# Descope vs Ory

**Leader by vioscaleAI score:** Descope

| Attribute | Descope | Ory |
|---|---|---|
| **vioscaleAI score** | 84.8 (71% (medium)) | 76.4 (69% (medium)) |
| activity.commits_last_30d | - | 60 |
| adoption.dependent_repos | - | 9 |
| adoption.github_stars | - | 13,872 |
| content.faq | `[{"answer":"Cloud-based identity platform that handles user authentication, single sign-on, multi-factor authentication, and access control through visual flow orchestration. Designed for B2B enterprises and supports passwordless methods, role-based access control, and multi-tenant configurations. It is indexed under Auth & Identity Software.","source":"https://www.descope.com/blog/post/m2m-agentic-identity-pricing-update","question":"What is Descope?","confidence":0.6},{"answer":"Descope offers a free tier, so you can start without paying. Paid plans are also available: Free Forever and Pro. Pricing changes often, so verify at source before relying on it.","source":"https://www.descope.com/blog/post/m2m-agentic-identity-pricing-update","question":"Is Descope free?","confidence":0.6},{"answer":"Descope supports the web, iOS, Android and a command-line interface. Platforms we have not confirmed are simply not listed here rather than ruled out.","source":"https://www.descope.com/blog/post/m2m-agentic-identity-pricing-update","question":"What platforms does Descope support?","confidence":0.6},{"answer":"We have only confirmed a cloud / SaaS deployment for Descope, so it appears to be vendor-hosted. If a self-hosted option exists we have not found it documented publicly.","source":"https://www.descope.com/blog/post/m2m-agentic-identity-pricing-update","question":"Can Descope be self-hosted?","confidence":0.6},{"answer":"We have confirmed 22 integrations for Descope, including Vercel, OpenAI, Google Calendar, Facebook, MCP servers, Email/SMS platforms, CRM platforms and CDP platforms, plus 14 more. This is what we could verify from public sources, so the vendor may support others we have not indexed.","source":"https://www.descope.com/blog/post/m2m-agentic-identity-pricing-update","question":"What does Descope integrate with?","confidence":0.6},{"answer":"We have independently confirmed SOC 2, ISO 27001, HIPAA and GDPR for Descope. Certifications we do not list are ones we have not been able to verify from public sources, which is not the same as Descope not holding them. Always confirm compliance directly before you rely on it.","source":"https://www.descope.com/security-compliance","question":"What security certifications does Descope have?","confidence":0.7},{"answer":"Descope is available in Australia and the EU. Its primary markets are the United States, the EU and Australia.","source":"https://www.descope.com/blog/post/m2m-agentic-identity-pricing-update","question":"Where is Descope available?","confidence":0.75}]` | `[{"answer":"Flexible IAM platform offering modular authentication, authorization, and user management components. Supports multiple deployment modes—managed cloud services, self-hosted open-source, or on-premise enterprise—with built-in support for modern standards including OAuth 2.0, OpenID Connect, SAML, SCIM, and device-based authentication. It is indexed under Auth & Identity Software.","source":"https://www.ory.com/blog/mau-vs-adau-identity-pricing-compared","question":"What is Ory?","confidence":0.6},{"answer":"Ory is open source, so it can be self-hosted and used at no licence cost. It is released under the Apache-2.0 licence. A commercial or hosted edition starts at $0.14. Prices are published openly on the vendor's own pricing page. Pricing changes often, so verify at source before relying on it.","source":"https://www.ory.sh","question":"Is Ory free to use?","confidence":0.6},{"answer":"Ory supports the web and a command-line interface. Platforms we have not confirmed are simply not listed here rather than ruled out.","source":"https://www.ory.com/blog/mau-vs-adau-identity-pricing-compared","question":"What platforms does Ory support?","confidence":0.6},{"answer":"Yes. Ory can be deployed cloud / SaaS, on-premise, air-gapped and self-hosted, so it does not have to run on the vendor's infrastructure.","source":"https://www.ory.com/blog/mau-vs-adau-identity-pricing-compared","question":"Can Ory be self-hosted?","confidence":0.6},{"answer":"We have independently confirmed SOC 2, ISO 27001 and GDPR for Ory. Certifications we do not list are ones we have not been able to verify from public sources, which is not the same as Ory not holding them. Always confirm compliance directly before you rely on it.","source":"https://www.ory.sh/security","question":"What security certifications does Ory have?","confidence":0.7},{"answer":"Yes. Ory is published under the Apache-2.0 licence, a permissive licence that generally allows commercial use and modification. Licence terms can change between releases, so verify against the repository for the version you intend to use.","source":"https://github.com/ory/kratos","question":"Is Ory open source?","confidence":0.95}]` |
| deployment.options | `{"cloud":true}` | `{"cloud":true,"hybrid":true,"on_prem":true,"air_gapped":true,"self_hosted":true}` |
| description.long | A managed identity and access management service that enables businesses to build and customize authentication journeys across applications. Supports passwordless authentication, multi-tenant configurations, role-based access control, and integration with external identity providers. | An open-source and cloud-based identity platform offering authentication, authorization, and access control for applications and AI agents. Available as self-hosted open-source software, a managed cloud service, or an enterprise license with dedicated support. |
| features.capabilities | `{"mfa":true,"oidc":true,"rbac":true,"hosting":"cloud","saml_sso":true,"hosted_ui":"both","open_source":false,"passwordless":true,"social_login":true,"b2b_multi_tenant":true,"passkeys_webauthn":true,"scim_provisioning":true}` | `{"mfa":true,"oidc":true,"rbac":true,"hosting":"both","saml_sso":true,"hosted_ui":"both","open_source":true,"passwordless":true,"social_login":true,"b2b_multi_tenant":true,"passkeys_webauthn":true,"scim_provisioning":true}` |
| integrations.count | 50 | 6 |
| integrations.list | `[{"name":"Vercel"},{"name":"OpenAI"},{"name":"Google Calendar"},{"name":"Facebook"},{"name":"MCP servers"},{"name":"Email/SMS platforms"},{"name":"CRM platforms"},{"name":"CDP platforms"},{"name":"Audit solutions"},{"name":"Fraud detection systems"},{"name":"OpenID Connect","native":true,"category":"auth","direction":"bidirectional"},{"name":"SAML","native":true,"category":"auth","direction":"bidirectional"},{"name":"Fingerprint","native":true,"category":"fraud"},{"name":"Sardine","native":true,"category":"fraud"},{"name":"Forter","native":true,"category":"fraud"},{"name":"Incode","native":true,"category":"identity_verification"},{"name":"Amazon Rekognition","native":false,"category":"identity_verification"},{"name":"Cloudflare","native":false,"category":"security"},{"name":"reCAPTCHA","native":false,"category":"security"},{"name":"Turnstile","native":false,"category":"security"},{"name":"AbuseIPDB","native":false,"category":"security"},{"name":"Box","native":false,"category":"document_management"},{"name":"Vercel AI SDK","native":false}]` | `[{"name":"Amazon SES"},{"name":"AWS API Gateway"},{"name":"Google","native":true,"category":"social","direction":"bidirectional"},{"name":"Kubernetes","native":true,"category":"infrastructure","direction":"bidirectional"},{"name":"Ambassador","native":false,"category":"infrastructure","direction":"bidirectional"},{"name":"Kong","native":false,"category":"infrastructure","direction":"bidirectional"},{"name":"Splunk","native":true,"category":"siem","direction":"outbound"},{"name":"Model Context Protocol (MCP)","native":true,"category":"ai","direction":"bidirectional"}]` |
