# warrant

Source: https://startwithidentity.com/vendors/authorization/warrant/
Last updated: 2026-07-03
License: content by Start with Identity. Cite the source URL.

---

## Overview
Warrant is a fine-grained authorization service, acquired by WorkOS in 2024, offering relationship-based access control inspired by Google's Zanzibar. It lets developers model and check permissions centrally instead of scattering authorization logic through application code.

## What it is good at
Warrant provides a hosted authorization engine for ReBAC, RBAC, and ABAC patterns, with a clean API and low latency, and it fits naturally alongside the rest of the WorkOS enterprise-readiness stack (SSO, SCIM, audit logs), so B2B products can add fine-grained access control without building it.

## Where it falls short
As a hosted service now within WorkOS, it is less suited to teams that require self-hosting or a cloud-neutral, standalone engine.

## Pricing
Usage-based, within the WorkOS platform.

## Best for, and who should look elsewhere
Choose Warrant for hosted, Zanzibar-style authorization, especially with WorkOS. Look elsewhere for self-hosted or standalone engines (see [OpenFGA](https://startwithidentity.com/vendors/authorization/openfga/) or [Cerbos](https://startwithidentity.com/vendors/authorization/cerbos/)).

## Bottom line
A developer-friendly relationship-based authorization service, now part of the WorkOS enterprise-readiness stack.
