- Published on
Today I Learnt: Getting Started with Oso Authorization in Node.js
- Authors

- Name
- Mehdi Akiki
Oso provides a concise policy language (Polar) for authorization. Treat authentication as who you are, and Oso policies decide what the identity can do.
Quick example (Express + Oso):
// install: npm i oso express
const express = require("express");
const { Oso } = require("oso");
const oso = new Oso();
oso.loadStr(`allow(actor, action, resource) if actor.role = "admin";`);
const app = express();
app.get("/invoices/:id", async (req, res) => {
const user = { id: 1, role: "admin" }; // from auth middleware
const invoice = { id: +req.params.id, ownerId: 1 };
const allowed = await oso.isAllowed(user, "read", invoice);
res.status(allowed ? 200 : 403).json(invoice);
});
Tips:
- Keep policies declarative and small.
- Use resources that represent domain objects, not HTTP routes.
- Run policy tests — Oso supports unit-testing Polar rules.
Resources: Oso docs for Polar language and SDK usage per language.
I build and scale reliable production systems. Open to full-time and freelance work with U.S.-based teams that value ownership and execution.
Got something in mind?
Book a Discovery Call