Zero-database · File-based · Multi-tenant

Git-friendly RBAC,
in the open.

Roles and permissions live as human-readable JSON files under .rbac/ — no database, no opaque policy blob. Every change is a normal, reviewable diff in your PR.

.rbac/tenants/acme-corp/roles/manager.jsonPR #482
"name": "manager",
"permissions": [
{ "resource": "invoice", "actions": ["view", "approve"] },
+ { "resource": "invoice.line-items", "actions": ["edit"] },
- { "resource": "vendor", "actions": ["delete"] },
]

Built to be trusted, not just used.

01

File-based, PR-reviewable

Roles are JSON on disk — every permission change is a normal git diff, not an opaque policy blob.

02

Multi-tenant, folder-isolated

Tenant separation is structural, not a WHERE clause you can forget.

03

Node + browser, one package

Full read/write core on the server; a synchronous, read-only snapshot client in the browser.

04

8 framework adapters, built in

NestJS, Express, Fastify, Koa, React, Vue, Angular, Svelte — thin, zero duplicated logic.

One install. Pick your framework.

Every adapter is a thin subpath export — none re-implement permission logic, all call straight into RBAC.can().

NestJSrbac-fs/nestjsExpressrbac-fs/expressFastifyrbac-fs/fastifyKoarbac-fs/koaReactrbac-fs/reactVuerbac-fs/vueAngularrbac-fs/angularSvelterbac-fs/svelte