The authority boundary for autonomous software.
Authentication tells you who is acting.
AuthBoundry determines what they're allowed to cause.
Modern software has autonomous actors
- 👤Humans: Users operating applications
- 🤖Agents: Autonomous systems making decisions
- ⚙️Services: Microservices calling each other
- 🔌Applications: Integrations and webhooks
Traditional Authentication
Human
↓
AUTHENTICATED
Q: Who is this?
A: Authentication knows.
But what can they do?
The Authority Model
AuthBoundry answers a different question at each boundary.
Identity
Who is acting?
Session
Are they still authenticated?
Principal
What authority-bearing subject is this?
Claims
What does their identity assert?
Delegation
Has their authority been delegated?
Policy
What policies govern this principal?
Capability
What specific action is requested?
Authorization
Is this principal allowed?
Evidence
Why was this allowed or denied?
A Concrete Example
An application exposes
- invoice.read
- invoice.refund
- invoice.void
A principal may have
✓invoice.read
✗invoice.refund
✗invoice.void
AuthBoundry decides
ALLOWinvoice.read
DENYinvoice.refund
DENYinvoice.void
Capabilities are explicit. Policies determine authority. Authorization is evaluated at the boundary. Decisions produce evidence.
Ready to get started?
Explore the authority model, read the documentation, or jump into the quickstart.