# ory/hydra

Internet-scale OpenID Certified™ OpenID Connect and OAuth2.1 provider that integrates with your user management through headless APIs. Solve OIDC/OAuth2 user cases over night. Consume as a service on Ory Network or self-host. Trusted by OpenAI and many others for scale and security. Written in Go.

Repository: https://github.com/ory/hydra
Canonical: https://ross.abutalabs.com/products/hydra
Homepage: https://www.ory.com/?utm_source=github&utm_medium=banner&utm_campaign=hydra
Language: Go
License: Apache-2.0
License Family: permissive
Topics: hydra, oauth2, openid-connect, docker, server, security, authorization, identity, federation, cloud, sso, openid, oauth, openid-provider, openid-connect-provider, oauth2-server, oauth2-provider, oidc, hacktoberfest, oauth-provider
Last push: 2026-07-29T09:30:11+00:00

## Health v2 (maintenance only)
Score: 78/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 95, release rhythm 43, longevity 100
- inputs: {"age_days": 4121, "days_push": 35, "days_rel": 166, "gap_med": 213.0, "n_releases_24m": 3}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 17498, forks 1599 (observed 2026-08-28T04:11:19.925677+00:00)

## What it is
Ory Hydra is an OpenID Certified OAuth 2.0 and OpenID Connect provider server written in Go, handling token issuance, client management, and login/consent orchestration via headless APIs. It integrates with any existing identity system and can be self-hosted or consumed as a managed service on the Ory Network.

## Use cases
- issue OAuth2 access tokens for my APIs
- add OpenID Connect single sign-on to my apps
- self-host an OIDC provider that works with my existing user database
- implement machine-to-machine client credentials flows
- federate login with social providers via OIDC
- secure microservices with OAuth2 token validation
- run a certified OAuth2 server at high scale

## When to choose
- you need a hardened, OpenID Certified OAuth2/OIDC provider
- you want full control over login and consent UI while delegating identity to your own system
- you need low-latency, high-throughput token issuance
- you want to self-host or use a managed cloud IAM service

## When to avoid
- you need a full identity management solution with registration, login UI, and MFA out of the box (use Ory Kratos instead)
- you want a simple all-in-one auth library embedded in your app
- you need SAML as a first-class protocol

## Facets
- artifact type: service
- maturity: stable
- function: auth, authorization, http-server, api-framework, security
- domain: security, apis, backend, web-development, self-hosted
- platform: windows, self-hosted, cloud, go
- tags: oauth2, openid-connect, oidc, sso, identity, federation, token-issuance, headless, iam, linux, macos, docker, kubernetes

## Member repositories
- ory/hydra (main) score 78

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:11:19.925677+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:02:55.137458+00:00, confidence not recorded.
  - readme: https://github.com/ory/hydra (fetched 2026-08-28T04:11:19.925677+00:00, sha 587ee9490219)
  - homepage: https://www.ory.com/?utm_source=github&utm_medium=banner&utm_campaign=hydra (fetched 2026-08-29T08:01:04.266316+00:00, sha 9cd75b156cd4)
  - site_page: https://www.ory.com/docs/welcome (fetched 2026-08-29T08:01:04.271903+00:00, sha e6f2747eb4d2)
  - site_page: https://www.ory.com/about (fetched 2026-08-29T08:01:04.275753+00:00, sha e44652fde9f9)
  - site_page: https://www.ory.com/pricing (fetched 2026-08-29T08:01:04.269272+00:00, sha 35c1d920fc8d)
  - site_page: https://changelog.ory.com/ (fetched 2026-08-29T08:01:04.273895+00:00, sha c8e6b35f30bb)
  - site_page: https://www.ory.com/integrations (fetched 2026-08-29T08:01:04.277473+00:00, sha 966475eed325)
- Data as of 2026-08-30T08:39:29.467469+00:00.
