
Otoroshi extension · Open source
Biscuit Studio
Biscuit tokens, natively in your API gateway.
A set of Otoroshi plugins and entities to forge, attenuate and verify Biscuit tokens — decentralized, offline-verifiable authorization tokens — right in your gateway.
- Stars
- 4
- Language
- Scala
- License
- Apache-2.0
- Last update
- 6 days ago
Features
What's inside
Key pairs
Generate and manage the key pairs used to sign and verify your tokens.
Forges
Token templates to mint Biscuit tokens with the facts, rules and checks you need.
Verifiers
Verify incoming tokens on any route with Datalog policies, without calling an authorization server.
Attenuators
Restrict an existing token's rights on the fly before forwarding it downstream.
RBAC policies & remote facts
Role-based policies and facts loaded from remote sources to enrich authorization decisions.
Bridges
Client credentials flow, Biscuit to user or API key, user to Biscuit, and public keys exposition.
Why Biscuit
Authorization tokens
that travel well.
Biscuit is a bearer token format with public-key signatures, offline attenuation and a Datalog-based authorization language. Any service can verify a token with only the public key, and any holder can restrict a token before passing it on.
Biscuit Studio brings all of it into Otoroshi as first-class entities and plugins: forge tokens for your consumers, verify and attenuate them on your routes, and bridge them with Otoroshi users and API keys.
Biscuit Studio also runs on Otoroshi Managed instances.
This project was funded by the French Government under the France 2030 plan, operated by Cap Digital and Bpifrance, and is supported by the European Union – NextGenerationEU.More open-source projects
Run it in productionwithout running Otoroshi.
Our extensions are available on Otoroshi Managed, fully operated by the people that wrote them. Or get professional support for your own clusters.

