{"id":51549506,"url":"https://github.com/ory/talos","last_synced_at":"2026-07-09T22:30:36.841Z","repository":{"id":362445217,"uuid":"1256905546","full_name":"ory/talos","owner":"ory","description":"Web-scale and security-hardened API key server for users, services, machine to machine, and AI agents. Token derivation brings fine-grained capability tokens to avoid common API key pitfalls. Apache2 open source for indie deployments, commercial for scalable and HA.","archived":false,"fork":false,"pushed_at":"2026-07-08T10:08:06.000Z","size":2655,"stargazers_count":176,"open_issues_count":1,"forks_count":7,"subscribers_count":0,"default_branch":"master","last_synced_at":"2026-07-08T12:05:14.358Z","etag":null,"topics":["api-auth","api-authentication","api-key","api-key-management","api-token","ory"],"latest_commit_sha":null,"homepage":"https://www.ory.com/talos","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ory.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-06-02T07:28:19.000Z","updated_at":"2026-07-08T10:08:29.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/ory/talos","commit_stats":null,"previous_names":["ory/talos"],"tags_count":5,"template":false,"template_full_name":null,"purl":"pkg:github/ory/talos","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ory%2Ftalos","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ory%2Ftalos/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ory%2Ftalos/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ory%2Ftalos/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ory","download_url":"https://codeload.github.com/ory/talos/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ory%2Ftalos/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35314872,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-07-09T02:00:07.329Z","response_time":57,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["api-auth","api-authentication","api-key","api-key-management","api-token","ory"],"created_at":"2026-07-09T22:30:36.198Z","updated_at":"2026-07-09T22:30:36.835Z","avatar_url":"https://github.com/ory.png","language":"Go","funding_links":["https://opencollective.com/ory"],"categories":[],"sub_categories":[],"readme":"\u003c!-- Follow-up: upload talos.svg to ory/meta:static/banners/talos.svg. --\u003e\n\u003ch1 align=\"center\"\u003e\n  \u003cimg src=\"https://raw.githubusercontent.com/ory/meta/master/static/banners/talos.svg\" alt=\"Ory Talos - API credential management for high-throughput systems\"\u003e\n\u003c/h1\u003e\n\n\u003ch4 align=\"center\"\u003e\n  \u003ca href=\"https://www.ory.com/chat\"\u003eChat\u003c/a\u003e ·\n  \u003ca href=\"https://github.com/ory/talos/discussions\"\u003eDiscussions\u003c/a\u003e ·\n  \u003ca href=\"https://www.ory.com/l/sign-up-newsletter\"\u003eNewsletter\u003c/a\u003e ·\n  \u003ca href=\"https://www.ory.com/docs/\"\u003eDocs\u003c/a\u003e ·\n  \u003ca href=\"https://console.ory.sh/\"\u003eTry Ory Network\u003c/a\u003e ·\n  \u003ca href=\"https://www.ory.com/jobs/\"\u003eJobs\u003c/a\u003e\n\u003c/h4\u003e\n\nOry Talos is a scalable and secure API key server optimized for low-latency verification, horizontal\nscaling, and predictable operations. It follows established security best-practices for API keys and\nissues, verifies, revokes, and derives API keys and short-lived tokens for high-throughput systems.\n\n---\n\n\u003c!-- START doctoc generated TOC please keep comment here to allow auto update --\u003e\n\u003c!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE --\u003e\n\n- [What is Ory Talos?](#what-is-ory-talos)\n  - [Why Ory Talos](#why-ory-talos)\n- [Deployment options](#deployment-options)\n  - [Use Ory Talos on the Ory Network](#use-ory-talos-on-the-ory-network)\n  - [Self-host Ory Talos](#self-host-ory-talos)\n- [Quickstart](#quickstart)\n- [Who is using Ory Talos](#who-is-using-ory-talos)\n- [Ecosystem](#ecosystem)\n  - [Ory Kratos: Identity and User Infrastructure and Management](#ory-kratos-identity-and-user-infrastructure-and-management)\n  - [Ory Hydra: OAuth2 \u0026 OpenID Connect Server](#ory-hydra-oauth2--openid-connect-server)\n  - [Ory Oathkeeper: Identity \u0026 Access Proxy](#ory-oathkeeper-identity--access-proxy)\n  - [Ory Keto: Access Control Policies as a Server](#ory-keto-access-control-policies-as-a-server)\n- [Documentation](#documentation)\n- [Developing Ory Talos](#developing-ory-talos)\n- [Security](#security)\n  - [Disclosing vulnerabilities](#disclosing-vulnerabilities)\n- [Telemetry](#telemetry)\n\n\u003c!-- END doctoc generated TOC please keep comment here to allow auto update --\u003e\n\n## What is Ory Talos?\n\nOry Talos is a server for issuing, verifying, and managing API keys. It follows\n[cloud architecture best practices](https://www.ory.com/docs/ecosystem/software-architecture-philosophy)\nand focuses on:\n\n- Issuing, verifying, and revoking API keys at scale\n- Importing externally-issued API keys for unified verification\n- Deriving short-lived JWT and macaroon tokens from long-lived keys\n- Side-car deployment for fast API key verification\n- Low-latency verification with caching and eventual revocation\n- Predictable operations through structured logging, metrics, and tracing\n\nWe recommend starting with the [Ory Talos documentation](https://www.ory.com/docs/talos) to learn\nmore about its architecture, feature set, and how it compares to other systems.