
Scalable API key server for issuing, verifying, and revoking credentials with token derivation for fine-grained capability tokens. Supports low-latency verification, horizontal scaling, and cloud-native deployment.
Ory Talos is a scalable and secure API key server optimized for low-latency verification, horizontal scaling, and predictable operations. It follows established security best-practices for API keys and issues, verifies, revokes, and derives API keys and short-lived tokens for high-throughput systems.
Ory Talos is a server for issuing, verifying, and managing API keys. It follows cloud architecture best practices and focuses on:
We recommend starting with the Ory Talos documentation to learn more about its architecture, feature set, and how it compares to other systems.
Ory Talos is designed to:
You can run Ory Talos in two main ways:
The Ory Network is the fastest way to use Ory Talos in production.
The Ory Network provides:
Sign up for a free developer account to get started.
You can run Ory Talos yourself for full control over infrastructure, deployment, and customization.
The install guide explains how to:
The open source distribution runs as a single instance against an embedded SQLite database. It is a great fit for individuals, researchers, hackers, and companies that want to experiment, prototype, or run low-traffic workloads without service level agreements (SLAs).
If you run Ory Talos as part of a business-critical system, for example API key verification on a hot path, you should use a commercial agreement to reduce operational and security risk. The Ory Enterprise License (OEL) layers on top of self-hosted Ory Talos and provides:
For guaranteed CVE fixes, current enterprise builds, advanced features, and production support, you need a valid Ory Enterprise License and access to the Ory Enterprise Docker registry. To learn more, contact the Ory team.
Install the Ory CLI and use the managed Ory Network, or run Ory Talos locally with Docker Compose.
# Install the Ory CLI if you do not have it yet:
bash <(curl https://raw.githubusercontent.com/ory/meta/master/install.sh) -b . ory
sudo mv ./ory /usr/local/bin/
# Sign in or sign up
ory auth
# Create a new project
ory create project --create-workspace "Ory Open Source" --name "GitHub Quickstart" --use-project
To run Ory Talos locally:
# Open source edition (SQLite, single-node)
docker-compose -f docker-compose.oss.yaml up --build
The API will be available at http://localhost:4420
For end-to-end walkthroughs of issuing, verifying, and revoking keys, see the Quickstart guide and Issue and verify.