convenient: just connect the 6 terminals to the corresponding numbers to complete the wiring, which is a step faster and solves the wiring pain points. It is really great.
  • WiFi access control keypad: supports 1000 users, IP68 outdoor waterproof, supports five ways to open the door: WiFi Tuya APP/temporary password/RFID card/password/RFID card + password, remote door opening , touch blue backlit keyboard, supports always-on mode, can set to add and delete cards
  • Sturdy 280kg Magnetic Lock - This magnetic lock has a powerful 600-pound holding force, ensuring your door stays securely locked. It features a fail-safe feature and comes with both Z- and L-shaped brackets to fit a wider range of door types. Easy installation. [Note: For single-door wooden doors, iron doors, and UPVC doors (inward opening), you can purchase the ZL bracket set.]
  • The power supply has been upgraded for super-easy installation: 1. The power input cable is pre-connected; simply plug it into an outlet (eliminating the hassle of wiring and increasing safety). The cable is available in 2-meter lengths to accommodate various installation scenarios. 2. The power output cable is pre-connected (the cable closest to the power supply is tightened before shipment; please do not loosen it). Simply plug the corresponding digital terminals into the connectors to easily complete the wiring.
Resource Action Permission
Project Read project.read
Project Change settings project.manage
Invoice Approve invoice.approve
Organization Invite a member member.invite
Organization Change billing billing.manage

Separate application capabilities from tenant and resource identity. A role key such as billing.manage describes a capability; it should not silently imply authority over every tenant or invoice. ZITADEL project role keys are machine-readable identifiers used in authorization checks and role claims, and are unique within a project. See the AddProjectRole API reference.

Configure ZITADEL roles and tenant relationships

Create application roles in the ZITADEL project that represents your application. In the Console, use the project’s role configuration; you can also create a role through the Project API. The API request shape is:

curl -X POST "https://example.com/zitadel.project.v2.ProjectService/AddProjectRole" 
  -H "Connect-Protocol-Version: 1" 
  -H "Content-Type: application/json" 
  -d '{
    "projectId": "PROJECT_ID",
    "roleKey": "project.editor",
    "displayName": "Project editor"
  }'

Use stable, narrowly named capabilities, for example:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
project.read
project.write
project.manage
member.invite
billing.read
billing.manage

Assign roles to users or service accounts through the Console or relevant ZITADEL APIs. For multi-tenant SaaS, decide explicitly how the customer organization relates to your project and who can assign roles to its users. ZITADEL’s SaaS scenario describes project grants that let customer organizations use a project and assign roles to their users.

Terminology can be confusing: current documentation commonly describes a role assignment; older material or APIs may call a related user-to-project relationship a user grant or authorization. These are not the same thing as ZITADEL administrative roles such as ORG_OWNER or PROJECT_OWNER, nor are they the same as a project grant between organizations. An application role named admin does not automatically grant authority to administer ZITADEL. See the current role retrieval guide and Actions objects reference.

Rank #2
AGPTEK RFID Door Access Control System Kit 280kg Electric Magnetic Lock
  • [Modern Technology for Home Security] This RFID Proximity door access control system kit is one of the modern electronic access control systems
  • [Safely and Reliable] The state-of-the-art CPU and integrated circuit techniques are applied to keep all the data from loss due to power failure.
  • [Easy To Access] AGPtEK door security system is powerful and can open the door using proximity cards, passwords, or the hybrid.
  • [More Convenient] The rfid lock kit access controller can provide users with more convenience by connecting to terminals, including the button for opening the door, doorbell, and electric lock that is normally open or closed.
  • [Wide Application] The door lock installation kit offers a method for controlling access safely and automatically, qualifying it as ideal equipment for businesses, offices, factories, and communities. Get the full set of door security system to update your home security!

For each request, carry or derive the relevant organization context, then verify that the resource actually belongs to that organization. A role by itself is not proof of tenant ownership.

Get role information into your API

Use token claims when a compact snapshot is enough

Roles do not necessarily appear in a token simply because they exist. Configure the project/application role settings and request the appropriate audience and scopes for your integration. A commonly documented ZITADEL audience scope has this form:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
openid
profile
email
urn:zitadel:iam:org:project:id:{project-id}:aud

Do not assume this exact set applies to every client type or flow: check the current ZITADEL guidance for your application and integration. Role retrieval and configuration details are in the role guide; claim behavior is covered by the claims documentation.

At the API boundary, validate the token’s signature, issuer, audience, expiration, and token type using a suitable library and your expected issuer configuration. Then extract the subject and configured authorization context. A sound request path is:

  1. Validate the access token. Reject missing or invalid credentials with 401 Unauthorized.
  2. Extract the subject and any configured role and organization context.
  3. Load the requested resource and its authoritative tenant or owner data.
  4. Check the tenant/resource boundary and the permission required for the requested action.
  5. Only then perform the operation. For a validly authenticated caller who lacks permission, return 403 Forbidden (or a consistent non-disclosing response where resource-existence privacy requires it).