\n\n### Why Ory Talos\n\nOry Talos is designed to:\n\n- Run as a single binary with three deployment modes: admin, self-service, or all-in-one\n- Verify API keys against the database with caching for low latency, while derived JWT and macaroon\n  tokens verify offline without a database lookup\n- Separate admin and self-service surfaces so key creation, revocation, derivation, and verification\n  scale and are secured independently from proof-of-possession self-revocation\n- Scale horizontally with external databases (Postgres, MySQL, CockroachDB) and optional distributed\n  caching\n- Fit modern cloud-native environments such as Kubernetes and managed platforms\n- Mint reduced-scope, short-lived tokens offline so agents, CI/CD jobs, and services don't call the\n  server on every request\n- Keep credential routing, hashing, and verification centralized and constant-time\n\n## Deployment options\n\nYou can run Ory Talos in two main ways:\n\n- As a managed service on the Ory Network\n- As a self-hosted service under your own control, with or without the Ory Enterprise License\n\n### Use Ory Talos on the Ory Network\n\nThe [Ory Network](https://www.ory.com/network) is the fastest way to use Ory Talos in production.\n\nThe Ory Network provides:\n\n- API key issuance, verification, and derivation with low-latency global edge\n- OAuth2 and OpenID Connect for single sign on, API access, and machine to machine authorization\n- Identity and credential management that scales to billions of users and devices\n- Registration, login, and account management flows for passkeys, biometrics, social login, SSO, and\n  multi factor authentication\n- Prebuilt login, registration, and account management pages and components\n- Low latency permission checks based on the Zanzibar model with the Ory Permission Language\n- GDPR friendly storage with data locality and compliance in mind\n- Web based Ory Console and Ory CLI for administration and operations\n- Cloud native APIs compatible with the open source servers\n- Fair, usage based [pricing](https://www.ory.com/pricing)\n\nSign up for a\n[free developer account](https://console.ory.sh/registration?utm_source=github\u0026utm_medium=banner\u0026utm_campaign=talos-readme)\nto get started.\n\n### Self-host Ory Talos\n\nYou can run Ory Talos yourself for full control over infrastructure, deployment, and customization.\n\nThe [install guide](https://www.ory.com/docs/talos/operate/install) explains how to:\n\n- Install Ory Talos on Linux, macOS, Windows, and Docker\n- Configure databases such as SQLite, PostgreSQL, MySQL, and CockroachDB\n- Deploy to Kubernetes and other orchestration systems\n\nThe open source distribution runs as a single instance against an embedded SQLite database. It is a\ngreat fit for individuals, researchers, hackers, and companies that want to experiment, prototype,\nor run low-traffic workloads without service level agreements (SLAs).\n\nIf you run Ory Talos as part of a business-critical system, for example API key verification on a\nhot path, you should use a commercial agreement to reduce operational and security risk. The\n**[Ory Enterprise License (OEL)](https://www.ory.com/ory-enterprise-license)** layers on top of\nself-hosted Ory Talos and provides:\n\n- Multi-node deployments backed by external databases (Postgres, MySQL, CockroachDB)\n- Multi-tenancy, distributed caching, rate-limit enforcement, and edge verification nodes\n- Regular security releases, including CVE patches, with SLAs\n- Support for advanced scaling and complex deployments\n- Premium support options with response SLAs, direct access to engineers, and onboarding help\n- Access to a private Docker registry with frequent, vetted enterprise builds\n\nFor guaranteed CVE fixes, current enterprise builds, advanced features, and production support, you\nneed a valid [Ory Enterprise License](https://www.ory.com/ory-enterprise-license) and access to the\nOry Enterprise Docker registry. To learn more, [contact the Ory team](https://www.ory.com/contact/).\n\n## Quickstart\n\nInstall the [Ory CLI](https://www.ory.com/docs/guides/cli/installation) and use the managed Ory\nNetwork, or run Ory Talos locally with Docker Compose.\n\n```bash\n# Install the Ory CLI if you do not have it yet:\nbash \u003c(curl https://raw.githubusercontent.com/ory/meta/master/install.sh) -b . ory\nsudo mv ./ory /usr/local/bin/\n\n# Sign in or sign up\nory auth\n\n# Create a new project\nory create project --create-workspace \"Ory Open Source\" --name \"GitHub Quickstart\" --use-project\n```\n\nTo run Ory Talos locally:\n\n```bash\n# Open source edition (SQLite, single-node)\ndocker-compose -f docker-compose.oss.yaml up --build\n```\n\nThe API will be available at http://localhost:4420\n\nFor end-to-end walkthroughs of issuing, verifying, and revoking keys, see the\n[Quickstart guide](https://www.ory.com/docs/talos/quickstart/index) and\n[Issue and verify](https://www.ory.com/docs/talos/docs/integrate/issue-and-verify).