Cedar: A New Language for Expressive, Fast, Safe, and Analyzable Authorization
Joseph W. Cutler, Craig Disselkoen, Aaron Eline, Shaobo He, Kyle Headley, Michael Hicks, Kesha Hietala, Eleftherios Ioannidis, John H. Kastner, Anwar Mamat, Darin McAdams, Matt McCutchen
Abstract
Cedar is a new authorization policy language designed to be ergonomic, fast, safe, and analyzable. Rather than embed authorization logic in an application’s code, developers can write that logic as Cedar policies and delegate access decisions to Cedar’s evaluation engine. Cedar’s simple and intuitive syntax supports common authorization use-cases with readable policies, naturally leveraging concepts from role-based, attribute-based, and relation-based access control models. Cedar’s policy structure enables access requests to be decided quickly. Cedar’s policy validator leverages optional typing to help policy writers avoid mistakes, but not get in their way. Cedar’s design has been finely balanced to allow for a sound and complete logical encoding, which enables precise policy analysis, e.g., to ensure that when refactoring a set of policies, the authorized permissions do not change. We have modeled Cedar in the Lean programming language, and used Lean’s proof assistant to prove important properties of Cedar’s design. We have implemented Cedar in Rust, and released it open-source. Comparing Cedar to two open-source languages, OpenFGA and Rego, we find (subjectively) that Cedar has equally or more readable policies, but (objectively) performs far better.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers8
- VERINA: Benchmarking Verifiable Code GenerationZhe Ye, Zhengxu Yan, Jingxuan He, Timothe Kasriel et al.ICLR 2026 · 34 citations
- ROSpec: A Domain-Specific Language for ROS-Based Robot SoftwarePaulo Canelas, Bradley R. Schmerl, Alcides Fonseca, Christopher Steven TimperleyOOPSLA 2025 · 2 citations
- Topaz: Declarative and Verifiable Authoritative DNS at CDN-ScaleJames Larisch, Timothy Alberdingk Thijm, Suleman Ahmad, Peter Wu et al.SIGCOMM 2024 · 1 citation
- Formally Verified Cloud-Scale AuthorizationAleks Chakarov, Jaco Geldenhuys, Matthew Heck, Michael Hicks et al.ICSE 2025 · 1 citation
- Accelerating Automated Program Verifiers by Automatic Proof LocalizationKiran Gopinathan, Dionysios Spiliopoulos, Vikram Goyal, Peter Müller et al.CAV 2025 · 1 citation
Builds on2
Related papers
- Probabilistic Access Policies with Automated Reasoning SupportShaowei Zhu, Yunbo ZhangCAV 2024 · 1 citation
- The Next 700 Policy Miners: A Universal Method for Building Policy MinersCarlos Cotrini, Luca Corinzia, Thilo Weghorn, David A. BasinCCS 2019 · 19 citations
- Relia: Accelerating the Analysis of Cloud Access Control PoliciesDan Wang, Peng Zhang, Zhenrong Gu, Weibo Lin et al.ASE 2025
- Automatically Reducing Privilege for Access Control PoliciesLoris D'Antoni, Shuo Ding, Amit Goel, Mathangi Ramesh et al.OOPSLA 2024 · 11 citations
- Block public access: trust safety verification of access control policiesMalik Bouchet, Byron Cook, Bryant Cutler, Anna Druzkina et al.FSE 2020 · 25 citations
