PermX vs CASL.
CASL is a popular isomorphic authorization library. PermX takes a different approach — structured permission keys instead of ability-based checks, with UI mappings baked into every permission. Here is how they compare.
Capability comparison
Ten dimensions scored head-to-head. Rows favouring PermX are bolded in the right column.
| Capability | CASL | PermX |
|---|---|---|
| Permission model | Ability-based: define what a user can do on a subject | Coordinate-based: module.resource:field.action.scope |
| Type safety | Requires manual typing of abilities and subjects | definePermissions() infers literal string types — rename a coordinate and the compiler finds every call site |
| UI integration | <Can> component only — no field-level gates, route guards, or feature gates | <Can>, <CanField>, <RouteGuard>, <FeatureGate> — headless gates + hooks + useSyncExternalStore-backed store |
| Role inheritance | Not built-in — must compose abilities manually | DFS with visited-set dedupe, cycle detection, depth cap 10 |
| Multi-tenancy | Not built-in | Built-in — cache keyed by tenantId::userId, tenant-scoped data provider |
| Database adapter | Mongoose conditions via @casl/mongoose — tightly coupled | PermXDataProvider interface — Mongoose, Prisma, or any custom adapter |
| Runtime dependencies | @casl/ability + framework-specific packages | Zero runtime dependencies in core |
| React SDK size | ~12 KB (ability + react) | ~5 KB gzipped — full suite of gates, hooks, and store |
| Framework support | Primarily Express, adapters for others | Framework-agnostic — Express, Hono, Fastify, Koa, or raw HTTP |
| Field-level permissions | Via conditions on subject fields | First-class — field coordinate in the permission key, CanField gate in React |
When to choose CASL
- You need ABAC-style attribute-based conditions on every check
- Your permission model is subject-oriented rather than module/resource-oriented
- You want to evaluate complex conditional rules (e.g., "can edit Post where authorId matches userId")
When to choose PermX
- You want structured, refactor-safe permission keys across backend and UI
- You need field-level, route-level, and component-level gates in React
- You need role inheritance with cycle protection
- You want multi-tenant support built-in
- Zero runtime dependencies matter for your supply-chain security
- You are building a SaaS with roles + subscription tiers + feature flags
related comparisons