| language.primary | - | Go |
| license.spdx | - | Apache-2.0 |
| market.availability | `{"primaryMarkets":["US","EU","AU"],"availabilityScope":"global","availableCountries":["AU","EU"],"notAvailableCountries":[]}` | `{"primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"web":true}` | `{"cli":true,"mac":true,"web":true,"linux":true,"windows":true}` |
| pricing | `{"type":"hybrid","plans":[{"free":true,"name":"Free Forever","summary":"Free tier with M2M and agentic identity essentials","description":"Includes M2M and agentic identity essentials available to all developers","contactSales":false},{"free":false,"name":"Pro","contactSales":false}],"summary":"Usage-based pricing with Monthly Active Consents (MAC), Monthly Active Tokens (MATK), and M2M Exchanges. Free tier available.","currency":"USD","freeTier":true,"sourceUrl":"https://www.descope.com/blog/post/m2m-agentic-identity-pricing-update","retrievedAt":"2026-08-14T08:38:03.189Z","billingPeriods":["month"]}` | `{"type":"hybrid","plans":[{"free":true,"name":"Developer","summary":"Free tier for developers and proof of concept","contactSales":false},{"free":false,"name":"Production","summary":"$770/year plus $0.14/aDAU/month","features":["All top-tier security features","1 production environment and 3 staging environments","Permissions and machine-to-machine tokens"],"commitment":"annual","components":[{"kind":"fixed","amount":770,"period":"year","currency":"USD"},{"per":{"qty":1,"unit":"aDAU"},"kind":"metered","amount":0.14,"currency":"USD"}],"description":"Everything you need to thoroughly test and explore the landscape of identity security.","contactSales":false},{"free":false,"name":"Growth","summary":"$9,350/year","features":["Everything from Production","Advanced analytics and insights","2 production environments and 5 staging environments","B2B SSO (OIDC only)"],"commitment":"annual","components":[{"kind":"fixed","amount":9350,"period":"year","currency":"USD"}],"description":"Optimal for piloting traffic growth, getting insights into sign up and login conversions, and basic B2B features.","contactSales":false},{"free":false,"name":"Enterprise (SaaS)","summary":"Custom pricing","features":["Everything from Growth","Event firehose to data lake","Multi-region deployments with data residency","Volume pricing","Enterprise integrations for legacy systems","Multi-tenancy","Concierge onboarding","Premium support with SLAs","99.99% uptime SLA"],"description":"Managed SaaS for companies needing strict SLAs, premium support, or regulatory compliance.","contactSales":true},{"free":false,"name":"Enterprise License (Self-Hosted)","summary":"Custom pricing","features":["Full control of hosting","Multi-region deployment flexibility","Custom pricing","Premium enterprise integrations","Premium support with SLAs"],"description":"Self-hosted option for maximum control and in-house expertise.","contactSales":true}],"summary":"From $770/year. Free Developer tier. Usage-based (aDAU) metered pricing available.","currency":"USD","freeTier":true,"sourceUrl":"https://www.ory.sh","retrievedAt":"2026-08-05T14:11:20.676Z","startingPrice":{"amount":0.14,"period":"month","currency":"USD"},"billingPeriods":["month","year"]}` |
| pricing.free_tier | yes | yes |
| pricing.model | freemium | freemium |
| pricing.price_level | low | low |
| pricing.transparent | no | yes |
| release.cadence_days | - | 66 |
