ory/kratos
Headless cloud-native authentication and identity management written in Go. Scales to a billion+ users. Replace Homegrown, Auth0, Okta, Firebase with better UX and DX. Passkeys, Social Sign In, OIDC, Magic Link, Multi-Factor Auth, SMS, SAML, TOTP, and more. Runs everywhere, runs best on Ory Network. observed · 2026-08-28
Health v2 · maintenance only
81/100
- Activity 95
- Release rhythm 51
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: 132
- age_days: 3018
- days_rel: 166
- days_push: 35
- n_releases_24m: 4
Adoption not part of the score
13849 stars · 1179 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
Ory Kratos is a headless, API-first identity and user management server written in Go that centralizes login, registration, account recovery, verification, MFA, and profile management flows. It is cloud-native, scales to very large user bases, and can be self-hosted or used via the managed Ory Network.
Use cases
- replace Auth0 or Okta with a self-hosted identity provider
- add login and registration flows to my app without building them myself
- self-host a headless authentication server with passkeys and social sign-in
- implement multi-factor authentication and account recovery for my users
- manage user profiles and identity schemas via admin APIs
- migrate from Firebase Auth to an open-source identity system
- add SSO with OIDC and SAML to my application
When to choose
- you need a dedicated, scalable identity server decoupled from your application code
- you want self-hosted or open-source CIAM with passkeys, OIDC, SAML, and MFA support
- you are building cloud-native apps on Kubernetes and want API-first auth
- you need headless auth that works with any frontend framework or native app
When to avoid
- you want a batteries-included UI or a fully managed service out of the box
- your app is small and a simple library-based auth solution suffices
- you need OAuth2 authorization server features alone - use Ory Hydra instead
Facets
service · maturity stable
auth http-server api-framework security security web-development backend apis self-hosted windows go cloud self-hosted identity-management ciam authentication mfa oidc saml passkeys headless user-management api-first docker kubernetes linux macos
7 sources
- readme: https://github.com/ory/kratos · fetched 2026-08-28 · 19390bdbb9cf
- homepage: https://www.ory.com/?utm_source=github&utm_medium=banner&utm_campaign=kratos · fetched 2026-08-29 · 9cd75b156cd4
- site_page: https://www.ory.com/docs/welcome · fetched 2026-08-29 · e6f2747eb4d2
- site_page: https://www.ory.com/about · fetched 2026-08-29 · e44652fde9f9
- site_page: https://www.ory.com/integrations · fetched 2026-08-29 · 966475eed325
- site_page: https://www.ory.com/pricing · fetched 2026-08-29 · 35c1d920fc8d
- site_page: https://changelog.ory.com/ · fetched 2026-08-29 · c8e6b35f30bb
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| ory/kratos | main | 81 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem