# Authentik vs Ory

**Leader by Vioscale score:** Ory

| Attribute | Authentik | Ory |
|---|---|---|
| **Vioscale score** | 54.3 (40% (low)) | 71.9 (66% (medium)) |
| activity.commits_last_30d | 100 | 60 |
| adoption.dependent_repos | 0 | 9 |
| adoption.github_stars | 25,174 | 13,848 |
| deployment.options | `{"cloud":true,"self_hosted":true}` | `{"cloud":true,"on_prem":true,"air_gapped":true,"self_hosted":true}` |
| description.long | An open-source identity provider offering single sign-on, multi-factor authentication, role-based access control, and application integration capabilities. Organizations can deploy it on their own infrastructure as a self-hosted alternative to commercial solutions. | Flexible IAM platform offering modular authentication, authorization, and user management components. Supports multiple deployment modes—managed cloud services, self-hosted open-source, or on-premise enterprise—with built-in support for modern standards including OAuth 2.0, OpenID Connect, SAML, SCIM, and device-based authentication. |
| features.capabilities | `{"mfa":true,"oidc":true,"rbac":true,"hosting":"both","saml_sso":true,"open_source":true,"passwordless":true,"b2b_multi_tenant":true,"passkeys_webauthn":true,"scim_provisioning":true}` | `{"oidc":true,"rbac":true,"hosting":"both","saml_sso":true,"hosted_ui":"both","open_source":true,"passwordless":true,"b2b_multi_tenant":true,"passkeys_webauthn":true,"scim_provisioning":true}` |
| integrations.count | 10 | 2 |
| integrations.list | `[{"name":"OAuth2"},{"name":"OpenID Connect"},{"name":"SAML2"},{"name":"LDAP"},{"name":"RADIUS"},{"name":"SCIM"},{"name":"WS-Federation"},{"name":"Microsoft Entra ID"},{"name":"Google Workspace"},{"name":"Shared Signals Framework (SSF)"}]` | `[{"name":"Amazon SES"},{"name":"AWS API Gateway"}]` |
| language.primary | Python | Go |
| license.spdx | - | Apache-2.0 |
| market.availability | `{"hqCountry":"US","primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | `{"primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"cli":true,"mac":true,"web":true,"linux":true,"windows":true}` | `{"cli":true,"web":true}` |
| pricing | `{"type":"hybrid","plans":[{"free":true,"name":"Open Source","features":["Self-hosting on Docker, Kubernetes, Terraform","OAuth2/OIDC","SAML2","LDAP","RADIUS","SCIM","MFA (TOTP, WebAuthn)","Passkeys/WebAuthn","Remote Access Control (RDP, SSH, VNC)","RBAC","Conditional Access"],"description":"Free open source core with community support","contactSales":false},{"free":false,"name":"Professional","components":[{"kind":"fixed","amount":1000,"period":"year","currency":"USD"}],"description":"Enterprise features available. Annual subscriptions over $1,000 include support ticketing (response within 1-3 business days)","contactSales":false},{"free":false,"name":"Enterprise","components":[{"kind":"fixed","amount":20000,"period":"year","currency":"USD"}],"description":"Custom contracts with dedicated support team, biweekly check-ins, and prioritized feature requests","contactSales":true}],"summary":"Free open source. Professional plans from $1,000/year with support. Enterprise from $20,000/year with dedicated support.","currency":"USD","freeTier":true,"sourceUrl":"https://goauthentik.io/blog/2025-02-04-open-source-rac-and-pricing-support-updates/","retrievedAt":"2026-08-14T08:33:07.076Z","startingPrice":{"amount":1000,"period":"month","currency":"USD"}}` | `{"type":"hybrid","plans":[{"free":true,"name":"Developer","summary":"Free tier for developers and proof of concept","contactSales":false},{"free":false,"name":"Production","summary":"$770/year plus $0.14/aDAU/month","features":["All top-tier security features","1 production environment and 3 staging environments","Permissions and machine-to-machine tokens"],"commitment":"annual","components":[{"kind":"fixed","amount":770,"period":"year","currency":"USD"},{"per":{"qty":1,"unit":"aDAU"},"kind":"metered","amount":0.14,"currency":"USD"}],"description":"Everything you need to thoroughly test and explore the landscape of identity security.","contactSales":false},{"free":false,"name":"Growth","summary":"$9,350/year","features":["Everything from Production","Advanced analytics and insights","2 production environments and 5 staging environments","B2B SSO (OIDC only)"],"commitment":"annual","components":[{"kind":"fixed","amount":9350,"period":"year","currency":"USD"}],"description":"Optimal for piloting traffic growth, getting insights into sign up and login conversions, and basic B2B features.","contactSales":false},{"free":false,"name":"Enterprise (SaaS)","summary":"Custom pricing","features":["Everything from Growth","Event firehose to data lake","Multi-region deployments with data residency","Volume pricing","Enterprise integrations for legacy systems","Multi-tenancy","Concierge onboarding","Premium support with SLAs","99.99% uptime SLA"],"description":"Managed SaaS for companies needing strict SLAs, premium support, or regulatory compliance.","contactSales":true},{"free":false,"name":"Enterprise License (Self-Hosted)","summary":"Custom pricing","features":["Full control of hosting","Multi-region deployment flexibility","Custom pricing","Premium enterprise integrations","Premium support with SLAs"],"description":"Self-hosted option for maximum control and in-house expertise.","contactSales":true}],"summary":"From $770/year. Free Developer tier. Usage-based (aDAU) metered pricing available.","currency":"USD","freeTier":true,"sourceUrl":"https://www.ory.sh","retrievedAt":"2026-08-05T14:11:20.676Z","startingPrice":{"amount":0.14,"period":"month","currency":"USD"},"billingPeriods":["month","year"]}` |
| pricing.free_tier | yes | yes |
| pricing.model | commercial | freemium |
| pricing.price_level | high | unknown |
| pricing.transparent | yes | yes |
| release.cadence_days | - | 66 |
| release.history | `[{"url":"https://github.com/goauthentik/authentik/releases/tag/version/2026.8.0","date":"2026-08-18T22:04:25Z","type":"stable","version":"version/2026.8.0"},{"url":"https://github.com/goauthentik/authentik/releases/tag/version/2026.8.0-rc7","date":"2026-08-10T22:16:59Z","type":"prerelease","version":"version/2026.8.0-rc7"},{"url":"https://github.com/goauthentik/authentik/releases/tag/version/2026.8.0-rc6","date":"2026-08-03T22:43:11Z","type":"prerelease","version":"version/2026.8.0-rc6"},{"url":"https://github.com/goauthentik/authentik/releases/tag/version/2026.8.0-rc5","date":"2026-08-03T20:14:23Z","type":"prerelease","version":"version/2026.8.0-rc5"},{"url":"https://github.com/goauthentik/authentik/releases/tag/version/2026.8.0-rc4","date":"2026-08-03T18:59:58Z","type":"prerelease","version":"version/2026.8.0-rc4"},{"url":"https://github.com/goauthentik/authentik/releases/tag/version/2026.8.0-rc3","date":"2026-08-03T17:49:08Z","type":"prerelease","version":"version/2026.8.0-rc3"},{"url":"https://github.com/goauthentik/authentik/releases/tag/version/2026.8.0-rc2","date":"2026-08-03T16:34:28Z","type":"prerelease","version":"version/2026.8.0-rc2"},{"url":"https://github.com/goauthentik/authentik/releases/tag/version/2026.8.0-rc1","date":"2026-08-03T15:04:52Z","type":"prerelease","version":"version/2026.8.0-rc1"},{"url":"https://github.com/goauthentik/authentik/releases/tag/version/2026.5.6","date":"2026-07-22T14:52:57Z","type":"stable","version":"version/2026.5.6"},{"url":"https://github.com/goauthentik/authentik/releases/tag/version/2026.5.5","date":"2026-07-15T17:15:23Z","type":"stable","version":"version/2026.5.5"},{"url":"https://github.com/goauthentik/authentik/releases/tag/version/2026.2.6","date":"2026-07-15T17:14:01Z","type":"stable","version":"version/2026.2.6"},{"url":"https://github.com/goauthentik/authentik/releases/tag/version/2026.5.4","date":"2026-07-08T01:29:03Z","type":"stable","version":"version/2026.5.4"},{"url":"https://github.com/goauthentik/authentik/releases/tag/version/2026.2.5","date":"2026-07-07T16:56:46Z","type":"stable","version":"version/2026.2.5"},{"url":"https://github.com/goauthentik/authentik/releases/tag/version/2026.5.3","date":"2026-06-10T18:33:55Z","type":"stable","version":"version/2026.5.3"},{"url":"https://github.com/goauthentik/authentik/releases/tag/version/2026.5.2","date":"2026-05-28T15:13:31Z","type":"stable","version":"version/2026.5.2"},{"url":"https://github.com/goauthentik/authentik/releases/tag/version/2026.2.4","date":"2026-05-28T15:04:46Z","type":"stable","version":"version/2026.2.4"},{"url":"https://github.com/goauthentik/authentik/releases/tag/version/2025.12.6","date":"2026-05-28T15:00:00Z","type":"stable","version":"version/2025.12.6"},{"url":"https://github.com/goauthentik/authentik/releases/tag/version/2026.5.0","date":"2026-05-22T00:40:51Z","type":"stable","version":"version/2026.5.0"},{"url":"https://github.com/goauthentik/authentik/releases/tag/version/2026.5.0-rc2","date":"2026-05-13T08:42:06Z","type":"prerelease","version":"version/2026.5.0-rc2"},{"url":"https://github.com/goauthentik/authentik/releases/tag/version/2026.2.3","date":"2026-05-12T19:55:59Z","type":"stable","version":"version/2026.2.3"}]` | `[{"url":"https://github.com/ory/kratos/releases/tag/v26.2.0","date":"2026-03-20T14:10:32Z","type":"stable","version":"v26.2.0"},{"url":"https://github.com/ory/kratos/releases/tag/v25.4.0","date":"2025-11-07T15:48:50Z","type":"stable","version":"v25.4.0"},{"url":"https://github.com/ory/kratos/releases/tag/v1.3.1","date":"2024-10-28T10:21:42Z","type":"stable","version":"v1.3.1"},{"url":"https://github.com/ory/kratos/releases/tag/v1.3.0","date":"2024-09-26T10:33:37Z","type":"stable","version":"v1.3.0"},{"url":"https://github.com/ory/kratos/releases/tag/v1.2.0","date":"2024-06-05T11:02:56Z","type":"stable","version":"v1.2.0"},{"url":"https://github.com/ory/kratos/releases/tag/v1.1.0","date":"2024-02-20T12:26:07Z","type":"stable","version":"v1.1.0"},{"url":"https://github.com/ory/kratos/releases/tag/v1.0.0","date":"2023-07-12T20:24:48Z","type":"stable","version":"v1.0.0"},{"url":"https://github.com/ory/kratos/releases/tag/v0.13.0","date":"2023-04-18T17:07:18Z","type":"stable","version":"v0.13.0"},{"url":"https://github.com/ory/kratos/releases/tag/v0.11.1","date":"2023-01-14T11:40:30Z","type":"stable","version":"v0.11.1"},{"url":"https://github.com/ory/kratos/releases/tag/v0.11.0","date":"2022-12-02T18:41:38Z","type":"stable","version":"v0.11.0"},{"url":"https://github.com/ory/kratos/releases/tag/v0.10.1","date":"2022-06-01T11:15:28Z","type":"stable","version":"v0.10.1"},{"url":"https://github.com/ory/kratos/releases/tag/v0.10.0","date":"2022-05-30T13:09:17Z","type":"stable","version":"v0.10.0"},{"url":"https://github.com/ory/kratos/releases/tag/v0.9.0-alpha.3","date":"2022-03-25T10:02:51Z","type":"prerelease","version":"v0.9.0-alpha.3"},{"url":"https://github.com/ory/kratos/releases/tag/v0.9.0-alpha.2","date":"2022-03-22T10:20:26Z","type":"prerelease","version":"v0.9.0-alpha.2"},{"url":"https://github.com/ory/kratos/releases/tag/v0.9.0-alpha.1","date":"2022-03-21T22:20:48Z","type":"prerelease","version":"v0.9.0-alpha.1"},{"url":"https://github.com/ory/kratos/releases/tag/v0.8.2-alpha.1","date":"2021-12-17T15:04:04Z","type":"prerelease","version":"v0.8.2-alpha.1"},{"url":"https://github.com/ory/kratos/releases/tag/v0.8.1-alpha.1","date":"2021-12-13T18:59:53Z","type":"prerelease","version":"v0.8.1-alpha.1"},{"url":"https://github.com/ory/kratos/releases/tag/v0.8.0-alpha.3","date":"2021-10-28T22:56:46Z","type":"prerelease","version":"v0.8.0-alpha.3"},{"url":"https://github.com/ory/kratos/releases/tag/v0.8.0-alpha.2","date":"2021-10-28T10:03:55Z","type":"prerelease","version":"v0.8.0-alpha.2"},{"url":"https://github.com/ory/kratos/releases/tag/v0.8.0-alpha.1","date":"2021-10-28T08:23:21Z","type":"prerelease","version":"v0.8.0-alpha.1"}]` |
| reliability.sla_pct | - | 99.99 |
| reliability.status_page | yes | yes |
| security.disclosure_policy | yes | yes |
| security.gdpr | - | yes |
| security.iso27001 | - | yes |
| security.pci | - | yes |
| security.scorecard | - | 6.7 |
| security.soc2 | - | yes |
| security.vulnerabilities | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=npm&package_name=%40goauthentik%2Fprettier-config&per_page=100","last_12m":0,"max_severity":null}` | `{"count":2,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=github.com%2Fory%2Fkratos&per_page=100","last_12m":1,"max_severity":"HIGH"}` |

## Capabilities (Auth & Identity Software)

| Capability | Authentik | Ory |
|---|:--:|:--:|
| **Deployment** |  |  |
| Hosting | Cloud + self-hosted | Cloud + self-hosted |
| **Methods** |  |  |
| Social login | - | - |
| Passwordless | ✓ | ✓ |
| Passkeys / WebAuthn | ✓ | ✓ |
| Multi-factor auth | ✓ | - |
| **Enterprise** |  |  |
| SAML SSO | ✓ | ✓ |
| SCIM provisioning | ✓ | ✓ |
| B2B / multi-tenancy | ✓ | ✓ |
| **Standards** |  |  |
| OpenID Connect provider | ✓ | ✓ |
| **Delivery** |  |  |
| Hosted UI | - | Both |
| **Access** |  |  |
| RBAC | ✓ | ✓ |
| **Licensing** |  |  |
| Self-hostable OSS core | ✓ | ✓ |

*Source: Vioscale. Generated 2026-09-01T16:42:10.616Z. "-" = undocumented, not absent.*
