---
source_url: "https://www.ory.com/kratos/?utm_source=openai"
title: "Cloud Native Identity & User Management System | Ory Kratos"
mirrored_at: 2026-08-17T13:03:57.599Z
host: www.ory.com
cited_in_42a: true
mirror_canonical: "https://index.42a.ai/www.ory.com/kratos/index__q__utm_source_openai"
---

> **Original source:** https://www.ory.com/kratos/?utm_source=openai

Headless user authentication and identity management with MFA, social login, custom identities, and a clean API.

Secure, _scalable identity management and user authentication_ is complex. Ory Kratos streamlines it with a headless, cloud-native identity management system that runs in the cloud or self-hosted — letting developers focus on building their applications.

### Need support?

Run Ory Kratos on your own infrastructure with the Ory Enterprise License. Self-hosted control, 24x7 support, security patches, and SLAs.

### Need to move quickly?

Get cloud identity management without the operational overhead. Ory Network runs Ory Kratos for you — fully managed, multi-region, free to start.

## Full control. A cloud-native identity management system that fits your stack.

Ory Kratos is a fully featured identity and user management system with a clean, API-first architecture. Run it cloud-native, self-hosted, or fully managed — you control every aspect through the headless API.

Our system needs to handle sudden increases in traffic — authentication is always in the critical path for every request a user is making to our platform.

[Read how Fandom uses Ory Kratos to handle authentication for hundreds of millions of users across thousands of communities](https://www.ory.com/case-studies/fandom)

-   ### Self service login and registration
    
    Users create and sign in to accounts using username/email and password combinations, Social Login, passwordless flows, TOTP and more.
    
-   ### Multifactor Authentication
    
    Implement proven standards of web security with FIDO2, WebAuthn, TOTP. Use Yubikeys, Google Authenticator or FaceID to reduce friction and increase security.
    
-   ### User management
    
    Run a complete user management system: create, update, retrieve, and delete user identities through the API, with webhooks for lifecycle events. Full admin control over every identity in your system.
    
-   ### Bring your identity model
    
    Use customizable identity models (defining custom fields such as name, address, favorite pet) and create your own interfaces in your style and branding.
    
-   ### Social Login & SSO
    
    Let users sign in with Google, GitHub, Apple, and any OIDC provider. [Single sign-on (SSO)](https://www.ory.com/single-sign-on) with the social and enterprise identity providers your users already trust.
    
-   ### Account verification and recovery
    
    Verify an identity by checking the email, phone number, or physical address of that user. Provide recovery of accounts using "Forgot Password" flows, security codes, etc.
    

## How to de-risk identity at scale with Ory

OSS is where most teams start. The question is whether it holds up as scale, compliance, and security requirements grow. Running identity infrastructure yourself means owning everything, from patches to incident response, compliance controls, and performance tuning. At enterprise scale, that overhead competes with product innovation. Ory's commercial offerings, OEL and Ory Network, trade that burden for SLA-backed support, managed CVE patching, and audit-ready controls.

OSS

Evaluate and prototype

OEL

Self-hosted, great for enterprises that require air-gapped or certified environments

Ory Network

Fully-managed, fastest path to production without operational overhead

OSS: No

Compliance-ready

Ory Network: Yes

OSS: No

Multi-region capable

Ory Network: Yes

OSS: No

OEL: Yes

Ory Network: Yes

OSS: No

OEL: Yes

Ory Network: Yes

OSS: No

OEL: Yes

Ory Network: Yes

CLI

CLI & GUI

CLI & GUI

OSS: No

OEL: Yes

n/a

OSS: No

n/a

Ory Network: Yes

OSS: No

OEL: Yes

Ory Network: Yes

OSS: No

OEL: Yes

Ory Network: Yes

OSS: No

OEL: Yes

Ory Network: Yes

OSS: Yes

OEL: Yes

Ory Network: Yes

OSS: No

OEL: Yes

Ory Network: Yes

OSS: No

OEL: Yes

Ory Network: Yes

OSS: No

OEL: Yes

Ory Network: Yes

OSS: No

OEL: Yes

Ory Network: Yes

## Deploy Ory _Kratos_ on your preferred infrastructure

Self-hosted to SaaS: full control over your infrastructure, data, and compliance.

page.tsx

```
import React, { useEffect, useState } from "react"
import { FrontendApi, Configuration, Session } from "@ory/client"

const basePath = "https://ory.example.com"

const ory = new FrontendApi(
  new Configuration({
    basePath,
    baseOptions: { withCredentials: true },
  }),
)

function Example() {
  const [session, setSession] = useState<Session | undefined>()

  useEffect(() => {
    ory
      .toSession()
      .then(({ data }) => {
        setSession(data)
      })
      .catch((err) => {
        console.error(err)
        // Not signed in, redirect to login
        window.location.replace(`${basePath}/self-service/login/browser`)
      })
  }, [])

  if (!session) {
    return <p>No session found.</p>
  }

  return <p>Welcome to, {session?.identity.traits.email}.</p>
}
```

![](https://cdn.sanity.io/images/33xluxe1/production/098c90a547632746c4c0aea6c60693a6e57272ba-1540x1232.png?w=1536&h=1229&auto=format&fit=min&q=75)