Start here · Explore the projects · Try the playground · Cedarling docs
Practice authorization with fifteen independent applications, from a task board to AI assistants and machine-to-machine transfers. Each project has sample users or workloads, a setup guide, exercises, and tests. Start with P1 or pick a problem that matches your own application.
Note
P1-P5 include Cedarling authorization. P6-P15 retain the tutorial starting
applications, whose marked authorization checks return FAKE ALLOW.
Run P1 to try a React task board whose API checks task permissions with Cedarling. To build the integration yourself, follow the tutorial from its permissive starting application through server enforcement and browser guidance.
Project links open the setup guides; article links open the published tutorials.
| Project | Stack | What you'll learn | Articles |
|---|---|---|---|
| P1 - Protecting a Node.js REST API with Cedarling | Node.js, Fastify, React, SQLite | Keep tenants' tasks separate and control who can read or change them. | Read tutorial |
| P2 - Preventing Cross-Tenant RAG Data Leaks with Cedarling | Node.js, Fastify, Orama, Voyage, OpenRouter | Check access to search results before documents reach AI generation. | Read tutorial |
| P3 - Authorizing MCP Incident Operations with Cedarling | Node.js, MCP, Express, OpenRouter | Control an assistant's access to incident tools, runbooks, and triage prompts. | Read tutorial |
| P4 - Securing Editorial Publishing with Cedarling | Node.js, Next.js App Router, React, SQLite | Tie publishing approval to the reviewed revision and current reviewer authority. | Read tutorial |
| P5 - Protecting Sensitive Fields and Data Exports with Cedarling | Node.js, Hono, React, SQLite | Protect individual records, sensitive fields, aggregates, and data exports. | Read tutorial |
| P6 - Reauthorizing Offline Field Inspections with Cedarling | Node.js, Fastify, React, SQLite, IndexedDB | Check current assignments before accepting work saved while offline. | - |
| P7 - Securing Real-Time Collaborative Documents with Cedarling | Node.js, Fastify, React, SQLite, SSE | Apply changing permissions to document edits, comments, sharing, and live updates. | - |
| P8 - Securing File Sharing and Blocking Path Traversal with Cedarling | Node.js, Express, React, SQLite | Combine file-access decisions with application-owned filesystem safeguards. | - |
| P9 - Securing Realtime Chat Rooms and Events with Cedarling | Node.js, Express, Socket.IO, React, SQLite | Recheck access when people join, reconnect, receive messages, or moderate a room. | - |
| P10 - Authorizing Warehouse Workloads with Cedarling | Node.js, Fastify, React, SQLite, OAuth Client Credentials | Authorize machine-to-machine transfers using warehouse relationships and current state. | - |
| P11 - Securing Active-Tenant Switching in a SaaS Workspace with Cedarling | Node.js, React Router Framework Mode, Express, PostgreSQL | Reevaluate access as users switch tenants, accept invitations, or receive support access. | - |
| P12 - Governing Employee Record Access with Cedarling | Node.js, Express, React, SQLite | Grant and revoke employee-record access while separating requesters from approvers. | - |
| P13 - Protecting Grade Publication and Guardian Access with Cedarling | Node.js, Express, React, SQLite | Separate grade editing, publication, student access, and guardian access. | - |
| P14 - Governing an AI Scheduling Assistant with Cedarling | Node.js, Fastify, React, SQLite | Authorize each scheduling action an assistant proposes before it changes anything. | - |
| P15 - Authorizing a Multi-Party Marketplace Refund with Cedarling | Node.js, Express, React, SQLite | Give buyers, sellers, support, and fraud reviewers the right views and refund actions. | - |
Follow the chosen project's README for prerequisites and startup commands. Most support Docker and native Node.js development. P3 requires Docker for its Cedarling sidecar and runs the chat client on the host.
Project PN uses application port 17000 + N and identity-provider port 18000 + N:
P1 uses 17001 / 18001, and P15 uses 17015 / 18015.
Each project README gives its exact URL; P3 exposes an MCP service rather than a web interface.
You can run different projects together. Stop a project's Docker stack before running that same project natively. Each project runs its own identity provider from shared source code, with separate registrations and cookie names.
These stacks assume a trusted local machine. Ports do not isolate browser cookies, and a project's Docker application services share its IdP's network namespace.
Each pN-project-name/ directory owns its source, dependencies, lockfile,
configuration, and tests. Shared identity-provider code lives in
shared/identity-provider/. Install dependencies
inside the package you are working on; there is no root pnpm workspace.
From that package directory:
pnpm install --frozen-lockfile
pnpm check
pnpm audit --audit-level lowpnpm check runs the package's quality checks. Also run pnpm test:e2e when
listed separately in the project's Verify section.
For more examples, visit Cedarling Learn. The engine source is maintained in the Janssen Project repository.
