We evaluated Ory a few months ago. My understanding:
1. Ory Kratos provides session-based authentication and user management.
2. Ory Hydra is a self-managed server that secures access to your applications and APIs with OAuth 2.0 and OpenID Connect.
Basically we want to replace AWS Cognito (which is pretty much abandonware) to secure our API so we needed both applications. Unfortunately we had to put our efforts on hold:
1. Bugs around traits meant we had issues around password change, password recovery and email change/reverifications for our use-case
2. Lack of documentation prevented us making progress on 2FA/WebAuthn
3. Bearer token/Oauth consent flow wasn't available without a lot of work because Kratos and Hydra are not "integrated" [1]. Someone shows how they rolled their own integration [2].
I'd love for someone to advise that we were wrong or misunderstood things or that things have moved on since then!
[1] https://github.com/ory/kratos/issues/273 [2] https://blog.px.dev/open-source-auth/
Sounds about right.
> 1. Bugs around traits meant we had issues around password change, password recovery and email change/reverifications for our use-case
Can't comment much on these as I haven't experienced those issues, but I'm curious to hear what the issues were.
> 2. Lack of documentation prevented us making progress on 2FA/WebAuthn
Things have moved on in the last months, and the 2FA/WebAuthn implementation seems more mature and documented.
> 3. Bearer token/Oauth consent flow wasn't available without a lot of work because Kratos and Hydra are not "integrated" [1]. Someone shows how they rolled their own integration [2].
That's right, sadly there's no 'integration' available officially. There've been at least two pull requests (I made one of them) to add Hydra integration to the official demo Kratos UI, which for different reasons weren't merged. I'm not sure I'd say it's so much work (essentially, it's getting the existing Kratos session and translating those into a Hydra session, with a couple of API calls), but it's not something very well documented (or at all) and you're left to figure it out by yourself from the API documentation. I hope that integration between the two is improved, at least with an official demo showcasing the calls needed in order and with the right parameters.
Regarding Kratos and Hydra is this[1] your PR?
[1]https://github.com/ory/kratos-selfservice-ui-node/pull/149
Sorry for the rant and what may sound like a very negative comment, I wrote this quickly. I think it would be great to right away stop using the term "identity" so freely and use something else, or at least clearly explain what do you understand for identity. I think it would be great for programmers to start disambiguating the concept, and I think projects like ory have a good opportunity (that you yourselves created and built, of course!) to make it a bit better.
Edit: "account" may not fully capture everything ory might be trying to do, but it's definitely closer than "identity".
Authentication is the verification of identity after registration.
Authorization is the verification of permission for an identity to take an action.
I see the API part. But is there an UI part, besides the self-service account management?
Because that general management interface is the missing piece in many of the identity services.
For permissions, that’s a different service: https://github.com/ory/keto
UI for management, impersonation, configuration, etc... with RBAC, end-user UI for account preferences, profile, login, password reset, etc... all customizable/themeable.
With the switch to quarkus, is has a much more "single binary" feel and is very easy to deploy / configure.