\n\n## Who is using Ory Talos\n\n\u003c!--BEGIN ADOPTERS--\u003e\n\nThe Ory community stands on the shoulders of individuals, companies, and maintainers. The Ory team\nthanks everyone involved - from submitting bug reports and feature requests, to contributing patches\nand documentation. The Ory community counts more than 50.000 members and is growing. The Ory stack\nprotects 7.000.000.000+ API requests every day across thousands of companies. None of this would\nhave been possible without each and everyone of you!\n\nIf you would like to be featured here once Ory Talos lands on the Network, reach out to\n\u003ca href=\"mailto:office@ory.com\"\u003eoffice@ory.com\u003c/a\u003e.\n\nMany thanks to all individual contributors\n\n\u003ca href=\"https://opencollective.com/ory\" target=\"_blank\"\u003e\u003cimg src=\"https://opencollective.com/ory/contributors.svg?width=890\u0026limit=714\u0026button=false\" /\u003e\u003c/a\u003e\n\n\u003c!--END ADOPTERS--\u003e\n\n## Ecosystem\n\n\u003c!--BEGIN ECOSYSTEM--\u003e\n\nWe build Ory on several guiding principles when it comes to our architecture design:\n\n- Minimal dependencies\n- Runs everywhere\n- Scales without effort\n- Minimize room for human and network errors\n\nOry's architecture is designed to run best on a container orchestration system such as Kubernetes,\nCloudFoundry, OpenShift, and similar projects. Binaries are small and available for all popular\nprocessor types (ARM, AMD64, i386) and operating systems (FreeBSD, Linux, macOS, Windows) without\nsystem dependencies (Java, Node, Ruby, libxml, ...).\n\n### Ory Kratos: Identity and User Infrastructure and Management\n\n[Ory Kratos](https://github.com/ory/kratos) is an API-first Identity and User Management system that\nis built according to\n[cloud architecture best practices](https://www.ory.com/docs/next/ecosystem/software-architecture-philosophy).\nIt implements core use cases that almost every software application needs to deal with: Self-service\nLogin and Registration, Multi-Factor Authentication (MFA/2FA), Account Recovery and Verification,\nProfile, and Account Management.\n\n### Ory Hydra: OAuth2 \u0026 OpenID Connect Server\n\n[Ory Hydra](https://github.com/ory/hydra) is an OpenID Certified™ OAuth2 and OpenID Connect Provider\nwhich easily connects to any existing identity system by writing a tiny \"bridge\" application. It\ngives absolute control over the user interface and user experience flows.\n\n### Ory Oathkeeper: Identity \u0026 Access Proxy\n\n[Ory Oathkeeper](https://github.com/ory/oathkeeper) is a BeyondCorp/Zero Trust Identity \u0026 Access\nProxy (IAP) with configurable authentication, authorization, and request mutation rules for your web\nservices: Authenticate JWT, Access Tokens, API Keys, mTLS; Check if the contained subject is allowed\nto perform the request; Encode resulting content into custom headers (`X-User-ID`), JSON Web Tokens\nand more!\n\n### Ory Keto: Access Control Policies as a Server\n\n[Ory Keto](https://github.com/ory/keto) is a policy decision point. It uses a set of access control\npolicies, similar to AWS IAM Policies, in order to determine whether a subject (user, application,\nservice, car, ...) is authorized to perform a certain action on a resource.\n\n\u003c!--END ECOSYSTEM--\u003e\n\n## Documentation\n\nThe Ory Talos documentation lives at [www.ory.com/docs/talos](https://www.ory.com/docs/talos).\n\n## Developing Ory Talos\n\nSee [CONTRIBUTING.md](./CONTRIBUTING.md) for information on:\n\n- Contribution guidelines\n- Prerequisites and development setup\n- Running tests for OSS and commercial builds\n- Generating protobuf, SQL, and SDK artifacts\n- Building Docker images\n\n## Security\n\nOry Talos handles credentials on the hot path: raw API keys, derived tokens, and signing keys. The\nimplementation uses constant-time comparisons, centralized credential routing, and per-tenant\nnetwork isolation. Read [the security model](https://www.ory.com/docs/talos/concepts/security-model)\nand [security hardening guide](https://www.ory.com/docs/talos/operate/security-hardening) for the\ndetails on cryptography, tenant isolation, and operational hardening.\n\n### Disclosing vulnerabilities\n\nIf you think you found a security vulnerability, please refrain from posting it publicly on the\nforums, the chat, or GitHub. You can find all info for responsible disclosure in our\n[security.txt](https://www.ory.com/.well-known/security.txt).\n\n## Telemetry\n\nOur services collect summarized, anonymized data that can optionally be turned off. Click\n[here](https://www.ory.com/docs/ecosystem/sqa) to learn more.\n\n## Libraries and third-party projects\n\nOry Community:\n\n- Visit\n  [this document for an overview of community projects and articles](https://www.ory.com/docs/ecosystem/community)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fory%2Ftalos","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fory%2Ftalos","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fory%2Ftalos/lists"}