# ory/kratos

Headless cloud-native authentication and identity management written in Go. Scales to a billion+ users. Replace Homegrown, Auth0, Okta, Firebase with better UX and DX. Passkeys, Social Sign In, OIDC, Magic Link, Multi-Factor Auth, SMS, SAML, TOTP, and more. Runs everywhere, runs best on Ory Network.

Repository: https://github.com/ory/kratos
Canonical: https://ross.abutalabs.com/products/ory-kratos
Homepage: https://www.ory.com/?utm_source=github&utm_medium=banner&utm_campaign=kratos
Language: Go
License: Apache-2.0
License Family: permissive
Topics: identity, identity-management, user-management, users, user, login, registration, profile-management, user-profiles, user-profile, hacktoberfest
Last push: 2026-07-29T09:30:37+00:00

## Health v2 (maintenance only)
Score: 81/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 95, release rhythm 51, longevity 100
- inputs: {"age_days": 3018, "days_push": 35, "days_rel": 166, "gap_med": 132, "n_releases_24m": 4}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 13849, forks 1179 (observed 2026-08-28T04:11:04.952268+00:00)

## What it is
Ory Kratos is a headless, API-first identity and user management server written in Go that centralizes login, registration, account recovery, verification, MFA, and profile management flows. It is cloud-native, scales to very large user bases, and can be self-hosted or used via the managed Ory Network.

## Use cases
- replace Auth0 or Okta with a self-hosted identity provider
- add login and registration flows to my app without building them myself
- self-host a headless authentication server with passkeys and social sign-in
- implement multi-factor authentication and account recovery for my users
- manage user profiles and identity schemas via admin APIs
- migrate from Firebase Auth to an open-source identity system
- add SSO with OIDC and SAML to my application

## When to choose
- you need a dedicated, scalable identity server decoupled from your application code
- you want self-hosted or open-source CIAM with passkeys, OIDC, SAML, and MFA support
- you are building cloud-native apps on Kubernetes and want API-first auth
- you need headless auth that works with any frontend framework or native app

## When to avoid
- you want a batteries-included UI or a fully managed service out of the box
- your app is small and a simple library-based auth solution suffices
- you need OAuth2 authorization server features alone - use Ory Hydra instead

## Facets
- artifact type: service
- maturity: stable
- function: auth, http-server, api-framework, security
- domain: security, web-development, backend, apis, self-hosted
- platform: windows, go, cloud, self-hosted
- tags: identity-management, ciam, authentication, mfa, oidc, saml, passkeys, headless, user-management, api-first, docker, kubernetes, linux, macos

## Member repositories
- ory/kratos (main) score 81

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:11:04.952268+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:12:59.674565+00:00, confidence not recorded.
  - readme: https://github.com/ory/kratos (fetched 2026-08-28T04:11:04.952268+00:00, sha 19390bdbb9cf)
  - homepage: https://www.ory.com/?utm_source=github&utm_medium=banner&utm_campaign=kratos (fetched 2026-08-29T08:07:10.184316+00:00, sha 9cd75b156cd4)
  - site_page: https://www.ory.com/docs/welcome (fetched 2026-08-29T08:07:10.197042+00:00, sha e6f2747eb4d2)
  - site_page: https://www.ory.com/about (fetched 2026-08-29T08:07:10.201898+00:00, sha e44652fde9f9)
  - site_page: https://www.ory.com/integrations (fetched 2026-08-29T08:07:10.203822+00:00, sha 966475eed325)
  - site_page: https://www.ory.com/pricing (fetched 2026-08-29T08:07:10.193823+00:00, sha 35c1d920fc8d)
  - site_page: https://changelog.ory.com/ (fetched 2026-08-29T08:07:10.199846+00:00, sha c8e6b35f30bb)
- Data as of 2026-08-30T08:39:29.467469+00:00.
