Skip to content
Open source

Otoroshi extension · Open source

Biscuit Studio

Biscuit tokens, natively in your API gateway.

A set of Otoroshi plugins and entities to forge, attenuate and verify Biscuit tokens — decentralized, offline-verifiable authorization tokens — right in your gateway.

Stars
4
Language
Scala
License
Apache-2.0
Last update
6 days ago

Features

What's inside

Key pairs

Generate and manage the key pairs used to sign and verify your tokens.

Forges

Token templates to mint Biscuit tokens with the facts, rules and checks you need.

Verifiers

Verify incoming tokens on any route with Datalog policies, without calling an authorization server.

Attenuators

Restrict an existing token's rights on the fly before forwarding it downstream.

RBAC policies & remote facts

Role-based policies and facts loaded from remote sources to enrich authorization decisions.

Bridges

Client credentials flow, Biscuit to user or API key, user to Biscuit, and public keys exposition.

Why Biscuit

Authorization tokens that travel well.

Biscuit is a bearer token format with public-key signatures, offline attenuation and a Datalog-based authorization language. Any service can verify a token with only the public key, and any holder can restrict a token before passing it on.

Biscuit Studio brings all of it into Otoroshi as first-class entities and plugins: forge tokens for your consumers, verify and attenuate them on your routes, and bridge them with Otoroshi users and API keys.

Biscuit Studio also runs on Otoroshi Managed instances.

This project was funded by the French Government under the France 2030 plan, operated by Cap Digital and Bpifrance, and is supported by the European Union – NextGenerationEU.

More open-source projects

Run it in productionwithout running Otoroshi.

Our extensions are available on Otoroshi Managed, fully operated by the people that wrote them. Or get professional support for your own clusters.