Hacker News new | past | comments | ask | show | jobs | submit login

There are already true open source alternatives on the horizon such as https://github.com/ory

It is about time for a new generation of identity systems in my opinion. This acquisition shows the risk of centralized, vendor locked-in services.




https://www.keycloak.org/ is another open source option.

Compared to other choices, it's more mature and well-vetted because it forms the upstream for RedHat's SSO offering.

On the other hand, it's a big monolithic Java app, but they are making some moves to be more CNF-friendly: https://www.keycloak.org/2020/12/first-keycloak-x-release.ad...


If you are going to use keycloak it's worth making sure their mental model matches your own. Specifically we had issues with our model of multi-tennacy, each in their own realm vs. the keycloak idea of multiple tennants in a single realm. It caused some large performance and management issues.


We're evaluating Keycloak. Would love to get some insights on your experience


Can you please share where you heard the Keycloak preferred way for MT is multiple tenants per realm? I have never seen this before.


Yeah Keycloak is great. I've tried using other open source alternatives, but none are as full-featured and mature as Keycloak.


Ory is really interesting but not, IMO, quite there yet. There are a bunch of Kratos features that aren't there but, once they are, I think it's a really compelling option.


We used ORY fosite to write our auth service, and I have so far really enjoyed working with the lib. Feels like they aren't as focused on external users of the fosite lib though so much as their hydra solution which consumes it. The overall ORY ecosystem seems nice though, though I have not delved into it in detail past fosite.



They just went private and you need to pay $12,000/year for unlimited clients.


I try to like it but it have a HARD stand against multi-tenant deployment.

This is a major weak point of many solution, in special how automate it.


If you're looking for next generation of identity solutions? https://magic.link is what everyone would need, provides decentralised identity, fair pricing and no vendor lock-in.

I love their startup pricing.


I hate this magic link flow. Its a major pain in my ass when I already have a password manager that knows how to login. Now I have to leave my browser and go to my e-mail client that will open a new tab even though I already have one open.


I wish I knew python. I would kill for the backend developer job they have open. I love IAM.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: