hydra is a free, open source identity & access management (iam) project written in Go and released under Apache-2.0. It has 17,549 GitHub stars, 1,610 forks and 98 open issues, and was last pushed 2 months ago. On this registry it ranks #8 of 23 tracked projects in Identity & Access Management (IAM), with 5 head-to-head comparisons available.

What is hydra?

Ory Hydra is an OpenID Certified OpenID Connect and OAuth 2.1 provider written in Go and licensed under Apache-2.0, built for teams that need standards-compliant token issuance, client management, and consent flows while user accounts stay in their own existing identity system.

What it is

Ory Hydra is a hardened server implementation of the OAuth 2.0 authorization framework and OpenID Connect Core 1.0. It is deliberately a standalone authorization server without user management: it does not store identities, profiles, or passwords, and instead connects to whatever identity provider already exists through a login and consent app that the operator writes. That app lets the operator keep absolute control over the user interface and experience flows, and Hydra works with any authentication endpoint, including Ory Kratos, authboss, User Frosting, or a proprietary system.

The concrete problem it solves is the cost of building and maintaining an authorization server by hand. Token issuance and validation, client management, consent and login flow orchestration, and JWKS management are the parts of OAuth 2.0 and OpenID Connect that are easy to get subtly wrong and expensive to keep current with the specifications. Hydra replaces that hand-rolled work with a server that implements the IETF and OpenID Foundation standards, follows cloud architecture best practices, and fits modern cloud native environments such as Kubernetes and managed platforms.

Key capabilities

  • Implements the OAuth 2.0 Authorization Framework (RFC 6749), plus the OAuth 2.0 Threat Model and Security Considerations (RFC 6819).
  • Supports OAuth 2.0 Token Revocation (RFC 7009) and OAuth 2.0 Token Introspection (RFC 7662).
  • Covers OAuth 2.0 for Native Apps and Proof Key for Code Exchange (RFC 7636) for public clients.
  • Offers OAuth 2.0 Dynamic Client Registration and its management counterpart (RFC 7591 and RFC 7592).
  • Issues and validates tokens using the JSON Web Token profile for client authentication and authorization grants (RFC 7523).
  • Implements OpenID Connect Core 1.0, OpenID Connect Discovery 1.0, and OpenID Connect Dynamic Client Registration 1.0.
  • Handles OpenID Connect Front-Channel Logout 1.0 and Back-Channel Logout 1.0, and manages JWKS.
  • Exposes headless APIs for integration with existing user management, and ships a Docker-based deployment path.

Who uses it and how

  • Organizations that already own an identity store use Hydra behind that store, wiring Ory Kratos, authboss, User Frosting, or a proprietary system into the login and consent app.
  • Teams running cloud native infrastructure deploy Hydra next to Kubernetes workloads and managed platforms, where its low latency, high throughput, and low resource consumption matter.
  • Operators that need login screens, consent copy, and branding under their own control use the login and consent app boundary to own the entire user-facing flow.
  • Deployments serving large numbers of clients and tokens rely on Hydra for authorization server duties while user management stays elsewhere.
  • The project is trusted by OpenAI and many others for scale and security.

Getting started

Consume Hydra as a service on Ory Network, or self-host it; the README points to the Ory Hydra introduction docs and a quickstart, and Docker appears among the project topics as the container path.

How it compares

The facts name no paid products that Hydra replaces. Within the Ory ecosystem, Ory Kratos handles identity and user management, Ory Oathkeeper is an identity and access proxy, and Ory Keto serves access control policies as a server, while Hydra handles only OAuth 2.0 and OpenID Connect. Outside that ecosystem, projects such as authboss and User Frosting are named as authentication endpoints Hydra can sit behind rather than as substitutes for it.

When to use it — and when not

A self-hoster must operate the Hydra server itself and also design and run the login and consent app, because Hydra deliberately ships no user management and no built-in login interface. Teams that want identity storage, password handling, and a ready-made user interface in one package should look at an identity management system instead of Hydra, and anyone unwilling to own an authorization server's operational surface should prefer the hosted Ory Network option. The registry data shows 98 open issues, so the project carries an active but not empty issue backlog.

project readme (upstream, from github) — read inline

Ory Hydra - Open Source OAuth 2 and OpenID Connect server

Chat · Discussions · Newsletter · Docs · Try Ory Network · Jobs

Ory Hydra is a hardened, OpenID Certified OAuth 2.0 Server and OpenID Connect Provider optimized for low-latency, high throughput, and low resource consumption. It connects to your existing identity provider through a login and consent app, giving you absolute control over the user interface and experience.


