PermX vs Casbin.
Casbin is a powerful, policy-driven authorization library with support for ACL, RBAC, ABAC, and custom models. PermX is narrowly focused on structured RBAC with zero dependencies and a React SDK. Different tools for different needs.
Capability comparison
Ten dimensions scored head-to-head. Rows favouring PermX are bolded in the right column.
| Capability | Casbin | PermX |
|---|---|---|
| Authorization model | Policy-file driven — supports ACL, RBAC, ABAC, RESTful, and custom models via Casbin model language | Structured RBAC only — permission keys carry meaning: module.resource:field.action.scope |
| Configuration | Requires model file (.conf) + policy file (.csv) or adapter | Code-first with definePermissions() — no separate config files |
| Type safety | String-based enforcement — no compile-time key validation | Literal string types inferred from definePermissions() — compiler catches stale keys |
| React / UI integration | No official React SDK | Full React SDK: <Can>, <CanField>, <RouteGuard>, <FeatureGate>, hooks, store (~5 KB) |
| Role inheritance | Via g (grouping) function in policy — powerful but policy-language dependent | Built-in DFS with visited-set, cycle detection, depth cap 10 — no policy language |
| Database adapters | Large ecosystem of adapters (MySQL, PostgreSQL, MongoDB, Redis, etc.) | PermXDataProvider interface — Mongoose and Prisma built-in, custom adapters via single interface |
| Multi-tenancy | Via domain-based RBAC model (requires model configuration) | Built-in — cache keyed by tenantId::userId, tenant-scoped data provider |
| Runtime dependencies | casbin package + adapter packages | Zero runtime dependencies in core |
| Learning curve | Steeper — requires understanding Casbin model language, matchers, and policy syntax | Minimal — define permissions as objects, call authorize() with typed keys |
| Flexibility | Very high — can model almost any access control pattern | Focused — structured RBAC with scopes. Custom ABAC logic wraps authorize() calls |
When to choose Casbin
- You need ABAC, ACL, or custom authorization models beyond RBAC
- Your authorization rules are complex enough to warrant a policy language
- You need to share authorization models across multiple languages (Go, Java, Python, etc.)
- You want the largest ecosystem of database adapters
When to choose PermX
- RBAC with structured keys is sufficient for your access control needs
- You want typed permission keys that refactor safely across backend and frontend
- You need a React SDK with field-level, route-level, and component-level gates
- You prefer code-first configuration over policy files
- Zero runtime dependencies matter for supply-chain security and bundle weight
- You want built-in multi-tenant support without model configuration
related comparisons