# Ory vs WorkOS

| Attribute | Ory | WorkOS |
|---|---|---|
| **vioscaleAI score** | 76.4 (69% (medium)) | 72 (71% (medium)) |
| activity.commits_last_30d | 60 | - |
| adoption.dependent_repos | 9 | - |
| adoption.github_stars | 13,872 | - |
| content.faq | `[{"answer":"Flexible IAM platform offering modular authentication, authorization, and user management components. Supports multiple deployment modes—managed cloud services, self-hosted open-source, or on-premise enterprise—with built-in support for modern standards including OAuth 2.0, OpenID Connect, SAML, SCIM, and device-based authentication. It is indexed under Auth & Identity Software.","source":"https://www.ory.com/blog/mau-vs-adau-identity-pricing-compared","question":"What is Ory?","confidence":0.6},{"answer":"Ory is open source, so it can be self-hosted and used at no licence cost. It is released under the Apache-2.0 licence. A commercial or hosted edition starts at $0.14. Prices are published openly on the vendor's own pricing page. Pricing changes often, so verify at source before relying on it.","source":"https://www.ory.sh","question":"Is Ory free to use?","confidence":0.6},{"answer":"Ory supports the web and a command-line interface. Platforms we have not confirmed are simply not listed here rather than ruled out.","source":"https://www.ory.com/blog/mau-vs-adau-identity-pricing-compared","question":"What platforms does Ory support?","confidence":0.6},{"answer":"Yes. Ory can be deployed cloud / SaaS, on-premise, air-gapped and self-hosted, so it does not have to run on the vendor's infrastructure.","source":"https://www.ory.com/blog/mau-vs-adau-identity-pricing-compared","question":"Can Ory be self-hosted?","confidence":0.6},{"answer":"We have independently confirmed SOC 2, ISO 27001 and GDPR for Ory. Certifications we do not list are ones we have not been able to verify from public sources, which is not the same as Ory not holding them. Always confirm compliance directly before you rely on it.","source":"https://www.ory.sh/security","question":"What security certifications does Ory have?","confidence":0.7},{"answer":"Yes. Ory is published under the Apache-2.0 licence, a permissive licence that generally allows commercial use and modification. Licence terms can change between releases, so verify against the repository for the version you intend to use.","source":"https://github.com/ory/kratos","question":"Is Ory open source?","confidence":0.95}]` | `[{"answer":"WorkOS provides a unified interface for integrating enterprise authentication methods, including SAML and OIDC identity providers, along with user directory synchronization and access control features. It helps developers quickly add enterprise-ready authentication to their applications. It is indexed under Auth & Identity Software.","source":"https://workos.com/","question":"What is WorkOS?","confidence":0.6},{"answer":"WorkOS offers a free tier, so you can start without paying. Pricing changes often, so verify at source before relying on it.","source":"https://workos.com/blog/auth0-pricing-how-it-works-and-compares-to-workos","question":"Is WorkOS free?","confidence":0.6},{"answer":"We have confirmed browser-based access to WorkOS. That is the extent of what we could verify from public sources, so it may well offer desktop or mobile clients we have not indexed.","source":"https://workos.com/","question":"What platforms does WorkOS support?","confidence":0.6},{"answer":"We have only confirmed a cloud / SaaS deployment for WorkOS, so it appears to be vendor-hosted. If a self-hosted option exists we have not found it documented publicly.","source":"https://workos.com/","question":"Can WorkOS be self-hosted?","confidence":0.6},{"answer":"We have confirmed 25 integrations for WorkOS, including LinkedIn, Slack, GitLab, Bitbucket, Xero, Rippling, ADP and Intuit, plus 17 more. This is what we could verify from public sources, so the vendor may support others we have not indexed.","source":"https://workos.com/","question":"What does WorkOS integrate with?","confidence":0.6},{"answer":"We have independently confirmed SOC 2, HIPAA and GDPR for WorkOS. Certifications we do not list are ones we have not been able to verify from public sources, which is not the same as WorkOS not holding them. Always confirm compliance directly before you rely on it.","source":"https://workos.com/security","question":"What security certifications does WorkOS have?","confidence":0.7},{"answer":"WorkOS is available worldwide. Its primary market is the United States.","source":"https://workos.com/blog/auth0-pricing-how-it-works-and-compares-to-workos","question":"Where is WorkOS available?","confidence":0.5}]` |
| deployment.options | `{"cloud":true,"hybrid":true,"on_prem":true,"air_gapped":true,"self_hosted":true}` | `{"cloud":true}` |
| description.long | An open-source and cloud-based identity platform offering authentication, authorization, and access control for applications and AI agents. Available as self-hosted open-source software, a managed cloud service, or an enterprise license with dedicated support. | A platform providing identity infrastructure including SSO, multi-factor authentication, directory synchronization, and user management capabilities for SaaS applications and enterprise software. |
| features.capabilities | `{"mfa":true,"oidc":true,"rbac":true,"hosting":"both","saml_sso":true,"hosted_ui":"both","open_source":true,"passwordless":true,"social_login":true,"b2b_multi_tenant":true,"passkeys_webauthn":true,"scim_provisioning":true}` | `{"mfa":true,"oidc":true,"rbac":true,"hosting":"cloud","saml_sso":true,"hosted_ui":"both","open_source":false,"passwordless":true,"social_login":true,"b2b_multi_tenant":true,"scim_provisioning":true}` |
| integrations.count | 6 | 17 |
| integrations.list | `[{"name":"Amazon SES"},{"name":"AWS API Gateway"},{"name":"Google","native":true,"category":"social","direction":"bidirectional"},{"name":"Kubernetes","native":true,"category":"infrastructure","direction":"bidirectional"},{"name":"Ambassador","native":false,"category":"infrastructure","direction":"bidirectional"},{"name":"Kong","native":false,"category":"infrastructure","direction":"bidirectional"},{"name":"Splunk","native":true,"category":"siem","direction":"outbound"},{"name":"Model Context Protocol (MCP)","native":true,"category":"ai","direction":"bidirectional"}]` | `[{"name":"LinkedIn"},{"name":"Slack"},{"name":"GitLab"},{"name":"Bitbucket"},{"name":"Xero"},{"name":"Rippling"},{"name":"ADP"},{"name":"Intuit"},{"name":"Google"},{"name":"GitHub"},{"name":"Microsoft"},{"name":"Apple"},{"name":"SAML","native":true,"direction":"inbound"},{"name":"OIDC","native":true,"direction":"inbound"},{"name":"Vercel","native":true,"category":"authentication","direction":"inbound"},{"name":"Clever","native":true,"category":"authentication","direction":"inbound"},{"name":"Asana","native":true},{"name":"Box","native":true},{"name":"Dropbox","native":true},{"name":"Front","native":true},{"name":"HelpScout","native":true},{"name":"Hubspot","native":true,"category":"crm"},{"name":"Intercom","native":true,"category":"chat"},{"name":"Jira","native":true},{"name":"Sentry","native":true},{"name":"Mailgun","native":true,"category":"email","direction":"outbound"},{"name":"Microsoft Sentinel","native":true,"direction":"outbound"}]` |
| language.primary | Go | - |
| license.spdx | Apache-2.0 | - |
| market.availability | `{"primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | `{"primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"cli":true,"mac":true,"web":true,"linux":true,"windows":true}` | `{"ios":true,"web":true,"android":true}` |