Missing role claims should not turn into access. Treat them as denial or a configuration issue to diagnose.

Rank #3
Door Access Control System RFID Keypad 600lb Electric Magnetic Door Lock Kit with Exit Button Doorbell Chime Remote Control
  • Multiple Access Options - This access control system offers a variety of ways to enter and exit a secure area including password input, card swiping and remote control.
  • Enhanced Security - The 600LBS electromagnetic lock ensures that the door is tightly secured, enhancing the safety and security of the premises.
  • Visitor Management - Visitors can easily press the doorbell on the access keypad, letting those indoors know when someone has arrived. The indoor unit comes with a remote control that allows easy entry for visitors without the need to go outside.
  • Easy Installation - The system is user-friendly and can be installed with ease, requiring minimal time and effort.

Query the Auth API when you need current roles

If roles are too large for a token, or your application needs a fresh role lookup rather than a token snapshot, ZITADEL documents this authenticated-user permissions endpoint:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -L -X POST 
  "https://${CUSTOM_DOMAIN}/auth/v1/permissions/me/_search" 
  -H "Accept: application/json" 
  -H "Authorization: Bearer ${TOKEN}"

Use the response according to the documented API contract and requesting project context. The role guide also notes that administrator roles cannot currently be included directly in tokens and must be retrieved through ZITADEL APIs. A remote lookup adds latency and an availability dependency: define bounded caching, timeouts, and fail-closed behavior, and do not call the endpoint once per database row or object.

Use Actions for claim shaping—not as a policy engine

ZITADEL Actions can add claims or transform authorization context, but creating an Action alone does not make it run. It must be connected to a supported flow and trigger. The Actions overview and Actions concepts explain execution and configuration; the complement-token flow is relevant when adding claims to tokens.

For example, ZITADEL documents flattening role grants into a custom claim:

function flatRoles(ctx, api) {
  if (ctx.v1.user.grants === undefined ||
      ctx.v1.user.grants.count === 0) {
    return;
  }

  const grants = [];

  ctx.v1.user.grants.grants.forEach(grant => {
    grant.roles.forEach(role => {
      grants.push(grant.projectId + ":" + role);
    });
  });

  api.v1.claims.setClaim("my:zitadel:grants", grants);
}

A resulting claim might look like this:

{
  "my:zitadel:grants": [
    "project-id:project.read",
    "project-id:project.editor"
  ]
}

This makes grants easier for an application to consume; it does not decide whether a particular user may edit document:456. The API still has to evaluate the requested action and resource.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Access Control System 600lb Electric Magnetic Door Lock Kit: RFID Keypad, Remotes, Exit Button, Close to Entry Keypad & ID Card with 110-240VAC to 12VDC Power Supply(280Kg /600LB Kits)
  • Security: The electromagnetic lock provides reliable access control security, preventing unauthorized entry.
  • Convenience: The remote access control system allows authorized personnel to conveniently unlock the door remotely, for example, using a remote control.
  • Flexibility: The electromagnetic lock can release immediately upon receiving the unlock signalled, allowing for quick access.
  • Automation: The electromagnetic lock can be integrated into an automatic access control system, streamlining the entry and exit process.Multiple authorization methods: Access control systems typically support various authorization methods, such as passwords, card access, and fingerprint recognition, offering a range of access management options.
  • Practicality: The electromagnetic lock is easy to install, requires minimal space, and is suitable for various access control scenarios.

Actions can also read organization metadata and emit an application-specific tenant identifier. For instance, an organization metadata value such as crm-id can map a ZITADEL organization to the identifier your business database uses. ZITADEL provides organization metadata and custom-claim examples. Treat such values as trusted only if they are managed through a trusted administrative path; never let an end user supply a privilege-bearing tenant claim.

Keep claims compact and relatively stable. Claims are snapshots issued with a token, not a live ACL. Avoid embedding every document entitlement or large, rapidly changing permission list. Actions also have failure and timeout behavior; if a security-critical claim transformation fails, ensure the configured flow does not silently continue in a way that grants access.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Enforce tenant and resource checks in the API

For straightforward tenant-scoped RBAC, a role check can be simple, but it must be combined with a resource-scope check:

def can_update_project(user, project):
    return (
        project.organization_id == user.organization_id
        and "project.write" in user.roles
    )

For an invoice, document, or other object, load the object using an organization-scoped query where possible, then check the capability. This reduces the chance that a caller can probe or mutate another tenant’s records by changing an ID in a request. The frontend may hide buttons based on roles, but that is only a usability feature: the server is the enforcement point.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a modest system, tables such as organization_members, project_members, and document_acl may be sufficient. The application owns the rules, audit history, migrations, and consistency. For high-risk actions, consult current permissions rather than relying solely on an older token snapshot.

