# Alternatives to Ory

Ory is an open-source identity platform composed of modular services — Kratos for identity/authentication, Hydra for OAuth2/OIDC, and Keto for permissions — that can be self-hosted or consumed as a managed cloud product (Ory Network). It's used by engineering teams that want API-first, protocol-compliant identity infrastructure they can run themselves. It distinguishes itself from all-in-one platforms like Auth0 by offering composable, independently deployable building blocks.

Ory ranks #2 of 12 in Authentication & identity providers, with an Alt Score of 93. It is licensed under Apache-2.0, open source with paid hosting from $770/yr and available on Linux, macOS and Windows. 12 of 12 checklist rows are verified against a public source.

Source: https://altcatalog.com/alternatives/ory/
Category: Authentication & identity providers

## Where Ory stands out

- **Open source** — 3 of 12 apps with a verified answer have this
- **Self-hostable** — 4 of 11 apps with a verified answer have this

## Overview

- **Who it's for**: Ory is for engineering teams building login, registration, and access-control infrastructure for their own applications or B2B/SaaS products, ranging from individual developers self-hosting the open-source core to enterprises needing SSO, SCIM, and multi-tenant organization support.
- **What you get**: Ory provides API-first identity and access management: social login, passwordless (one-time codes) and passkey/WebAuthn authentication, MFA, enterprise SSO (SAML/OIDC), SCIM directory sync, B2B organizations, fine-grained permissions/RBAC, and pre-built React UI components (Ory Elements). The core services (Kratos, Hydra, Keto, Oathkeeper) are Apache-2.0 licensed and self-hostable.
- **How it works**: Applications integrate with Ory's APIs to run identity, OAuth2/OIDC, and permissions flows instead of building them in-house, either by self-hosting the open-source components (optionally layering the commercial Ory Enterprise License) or by using Ory Network, a managed cloud service configured through a web console and billed on a per-plan base fee plus usage (active daily users, M2M tokens, permission checks).

## Profile

- **License**: Apache-2.0 (verified 2026-07-30)
- **Pricing model**: OSS + paid hosting (verified 2026-07-30)
- **Starts at**: $770/yr (verified 2026-07-30)
- **Platforms**: Linux, macOS, Windows
- **Status**: active (verified 2026-07-30)

## Ranked alternatives

| # | App | Alt Score | Licence | Platforms |
|---|-----|-----------|---------|-----------|
| 1 | [FusionAuth](https://altcatalog.com/alternatives/fusionauth.md) | 93 | Proprietary | Windows, macOS, Linux, Web |
| 2 | [Zitadel](https://altcatalog.com/alternatives/zitadel.md) | 93 | AGPL-3.0 | Linux, macOS, Web |
| 3 | [Auth0](https://altcatalog.com/alternatives/auth0.md) | 89 | Proprietary | Web |
| 4 | [Clerk](https://altcatalog.com/alternatives/clerk.md) | 89 | Proprietary | Web, iOS, Android |
| 5 | [Frontegg](https://altcatalog.com/alternatives/frontegg.md) | 89 | Proprietary | Web, iOS, Android |
| 6 | [Stytch](https://altcatalog.com/alternatives/stytch.md) | 89 | Proprietary | Web, iOS, Android |
| 7 | [Descope](https://altcatalog.com/alternatives/descope.md) | 85 | Proprietary | Web, iOS, Android |
| 8 | [WorkOS](https://altcatalog.com/alternatives/workos.md) | 85 | Proprietary | Web |
| 9 | [Keycloak](https://altcatalog.com/alternatives/keycloak.md) | 81 | Apache License 2.0 | Linux, Windows, Web |
| 10 | [Amazon Cognito](https://altcatalog.com/alternatives/cognito.md) | 78 | ? | Web |
| 11 | [Kinde](https://altcatalog.com/alternatives/kinde.md) | 74 | Proprietary | Web |

Alt Score = Verified coverage (90%) + Visibility (10%). See https://altcatalog.com/how-alt-score-works/

## Feature comparison

Legend: Yes / No / Partial / ? (not verified).

| Authentication & identity providers checklist | Ory | FusionAuth | Zitadel | Auth0 | Clerk | Frontegg |
|---|---|---|---|---|---|---|
| Pricing model | OSS + paid hosting | Freemium | Freemium | Freemium | Freemium | Usage-based |
| Starts at | $770/yr | $162/mo | US$100/mo | $35/mo | $25/mo | $0/mo |
| License | Apache-2.0 | Proprietary | AGPL-3.0 | Proprietary | Proprietary | Proprietary |
| Platforms | Linux, macOS, Windows | Windows, macOS, Linux, Web | Linux, macOS, Web | Web | Web, iOS, Android | Web, iOS, Android |
| Social login | Yes | Yes | Yes | Yes | Yes | Yes |
| Passwordless / magic links | Yes | Yes | Yes | Yes | Yes | Yes |
| Passkeys / WebAuthn | Yes | Yes | Yes | Yes | Yes | Yes |
| MFA | Yes | Yes | Yes | Yes | Yes | Yes |
| Enterprise SSO (SAML / OIDC) | Yes | Yes | Yes | Yes | Yes | Yes |
| SCIM provisioning | Yes | Yes | Yes | Yes | Yes | Yes |
| B2B org / multi-tenant | Yes | Yes | Yes | Yes | Yes | Yes |
| Self-hostable | Yes | Yes | Yes | Partial | No | Partial |
| Pre-built UI components | Yes | Yes | Yes | Yes | Yes | Yes |
| RBAC / permissions | Yes | Yes | Yes | Yes | Yes | Yes |
| Open source | Yes | No | Yes | No | Partial | No |
| Generous free tier (MAUs) | No | Yes | No | Yes | Yes | Yes |

## Sources

Sources for Ory. Each alternative is sourced on its own page.

