permxv0.4

PermX vs Casbin.

Casbin is a powerful, policy-driven authorization library with support for ACL, RBAC, ABAC, and custom models. PermX is narrowly focused on structured RBAC with zero dependencies and a React SDK. Different tools for different needs.

Capability comparison

Ten dimensions scored head-to-head. Rows favouring PermX are bolded in the right column.

CapabilityCasbinPermX
Authorization modelPolicy-file driven — supports ACL, RBAC, ABAC, RESTful, and custom models via Casbin model languageStructured RBAC only — permission keys carry meaning: module.resource:field.action.scope
ConfigurationRequires model file (.conf) + policy file (.csv) or adapterCode-first with definePermissions() — no separate config files
Type safetyString-based enforcement — no compile-time key validationLiteral string types inferred from definePermissions() — compiler catches stale keys
React / UI integrationNo official React SDKFull React SDK: <Can>, <CanField>, <RouteGuard>, <FeatureGate>, hooks, store (~5 KB)
Role inheritanceVia g (grouping) function in policy — powerful but policy-language dependentBuilt-in DFS with visited-set, cycle detection, depth cap 10 — no policy language
Database adaptersLarge ecosystem of adapters (MySQL, PostgreSQL, MongoDB, Redis, etc.)PermXDataProvider interface — Mongoose and Prisma built-in, custom adapters via single interface
Multi-tenancyVia domain-based RBAC model (requires model configuration)Built-in — cache keyed by tenantId::userId, tenant-scoped data provider
Runtime dependenciescasbin package + adapter packagesZero runtime dependencies in core
Learning curveSteeper — requires understanding Casbin model language, matchers, and policy syntaxMinimal — define permissions as objects, call authorize() with typed keys
FlexibilityVery high — can model almost any access control patternFocused — structured RBAC with scopes. Custom ABAC logic wraps authorize() calls

When to choose Casbin

When to choose PermX

related comparisons