> ## Documentation Index
> Fetch the complete documentation index at: https://docs.bijection.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Module: access/cedar

> Offline Cedar exports of a completed access model.

Offline Cedar exports of a completed access model. Supplied rows and
identities are comparison inputs, never proof of current authority.

## Type Aliases

### AccessCedarPolicies

Ƭ **AccessCedarPolicies**: `Object`

A model compiled to Cedar: a schema in Cedar's schema syntax, one template
per role and the static policies, all in Cedar's policy syntax. They depend
on the declaration only.

#### Type declaration

| Name | Type |
| :- | :- |
| `schema` | `string` |
| `templates` | `Record`\<`string`, `string`> |
| `policies` | `Record`\<`string`, `string`> |

***

### AccessCedarUid

Ƭ **AccessCedarUid**: `Object`

A Cedar entity reference in Cedar's JSON format.

#### Type declaration

| Name | Type |
| :- | :- |
| `type` | `string` |
| `id` | `string` |

***

### AccessCedarEntities

Ƭ **AccessCedarEntities**: `Object`

The Cedar data a world of rows determines, in Cedar's JSON formats: the
entities, one template per tenant-defined role and scope, and one template
link per live grant or directory row.

#### Type declaration

| Name | Type |
| :- | :- |
| `templates` | `Record`\<`string`, `string`> |
| `entities` | \{ `uid`: [`AccessCedarUid`](/api/modules/access_cedar#accesscedaruid) ; `attrs`: `Record`\<`string`, `unknown`> ; `parents`: [`AccessCedarUid`](/api/modules/access_cedar#accesscedaruid)\[]  }\[] |
| `templateLinks` | \{ `templateId`: `string` ; `newId`: `string` ; `values`: \{ `?principal`: [`AccessCedarUid`](/api/modules/access_cedar#accesscedaruid) ; `?resource`: [`AccessCedarUid`](/api/modules/access_cedar#accesscedaruid)  }  }\[] |

## Functions

### cedarPolicies

▸ **cedarPolicies**(`access`): [`AccessCedarPolicies`](/api/modules/access_cedar#accesscedarpolicies)

Serialize the model's schema, role templates and static policies.

#### Parameters

| Name | Type |
| :- | :- |
| `access` | [`AccessModel`](/api/interfaces/server.AccessModel) |

#### Returns

[`AccessCedarPolicies`](/api/modules/access_cedar#accesscedarpolicies)

***

### cedarEntities

▸ **cedarEntities**(`access`, `tables`, `now`, `coverage?`): [`AccessCedarEntities`](/api/modules/access_cedar#accesscedarentities)

Serialize the entities and live grant links implied by rows at `now`.
Source-backed directory rows require their explicit coverage evidence.
Export does not authenticate the inputs or read deployment state.

#### Parameters

| Name | Type |
| :- | :- |
| `access` | [`AccessModel`](/api/interfaces/server.AccessModel) |
| `tables` | `Record`\<`string`, readonly `Record`\<`string`, `unknown`>\[]> |
| `now` | `number` |
| `coverage?` | (`sourceId`: `string`, `table`: `string`, `record`: `string`) => `null` \| [`AccessDirectoryCoverage`](/api/modules/server#accessdirectorycoverage) |

#### Returns

[`AccessCedarEntities`](/api/modules/access_cedar#accesscedarentities)

***

### cedarContext

▸ **cedarContext**(`access`, `identity`): `Record`\<`string`, `unknown`>

Encode the model's declared claims and request narrowing for an identity.
The model is required: claim defaults and resource scopes depend on it.
This transformation never authenticates or impersonates the identity.

#### Parameters

| Name | Type |
| :- | :- |
| `access` | [`AccessModel`](/api/interfaces/server.AccessModel) |
| `identity` | `null` \| [`UserIdentity`](/api/interfaces/server.UserIdentity) |

#### Returns

`Record`\<`string`, `unknown`>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.