polis is a free, open source identity & access management (iam) project written in TypeScript and released under Apache-2.0. It has 2,266 GitHub stars, 234 forks and 35 open issues, and was last pushed 2 months ago. On this registry it ranks #30 of 44 tracked projects in Identity & Access Management (IAM), with 5 head-to-head comparisons available.

What is polis?

Ory Polis is an open-source, Apache-2.0-licensed single sign-on service that bridges SAML login flows to OAuth 2.0 or OpenID Connect and adds SCIM 2.0 directory sync, aimed at developers and platform teams that need enterprise authentication and automated user provisioning in web applications without implementing those protocols themselves.

What it is

Ory Polis — formerly known as BoxyHQ Jackson — is a TypeScript project in the Security & Privacy / Identity & Access Management category, distributed under the Apache-2.0 licence and maintained under the Ory umbrella. Its repository carries 2,266 stars, 234 forks and 35 open issues, with the most recent push on 27 July 2026. The topic list places it squarely in the identity space and in the JavaScript server ecosystem: enterprise-software, identity-access-management, oidc, openid, openid-connect, saml, next-auth, nextjs, nodejs, javascript, open-source and hacktoberfest.

The concrete problem it solves is enterprise login. Large customers expect their workforce to sign in through a SAML identity provider, and implementing SAML directly in an application is complex. Ory Polis bridges or proxies a SAML login flow to OAuth 2.0 or OpenID Connect, abstracting away all the complexities of the SAML protocol so the application keeps speaking the protocols it already understands; it also supports OpenID Connect providers. A second problem is the user lifecycle. Directory Sync over the SCIM 2.0 protocol automates the provisioning and de-provisioning of users and groups, which the README frames as saving organisational hours, creating a single source of truth for user identity data, and helping keep that data secure.

Key capabilities

  • Bridges or proxies SAML login flows to OAuth 2.0 or OpenID Connect, removing the need for applications to implement SAML themselves.
  • Supports OpenID Connect providers in addition to SAML identity providers.
  • Provides Directory Sync based on the SCIM 2.0 protocol for automatic user and group provisioning and de-provisioning.
  • Powers the SAML and SCIM capabilities of the Ory Network, the vendor's managed offering.
  • Is available as a self-hosted premium option under the Ory Enterprise License (OEL), which adds features beyond the open-source version, CVE and security releases with patching SLAs by severity, advanced scaling and multi-tenancy, premium support, and access to a private Docker registry of enterprise builds.
  • Ships with documentation at ory.com/docs/polis and a repository README that includes an Installation section and an Ecosystem section.

Who uses it and how

  • Application teams whose enterprise customers require SAML sign-in, who add enterprise SSO without writing or maintaining a SAML implementation.
  • Organisations that need automated onboarding and offboarding of users and groups from an upstream directory, using SCIM 2.0 Directory Sync to keep identity data in one place.
  • Teams building on the Ory Network, where SAML and SCIM are powered by Ory Polis and are delivered as managed infrastructure alongside identity and credential management.
  • Organisations running mission-critical, commercial, production or global deployments that adopt the Ory Enterprise License for a self-hosted premium offering with support, scaling and multi-tenancy features.
  • Projects in the Node.js, Next.js and NextAuth environment indicated by the project's topic list.

Getting started

The README points to the Ory Polis documentation at ory.com/docs/polis and includes an Installation section, and it offers the Ory Network as the hosted route with a free developer account sign-up. Self-hosting in a mission-critical commercial environment requires a valid Ory Enterprise License and access to the Ory Enterprise Docker Registry.

How it compares

No list of paid products that this project replaces is provided in the facts, so its position is best read from the ecosystem it names. It sits alongside other Ory services, including Ory Kratos, whose section appears in the README's own table of contents, and its commercial counterpart is the Ory Network, the vendor's fully managed platform with usage-based pricing where SAML and SCIM are powered by Polis itself.

When to use it — and when not to

A self-hoster takes on operating the service, and the features that mission-critical deployments usually want — additional features beyond the open-source version, CVE patching with severity-based SLAs, advanced scaling and multi-tenancy, premium support and private Docker registry access — are gated behind the Ory Enterprise License. Teams that need only basic login, or that have no SAML or SCIM requirement, gain little from it. The README excerpt also does not set out the supporting infrastructure a self-hosted deployment needs, and the exact installation steps live in the external documentation rather than in the repository excerpt itself.

project readme (upstream, from github) — read inline

Ory polis - Open source Enterprise SSO and Directory Sync

Chat | Discussions | Newsletter

Guide | API Docs | Support this project!

Work in Open Source, Ory is hiring!


CI Tasks for Ory polis CII Best Practices

Ory Polis - formerly known as BoxyHQ Jackson - bridges or proxies a SAML login flow to OAuth 2.0 or OpenID Connect, abstracting away all the complexities of the SAML protocol. It also supports Directory Sync via the SCIM 2.0 protocol for automatic user and group provisioning/de-provisioning. Ory Polis also supports OpenID Connect providers.

