permxv0.4

PermX vs CASL.

CASL is a popular isomorphic authorization library. PermX takes a different approach — structured permission keys instead of ability-based checks, with UI mappings baked into every permission. Here is how they compare.

Capability comparison

Ten dimensions scored head-to-head. Rows favouring PermX are bolded in the right column.

CapabilityCASLPermX
Permission modelAbility-based: define what a user can do on a subjectCoordinate-based: module.resource:field.action.scope
Type safetyRequires manual typing of abilities and subjectsdefinePermissions() infers literal string types — rename a coordinate and the compiler finds every call site
UI integration<Can> component only — no field-level gates, route guards, or feature gates<Can>, <CanField>, <RouteGuard>, <FeatureGate> — headless gates + hooks + useSyncExternalStore-backed store
Role inheritanceNot built-in — must compose abilities manuallyDFS with visited-set dedupe, cycle detection, depth cap 10
Multi-tenancyNot built-inBuilt-in — cache keyed by tenantId::userId, tenant-scoped data provider
Database adapterMongoose conditions via @casl/mongoose — tightly coupledPermXDataProvider interface — Mongoose, Prisma, or any custom adapter
Runtime dependencies@casl/ability + framework-specific packagesZero runtime dependencies in core
React SDK size~12 KB (ability + react)~5 KB gzipped — full suite of gates, hooks, and store
Framework supportPrimarily Express, adapters for othersFramework-agnostic — Express, Hono, Fastify, Koa, or raw HTTP
Field-level permissionsVia conditions on subject fieldsFirst-class — field coordinate in the permission key, CanField gate in React

When to choose CASL

When to choose PermX

related comparisons