New Ory Agent Security is now live! Claim your complimentary test drive. Get Started!

Skip to main content

Ory Console Lite

Ory Console Lite is a web console for self-hosted Ory deployments. It talks to the admin APIs of Ory Kratos Identities, Ory Hydra Authorization, and Ory Keto Permissions, and gives your team a browser interface for the day-to-day work that otherwise needs API calls: looking up a user, ending a session, registering an OAuth2 client, or granting a permission.

Ory Console Lite is stateless. It stores nothing of its own, owns no database, and holds no configuration beyond the URLs of the services it manages. Everything you see in it lives in Ory Kratos, Ory Hydra, or Ory Keto.

Set up Ory Console Lite against your own deployment in about 10 minutes.

danger

Ory Console Lite has no authentication of its own. Anyone who can reach it has full administrative access to every identity, session, OAuth2 client, and permission in your deployment. Run it on a private network, behind a VPN, or behind an authenticating proxy — never expose it to the public internet. See Secure Ory Console Lite.

What can Ory Console Lite do?​

User management — Browse and search identities, filter by organization, and inspect an identity's profile, traits, metadata, verifiable addresses, credentials, connected social accounts, and OAuth2 consents. Create an identity from your schema, generate a password, start account recovery, terminate every session a user holds, and delete an identity.

Sessions — List active and expired sessions, inspect the devices behind them, and terminate a session.

Message delivery — Review the emails and SMS messages Ory Kratos Identities queued, filter them by delivery status, read the dispatch history of a single message, and jump to the identity it was addressed to.

OAuth 2 — List, search, create, edit, and delete OAuth2 clients. New clients start from a template for the grant type you need.

Permissions — List and search Ory Keto Permissions relationships by namespace, object, or subject, and create, edit, and delete them.

Settings — See every service Ory Console Lite is configured for, its URL, and whether it currently answers its health endpoint, together with a per-feature readiness table.

What Ory Console Lite can't do​

Ory Console Lite manages the data in your Ory services. It does not configure the services themselves. Anything that changes how Ory Kratos, Ory Hydra, or Ory Keto behave continues to belong in your configuration files:

  • Login, registration, recovery, and verification settings, and identity schemas
  • Multi-factor and passwordless method configuration, and social sign-in providers
  • Branding, theming, custom domains, and email templates
  • Actions and webhooks
  • Ory Keto Permissions namespaces and the Ory Permission Language

Ory Console Lite has no project or workspace concept, no billing, no user accounts of its own, and no members or API keys screens. Those exist only in Ory Network, where a single Ory Console manages many projects. Ory Console Lite manages one deployment, and the local segment its URLs carry, as in /projects/local/get-started, is a fixed placeholder rather than a project.

Which services drive which features​

Ory Console Lite adapts to the services you point it at. Configure only Ory Kratos Identities and the OAuth 2 and Permissions tabs stay visible but disabled, with a tooltip naming the service that is missing. Nothing breaks and nothing needs to be turned on or off.

FeatureService
User managementOry Kratos admin API. Creating an identity also needs the Ory Kratos public API.
SessionsOry Kratos admin API
Message deliveryOry Kratos admin API
OAuth 2Ory Hydra admin API
PermissionsOry Keto read and write APIs

The Settings page reports the following information live: every configured service's health, and every feature with its capabilities. If a feature's configured services only partly answer, the feature is reported as Partial rather than as Enabled.

How to get Ory Console Lite​

Ory Console Lite is part of the Ory Enterprise License (Ory OEL). It is published to the Ory Enterprise Docker registry on the same release train as the other Ory OEL products, and pulling it needs the service account key you received with your license.

It runs against the Ory OEL builds of Ory Kratos, Ory Hydra, and Ory Keto and their Apache-2.0 releases, because it uses only their public admin APIs.

Next steps​

  • Quickstart — run Ory Console Lite against your Ory deployment
  • Configuration — every environment variable, and how Ory Console Lite reaches your services
  • Security — Ory Console Lite has no authentication of its own, so run it behind something that does