- **License**: Apache-2.0 — <https://raw.githubusercontent.com/ory/kratos/master/LICENSE> (verified 2026-07-30)
  - Note: Core components (Kratos, Hydra, Keto, Oathkeeper) are Apache-2.0. Enterprise-only features require the separate Ory Enterprise License (OEL), a commercial license layered on top.
  - Quote: “Apache License Version 2.0, January 2004”
- **Pricing model**: OSS + paid hosting — <https://www.ory.com/network> (verified 2026-07-30)
  - Note: Self-host the Apache-2.0 core for free; Ory Network (hosted) bills usage-based per aDAU/M2M token/permission check on top of a plan base fee.
  - Quote: “Open source software, supercharged. Enterprise-grade features all accessible through our visual console. All that plus hosting, operations, and maintenance, too.”
- **Starts at**: $770/yr — <https://www.ory.com/pricing> (verified 2026-07-30)
  - Note: Cheapest paid Ory Network plan is 'Production' at $770/year (annual billing), plus $0.14/aDAU/month usage. Growth is $9,350/year. The 'Developer' plan is $0 but has 0 production environments (dev/stag
  - Quote: “Total invoice $770 /year”
- **Platforms**: Linux, macOS, Windows — <https://raw.githubusercontent.com/ory/kratos/master/README.md> (verified 2026-07-30)
  - Note: Self-hosted binaries/Docker run on Linux, macOS, and Windows. Ory Network is additionally usable via the browser-based Ory Console (console.ory.com).
  - Quote: “Install Kratos on Linux, macOS, Windows, and Docker”
- **Status**: active — <https://github.com/ory/kratos/releases> (verified 2026-07-30)
  - Note: Latest Kratos release v26.2.0 was published 2026-03-20; blog and docs show ongoing 2026 activity.
  - Quote: “v26.2.0”
- **Social login**: Yes — <https://www.ory.com/social-signin> (verified 2026-07-30)
  - Quote: “With social SSO, visitors can register for an account in seconds using the websites they already know, like GitHub, Google, Apple, Facebook, Discord, and many more.”
- **Passwordless / magic links**: Yes — <https://www.ory.com/docs/identities/get-started/passwordless> (verified 2026-07-30)
  - Note: Ory implements email/SMS passwordless via one-time codes rather than clickable magic links, plus passkeys — same category of passwordless login.
  - Quote: “One-time codes (OTC) provide a secure authentication method where codes are sent directly to the user's email.”
- **Passkeys / WebAuthn**: Yes — <https://www.ory.com/passkeys> (verified 2026-07-30)
  - Quote: “Passkeys are the easiest and most secure way to sign in to apps and websites. Phishing-resistant by design, and based on public key cryptography.”
- **MFA**: Yes — <https://www.ory.com/docs/identities/get-started/mfa> (verified 2026-07-30)
  - Quote: “This guide shows you how to enable multi-factor authentication (MFA) for your Ory project.”
- **Enterprise SSO (SAML / OIDC)**: Yes — <https://www.ory.com/enterprise-sso> (verified 2026-07-30)
  - Quote: “Effortlessly integrate Enterprise Single Sign-On (SSO) into your SaaS app with Ory. Our solution supports SAML & OIDC, enhancing security and user experience while reducing development time and cost.”
- **SCIM provisioning**: Yes — <https://www.ory.com/docs/kratos/manage-identities/scim> (verified 2026-07-30)
  - Note: Page title: 'System for Cross-domain Identity Management'. Includes Okta/Entra/Google Workspace SCIM connectors.
  - Quote: “SCIM in Ory Network is always scoped to an organization”
- **B2B org / multi-tenant**: Yes — <https://www.ory.com/docs/solutions/solution-B2B> (verified 2026-07-30)
  - Quote: “Ory Oathkeeper — enforces tenant isolation at the API layer, ensuring users only access their organization's data.”
- **Self-hostable**: Yes — <https://raw.githubusercontent.com/ory/kratos/master/README.md> (verified 2026-07-30)
  - Quote: “You can run Ory Kratos yourself for full control over infrastructure, deployment, and customization.”
- **Pre-built UI components**: Yes — <https://raw.githubusercontent.com/ory/elements/main/README.md> (verified 2026-07-30)
  - Quote: “Ory Elements is a component library that makes building login, registration and account pages for Ory a breeze”
- **RBAC / permissions**: Yes — <https://www.ory.com/permissions> (verified 2026-07-30)
  - Quote: “Whether you need role-based access control (RBAC) or are controlling access and edit rights to files and resources, Ory Permissions makes it simple.”
- **Open source**: Yes — <https://www.ory.com/open-source> (verified 2026-07-30)
  - Quote: “Ory Open Source: Run and manage the open source Ory components yourself with community support.”
- **Generous free tier (MAUs)**: No — <https://www.ory.com/pricing> (verified 2026-07-30)
  - Note: The free 'Developer' plan on the pricing comparison table shows 0 production environments (dev/staging only) — no free tier for live production MAU traffic. Production use starts on the paid 'Producti
  - Quote: “Production Environments — Developer: 0”

---
Ranked by verified data, never by who paid. https://altcatalog.com/trust/