8 ms·
Kratos - Cloud native Auth0 open-source alternative (self-hosted)
- caleblloyd 11mo agoI used Ory Kratos in a Go application a couple years ago by installing it as a dependency. It worked pretty well but in hindsight I would have hosted it as a separate application because it was a pain to bring along all of its dependencies. One of my biggest complaints was that one of the Account Recovery flows was just an emailed 6-digit code. So a 1 in 1 million chance that somebody without access to any of your stuff could hack you by just hitting reset and guessing "123456". It's actually surprising how many other Account Recovery flows across the web I have noticed recently that do the same thing. Not sure if Ory has added the option for more entropy in this code as of today's release though it's been a while since I've used it. Otherwise it was a great project to work with that has tons of knobs to customize. I commend the authors, aeneasr especially. It must be a ton of work to keep up with all of the auth standards and offer this in an Apache2 licensed package all while building a business around it as well!
- fady0 11mo agoAren’t these codes supposed to have a timeout, like you have to use them within 10 minutes or they become invalid?
- jdmoreira 11mo agoI've implemented otp codes / magic links many times now. They absolutely always have a timeout. Say 30 minutes.
- caleblloyd 11mo agoSure, but say the implementation lets you try 5 codes in that 10 minutes with a 30 minute lockout. An attacker could trigger Account Recovery, blindly try 5 six-digit codes immediately, and have a 0.0005% chance getting into your account. They could script this to run over a long period of time targeting 1 account, or they could target many accounts at once, and would probably have success.
- vablings 11mo agoThis is my biggest gripe with email auth or any kind of security code via sms/mms. I pray for the day I can fully move to a passwordless setup and break free the mess of email addresses spaghetti and phone numbers.
- tracker1 11mo agoFeel free to implement something that sends a UUID, and deal with the complaints instead.
- conception 11mo agoIt’s probably easier to just have an exception log when someone(s) have 100 bad password attempts in a day or whatever.
- nja 11mo agoI've used [Keycloak](https://www.keycloak.org/ https://www.keycloak.org/) in the past for "open-source Auth0" -- though I'm not sure it has ever described itself that way. Keycloak ended up being quite extensible and powerful, but the UI and data model both sometimes made things more difficult than they had to be... this could be an interesting project to look at. One bonus (for us) for Keycloak was that it was JVM-based, meaning it was easier to integrate our existing JVM libraries. Though its use of Hibernate was frustrating at times, heh
- bitcrshr 11mo agoI tried Keycloak for a while, it’s really good too. Given it has an admkn dashboard, it’s a bit more “batteries included” than Ory.
- rirze 11mo agoI'm very familiar with Keycloak, and I don't see this replacing it any time soon. As soon as I read: > The Ory Enterprise License (OEL) layers on top of self-hosted Kratos and provides: Additional enterprise features that are not available in the open source version such as SCIM, SAML, organization login ("SSO"), CAPTCHAs and more I knew it couldn't compete. Good luck to this product.
- ikiris 11mo agoYeah that’s very disappointing and basically kills my interest in the product.
- vinckr 11mo agoYou can use other parts of the Ory ecosystem to add these features, such as Ory Polis for SAML/SCIM support: https://github.com/ory/polis https://github.com/ory/polis CAPTCHAs aren’t a big help anymore in my personal opinion, but you can easily integrate them on the frontend when using Kratos. The commercial offering just bundles all of this out of the box for you. If Keycloak fits your needs well and you see no room for improvement, that’s perfectly fine; by all means use what works best for you.
- deleted 11mo ago[deleted]
- bitcrshr 11mo agoKratos is awesome, especially alongside Hydra, OathKeeper, and Keto. Super powerful combo, if not a little intimidating at first. There’s a LOT of configuration involved, but that’s to be expected if you want to host your own Auth0 replacement. Their dynamic forms stuff is really cool too, always liked how they chose to go about that. Only complaint I really ever had is that while their docs were overall serviceable, I remember some areas were pretty lacking and I had to dig really far to find answers to some fairly common issues.
- throwaway894345 11mo agoI've often wondered why there isn't a simpler identity provider service that does the thing that ~90% of applications need without all of the complex configuration.
- ChristianJacobs 11mo agoHave you tried Pocket-ID? I use it for my home server with LLDAP as the identity provider.
- AlphaSite 11mo agoHonestly. We used dex. It worked pretty well.
- throwaway894345 11mo agoThanks for the rec. I’ll look into that.
- snowfield 11mo agoYou can host authentik with one click in docker. It's super easy to set up
- trenchpilgrim 11mo agoIronically, their hard dependency on Docker is a showstopper for me - none of my systems run Docker Engine, they use containerd and Podman, neither of which are supported.
- larrywinch 11mo agoThis looks like great stuff. In the TypeScript ecosystem, I'd probably take a look at Better Auth though, as the developer experience is really great!