Best Value
MENGQI-CONTROL 4 Doors Complete TCP/IP PIN Code RFID Card/Fob Access Control Systems with North American Standard Electric Strike for Latch Doors Keypad Reader 110V Power Supply APP Remote Open Door
  • It's ANSI strike lock,widely used in North American. Note that 1).It's installed within your door frame,need to Cut Door Frame if have no existing hole. 2).It's NOT for PUSH Bar,it's for Knob lock or Mechanic Lock which has handle. 3).Lock Length is 4.84 in. Make sure size is sutiable for your door before purchase. 4)1000kg Force, Keep locked in case of power failure by default(fail secure mode), also can adjust to Fail Safe mode.
  • Control 4 doors.Get in door by swiping card or PIN code, and get out door by push button or turn lock handle/knob. Can store/download/check entry records and generate report by professional management software.Powerful and professional management software makes the system have many extended control functions.Have phone APP to open lock remotely(Support iPhone & Android )
  • User capacity: 20,000 user / up to 100,000 records. Auto open/close at any pre-set time during any day. Support "who" can enter which door at certain time, authorized access control.
  • Card Type: EM-ID Card. Less than 0.2 second Response Speed, 5-10cm Proximity Range. Desktop USB reader,read card number into software so that easy programming/register user. Detail video guide and wire diagram make all easily, you can DIY.
  • Network communication via TCP/IP, Software Support Win7/Win8/Win10/Win11 both 32 & 64 bit ALL Windows system. After programming done, it's fully stand alone running system, no need network connection, no need hook to computer.

When to add a dedicated authorization layer

Keep ZITADEL as the identity, organization, role-assignment, and token-context layer. Add application-owned checks or a policy service when decisions depend on individual resources, nested teams, sharing, delegation, inheritance, temporary access, or multiple relationship paths. For example: “A contractor may view but not export documents in projects managed by their team” is no longer just a global role lookup.

User
  |
  | OIDC login
  v
ZITADEL (identity, tenant context, coarse roles)
  |
  v
API (token validation and enforcement point)
  |
  | subject + action + resource + context
  v
Application policy or authorization engine
  |
  | allow / deny
  v
Database operation

A policy check might receive subject=user-123, action=document.edit, resource=document:456, and context such as organization=tenant-a. The API must still enforce the result before touching the resource.

Approach Use it when Main trade-off
ZITADEL roles and claims only Stable, compact application or tenant RBAC is enough. Claims are snapshots; resource-level rules can become awkward or unsafe to encode as roles.
ZITADEL plus application checks Roles are simple and ownership or membership is easy to verify in your database. Your team owns policy code, migrations, audits, and consistency.
ZITADEL plus OpenFGA/Auth0 FGA Teams, sharing, nested objects, and relationship traversal dominate access decisions. Add an authorization model, service dependency, and operational or vendor considerations.
ZITADEL plus Cedar You want explicit, reviewable, testable policy-as-code. You still need to choose and operate the evaluation architecture.
ZITADEL plus OPA/Rego Authorization belongs in a broader platform policy program spanning APIs or infrastructure. May be more operationally involved than needed for a simple application sharing model.

OpenFGA is an open-source relationship-based authorization system inspired by Zanzibar; the FGA documentation describes modeling and checks. It is a better match than roles alone when access follows resource relationships, but unnecessary for an application with only a few stable tenant roles. WorkOS FGA may suit teams already using WorkOS identity products; adopting it solely for authorization in a ZITADEL-centered stack adds another platform. Cedar comparison research is useful context, but reported comparisons should not be treated as universal performance results. Choose based on your permission shape and operational needs, not a blanket claim that one engine is always better.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Test the policy, not just the login

Build tests for allow and deny paths before relying on the configuration in production. At minimum, cover:

  • A user with the required role accessing a resource in their own organization.
  • The same user requesting an equivalent resource in a different organization.
  • A user missing the role, with the role claim missing, and with an invalid or expired token.
  • Role removal while an older access token is still valid; verify the actual revocation delay for your chosen lookup and cache strategy.
  • Action execution, timeout, and failure behavior where claims depend on Actions.
  • Authorization-service timeout or unavailability; sensitive operations should fail closed rather than proceed on an uncertain decision.
  • Cache invalidation and audit logging for grants, revocations, and consequential allow/deny decisions.

Log the subject, action, resource identifier, tenant, decision, and policy version where appropriate, while avoiding sensitive token contents. Identity audit events and authorization decision logs answer different questions; plan for both if your compliance or incident-response needs require them.

A practical decision rule

Use ZITADEL alone when your authorization model is primarily small, stable RBAC, roles are scoped clearly, and your API performs straightforward tenant and resource checks. Use ZITADEL plus application logic when relationships are simple and your database is the natural source of truth. Introduce OpenFGA or another policy system when access depends on a graph of subjects and resources, and consider Cedar or OPA when policy-as-code and broader policy governance are central requirements. In every design, validate the token, check the tenant boundary, authorize the specific action on the specific resource, and fail closed when the answer is unavailable.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.