Authorizer 2.4 Adds Embedded OpenFGA and MCP Authorization for AI Agents
Authorizer 2.4 combines a self-hosted authentication server with an embedded OpenFGA authorization engine and a Model Context Protocol interface for permission-aware AI applications. The Go-based server supports OAuth 2.0/OIDC identity flows, relationship-based access control and API surfaces spanning GraphQL, REST, gRPC and MCP.
The current stable release is 2.4.1, published September 3, 2026. New deployments and upgrades should use 2.4.1 because it fixes security flaws in 2.4.0-era builds, including a critical admin-secret brute-force lockout bypass and high-severity machine-identity classification problems in token exchange and authorization checks.
For teams building agents over internal data, the practical change is architectural: authentication and fine-grained authorization can run in the same self-hosted service, while an MCP client can query permission decisions before accessing application resources. Authorizer is Apache-2.0 licensed and supports self-hosted database backends including SQLite, PostgreSQL and MySQL.
What Authorizer 2.4 adds
Authorizer already provided sign-in, sessions, tokens and application authentication. Version 2.4 expands that identity layer with an OpenFGA-based relationship authorization engine.
OpenFGA models permissions as relationships between subjects and objects. An application can represent facts such as a user being a member of an organization, an organization owning a project, and a member having a viewer or editor relationship to a resource. Authorization checks then evaluate those relationships instead of relying only on coarse application roles.
Authorizer can run this engine in-process or use an external OpenFGA store. The embedded option reduces the number of independently deployed services for smaller self-hosted installations, while the external path remains available for architectures that already operate OpenFGA separately.
The authorization functionality is exposed across Authorizer's GraphQL, REST, gRPC and MCP surfaces. OpenFGA's own community adopter registry describes Authorizer as embedding OpenFGA in-process and exposing model management, tuple writes and authorization decisions across those interfaces.
MCP is a permission-checking surface
Authorizer's MCP integration is aimed at applications where an AI assistant or coding agent needs to determine whether the current identity may access a resource.
The MCP server exposes read-side permission functions including profile lookup, permission checking and permission listing. This gives an agent a structured authorization query before a retrieval or application action is performed. The same underlying authorization model can also serve conventional web and API requests.
This pattern is particularly relevant to enterprise retrieval systems. A document assistant can authenticate a user through the normal identity layer and ask the authorization engine whether that identity has the required relationship to a document, project or workspace before retrieval.
The built-in MCP server uses local stdio according to the project's current documentation. That keeps the MCP transport local to the process environment; network-facing application APIs remain separate deployment surfaces.
Deployment requirements and interfaces
Authorizer is written in Go. The current source-build instructions require Go 1.24 or newer; Node.js 18 or newer is needed when building the web application and dashboard from source.
The project publishes a container image and prebuilt macOS and Linux bundles. Windows users are directed to the Docker deployment path. A basic Docker deployment can use SQLite, while production deployments can connect to PostgreSQL, MySQL and other supported databases.
Version 2 also moved server configuration to command-line arguments. Existing .env-driven deployments therefore need to account for the current configuration model when migrating.
2.4.1 is the security baseline
The 2.4.1 release is important for any evaluation of the new authorization stack because it closes flaws affecting identity classification and administrative lockout behavior.
One critical issue allowed the admin-secret brute-force lockout to be bypassed because client IP resolution could rely on spoofable forwarding headers or otherwise create separate lockout buckets. The fix centralizes trusted-proxy-aware client IP handling.
A separate high-severity issue affected delegated machine identities. A token derived from a service-account subject could lose the identity classification needed by the authorization resolver, causing the subject to be evaluated as a user in OpenFGA decisions. The release also fixes a related required_relations path that evaluated a machine token against a user subject.
Operators behind a reverse proxy, CDN or load balancer must review the 2.4.1 migration note for --trusted-proxies. Client-IP resolution now consistently uses that configuration, so every trusted proxy hop needs to be listed for accurate client attribution and lockout behavior.
Where it fits
Authorizer 2.4 is most relevant when a team wants to own its authentication data while adding object-level or relationship-level authorization to conventional applications and AI-agent workflows. Its main integration advantage is that OAuth/OIDC identity, OpenFGA decisions and an MCP-facing permission interface can share one self-hosted service.
Larger deployments should still evaluate the operational trade-off between the embedded engine and a separately managed OpenFGA service. The decision depends on scale, fault isolation, existing authorization infrastructure and whether multiple independent applications need to share the same authorization store.
For agent systems, the central design requirement remains enforcement at the resource boundary. MCP permission queries provide a useful interface for agents, while the application or retrieval service should continue enforcing authorization on the actual data operation.
Sources
- Authorizer repository and deployment documentation: https://github.com/authorizerdev/authorizer
- Authorizer 2.4 release overview: https://blog.authorizer.dev/authorizer-2-4-open-source-auth-for-ai-agents-and-modern-enterprise-apps
- Authorizer 2.4.1 security release and migration notes: https://github.com/authorizerdev/authorizer/releases/tag/2.4.1
- OpenFGA community adopter entry for Authorizer: https://github.com/openfga/community/blob/main/ADOPTERS.md
- Independent current overview: https://www.helpnetsecurity.com/2026/09/28/authorizer-open-source-authentication-server/