Ory Polis on the Ory Network

The Ory Network is the fastest, most secure and worry-free way to use Ory's Services. SAML & SCIM on Ory Network are powered by Ory Polis.

The Ory Network provides the infrastructure for modern end-to-end security:

  • Identity & credential management scaling to billions of users and devices
  • Registration, Login and Account management flows for passkey, biometric, social, SSO and multi-factor authentication
  • Pre-built login, registration and account management pages and components
  • OAuth2 and OpenID provider for single sign on, API access and machine-to-machine authorization
  • Low-latency permission checks based on Google's Zanzibar model and with built-in support for the Ory Permission Language
  • SAML, SCIM, and complex Enterprise SSO capabilities

It's fully managed, highly available, developer & compliance-friendly!

  • GDPR-friendly secure storage with data locality
  • Cloud-native APIs, compatible with Ory's Open Source servers
  • Comprehensive admin tools with the web-based Ory Console and the Ory Command Line Interface (CLI)
  • Extensive documentation, straightforward examples and easy-to-follow guides
  • Fair, usage-based pricing

Sign up for a free developer account today!

Ory Polis On-premise support

Are you running Ory Polis in a mission-critical, commercial environment? The Ory Enterprise License (OEL) provides enhanced features, security, and expert support directly from the Ory core maintainers.

Organizations that require advanced features, enhanced security, and enterprise-grade support for Ory's identity and access management solutions benefit from the Ory Enterprise License (OEL) as a self-hosted, premium offering including:

  • Additional features not available in the open-source version.
  • Regular releases that address CVEs and security vulnerabilities, with strict SLAs for patching based on severity.
  • Support for advanced scaling and multi-tenancy features.
  • Premium support options, including SLAs, direct engineer access, and concierge onboarding.
  • Access to private Docker registry for a faster, more reliable access to vetted enterprise builds.

A valid Ory Enterprise License and access to the Ory Enterprise Docker Registry are required to use these features. OEL is designed for mission-critical, production, and global applications where organizations need maximum control and flexibility over their identity infrastructure. Ory's offering is the only official program for qualified support from the maintainers. For more information book a meeting with the Ory team to discuss your needs!

Directory Sync

Ory Polis also supports Directory Sync based on the SCIM 2.0 protocol.

Directory sync helps organizations automate the provisioning and de-provisioning of their users. As a result, it streamlines the user lifecycle management process by saving valuable organizational hours, creating a single truth source of the user identity data, and facilitating them to keep the data secure.

For complete documentation, visit the Ory Polis documentation

What is Ory Polis?

Ory Polis - formerly known as BoxyHQ Jackson - is an Enterprise Single Sign-On (SSO) service for SAML and OIDC identity providers. It implements SSO as an OAuth 2.0 flow, abstracting away the complexities of the underlying SAML or OIDC protocol. Ory Polis offers a range of features to simplify and secure enterprise SSO:

  • SAML/OIDC Enterprise SSO: Implements Single Sign-On for SAML or OIDC Identity Providers, abstracting the underlying protocol complexities and making it easy to connect with various enterprise identity systems.
  • OAuth 2.0 flow abstraction: Presents the SSO process as a standard OAuth 2.0 flow. Ideal for developers already familiar with OAuth 2.0 and OpenID Connect.
  • Data ownership and control: As an open-source solution, Ory Polis allows you to host the service yourself, ensuring you maintain full control over your data and your customers' identity information.
  • Flexible database support (BYOD): Supports a "Bring Your Own Database" model. This includes built-in compatibility for databases such as MySQL, MariaDB, Postgres, MongoDB, Redis, and PlanetScale, and works well with databases from major hosting providers.
  • Modular design: Built with a modular architecture where business logic is separated into distinct controllers, enhancing flexibility, maintainability, and the ability to adopt features incrementally.

We highly recommend reading the Ory Polis introduction docs to learn more about Ory Polis's background, feature set, and differentiation from other products.

Who is using it?

The Ory community stands on the shoulders of individuals, companies, and maintainers. The Ory team thanks everyone involved - from submitting bug reports and feature requests, to contributing patches and documentation. The Ory community counts more than 50.000 members and is growing. The Ory stack protects 7.000.000.000+ API requests every day across thousands of companies. None of this would have been possible without each and everyone of you!

The following list represents companies that have accompanied us along the way and that have made outstanding contributions to our ecosystem. If you think that your company deserves a spot here, reach out to [email protected] now!

