AuthZEN

The eval-server answers the OpenID AuthZEN Authorization API 1.0, so an API gateway, an identity platform or a SaaS app that already speaks AuthZEN can ask Prismor for a decision with no Prismor adapter.

prismor eval-server --port 7071 --api-key "$KEY"   # add --identity-* to verify end users
Endpoint
POST /access/v1/evaluationone decision
POST /access/v1/evaluationsa batch, with top-level defaults and options.evaluations_semantic (execute_all, deny_on_first_deny, permit_on_first_permit)
GET /.well-known/authzen-configurationPDP metadata

X-Request-ID is echoed back. A denial is 200 with "decision": false; a malformed request is 400; a missing or wrong API key is 401.

How a request maps to a tool call

AuthZENPrismor
action.namethe tool (tool.name, matched by fields: [tool_name] rules)
action.propertiesthe tool's arguments (args.*)
resource.type / id / propertiesresource.kind / id / attr.*
subject.type + idthe asserted user, "<type>:<id>"
context.event_type, agent_name, session_id, explainoptional
curl -s localhost:7071/access/v1/evaluation \
  -H "Authorization: Bearer $KEY" \
  -H "X-Prismor-Identity: Bearer $USER_JWT" \
  -d '{"subject": {"type": "user", "id": "bob"},
       "action": {"name": "refund_order", "properties": {"amount": 900}},
       "resource": {"type": "order", "id": "o-1", "properties": {"owner": "alice"}}}'
{"decision": false,
 "context": {"verdict": "block", "rule_id": "refund-cap",
             "reason": "[HIGH] Refunds of 500 or more need finance", "subject": {"user_id": "bob", "source": "jwt", "roles": ["support"]}}}

Roles never come from subject.properties

AuthZEN lets a caller describe the subject however it likes. Prismor does not read subject.properties as principal attributes: that would let any caller grant itself admin. Roles and claims come only from the end user's token in X-Prismor-Identity (identity verification); when a valid token is present it also replaces the asserted subject.id.

The policy that judges an AuthZEN request is always the server's own: unlike /v1/evaluate, the request cannot name a workspace.

"context": {"explain": true} returns the decision trace under context.explain.