| release.history | - | `[{"url":"https://github.com/ory/kratos/releases/tag/v26.2.0","date":"2026-03-20T14:10:32Z","type":"stable","version":"v26.2.0"},{"url":"https://github.com/ory/kratos/releases/tag/v25.4.0","date":"2025-11-07T15:48:50Z","type":"stable","version":"v25.4.0"},{"url":"https://github.com/ory/kratos/releases/tag/v1.3.1","date":"2024-10-28T10:21:42Z","type":"stable","version":"v1.3.1"},{"url":"https://github.com/ory/kratos/releases/tag/v1.3.0","date":"2024-09-26T10:33:37Z","type":"stable","version":"v1.3.0"},{"url":"https://github.com/ory/kratos/releases/tag/v1.2.0","date":"2024-06-05T11:02:56Z","type":"stable","version":"v1.2.0"},{"url":"https://github.com/ory/kratos/releases/tag/v1.1.0","date":"2024-02-20T12:26:07Z","type":"stable","version":"v1.1.0"},{"url":"https://github.com/ory/kratos/releases/tag/v1.0.0","date":"2023-07-12T20:24:48Z","type":"stable","version":"v1.0.0"},{"url":"https://github.com/ory/kratos/releases/tag/v0.13.0","date":"2023-04-18T17:07:18Z","type":"stable","version":"v0.13.0"},{"url":"https://github.com/ory/kratos/releases/tag/v0.11.1","date":"2023-01-14T11:40:30Z","type":"stable","version":"v0.11.1"},{"url":"https://github.com/ory/kratos/releases/tag/v0.11.0","date":"2022-12-02T18:41:38Z","type":"stable","version":"v0.11.0"},{"url":"https://github.com/ory/kratos/releases/tag/v0.10.1","date":"2022-06-01T11:15:28Z","type":"stable","version":"v0.10.1"},{"url":"https://github.com/ory/kratos/releases/tag/v0.10.0","date":"2022-05-30T13:09:17Z","type":"stable","version":"v0.10.0"},{"url":"https://github.com/ory/kratos/releases/tag/v0.9.0-alpha.3","date":"2022-03-25T10:02:51Z","type":"prerelease","version":"v0.9.0-alpha.3"},{"url":"https://github.com/ory/kratos/releases/tag/v0.9.0-alpha.2","date":"2022-03-22T10:20:26Z","type":"prerelease","version":"v0.9.0-alpha.2"},{"url":"https://github.com/ory/kratos/releases/tag/v0.9.0-alpha.1","date":"2022-03-21T22:20:48Z","type":"prerelease","version":"v0.9.0-alpha.1"},{"url":"https://github.com/ory/kratos/releases/tag/v0.8.2-alpha.1","date":"2021-12-17T15:04:04Z","type":"prerelease","version":"v0.8.2-alpha.1"},{"url":"https://github.com/ory/kratos/releases/tag/v0.8.1-alpha.1","date":"2021-12-13T18:59:53Z","type":"prerelease","version":"v0.8.1-alpha.1"},{"url":"https://github.com/ory/kratos/releases/tag/v0.8.0-alpha.3","date":"2021-10-28T22:56:46Z","type":"prerelease","version":"v0.8.0-alpha.3"},{"url":"https://github.com/ory/kratos/releases/tag/v0.8.0-alpha.2","date":"2021-10-28T10:03:55Z","type":"prerelease","version":"v0.8.0-alpha.2"},{"url":"https://github.com/ory/kratos/releases/tag/v0.8.0-alpha.1","date":"2021-10-28T08:23:21Z","type":"prerelease","version":"v0.8.0-alpha.1"}]` |
| reliability.sla_pct | 99.99 | 99.99 |
| reliability.status_page | yes | yes |
| security.certifications | `[{"name":"SOC 2 Type II","status":"active"},{"name":"ISO 27001","status":"active"},{"name":"FedRAMP High","status":"active"},{"name":"CSA STAR Level 2","status":"active"},{"name":"PCI DSS","status":"active"}]` | - |
| security.disclosure_policy | yes | yes |
| security.fedramp | yes | - |
| security.gdpr | yes | yes |
| security.hipaa | yes | yes |
| security.iso27001 | yes | yes |
| security.pci | yes | yes |
| security.scorecard | - | 6.7 |
| security.soc2 | yes | yes |
| security.trust_center | https://www.descope.com/security-compliance | https://www.ory.com/blog/meeting-the-worlds-standards-ory-and-global-compliance-readiness |
| security.vulnerabilities | - | `{"count":2,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=github.com%2Fory%2Fkratos&per_page=100","last_12m":1,"max_severity":"HIGH"}` |

## Capabilities (Auth & Identity Software)

| Capability | Descope | Ory |
|---|:--:|:--:|
| **Deployment** |  |  |
| Hosting | Cloud only | Cloud + self-hosted |
| **Methods** |  |  |
| Social login | ✓ | ✓ |
| Passwordless | ✓ | ✓ |
| Passkeys / WebAuthn | ✓ | ✓ |
| Multi-factor auth | ✓ | ✓ |
| **Enterprise** |  |  |
| SAML SSO | ✓ | ✓ |
| SCIM provisioning | ✓ | ✓ |
| B2B / multi-tenancy | ✓ | ✓ |
| **Standards** |  |  |
| OpenID Connect provider | ✓ | ✓ |
| **Delivery** |  |  |
| Hosted UI | Both | Both |
| **Access** |  |  |
| RBAC | ✓ | ✓ |
| **Licensing** |  |  |
| Self-hostable OSS core | ✗ | ✓ |

*Source: vioscaleAI. Generated 2026-09-21T01:31:51.135Z. "-" = undocumented, not absent.*