What is Ory Hydra?

Ory Hydra is a server implementation of the OAuth 2.0 authorization framework and the OpenID Connect Core 1.0. It follows cloud architecture best practices and focuses on:

  • OAuth 2.0 and OpenID Connect flows
  • Token issuance and validation
  • Client management
  • Consent and login flow orchestration
  • JWKS management
  • Low latency and high throughput

We recommend starting with the Ory Hydra introduction docs to learn more about its architecture, feature set, and how it compares to other systems.

Why Ory Hydra

Ory Hydra is designed to:

  • Be a standalone OAuth 2.0 and OpenID Connect server without user management
  • Connect to any existing identity provider through a login and consent app
  • Give you absolute control over the user interface and experience flows
  • Work with any authentication endpoint: Ory Kratos, authboss, User Frosting, or your proprietary system
  • Scale to large numbers of clients and tokens
  • Fit into modern cloud native environments such as Kubernetes and managed platforms

OAuth2 and OpenID Connect: Open Standards

Ory Hydra implements Open Standards set by the IETF:

and the OpenID Foundation:

OpenID Connect Certified

Ory Hydra is an OpenID Foundation certified OpenID Provider (OP).

Ory Hydra is a certified OpenID Providier

The following OpenID profiles are certified:

To obtain certification, we deployed the reference user login and consent app (unmodified) and Ory Hydra v1.0.0.

Deployment options

You can run Ory Hydra in two main ways:

  • As a managed service on the Ory Network
  • As a self hosted service under your own control, with or without the Ory Enterprise License

Use Ory Hydra on the Ory Network

The Ory Network is the fastest way to use Ory services in production. Ory OAuth2 & OpenID Connect is powered by the open source Ory Hydra server and is API compatible.

The Ory Network provides:

  • OAuth2 and OpenID Connect for single sign on, API access, and machine to machine authorization
  • Identity and credential management that scales to billions of users and devices
  • Registration, login, and account management flows for passkeys, biometrics, social login, SSO, and multi factor authentication
  • Prebuilt login, registration, and account management pages and components
  • Low latency permission checks based on the Zanzibar model with the Ory Permission Language
  • GDPR friendly storage with data locality and compliance in mind
  • Web based Ory Console and Ory CLI for administration and operations
  • Cloud native APIs compatible with the open source servers
  • Fair, usage based pricing

Sign up for a free developer account to get started.

Self-host Ory Hydra

You can run Ory Hydra yourself for full control over infrastructure, deployment, and customization.

The install guide explains how to:

  • Install Hydra on Linux, macOS, Windows, and Docker
  • Configure databases such as PostgreSQL, MySQL, and CockroachDB
  • Deploy to Kubernetes and other orchestration systems
  • Build Hydra from source

This guide uses the open source distribution to get you started without license requirements. It is a great fit for individuals, researchers, hackers, and companies that want to experiment, prototype, or run unimportant workloads without SLAs. You get the full core engine, and you are free to inspect, extend, and build it from source.

If you run Hydra as part of a business-critical system, for example OAuth2 and OpenID Connect for all your users, you should use a commercial agreement to reduce operational and security risk. The Ory Enterprise License (OEL) layers on top of self-hosted Hydra and provides:

  • Additional enterprise features that are not available in the open source version
  • Regular security releases, including CVE patches, with service level agreements
  • Support for advanced scaling, multi-tenancy, and complex deployments
  • Premium support options with SLAs, direct access to engineers, and onboarding help
  • Access to a private Docker registry with frequent and vetted, up-to-date enterprise builds

For guaranteed CVE fixes, curre

readme truncated — read the full docs on github

Frequently asked questions

Is hydra free to use?

hydra is open source under the Apache-2.0 licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does hydra do?

Internet-scale OpenID Certified™ OpenID Connect and OAuth2.1 provider that integrates with your user management through headless APIs. Solve OIDC/OAuth2 user ca

What is hydra written in?

hydra is primarily written in Go. Its source is publicly available at https://github.com/ory/hydra, and it has 17,549 GitHub stars.