> ## Documentation Index
> Fetch the complete documentation index at: https://stytch.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Is Authorized

> Is Authorized using the Stytch Vanilla JS SDK

export const isReact_0 = undefined

{isReact_0 &&
<Info>
  In React, use the <a href="../../hooks/use-stytch-is-authorized"><code>useStytchIsAuthorized</code></a> hook to easily access the User's authorization and react to changes.
</Info>
}

`rbac.isAuthorized` is an asynchronous method that returns an authorization verdict on a resource-action pair (that is, whether the logged-in User is authorized to perform the specified action on the specified Resource).

Given a resource and action, this method will return a promise that resolves to a boolean value, indicating if the User is authorized to perform the action on the resource. Returns `true` if the User can perform the action, `false` otherwise.

If the User is not logged in, this method will always return `false`. If the resource or action provided are not valid for the configured RBAC policy, this method will return `false`.

<Note>
  As a best practice, authorization checks for sensitive actions should also occur on the backend.
</Note>

## Parameters

<ParamField path="resourceId" type="string" required>
  The human-readable ID of the resource to check authorization for.
</ParamField>

<ParamField path="action" type="string" required>
  The action to take on the specified resource.
</ParamField>

## Response

<ResponseField name="authorized" type="Promise<boolean>" required>
  `true` if the User is authorized to perform the specified action on the specified resource, `false` otherwise.

  Will resolve to `false` if the RBAC policy has not been loaded or if the resource or action provided are not valid for the configured RBAC policy.
</ResponseField>

<Panel>
  <RequestExample>
    ```js theme={null}
    import { StytchClient } from '@stytch/vanilla-js';

    const stytch = new StytchClient('${publicToken}');

    export const editDocument = async () => {
      const isAuthorized = await stytch.rbac.isAuthorized('documents', 'edit');

      if (isAuthorized) {
        // Perform edit operation
      } else {
        console.log('Not authorized to edit documents');
      }
    };
    ```
  </RequestExample>
</Panel>
