The best open source alternative to Ory is Hanko. If that doesn't suit you, we've compiled a ranked list of other open source Ory alternatives to help you find a suitable replacement. Other interesting open source alternatives to Ory are: Keycloak, Better Auth, Authentik, and SuperTokens.
Ory alternatives are mainly Authentication & SSO Providers but may also be Authorization & Permissions Tools or Identity & Access Management (IAM) Tools. Browse these if you want a narrower list of alternatives or looking for a specific functionality of Ory.
Open source authentication platform supporting passkeys, 2FA, SSO, and social login. Self-host or use Hanko Cloud, with full control over your data and no lock-in.

Hanko is an open source authentication platform that handles user onboarding and login for web applications. It covers the full range of modern auth methods: passkeys, email passcodes, passwords, social logins, SSO, and multi-factor authentication with TOTP apps or security keys. You can mix and match these into exactly the flows your app needs.
It's built for developer teams who want solid auth without building it from scratch or handing full control to a closed-source provider like Auth0. Unlike Keycloak, which is powerful but notoriously complex to configure, Hanko is designed to integrate in minutes. Unlike Logto or Stack Auth, Hanko puts particular emphasis on passkeys as a first-class citizen.
Key capabilities:
Hanko is developed by a Germany-based team and offers EU hosting options, making it a practical fit for teams with GDPR obligations. It supports multiple languages and is designed to stay GDPR compliant by default.
For teams evaluating Better Auth or Authentik, Hanko sits in a distinct position: it's opinionated toward passkey-first flows while still being flexible enough to support legacy password auth during a gradual migration.
Looking for open source alternatives to other popular services? Check out other posts in the alternatives series and openalternative.co, a directory of open source software with filters for tags and alternatives for easy browsing and discovery.
Comprehensive open source identity management solution offering single sign-on, social login, and fine-grained authorization for applications and services.

Keycloak simplifies application security by providing a complete identity and access management solution. With built-in single sign-on (SSO), users authenticate once to access multiple applications, eliminating repetitive logins and logouts.
The platform offers robust identity features including:
Administrators benefit from a centralized console to manage users, configure authentication flows, and set security policies. Users get a self-service portal to manage their profiles, passwords, and linked accounts.
Enterprise-ready capabilities include high performance, clustering support for scalability, customizable themes, and extensive APIs for integration. As a Cloud Native Computing Foundation project, Keycloak maintains high standards for security, reliability, and community-driven development.
A comprehensive authentication framework offering email/password, social sign-on, two-factor auth, and multi-tenant support with full TypeScript integration.

Better Auth is a powerful authentication framework built specifically for TypeScript applications. It provides a complete suite of authentication features including email and password authentication, social sign-on with providers like GitHub and Google, two-factor authentication, and multi-tenant support with organization management.
The framework is designed to be framework-agnostic, supporting popular frameworks like React, Vue, Svelte, Next.js, Nuxt, and more. It offers a plugin ecosystem that allows you to extend functionality, and comes with built-in session management and access control capabilities.
Key benefits include:
authentik is an open-source identity provider that offers self-hosted authentication, authorization, and user management for businesses of all sizes.

authentik is a powerful, open-source identity and access management solution designed to give organizations full control over their authentication and authorization needs. Here's why authentik stands out:
Self-hosted and Open Source:
Flexible and Customizable:
Enterprise-Grade Features:
Scalable and Easy to Deploy:
Comprehensive Identity Solution:
Cost-Effective:
authentik empowers organizations to prioritize security, simplify deployment, and automate identity workflows. Whether you're a small business or a large enterprise, authentik provides the tools and flexibility to meet your specific identity and access management needs.
Open-source authentication solution offering flexible, self-hosted user management with advanced features and easy integration.

SuperTokens is an open-source authentication solution that provides developers with a powerful, flexible, and secure way to implement user management in their applications. With SuperTokens, you can easily add robust authentication features to your web and mobile apps while maintaining full control over your user data.
Key benefits of SuperTokens include:
By choosing SuperTokens, you're not just getting an authentication solution; you're gaining a flexible, secure, and future-proof foundation for your user management needs. Whether you're building a small project or a large-scale application, SuperTokens provides the tools and flexibility to create a seamless authentication experience for your users.
ZITADEL provides a comprehensive identity management solution with easy APIs, customizable workflows, and serverless deployment options.

