> ## Documentation Index
> Fetch the complete documentation index at: https://stytch.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Is Authorized Sync

> Check if a user has RBAC authorization for specific resources using the Stytch Next.js SDK

export const isReact_0 = undefined

{isReact_0 &&
<Info>
  In React, use the <a href="../../hooks/use-stytch-is-authorized"><code>useStytchIsAuthorized</code></a> hook to easily access the User's authorization and react to changes.
</Info>
}

`rbac.isAuthorizedSync` is a synchronous method that returns an authorization verdict on a resource-action pair (that is, whether the logged-in User is authorized to perform the specified action on the specified Resource).

This method will use locally-cached instances of the User and the configured RBAC policy. If the RBAC policy has not been loaded, this method will always return `false`. See the [SWR caching strategy](../../resources/swr-and-caching).

If the User is not logged in, this method will always return `false`. If the resource or action provided are not valid for the configured RBAC policy, this method will return `false`.

If you need to asynchronously fetch guaranteed-fresh data from the API, use the [`rbac.isAuthorized`](./is-authorized) method.

<Note>
  As a best practice, authorization checks for sensitive actions should also occur on the backend.
</Note>

## Parameters

<ParamField path="resourceId" type="string" required>
  The human-readable ID of the resource to check authorization for.
</ParamField>

<ParamField path="action" type="string" required>
  The action to take on the specified resource.
</ParamField>

## Response

<ResponseField name="authorized" type="boolean" required>
  `true` if the User is authorized to perform the specified action on the specified resource, `false` otherwise.

  Will resolve to `false` if the RBAC policy has not been loaded or if the resource or action provided are not valid for the configured RBAC policy.
</ResponseField>

<Panel>
  <RequestExample>
    ```jsx theme={null}
    import { useStytch } from '@stytch/nextjs';

    export const AdminPanel = () => {
      const stytch = useStytch();
      const isAuthorized = stytch.rbac.isAuthorizedSync('documents', 'edit');

      return isAuthorized ? (
        <button>Edit Document</button>
      ) : (
        <p>You don't have permission to edit documents</p>
      );
    };
    ```
  </RequestExample>
</Panel>
