All 78 Dependencies

Every package Ory Kratos depends on, ranked by repo health score.

Ory Kratos is a headless, cloud-native identity server written in Go that takes full ownership of user authentication and account lifecycle. Instead of embedding auth logic into your application, you expose Kratos over HTTP and let it drive login, registration, account recovery, email verification, multi-factor authentication, and profile management as self-contained, configurable flows.

Every identity in Kratos is defined by a JSON Schema, meaning user traits—email, username, phone number, or any custom attributes your product requires—are declared in config rather than code. Credential types (password, passkey, TOTP, WebAuthn, OIDC social login, SAML, magic link codes) are strategies that can be mixed and matched per deployment without touching application logic.

Kratos is UI-agnostic by design. The server never renders HTML; it returns flow objects that your own frontend—React, Vue, mobile, or server-rendered—consumes to build whatever login screen you need. This strict separation means branding, accessibility, and UX are entirely in your control. Browser-based and API-native flows are first-class citizens, covering both traditional web apps and native mobile clients.

Born from the Ory ecosystem, Kratos integrates natively with Ory Hydra for OAuth2 and OpenID Connect, Ory Oathkeeper for request authorization, and the Ory Network managed service. It supports PostgreSQL, MySQL, and CockroachDB via the Ory Pop ORM, ships quickstart Docker Compose setups for most databases, and runs comfortably on Kubernetes. Adopted by companies including Segment, Arduino, and Sainsbury's, Kratos is proven at scale across both consumer and enterprise workloads.

33 promise-retry 2.0.1 35 deepcopy v0.0.0-20170929034955-c48cc78d4826 36 yaml.js 0.3.0 40 gddo v0.0.0-20190904175337-72a348e765d2 41 chrome-remote-interface 0.33.3 outdated 41 go-spew v1.1.2-0.20180830191138-d8f796af33cc 41 sjson v1.2.5 42 process 0.11.10 43 otp v1.4.0 outdated 44 securecookie v1.1.1 outdated 45 go-grpc-prometheus v1.2.0 45 json-patch v5.9.11 45 profile v1.7.0 45 yaml v1.0.0 46 mock v1.6.0 46 request 2.88.2 48 Sprig v3.3.0 48 errors v0.9.1 48 go-retryablehttp v0.7.8 48 sessions v1.3.0 outdated 49 sqlx v1.4.0 51 fsnotify v1.9.0 outdated 51 url-join 5.0.0 51 websocket v1.5.3 53 Cobra v1.10.2 55 cors v1.11.1 55 go-yaml v1.18.0 outdated 56 retry-go v4.6.1 outdated 59 go-oidc v3.11.0 59 jwt v4.5.2 outdated 59 jwt v5.3.1 60 backoff v2.2.1+incompatible outdated 61 faker v4.4.2 outdated 62 Ristretto v2.4.0 62 cast v1.9.2 outdated 62 glob v0.2.3 outdated 63 httpmock v1.3.1 outdated 65 color v1.19.0 65 go-toml v1.9.5 66 Dockertest v4.0.0-beta.4 68 gjson v1.19.0 outdated 69 doublestar v2.0.4 outdated 70 OTPAuth 9.4.1 outdated 70 prettier-plugin-packagejson 3.0.2 71 golang-lru v2.0.7 74 testify v1.11.1 outdated 74 uuid v4.4.0+incompatible 75 Day.js 1.11.19 outdated 75 go-jose v3.0.5 outdated 75 pflag v1.0.10 79 dotenv 17.2.3 outdated 79 koanf v0.1.2 outdated 79 koanf v0.1.0 outdated 79 koanf v0.1.0 outdated 79 koanf v0.1.0 outdated 79 koanf v0.1.0 outdated 79 koanf v0.1.0 outdated 79 koanf v2.2.2 outdated 84 pgx v4 v5.9.2 86 Go-MySQL-Driver v1.9.3 outdated 86 Logrus v1.9.3 outdated 88 got 14.6.3 outdated 88 lo v1.46.0 outdated 88 webauthn v0.11.2 outdated 89 jwx v1.2.31 outdated 89 jwx v2.1.1 outdated 90 Express 4.21.2 outdated 90 phonenumbers v1.7.4 outdated 91 Faker 10.1.0 outdated 91 client_golang v1.23.2 outdated 91 prettier 3.8.1 outdated 92 Playwright 1.56.1 outdated 93 Cypress 14.4.0 outdated 93 slack v0.23.1 outdated 96 go-github v89.0.0 outdated 97 TypeScript 5.9.3 outdated 98 moby/moby/api v1.54.2 outdated 98 moby/moby/api v0.4.1 outdated

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers