Skip to main content

Overview

Relationship tuples are the core data in OpenFGA - they define who can do what to which resource. This guide shows how to create, query, update, and delete tuples effectively.

Tuple Structure

A tuple has three parts:

User Field

The subject of the relationship:

Relation Field

The type of relationship:

Object Field

The resource being accessed:

Creating Tuples

Single Tuple

Multiple Tuples (Atomic)

Organization-Wide Access

Resource Ownership

Querying Tuples

List All Tuples

Filter by User

Filter by Object

Filter by Relation

List User’s Accessible Objects

List Users with Access

Updating Tuples

Replace Relation

Transfer Ownership

Deleting Tuples

Delete Specific Tuple

Delete All User Access to Object

Delete All Object Permissions

Bulk Delete

Common Patterns

User Onboarding

Resource Sharing

Group Access

Permission Inheritance

Bulk Operations

Import from CSV

Export to JSON

Sync from External System

Validation

Check Tuple Exists

Validate Before Write

Debugging

Trace Permission Path

Performance Tips

Batch Operations

Use Group Relations

Cache Queries

Next Steps

Permission Model

Define custom models

OpenFGA Setup

Deploy OpenFGA

Authorization Guide

Learn authorization

Keycloak Integration

Sync Keycloak roles

Powerful & Flexible: Relationship tuples provide fine-grained access control at scale!