- otabdeveloper4 11mo agoStoring auth data in MySQL or Postgres is insane and defeats the purpose of trying to be secure. Note to self: if I ever need a retirement project, open sourcing a properly architected auth solution would be it.
- exographicskip 11mo agoAs long as they're salted hashes, they could be stored anywhere right? Would sqlite be a better option?
- otabdeveloper4 11mo ago> As long as they're salted hashes, they could be stored anywhere right? Unless you're doing something exceedingly simple, you don't just have hashes, you have things like tokens, keys and authorization rules too.
- ilkhan4 11mo agoWhere else would you store them that's more secure?
- esafak 11mo agoauthn or authz?
- otabdeveloper4 11mo agoYou want to keep both in the same place anyways. (Anybody who compromises authz can now compromise authn, and vice-versa.)
- mariusor 11mo agoFor the rest of us that have less experience, what is the problem that you're seeing with that? You didn't really make an argument.
- danudey 11mo ago
- lordofgibbons 11mo agoDo I need to use the other services from the Ory stack to have this be complete? I tried reading the Ory docs a couple of times when I needed an auth solution but it was indecipherable to me as someone not living in the auth world
- vinckr 11mo agoIt depends what your requirements are. If you are "just" doing first-party login, session, and user mgmt then Ory Kratos is all you need. I would say in the majority of cases you would be fine with just Ory Kratos. If you want 3rd party integrations, or become an IDP (think "login with $yourcorp"), or you migrate an existing system that relies on OAuth2 that you want to keep, or you have more complex auth flows where OAuth2 shines, then you want Ory Hydra. If you want a "fine-grained" global, centralized authz system, complex and scalable authz as described by Google Zanzibar, then you want Ory Keto. If you want to support SAML as well, you want Ory Polis. If you want a "zero trust" setup, then you want Ory Oathkeeper. That being said in almost all cases Kratos will be fine and you can pick and choose what you actually need.
- blutoot 11mo agoCan you please review if this "simplification" is more or less accurate? :) https://chatgpt.com/s/69160cf5ed9481919a0a76a1e4f9ba93 https://chatgpt.com/s/69160cf5ed9481919a0a76a1e4f9ba93
- vinckr 11mo agosure, I would say its mostly correct. You can solve Permissions and API Gateway also differently - for example many use OAuth2 claims and scopes for permissions. I personally think that isn't good practice - like "first-party auth" I think its outside of the scope that OAuth2 was built for originally - but it works and many are used to building authz that way. You could also use the identity metadata on Kratos for permissions - this works well for simple RBAC usecases but if you want "large scale" and "finegrained" something like Ory Keto is probably the more reasonable choice. Feel free to message me on the Ory Community Slack if you want to discuss further: https://slack.ory.com/ https://slack.ory.com/
- nylonstrung 11mo agoI tried to use Ory for my company and cannot recommend it. Zitadel has been far better
- ethin 11mo agoI tried setting up Zitadel and couldn't because for whatever reason it's Nix build isn't reproduceable. So Nix always breaks when trying to verify that it, you know, actually built correctly. So I eventually gave up.
- ffo 11mo agoYeah I understand we did not really invest time there, sorry.
- joshring 11mo agoOriginally (maybe over a year ago) I had similar issues. But now Zitadel is one `enable = true;` option[1] away and in the official nixpkgs repo so you shouldn't really have this issue anymore. I was able to use it pretty easily with the built in service and postgres service[2] (note mine is encapsulated in a nixos container but otherwise the inner config is all you really need). [1]: https://search.nixos.org/options?channel=25.05&query=zitadel https://search.nixos.org/options?channel=25.05&query=zitadel [2]: https://git.joshuabell.xyz/ringofstorms/dotfiles/src/branch/master/hosts/h001/containers/zitadel.nix#L173-L213 https://git.joshuabell.xyz/ringofstorms/dotfiles/src/branch/...
- ffo 11mo agoTIL a thing about NIX again :D
- vinckr 11mo agoHey, if you want to share a bit more feedback would love to hear it! feel free to also message me directly if you don't want to share it here. tbh i don't know too much about it other than that they moved away from the apache2 license recently (disclaimer: I'm working for Ory)
- axegon_ 11mo agoI had to work with this at my old job(forked, messy-patched and outdated version). Honestly, I wasn't a big fan, mostly because of the horrible patches to make it do things it was never meant to do but also to some degree because of how unnecessarily over-complicated it was.
- vinckr 11mo agoi feel you; working with a heavily patched fork of anything can be rough check out the new version, i'm sure it has improved quite a bit since then. Of course simpler solutions than Ory Kratos exist, but they often come with other tradeoffs
- ethin 11mo agoI've tried Keycloak and quite a few other IAM solutions, and finally settled on Kanidm. Not because it was written in Rust but because the project was easy to learn and understand and it wasn't that hard to hook things up to it. It has it's quirks, but it's been phenomenal so far. The fact that it's super lightweight from my experience is also a big bonus.
