v0.1 — open beta, Apache 2.0 Open source · Apache 2.0

A native desktop GUI for SpiceDB.

Manage schemas, browse relationships, check permissions, and watch live changes — all in one fast, Apache-2.0-licensed app. Built with Rust and Tauri 2. No Electron, no telemetry, no account required.

Free · Apache 2.0 · Works with self-hosted SpiceDB and Authzed Cloud

The existing release was published under the former SpiceLens name; new releases will use the SpiceDepot name.

SpiceDepot
Active: prod · grpc.authzed.com:443
Resource
document
readme
Permission
view
Subject
user
alice
✓ Allowed
document:readme#view @ user:alice
checked_at
GhUKEzE3MTc2NzU1OTcyNDk2MTAwMA==
Consistency
fully_consistent
Built for it

Every SpiceDB API, in one window.

Six pages covering schema, relationships, checks, lookups, and a live watch stream — plus CSV import / export and a theme toggle. Forms, tables, and a streaming log; no YAML to write, no zed invocations to remember.

Schema editor

CodeMirror 6 with SpiceDB syntax highlighting. Read and write the live schema. Round-trips through the official SchemaService gRPC.

Permission check

CheckPermission with fully-consistent reads. A relationship you wrote a second ago shows up in the next check — no stale snapshots, no surprise denials.

Lookup

"Which docs can alice view?" and "Who can view doc1?" via LookupResources and LookupSubjects. Results render as a sortable table.

Relationship browser

Filter, read, and write the relationship store. Add or delete single rows inline. Bulk-delete every row matching a filter, with confirmation.

Live watch stream

Subscribe to the WatchService and see relationship changes the instant they hit the server. Filter by object type. Useful for debugging webhook integrations and bulk imports.

Multiple connections

Save endpoints for dev / staging / prod. Bearer tokens go straight to the OS keychain — Keychain on macOS, Credential Manager on Windows, Secret Service on Linux. Never written to disk.

CSV import & export

Bulk-load thousands of relationships from a CSV (TOUCH semantics, chunked under SpiceDB's per-write limit) and dump the current filter result back out the same way. Round-trip between environments without writing a script.

Dark & light themes

Toggle in the header. Preference persisted across launches. CodeMirror swaps its color scheme too, so the schema editor looks correct in both modes.

Why SpiceDepot

Built like a tool, not a portal.

SpiceDepot is a native binary. It talks gRPC directly — the same wire format as the zed CLI — so what you see in the GUI is exactly what your code sees in production.

No browser tab. No account. No telemetry. Insecure plaintext gRPC works out of the box for local dev. TLS uses rustls with native root certs.

  • Rs
    Rust + Tauri 2
    ~10 MB installer, instant cold start. The Rust side owns every gRPC call; the React webview never touches the wire.
  • Ap2.0
    Open source, permissive
    Apache 2.0 — same license SpiceDB itself uses. Read the code, file issues, send PRs. No CLA, no paid tier hiding the good features.
  • ∅
    Zero telemetry
    Nothing leaves your machine except the gRPC calls you explicitly make to SpiceDB. No analytics, no error reporting service, no "phone home" pings.
  • ×3
    Three platforms, one codebase
    macOS universal (Apple Silicon + Intel), Linux x64, Windows x64. Same UI, same features, native everywhere.
  • Actively maintained
    Development happens in the open. Follow progress, report a problem, or request a feature on GitHub.
SpiceDB APIs
8 / 8
Schema, Permissions, Watch, full coverage
Platforms
3
macOS · Linux · Windows
License
Apache 2.0
Permissive, same as SpiceDB
Price
$0
Free forever, no account
FAQ

Questions, answered.

Is SpiceDepot really free? ▾

Yes — Apache 2.0 licensed, no paid tier, no account, no ads. If it saves you time, you can chip in via GitHub Sponsors or Buy Me a Coffee, but it's never required.

What platforms does it support? ▾

macOS universal (works on Apple Silicon and Intel), Linux x64 (AppImage + .deb), and Windows x64 (.msi + setup .exe). The same Rust codebase compiles to all three.

Does it work with Authzed Cloud? ▾

Yes. Add a connection with endpoint grpc.authzed.com:443, your permission system's API token, and leave the "Insecure" checkbox unchecked (TLS via rustls). Everything else works identically to a self-hosted SpiceDB.

Is my data secure? ▾

Bearer tokens are written to your OS keychain — Apple Keychain on macOS, Credential Manager on Windows, Secret Service on Linux — never to a plain file. Schemas and relationships never leave your machine except through the gRPC calls you make. There is no telemetry of any kind.

Can I import or export relationships? ▾

Yes. The Relationships page has Import CSV and Export CSV buttons. Imports use TOUCH semantics (idempotent — existing rows don't error) and chunk automatically under SpiceDB's per-write limit, so a 50,000-row file just works. The format is plain CSV with one row per relationship.

Where do I get help? ▾

File an issue on GitHub — that's where bugs, feature requests, and questions all live.

Is it affiliated with Authzed? ▾

No. SpiceDepot is an independent open-source project. SpiceDB is built by Authzed; SpiceDepot just talks to it over the same gRPC API that any SpiceDB client uses.

Stop squinting at YAML.

Explore and manage your SpiceDB authorization data from one native desktop app. Browse the source, see what’s shipping, and help shape what comes next.

macOS · Linux · Windows · Apache 2.0