
What I like best about Ory is its modular, composable architecture — Kratos and Oathkeeper run as independent services with no hard dependencies, so we deploy and scale only what we need, unlike monolithic IAM stacks.
It's cloud-native and Kubernetes-friendly by design, slotting naturally into our infrastructure and scaling horizontally without surprises.
Being open-source with a real self-hosting option (same codebase as Ory Network) gives us full transparency, architectural control, and zero vendor lock-in.
We implemented the UI/UX entirely on our own using Ory's headless APIs, so we have full control over the user experience. We haven't used any third-party integrations — Ory covers our identity and access needs on its own. Performance has been solid and fully meets our requirements. Pricing isn't relevant for us since we're running the open-source self-hosted version. We don't use Ory's support or any AI/intelligence features. Review collected by and hosted on G2.com.
The documentation has gaps and is hard to navigate, especially for the open-source offering — some configuration fields aren't well described, and common scenarios (like wiring Kratos and Oathkeeper together) lack clear end-to-end examples.
Since Ory is composable, you have to glue the services together yourself, which is doable but non-trivial to do robustly in production. Better out-of-the-box orchestration between Ory's own products would make self-hosting noticeably smoother.
We also feel the open-source version lacks several capabilities we'd really like to have: a proper administrative UI, built-in brute force protection, DoS protection, credential stuffing protection, suspicious IP throttling, a fine-grained permission API, permissions tied to machine-to-machine tokens, and multi-tenancy with B2B SSO. The OSS release generally doesn't keep pace with Enterprise/Network, so these gaps occasionally force us to build workarounds. Review collected by and hosted on G2.com.