Decoupling Identity: Managing User Flows with Ory Kratos
Learn how Ory Kratos decouples identity management from application logic using a headless architecture, state-machine flows, and JSON schemas.
ReadMeFeed / Community knowledge
Real questions. Useful conversations. Find the people who know your stack.
Learn how Ory Kratos decouples identity management from application logic using a headless architecture, state-machine flows, and JSON schemas.
Avoid registration failures in Ory Kratos by using a local SMTP mock to verify that email tokens are sent and identities are correctly marked as verified.
Step‑by‑step guide to enable Ory Kratos self‑service registration with email verification, including config snippets, verification checks, and recovery actions.
Dynamic client registration (DCR) lets you add new OAuth2/OIDC clients to Ory Hydra automatically, cutting admin overhead. Learn how to craft the payload, validate redirect URIs, and avoid common pitfalls.
Database Schema Transition Ory Kratos manages identity data using a SQL database, where schema updates are applied via the ory migrate sql command during version transitions. While the identity attributes are stored in a flexible JSONB format in PostgreSQL, the underlying table structures are subject to version-specific migrations. Migration Constraints Curr
Goal Ensure that a single‑page application hosted on a subdomain can maintain an authenticated session after upgrading Ory Kratos from v0.10.5 to v0.11+, while the service runs on PostgreSQL 12+. Constraints and uncertainty Kratos v0.11+ sets the session cookie with SameSite=None and a new name ending in an underscore (ory_kratos_session_). Browsers only hon
Goal Determine how Ory Keto handles cache invalidation when policy changes occur, ensuring no stale decisions persist beyond the configured TTL. Constraints & Uncertainty In‑memory cache keyed by CACHE_TTL_SECONDS, default 300 s. Documentation does not specify automatic invalidation triggers on policy mutation. Concurrent evaluations may read stale entri
The ORY Kratos self‑service registration endpoint works correctly when backed by a local SQLite database, but returns a 500 Internal Server Error in a production PostgreSQL deployment. In the SQLite environment the ORM automatically creates the required verification_token column, masking the missing migration step, whereas the PostgreSQL schema lacks this co
The goal is to configure Ory Oathkeeper so that any request forwarded to an upstream API is only allowed when the TLS certificate presented by the upstream matches the hostname in the configured upstream URL. However, the documentation does not explicitly state the default behavior of the skip_tls_verify flag when it is omitted, nor does it clarify whether O