Ross ROSS = Recommend OSS · open-source software intelligence for agents

ory/kratos

Headless cloud-native authentication and identity management written in Go. Scales to a billion+ users. Replace Homegrown, Auth0, Okta, Firebase with better UX and DX. Passkeys, Social Sign In, OIDC, Magic Link, Multi-Factor Auth, SMS, SAML, TOTP, and more. Runs everywhere, runs best on Ory Network. observed · 2026-08-28

github.com/ory/kratos · homepage · Go · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

81/100

  • Activity 95
  • Release rhythm 51
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 132
  • age_days: 3018
  • days_rel: 166
  • days_push: 35
  • n_releases_24m: 4

Full methodology

Adoption not part of the score

13849 stars · 1179 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Ory Kratos is a headless, API-first identity and user management server written in Go that centralizes login, registration, account recovery, verification, MFA, and profile management flows. It is cloud-native, scales to very large user bases, and can be self-hosted or used via the managed Ory Network.

Use cases

  • replace Auth0 or Okta with a self-hosted identity provider
  • add login and registration flows to my app without building them myself
  • self-host a headless authentication server with passkeys and social sign-in
  • implement multi-factor authentication and account recovery for my users
  • manage user profiles and identity schemas via admin APIs
  • migrate from Firebase Auth to an open-source identity system
  • add SSO with OIDC and SAML to my application

When to choose

  • you need a dedicated, scalable identity server decoupled from your application code
  • you want self-hosted or open-source CIAM with passkeys, OIDC, SAML, and MFA support
  • you are building cloud-native apps on Kubernetes and want API-first auth
  • you need headless auth that works with any frontend framework or native app

When to avoid

  • you want a batteries-included UI or a fully managed service out of the box
  • your app is small and a simple library-based auth solution suffices
  • you need OAuth2 authorization server features alone - use Ory Hydra instead

Facets

service · maturity stable

auth http-server api-framework security security web-development backend apis self-hosted windows go cloud self-hosted identity-management ciam authentication mfa oidc saml passkeys headless user-management api-first docker kubernetes linux macos

7 sources

Member repositories

RepositoryRoleHealth v2
ory/kratosmain81

For agents

markdown · JSON · MCP: product_card(name="ory/kratos")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem