Schema editor
CodeMirror 6 with SpiceDB syntax highlighting. Read and write
the live schema. Round-trips through the official
SchemaService gRPC.
Manage schemas, browse relationships, check permissions, and watch live changes — all in one fast, Apache-2.0-licensed app. Built with Rust and Tauri 2. No Electron, no telemetry, no account required.
Free · Apache 2.0 · Works with self-hosted SpiceDB and Authzed Cloud
The existing release was published under the former SpiceLens name; new releases will use the SpiceDepot name.
Six pages covering schema, relationships, checks, lookups, and a live watch stream — plus CSV import / export and a theme toggle. Forms, tables, and a streaming log; no YAML to write, no zed invocations to remember.
CodeMirror 6 with SpiceDB syntax highlighting. Read and write
the live schema. Round-trips through the official
SchemaService gRPC.
CheckPermission with fully-consistent reads. A relationship you wrote a second ago shows up in the next check — no stale snapshots, no surprise denials.
"Which docs can alice view?" and "Who can view doc1?" via
LookupResources and
LookupSubjects.
Results render as a sortable table.
Filter, read, and write the relationship store. Add or delete single rows inline. Bulk-delete every row matching a filter, with confirmation.
Subscribe to the WatchService and see relationship changes the instant they hit the server. Filter by object type. Useful for debugging webhook integrations and bulk imports.
Save endpoints for dev / staging / prod. Bearer tokens go straight to the OS keychain — Keychain on macOS, Credential Manager on Windows, Secret Service on Linux. Never written to disk.
Bulk-load thousands of relationships from a CSV (TOUCH semantics, chunked under SpiceDB's per-write limit) and dump the current filter result back out the same way. Round-trip between environments without writing a script.
Toggle in the header. Preference persisted across launches. CodeMirror swaps its color scheme too, so the schema editor looks correct in both modes.
SpiceDepot is a native binary. It talks gRPC directly — the same
wire format as the zed CLI — so what you see
in the GUI is exactly what your code sees in production.
No browser tab. No account. No telemetry. Insecure plaintext gRPC works out of the box for local dev. TLS uses rustls with native root certs.
Yes — Apache 2.0 licensed, no paid tier, no account, no ads. If it saves you time, you can chip in via GitHub Sponsors or Buy Me a Coffee, but it's never required.
macOS universal (works on Apple Silicon and Intel), Linux x64 (AppImage + .deb), and Windows x64 (.msi + setup .exe). The same Rust codebase compiles to all three.
Yes. Add a connection with endpoint grpc.authzed.com:443,
your permission system's API token, and leave the "Insecure"
checkbox unchecked (TLS via rustls). Everything else works
identically to a self-hosted SpiceDB.
Bearer tokens are written to your OS keychain — Apple Keychain on macOS, Credential Manager on Windows, Secret Service on Linux — never to a plain file. Schemas and relationships never leave your machine except through the gRPC calls you make. There is no telemetry of any kind.
Yes. The Relationships page has Import CSV and Export CSV buttons. Imports use TOUCH semantics (idempotent — existing rows don't error) and chunk automatically under SpiceDB's per-write limit, so a 50,000-row file just works. The format is plain CSV with one row per relationship.
File an issue on GitHub — that's where bugs, feature requests, and questions all live.
No. SpiceDepot is an independent open-source project. SpiceDB is built by Authzed; SpiceDepot just talks to it over the same gRPC API that any SpiceDB client uses.
Explore and manage your SpiceDB authorization data from one native desktop app. Browse the source, see what’s shipping, and help shape what comes next.
macOS · Linux · Windows · Apache 2.0