# aws-verified-permissions

Source: https://startwithidentity.com/vendors/authorization/aws-verified-permissions/
Last updated: 2026-07-03
License: content by Start with Identity. Cite the source URL.

---

## Overview
Amazon Verified Permissions is a managed, fine-grained authorization service for custom applications, built on the open-source Cedar policy language. It lets developers define and evaluate permission policies outside application code.

## What it is good at
It brings policy-based access control (PBAC and ReBAC-style patterns) as a managed AWS service: define who can do what on which resource in Cedar, evaluate at runtime, and keep authorization logic centralized and auditable. Cedar is open source and analyzable, and the service fits naturally into AWS-native and Amazon Cognito applications.

## Where it falls short
It is AWS-centric and centered on Cedar, so teams wanting a cloud-neutral engine or a broad policy tooling ecosystem may prefer independent options like OpenFGA, Cerbos, or OPA.

## Pricing
Transparent, usage-based pricing per authorization request.

## Best for, and who should look elsewhere
Choose it for managed, Cedar-based authorization in AWS applications. Look elsewhere for a cloud-neutral or ecosystem-rich engine (see [Cerbos](https://startwithidentity.com/vendors/authorization/cerbos/) or [OpenFGA](https://startwithidentity.com/vendors/authorization/openfga/)).

## Bottom line
A managed Cedar authorization service, strong for AWS-native applications wanting externalized, fine-grained access control.