- adammiribyan 11mo agoDoes OpenAI use Ory? I thought they’re using Auth0.
- amaccuish 11mo agoThought so too, though I also recall seeing WorkOS urls when configuring SCIM.
- grinich 11mo agoOpenAI uses WorkOS for SSO and SCIM. https://help.openai.com/en/articles/9627404-openai-chatgpt-scim-integration-faq#:~:text=your%20IdP%20provider-,via%20the%20WorkOS,-portal.%20Here%E2%80%99s%20a https://help.openai.com/en/articles/9627404-openai-chatgpt-s...
- ffo 11mo agoI lost track what they use … Auth0, Ory, WorkOS… sounds like they should go ahead and finally acquire something #scnr
- Sytten 11mo agoWe are using ory kratos in production. - It works and does the job. I appreciate that we got this piece of tech for free when we needed with quickly. - The doc is clearly written in a way to steer you toward their cloud (fair enough everybody needs to eat). Setting things up is not straight forward even after years of using it. - Backend driven UI is just weird. - The founder used to be very opinionated on some things but let bigger issues "rot", better now that they have grown as a business. - The fact that they wont do SAML in kratos cause its part of their cloud thing and they bought another business speaks volume to me. OSS for ory is a growth strategy, their enterprise version cloud is also not the same as the OSS one. For OAuth2 we considered Hydra but decided to build it ourselves since we want to host on prem and want to reduce moving parts. We will also likely end up replacing kratos eventually. TLDR it is a good tech to consider instead of building it yourself. It makes sense for B2C freemium products since all other providers charge per seat. But its not the easiest to setup.
- solarkraft 11mo agoOh my. The list of supported things is so long I just assumed it would obviously support SAML. That’s a big blind spot and possibly a deal breaker if somebody is looking for a versatile option.
- vinckr 11mo agoOry Kratos itself doesn't support SAML that is correct. However the newest addition to the Ory ecosystem, called Ory Polis (formerly known as BoxyHQ) does close that gap. It is also Apache2 licensed, do check it out here: https://github.com/ory/polis https://github.com/ory/polis
- vinckr 11mo agoyou should check out Ory Polis if you are looking for SAML support in the OSS version: https://github.com/ory/polis https://github.com/ory/polis
- ForHackernews 11mo agohttps://indigo-iam.github.io/ https://indigo-iam.github.io/ is another self-hosted open source IAM platform, that's come out of academia.
- parliament32 11mo ago> Passkeys, Social Sign In, OIDC, Magic Link, Multi-Factor Auth, SMS, SAML, TOTP, and more. Sounds great! But buried further in the page, > Additional enterprise features that are not available in the open source version such as SCIM, SAML, organization login ("SSO"), CAPTCHAs and more
- vinckr 11mo agoCheck out Ory Polis if you want SAML/SCIM support: https://github.com/ory/polis https://github.com/ory/polis CAPTCHA is not in scope for Kratos, there are already great solutions out there that you can use
- parliament32 11mo agoOry Polis also sounds great, but also suffers from: > Organizations that require advanced features, enhanced security, and enterprise-grade support for Ory's identity and access management solutions benefit from the Ory Enterprise License (OEL) as a self-hosted, premium offering including: Additional features not available in the open-source version, Regular releases that address CVEs and security vulnerabilities, with strict SLAs for patching based on severity, Support for advanced scaling and multi-tenancy features.
- lxdlam 11mo agoWe self hosted Kratos only as our IdP: three million total users, about 200k login/logout/session/jwt queries a day, using only four 1C 2G k8s pods with one extra for courier, a standard proxied 4c8g Postgres, everything works fine. Really easy to maintain with simple configuration and fully featured API. But their documentation is really bad, especially in OSS suites. I generally use Claude Code to read their code, find the matching implementation, and try to figure out how to properly configure. Anyway, if you need self host your IdP, just go for it, you cannot go wrong.
- trollbridge 11mo agoExactly our experience (poor documentation). We switched to Authentik because of this.
- yetanother-1 11mo agoMay I ask how is your experience with authentik?
- Bombthecat 11mo agoI use it, I love it! My go to recommendation now!
- trollbridge 11mo agoIt’s great. We use it for all of our apps.
- dizhn 11mo agoIt might be poor taste to hijack another product's post but I would check out Authentik before commiting to any idP. It recently started to have enterprise only features lately but its licence ensures they are added to the open source product after a set time period. Super nice developer too.
- killingtime74 11mo agoIt's not poor taste, it's good to compare
- wg0 11mo agoWhat is the simplest IdP that is not Dex?