The complete toolkit to handle authentication, authorization, and organizational hierarchy, so you can stop building access systems and ship your product.
Scope permissions by organizational structure with downward inheritance. Assign a role once at a parent node and it cascades to every descendant.
Define your own permission model. Canopy stores, enforces, and evaluates it at runtime.
Users only see what they're allowed to, scoped automatically based on role assignments in the tree.
Every environment is a self-contained authorization system: its own hierarchy, roles, and permission catalog.
Hosted login with PKCE, RS256 JWTs, and JWKS. Your app never needs to handle passwords.
Manage end users, and their access, in one system.
REST API, API keys, and webhooks: everything you need to integrate Canopy into your application.
Every security-sensitive action is logged with actor, resource, and full context.