
Amazon Cognito
Customer identity and access management service for adding user sign-up, sign-in, and authentication to apps
Discover top open-source software, updated regularly with real-world adoption signals.

API‑first identity server for secure, scalable user management
Ory Kratos delivers developer‑friendly, security‑hardened identity and authentication APIs, supporting login, registration, MFA, social sign‑in, and admin management for cloud‑native applications.

Ory Kratos is an API‑first identity and user‑management server designed for cloud‑native applications. It targets developers and product teams that need a flexible, security‑focused authentication layer without building it from scratch.
The platform supports self‑service login and registration, passwordless and WebAuthn flows, MFA via TOTP, social sign‑in, and account recovery. Admin APIs let you import, update, or delete identities, while built‑in UI components and the Ory Console accelerate integration. It also offers OAuth2 and OpenID Connect endpoints for SSO and machine‑to‑machine authorization, and low‑latency permission checks based on the Zanzibar model.
You can self‑host Kratos on any infrastructure, leveraging the open‑source code and CLI, or use the fully managed Ory Network for a hassle‑free, GDPR‑friendly service with usage‑based pricing. Enterprises needing additional features, strict SLAs, and private Docker images can obtain an Ory Enterprise License.
When teams consider Ory Kratos, these hosted platforms usually appear on the same shortlist.
Looking for a hosted option? These are the services engineering teams benchmark against before choosing open source.
Passwordless login for mobile app
Reduces friction for users while enhancing security through WebAuthn.
Multi‑tenant SaaS onboarding
Provides a single identity hub that isolates tenant data and simplifies admin management.
Regulated industry compliance
Ensures GDPR‑friendly data storage and audit trails for sensitive user information.
Microservice API authentication
Delivers consistent identity verification across services via OAuth2/OpenID Connect.
Ory Kratos exposes a RESTful HTTP API, so any language that can make HTTP requests can integrate with it.
Yes, the Ory Network offers a fully managed, cloud‑native deployment of Kratos with built‑in scaling and compliance features.
It supports TOTP, WebAuthn, and other standard MFA methods, configurable per identity.
Absolutely; the open‑source code can be self‑hosted on any infrastructure using Docker or binary releases.
The license adds advanced scaling, multi‑tenancy, SLA‑backed security patches, and access to a private Docker registry.
Project at a glance
ActiveLast synced 4 days ago