ZITADEL is an all-in-one identity suite designed to streamline application development with robust authentication and authorization capabilities.
Key features:
ZITADEL empowers developers to offload complex identity tasks while maintaining adaptability. With security defaults and custom code extensions, it provides a solid foundation for building scalable applications with sophisticated user management.
Whether you need authentication for a small project or enterprise-grade identity infrastructure, ZITADEL offers the flexibility to grow with your needs. Focus on building your core product features while ZITADEL handles the intricacies of identity management.
Looking for open source alternatives to other popular services? Check out other posts in the alternatives series and openalternative.co, a directory of open source software with filters for tags and alternatives for easy browsing and discovery.
An open-source identity solution offering customizable login experiences, multi-tenant support, and comprehensive user management.

Logto is a powerful, open-source identity platform designed to simplify authentication and user management for modern applications. With its robust features and flexible architecture, Logto enables developers to implement secure, seamless authentication flows while providing an exceptional user experience.
Key benefits of Logto include:
Whether you're building a small application or managing a complex ecosystem of services, Logto provides the tools and flexibility to create secure, user-friendly authentication experiences that scale with your business.
Stack Auth provides secure authentication, authorization, and user management for developers in just 5 minutes.

Stack Auth is the open-source alternative to Auth0, offering a comprehensive authentication and user management solution for developers. With Stack Auth, you can implement secure authentication, authorization, and user management features in your applications in just 5 minutes.
Key benefits of Stack Auth include:
Stack Auth provides a REST API and client/server SDKs for custom integrations. It also offers features like user impersonation for debugging and webhooks for syncing with other services.
With its open-source nature and developer-first approach, Stack Auth offers a powerful, flexible, and cost-effective solution for authentication and user management in your applications.
Open-source authorization service for implementing fine-grained access controls. Centralized, scalable solution supporting RBAC, ABAC and ReBAC with Google Zanzibar-inspired architecture.

Centralized authorization service that transforms how you implement access controls across your applications. Instead of embedding authorization logic in your codebase, Permify provides a dedicated service that handles all permission checks and policy management.
Key capabilities include:
The platform centralizes permission data as structured relationships, enabling efficient management of large data volumes while maintaining consistent authorization policies across multiple applications. This approach eliminates development bottlenecks and allows teams to test, debug, and iterate authorization logic independently from application code.
Built for scalability, Permify handles complex permission scenarios while providing the performance needed for enterprise applications. The service integrates seamlessly with existing systems through well-documented APIs and supports various authentication patterns.
A scalable authorization layer that provides fine-grained access control through externalized policies, enabling secure and flexible permissions management.

Cerbos is an open-source authorization solution that simplifies complex access control implementation. It offers policy-based authorization that decouples access control logic from application code, making it easier to manage and update permissions without code changes.
Key benefits include:
The system supports both RBAC and ABAC models, allowing teams to implement sophisticated access control that adapts to changing business needs.
Authgear is a managed IAM platform handling authentication, SSO, and user management for B2C and B2B apps, with biometrics, MFA, and zero-trust support.

Authgear is a managed authentication and SSO platform built for developers who need to handle complex identity requirements without building auth infrastructure from scratch. It covers the full range: login flows, multi-factor authentication, biometrics, Single Sign-On, and fine-grained access control, all through a low-code setup that keeps integration overhead low.
It's designed to work for both B2C products (where you're managing large volumes of end users) and B2B setups with multi-tenant hierarchies, role-based permissions, and enterprise identity providers. Real-world deployments include integrating Azure AD for internal staff while routing external users through WhatsApp OTP, or adding biometric login to mobile apps without rearchitecting the backend.
Key capabilities include:
Compared to self-hosted options like Keycloak or authentik, Authgear trades configuration depth for operational simplicity. It's ISO 27001 and SOC 2 Type II certified, which matters for enterprise procurement. If you're evaluating managed alternatives to Okta or AWS Cognito, Authgear positions itself as a developer-friendly middle ground with enterprise compliance built in.
A free trial is available for teams evaluating it before committing.
Looking for open source alternatives to other popular services? Check out other posts in the alternatives series and openalternative.co, a directory of open source software with filters for tags and alternatives for easy browsing and discovery.
Complete B2B authentication solution with SSO, role management, API security, and pre-built UI components. Ship enterprise-grade auth in just a few lines of code.

Complete B2B authentication platform that handles everything from user login to enterprise-grade security features. Build sophisticated user management systems without the complexity of developing auth infrastructure from scratch.
Key features include:
Developer-friendly implementation with SDKs for all major frameworks including Next.js, React, Flask, Express.js, and Go. The platform includes user impersonation for customer support, real-time webhooks, and role-based access control that can be implemented with just one line of code.
Perfect for B2B SaaS companies looking to add enterprise-ready authentication and user management without building complex auth infrastructure in-house.