specification: FinOps Framework specificationVersion: '1.0' schema: https://www.finops.org/framework/ provider: Warrant providerId: warrant-dev created: '2026-07-11' modified: '2026-07-11' reconciled: false retired: true tags: - Access Control - Authorization - Fine-Grained Authorization - Open Source - FinOps - Cost Management - FOCUS description: >- FinOps view of Warrant spend. Warrant's core authorization engine is open source (Apache-2.0) and free to self-host - in that model the cost is your own compute, storage, and the backing datastore (MySQL, Postgres, or SQLite) that runs the Warrant service, with no vendor invoice. The hosted Warrant Cloud was billed on a usage basis driven by authorization activity (objects and warrants stored, plus access checks performed), above a free developer allowance. RETIRED - Warrant was acquired by WorkOS (2024-04-23) and the hosted service was sunset 2025-11-15; hosted per-unit rates were not reconciled. Current fine-grained authorization spend is invoiced by WorkOS. notes: >- Hosted per-unit rates are not reconciled and the hosted service is retired. For current pricing, evaluate WorkOS FGA. For self-hosted deployments, the dominant costs are infrastructure (the Warrant service plus its datastore), not a Warrant license fee. sources: - https://warrant.dev/ - https://github.com/warrant-dev/warrant - https://workos.com/pricing - https://focus.finops.org/focus-specification/v1-3/ alignedWith: framework: FinOps Foundation Framework frameworkUrl: https://www.finops.org/framework/ dataSpec: FOCUS dataSpecVersion: '1.3' dataSpecUrl: https://focus.finops.org/focus-specification/v1-3/ publisherName: Warrant serviceCategory: Identity and Access Management billingModel: pricingCategory: Usage-Based billingFrequency: Monthly billingCurrency: USD chargeCategories: - Usage - Purchase - Adjustment focusColumns: ServiceName: Warrant Cloud ServiceCategory: Identity and Access Management ProviderName: Warrant PublisherName: Warrant InvoiceIssuerName: Warrant BillingCurrency: USD ChargeCategory: Usage PricingCategory: Usage-Based meters: - name: access_checks description: Authorization checks performed (POST /v2/authorize), historically the primary billed unit on Warrant Cloud. unit: requests aggregation: sum dimensions: - account - objectType - name: warrants_stored description: Relationship tuples (warrants) stored in the authorization model. unit: count aggregation: max dimensions: - account - objectType - name: objects_stored description: Objects (resources and subjects) stored in the authorization model. unit: count aggregation: max dimensions: - account - objectType - name: self_hosted_compute description: Infrastructure cost of running the self-hosted Warrant service and its datastore (no Warrant invoice). unit: hours aggregation: sum dimensions: - deployment principles: - name: Visibility description: Track access-check volume and stored objects/warrants per account and object type; on self-hosted, monitor the Warrant service and datastore infrastructure costs. - name: Allocation description: Name object types and tenants per workload/team so authorization activity maps to internal cost centers. - name: Optimization description: Cache authorization decisions client-side to reduce check volume; prune stale warrants and objects; self-host the open-source engine to trade vendor fees for owned infrastructure. - name: Accountability description: Assign owners per tenant/object type; review monthly check volume against plan allowances or self-hosted infrastructure budget. maintainers: - FN: Kin Lane email: kin@apievangelist.com