Skip to main content

29 docs tagged with "authorization"

View all tags

Authority Integration & Token Mediation

Access Gateway integrates with Keycloak for token validation and exchange, and with the Keymate Authorization Decision Provider for fine-grained permission evaluation.

Decision Trace

Glossary definition for Decision Trace — the policy evaluation record, distinct from OpenTelemetry distributed traces.

Delegation

Glossary definition for Delegation in the Keymate platform.

DSAC

Glossary definition for DSAC (Data Security Authorization Control) in the Keymate platform.

Extending the APISIX Plugin

Understand the Keymate APISIX access plugin architecture, configuration options, and extension points for customization.

Extending the Istio WASM Plugin

Understand the Keymate Istio WASM access plugin architecture, configuration options, deployment model, and extension points.

FGA Engine

Glossary definition for FGA Engine (Fine-Grained Authorization Engine) in the Keymate platform.

Group Model

How Keymate uses Keycloak groups to manage collective permissions through hierarchical, attribute-bearing group structures at realm scope

Java SDK

Install, configure, and use the Keymate Java SDK to perform permission checks, list permissions, and retrieve organization context from JVM-based applications.

JavaScript SDK

Install, configure, and use the Keymate JavaScript SDK to check permissions, manage tokens, and retrieve organization context from Node.js or browser apps.

Overview

Access Gateway is the centralized PDP Proxy and Edge Orchestrator that validates tokens, evaluates access rules, and enforces authorization decisions for every permission check request.

Overview

The Keymate Authorization Decision Provider is the centralized authorization decision authority that evaluates fine-grained permission checks within Keycloak.

Overview

Choose the right Keymate SDK for your platform and understand the common authorization model shared across all client libraries.

Permission Model Reference

Reference for permission evaluation request and response structures used by the Authorization Decision Provider.

Permissions

Create, browse, edit, and delete permissions in the Admin Console to bind policies to resources and scopes on a resource server

Policies

Create, edit, assign, and delete authorization and Keycloak policies in the Admin Console to govern access across tenants and clients

Policy Engine

Glossary definition for Policy Engine in the Keymate platform.

Policy Engine Overview

Central service for managing authorization policies — supports RBAC, ABAC, ReBAC, PBAC, RADAC, and Dynamic policy models.

Policy Evaluation Model

How Keymate evaluates permission requests against configured policies and produces per-resource, per-scope GRANT or DENY decisions.

RADAC

Glossary definition for RADAC (Risk-Adaptive Access Control) in the Keymate platform.

Resource Model

Understand how Keymate models protected digital assets with extended metadata, classification, and lifecycle management.

Resources

Create, browse, edit, and delete resources, resource types, and resource categories in the Admin Console

Scope

Glossary definition for Scope in the Keymate platform.

Scope Model

Define actions on resources and organize authorization boundaries with Keymate's hierarchical scope type system.