Name Logo Website Case Study
OpenAI OpenAI
        </td>
openai.com OpenAI Case Study
Fandom Fandom
        </td>
fandom.com Fandom Case Study
Lumin Lumin
        </td>
luminpdf.com Lumin Case Study
Sencrop Sencrop
        </td>
sencrop.com Sencrop Case Study
OSINT Industries OSINT Industries
        </td>
osint.industries OSINT Industries Case Study
HGV HGV
        </td>
hgv.it HGV Case Study
Maxroll Maxroll
        </td>
maxroll.gg Maxroll Case Study
Zezam Zezam
        </td>
zezam.io Zezam Case Study
T.RowePrice T.RowePrice
        </td>
troweprice.com
Mistral Mistral
        </td>
mistral.ai
Axel Springer Axel Springer
        </td>
axelspringer.com
Hemnet Hemnet
        </td>
hemnet.se
Cisco Cisco
        </td>
cisco.com
Presidencia de la República Dominicana Presidencia de la República Dominicana
        </td>
presidencia.gob.do
Moonpig Moonpig
        </td>
moonpig.com
Booster Booster
        </td>
choosebooster.com
Zaptec Zaptec
        </td>
zaptec.com
Klarna Klarna
        </td>
klarna.com
Raspberry PI Foundation Raspberry PI Foundation
        </td>
raspberrypi.org
Tulip Tulip Retail
        </td>
tulip.com
Hootsuite Hootsuite
        </td>
hootsuite.com
Segment Segment
        </td>
segment.com
Arduino Arduino
        </td>
arduino.cc
Sainsbury's Sainsbury's
        </td>
sainsburys.co.uk
Contraste Contraste
        </td>
contraste.com
inMusic InMusic
        </td>
inmusicbrands.com
Buhta Buhta
        </td>
buhta.com
Amplitude amplitude.com
        </td>
amplitude.com
TIER IV Kyma Project Serlo Padis
Cloudbear Security Onion Solutions Factly All My Funds
Nortal OrderMyGear R2Devops Paralus
dyrector.io pinniped.dev pvotal.tech

Many thanks to all individual contributors

Get Started with Ory Polis

There are two ways to integrate Ory Polis into an application. Depending on your use case, you can choose either of them.

  1. As a separate service (Next.js application) This includes an admin portal out of the box for managing SSO and Directory Sync connections.
  2. NPM library as an embedded library in your application.

Installation

Head over to the Ory Developer Documentation to learn how to install Ory Polis.

Ecosystem

We build Ory on several guiding principles when it comes to our architecture design:

  • Minimal dependencies
  • Runs everywhere
  • Scales without effort
  • Minimize room for human and network errors

Ory's architecture is designed to run best on a Container Orchestration system such as Kubernetes, CloudFoundry, OpenShift, and similar projects. Binaries are small (5-15MB) and available for all popular processor types (ARM, AMD64, i386) and operating systems (FreeBSD, Linux, macOS, Windows) without system dependencies (Java, Node, Ruby, libxml, ...).

Ory Kratos: Identity and User Infrastructure and Management

Ory Kratos is an API-first Identity and User Management system that is built according to cloud architecture best practices. It implements core use cases that almost every software application needs to deal with: Self-service Login and Registration, Multi-Factor Authentication (MFA/2FA), Account Recovery and Verification, Profile, and Account Management.

Ory Hydra: OAuth2 & OpenID Connect Server

Ory Hydra is an OpenID Certified™ OAuth2 and OpenID Connect Provider which easily connects to any existing identity system by writing a tiny "bridge" application. It gives absolute control over the user interface and user experience flows.

Ory Oathkeeper: Identity & Access Proxy

Ory Oathkeeper is a BeyondCorp/Zero Trust Identity & Access Proxy (IAP) with configurable authentication, authorization, and request mutation rules for your web services: Authenticate JWT, Access Tokens, API Keys, mTLS; Check if the contained subject is allowed to perform the request; Encode resulting content into custom headers (X-User-ID), JSON Web Tokens and more!

Ory Keto: Access Control Policies as a Server

Ory Keto is a policy decision point. It uses a set of access control policies, similar to AWS IAM Policies, in order to determine whether a subject (user, application, service, car, ...) is authorized to perform a certain action on a resource.

End-to-End (E2E) tests

Create a .env.test.local file and populate the values. To execute the tests run:

npm run test:e2e

Security

Disclosing vulnerabilities

If you think you found a security vulnerability, please refrain from posting it publicly on the forums, the chat, or GitHub. You can find all info for responsible disclosure in our security.txt.

Telemetry

Ory's services collect summarized, anonymized data that can optionally be turned off. Click here to learn more.

Documentation

Guide

The Guide is available here.

HTTP API documentation

The HTTP API is documented here.

Upgrading and Changelog

New releases might introduce breaking changes. To help you identify and incorporate those changes, we document these changes in the Releases. For upgrading, please visit the upgrade guide.

Develop

We encourage all contributions and encourage you to read our contribution guidelines

Frequently asked questions

Is polis free to use?

polis is open source under the Apache-2.0 licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does polis do?

Streamline your web application's authentication with Polis, an SSO service supporting SAML and OpenID Connect protocols. Beyond enterprise-grade Single Sign-On

What is polis written in?

polis is primarily written in TypeScript. Its source is publicly available at https://github.com/ory/polis, and it has 2,266 GitHub stars.