| pricing | `{"type":"hybrid","plans":[{"free":true,"name":"Developer","summary":"Free tier for developers and proof of concept","contactSales":false},{"free":false,"name":"Production","summary":"$770/year plus $0.14/aDAU/month","features":["All top-tier security features","1 production environment and 3 staging environments","Permissions and machine-to-machine tokens"],"commitment":"annual","components":[{"kind":"fixed","amount":770,"period":"year","currency":"USD"},{"per":{"qty":1,"unit":"aDAU"},"kind":"metered","amount":0.14,"currency":"USD"}],"description":"Everything you need to thoroughly test and explore the landscape of identity security.","contactSales":false},{"free":false,"name":"Growth","summary":"$9,350/year","features":["Everything from Production","Advanced analytics and insights","2 production environments and 5 staging environments","B2B SSO (OIDC only)"],"commitment":"annual","components":[{"kind":"fixed","amount":9350,"period":"year","currency":"USD"}],"description":"Optimal for piloting traffic growth, getting insights into sign up and login conversions, and basic B2B features.","contactSales":false},{"free":false,"name":"Enterprise (SaaS)","summary":"Custom pricing","features":["Everything from Growth","Event firehose to data lake","Multi-region deployments with data residency","Volume pricing","Enterprise integrations for legacy systems","Multi-tenancy","Concierge onboarding","Premium support with SLAs","99.99% uptime SLA"],"description":"Managed SaaS for companies needing strict SLAs, premium support, or regulatory compliance.","contactSales":true},{"free":false,"name":"Enterprise License (Self-Hosted)","summary":"Custom pricing","features":["Full control of hosting","Multi-region deployment flexibility","Custom pricing","Premium enterprise integrations","Premium support with SLAs"],"description":"Self-hosted option for maximum control and in-house expertise.","contactSales":true}],"summary":"From $770/year. Free Developer tier. Usage-based (aDAU) metered pricing available.","currency":"USD","freeTier":true,"sourceUrl":"https://www.ory.sh","retrievedAt":"2026-08-05T14:11:20.676Z","startingPrice":{"amount":0.14,"period":"month","currency":"USD"},"billingPeriods":["month","year"]}` | `{"type":"subscription","plans":[{"free":true,"name":"Free","summary":"Free up to 1,000,000 MAUs/month","features":["Single Sign-On (SAML & OIDC)","SCIM provisioning","Role-based access control","Bot detection","Identity linking","Multi-factor authentication","Social authentication (Microsoft, Google, Apple, GitHub, LinkedIn, Slack, GitLab, Bitbucket, Xero, Rippling, ADP, Intuit)","Magic Auth (passwordless email codes)","Audit logs","Agent authentication"],"components":[{"kind":"fixed","amount":0,"period":"month","currency":"USD"}],"description":"Up to 1 million monthly active users with core features included","contactSales":false,"includedLimits":{"maus":"1,000,000/month","admins":"unlimited","organizations":"unlimited"}}],"addOns":[{"name":"Overage Monthly Active Users","components":[{"kind":"fixed","amount":2500,"period":"month","currency":"USD"}]},{"name":"SSO Connections per Organization","components":[{"kind":"fixed","amount":125,"period":"month","currency":"USD"}]},{"name":"Custom Domain","components":[{"kind":"fixed","amount":99,"period":"month","currency":"USD"}]}],"summary":"Free up to 1,000,000 MAUs. $2,500/month per additional million MAUs. $125/month per SSO-enabled organization.","currency":"USD","freeTier":true,"sourceUrl":"https://workos.com/blog/auth0-pricing-how-it-works-and-compares-to-workos","retrievedAt":"2026-08-14T08:35:19.116Z","billingPeriods":["month"]}` |
| pricing.free_tier | yes | yes |
| pricing.model | freemium | freemium |
| pricing.price_level | low | low |
| pricing.transparent | yes | yes |
| release.cadence_days | 66 | - |
