
OpenID Certified OAuth 2.0 and OpenID Connect provider for token issuance, client management, JWKS, and login/consent flow orchestration via headless APIs for cloud-native applications.
Ory Hydra is a hardened, OpenID Certified OAuth 2.0 Server and OpenID Connect Provider optimized for low-latency, high throughput, and low resource consumption. It connects to your existing identity provider through a login and consent app, giving you absolute control over the user interface and experience.
Ory Hydra is a server implementation of the OAuth 2.0 authorization framework and the OpenID Connect Core 1.0. It follows cloud architecture best practices and focuses on:
We recommend starting with the Ory Hydra introduction docs to learn more about its architecture, feature set, and how it compares to other systems.
Ory Hydra is designed to:
Ory Hydra implements Open Standards set by the IETF:
and the OpenID Foundation:
Ory Hydra is an OpenID Foundation certified OpenID Provider (OP).
The following OpenID profiles are certified:
code)id_token, id_token+token)code+id_token, code+id_token+token, code+token)To obtain certification, we deployed the reference user login and consent app (unmodified) and Ory Hydra v1.0.0.
You can run Ory Hydra in two main ways:
The Ory Network is the fastest way to use Ory services in production. Ory OAuth2 & OpenID Connect is powered by the open source Ory Hydra server and is API compatible.
The Ory Network provides:
Sign up for a free developer account to get started.
You can run Ory Hydra yourself for full control over infrastructure, deployment, and customization.
The install guide explains how to: