The authority boundary for autonomous software.

Authentication tells you who is acting.
AuthBoundry determines what they're allowed to cause.

Modern software has autonomous actors

  • 👤Humans: Users operating applications
  • 🤖Agents: Autonomous systems making decisions
  • ⚙️Services: Microservices calling each other
  • 🔌Applications: Integrations and webhooks

Traditional Authentication

Human
AUTHENTICATED

Q: Who is this?
A: Authentication knows.

But what can they do?

The Authority Model

AuthBoundry answers a different question at each boundary.

Identity
Who is acting?
Session
Are they still authenticated?
Principal
What authority-bearing subject is this?
Claims
What does their identity assert?
Delegation
Has their authority been delegated?
Policy
What policies govern this principal?
Capability
What specific action is requested?
Authorization
Is this principal allowed?
Evidence
Why was this allowed or denied?

A Concrete Example

An application exposes

  • invoice.read
  • invoice.refund
  • invoice.void

A principal may have

invoice.read
invoice.refund
invoice.void

AuthBoundry decides

ALLOWinvoice.read
DENYinvoice.refund
DENYinvoice.void

Capabilities are explicit. Policies determine authority. Authorization is evaluated at the boundary. Decisions produce evidence.

Ready to get started?

Explore the authority model, read the documentation, or jump into the quickstart.