| release.history | `[{"url":"https://github.com/ory/kratos/releases/tag/v26.2.0","date":"2026-03-20T14:10:32Z","type":"stable","version":"v26.2.0"},{"url":"https://github.com/ory/kratos/releases/tag/v25.4.0","date":"2025-11-07T15:48:50Z","type":"stable","version":"v25.4.0"},{"url":"https://github.com/ory/kratos/releases/tag/v1.3.1","date":"2024-10-28T10:21:42Z","type":"stable","version":"v1.3.1"},{"url":"https://github.com/ory/kratos/releases/tag/v1.3.0","date":"2024-09-26T10:33:37Z","type":"stable","version":"v1.3.0"},{"url":"https://github.com/ory/kratos/releases/tag/v1.2.0","date":"2024-06-05T11:02:56Z","type":"stable","version":"v1.2.0"},{"url":"https://github.com/ory/kratos/releases/tag/v1.1.0","date":"2024-02-20T12:26:07Z","type":"stable","version":"v1.1.0"},{"url":"https://github.com/ory/kratos/releases/tag/v1.0.0","date":"2023-07-12T20:24:48Z","type":"stable","version":"v1.0.0"},{"url":"https://github.com/ory/kratos/releases/tag/v0.13.0","date":"2023-04-18T17:07:18Z","type":"stable","version":"v0.13.0"},{"url":"https://github.com/ory/kratos/releases/tag/v0.11.1","date":"2023-01-14T11:40:30Z","type":"stable","version":"v0.11.1"},{"url":"https://github.com/ory/kratos/releases/tag/v0.11.0","date":"2022-12-02T18:41:38Z","type":"stable","version":"v0.11.0"},{"url":"https://github.com/ory/kratos/releases/tag/v0.10.1","date":"2022-06-01T11:15:28Z","type":"stable","version":"v0.10.1"},{"url":"https://github.com/ory/kratos/releases/tag/v0.10.0","date":"2022-05-30T13:09:17Z","type":"stable","version":"v0.10.0"},{"url":"https://github.com/ory/kratos/releases/tag/v0.9.0-alpha.3","date":"2022-03-25T10:02:51Z","type":"prerelease","version":"v0.9.0-alpha.3"},{"url":"https://github.com/ory/kratos/releases/tag/v0.9.0-alpha.2","date":"2022-03-22T10:20:26Z","type":"prerelease","version":"v0.9.0-alpha.2"},{"url":"https://github.com/ory/kratos/releases/tag/v0.9.0-alpha.1","date":"2022-03-21T22:20:48Z","type":"prerelease","version":"v0.9.0-alpha.1"},{"url":"https://github.com/ory/kratos/releases/tag/v0.8.2-alpha.1","date":"2021-12-17T15:04:04Z","type":"prerelease","version":"v0.8.2-alpha.1"},{"url":"https://github.com/ory/kratos/releases/tag/v0.8.1-alpha.1","date":"2021-12-13T18:59:53Z","type":"prerelease","version":"v0.8.1-alpha.1"},{"url":"https://github.com/ory/kratos/releases/tag/v0.8.0-alpha.3","date":"2021-10-28T22:56:46Z","type":"prerelease","version":"v0.8.0-alpha.3"},{"url":"https://github.com/ory/kratos/releases/tag/v0.8.0-alpha.2","date":"2021-10-28T10:03:55Z","type":"prerelease","version":"v0.8.0-alpha.2"},{"url":"https://github.com/ory/kratos/releases/tag/v0.8.0-alpha.1","date":"2021-10-28T08:23:21Z","type":"prerelease","version":"v0.8.0-alpha.1"}]` | - |
| reliability.sla_pct | 99.99 | 99.99 |
| reliability.status_page | yes | yes |
| security.disclosure_policy | yes | yes |
| security.gdpr | yes | yes |
| security.hipaa | yes | yes |
| security.iso27001 | yes | - |
| security.pci | yes | - |
| security.scorecard | 6.7 | - |
| security.soc2 | yes | yes |
| security.trust_center | https://www.ory.com/blog/meeting-the-worlds-standards-ory-and-global-compliance-readiness | - |
| security.vulnerabilities | `{"count":2,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=github.com%2Fory%2Fkratos&per_page=100","last_12m":1,"max_severity":"HIGH"}` | - |

## Capabilities (Auth & Identity Software)

| Capability | Ory | WorkOS |
|---|:--:|:--:|
| **Deployment** |  |  |
| Hosting | Cloud + self-hosted | Cloud only |
| **Methods** |  |  |
| Social login | ✓ | ✓ |
| Passwordless | ✓ | ✓ |
| Passkeys / WebAuthn | ✓ | - |
| Multi-factor auth | ✓ | ✓ |
| **Enterprise** |  |  |
| SAML SSO | ✓ | ✓ |
| SCIM provisioning | ✓ | ✓ |
| B2B / multi-tenancy | ✓ | ✓ |
| **Standards** |  |  |
| OpenID Connect provider | ✓ | ✓ |
| **Delivery** |  |  |
| Hosted UI | Both | Both |
| **Access** |  |  |
| RBAC | ✓ | ✓ |
| **Licensing** |  |  |
| Self-hostable OSS core | ✓ | ✗ |

*Source: vioscaleAI. Generated 2026-09-21T03:43:03.451Z. "-" = undocumented, not absent.*
