Quick Start
Install → first can() call, in under 10 lines. No database to stand up, no config file to write first.
1. Install
npm install rbac-fsRequires Node.js >=20. TypeScript is optional — every subpath ships plain .js (CJS + ESM) with bundled .d.ts types, so a .js-only project never needs a TypeScript compiler.
2. First permission check (JavaScript)
import { RBAC } from 'rbac-fs';
const rbac = new RBAC({ tenantId: 'acme-corp' });
await rbac.createRole('manager', {
permissions: [{ resource: 'invoice', actions: ['approve'] }],
});
const allowed = await rbac.can({ id: 'u1', role: 'manager' }, 'invoice', 'approve');
console.log(allowed); // true3. Same thing, in TypeScript
import { RBAC, type RbacUser } from 'rbac-fs';
const rbac = new RBAC({ tenantId: 'acme-corp' });
await rbac.createRole('manager', {
permissions: [{ resource: 'invoice', actions: ['approve'] }],
});
const user: RbacUser = { id: 'u1', role: 'manager' };
const allowed: boolean = await rbac.can(user, 'invoice', 'approve');Both snippets create .rbac/tenants/acme-corp/roles/manager.json on disk the first time they run. That file is the reviewable source of truth from then on — hand-editing it works too, and is picked up automatically (see Core Concepts → Live-reload).
4. Always close() before your process exits
await rbac.close();close() releases the chokidar file watcher (live-reload) and the audit-log write stream — skipping it can leave the Node event loop alive after your app should have exited. See examples/01-quickstart.mjs for the full runnable version.