Funny thing is that its powered by Auth0. Its funny that Ory is asking for the HAR file
HN user
advaitruia
YC Badge: 0xc94861973c23bd9ef99326efc950c7f20b35aef9
Could you clarify what OpenAI actually uses Ory for? Their main login page is powered by Auth0
Nothing like buying 12 TGIFs in the midwest?
https://svdisposition.hibid.com/catalog/607470/tgi-fridays--...
Congratulations! This is great - one of the few globally successful SaaS cos from India with an exit!
This is cool!
Can checkout SuperTokens which is also open source and self hostable but not sure if its worth it for now.
Have you seen open source authentication products like SuperTokens or Keycloak?
Alternatively, you could use framework specific authentication libraries like nextjs or Devise (Ruby)
Chiming in here as the cofounder of an 'open core' company:
This obviously wasnt handled as well as it could have been.
On the fundamental issue of building EE features: If 100% of the code was open source, there would be less incentive for them to continue to maintain, update, upgrade the product. The EE features ensures that there is an incentive for them to continue to work on this project. Infact, the community _should_ want project maintainers to be compensated.
As someone else said, the project is open source, you can always fork and add any specific feature you want. It comes down to how useful is the actual open source project. If it is very limited in features and functioning, then yes - it is against the spirit of the open source. But if its a fully usable, functioning product (not for all but atleast some number of usecases), then it has created value which it is not capturing for itself - which is a net good for society and the industry.
Supertokens - open source user authentication.
Our UI is native to your website (no redirects) and the auth logic sits within your backend api layer - giving you a lot more control
Im a OSS founder.
This is a balanced article and I definitely agree about being clear on what constitutes competition. A few questions:
1. Does Gitlab see much competition from hyperscale providers like AWS?
2. Given that Gitlab has a thicker proprietary crust and a relatively smaller open source core (compared to hashi), is Gitlab more insulated from these types of issues?
The metric to measure how expensive equity is sounds flawed. Expected earnings divided by share price is not indicative of actual equity returns - especially over 1 year?
More often than not, making money and making good software are complimentary outcomes. Its difficult to do the former without the latter.
Infisical is an open core business model. While there is a proprietary crust, the core is truly open source.
Disclaimer: I run an open core venture
Most of the comments on this thread make it appear that everyone will be affected by this change. The vast majority wont be affected at all.
This only affects people who are directly competing with hashicorp using hashicorps code. That sounds like a reasonable thing to want to prohibit.
Why should hashicorp have to spend tens of millions on product development only for a competitor to spend zero but be able to offer the same product? That sounds like a net negative for the whole industry as it disincentivizes R&D
Happy user here of the newly launched Discord integration :)
Not ideal..
What are you planning on using instead?
We're launching exactly this at supertokens.com
We wont have all the things you mention but will everything to do with tenant onboarding, identity management, user authentication will be out of the box. So in terms of functionality, it would be comparable to keycloak but easier to extend and integrate monitoring and billing tools.
Agreed on feature naming - will fix!
Also I definitely understand your perspective and it makes sense. SuperTokens still is 100% open source - but you are right, as we evolve into a paid offering, there is scope for improvement
We've raised money every year in the last 3 years. We just dont update crunchbase.
we're being used at scale of millions of monthly active companies by very large companies - which have done deep technical evaluation.
If the company dies or gets acquired (possible with companies of almost all stages), the product is actually open source. You can self host it without any permissions and we provide daily database backups
|| Without qualifying the weight of every feature, it numerically raises a significant challenge to your statement.
Well i think that is the only thing that matters.
If I split all auth methods into the 6 different features it really is, then it becomes 13 free features.
The ones listed as not open source is to indicate what we plan to build for our paid offering. If we removed those and 13/13 were open source, would that change your views? If yes, then that qualification is pretty important.
SAML client and OAuth client are both free. You can add auth with any OAuth 2.0 provider to SuperTokens.
Being an OAuth 'provider' (emphasis) is not open source as it is a feature you need for complex use cases.
You can add 2FA with email or SMS in the open source product too (just requires some customizations and overrides)
Yes, its a very subjective point.
We've mentioned the source (if you hover) and it is based on our internal user research and conversations with users of these products. By no means is it perfect and there are many many satisfied customers of each of the other products.
Your point is taken though and maybe we will edit that point out or try to add further nuance.
I do believe however that broadly speaking, that reviews of keycloak lean towards it being relatively harder to use and maintain than Firebase. Arguably the reviews of Cognito are more mixed than "Low"
Many of the core features are open source. Eg all the authentication methods - email password, passwordless, social etc are all in the open source product. You can also use the open source components to implement email based or SMS based 2FA.
RBAC, session management and user management dashboard are open source too. Its several years of an engineering team's work that is all open source.
Our philosophy is to keep features that are broadly required by developers and small companies in the open source version. Things that large companies require, will be source available.
We have several enterprises (more than $100M raised or several hundred employees) that are using SuperTokens at the scale of millions of monthly active users - all using the open source product. We think the open source product is a sufficient alternative (for a large enough population).
Are there any other features you feel should be in the open source version? Happy to hear any feedback and improve
(Project creator here)
All the features you see on github / the website is under the apache 2.0 license - truly open source.
The only code in EE so far is the feature flags. We will implement certain "source available" features in the future
The claim is that we saw traffic patterns on the .com mirror that of the .io even though nothing was on it yet and we had not migrated.
Our inference or best guess based on the above is that people were typing supertokens.com directly in the URL bar on the browser. Like you said - I would not have expected that (and still doubt it) but dont have any alternative explanations for why that would be the case.
Our agency doesnt know we've even written this. I still need to share it with them.
Thats a really interesting anecdote.. Most squatters sit on domains for 10+ years though. Both the 'good' .com domains I've bought were held unused by squatters for almost 20 years. Maybe thats what you need to do when you have a domain like that?
We used Ritch at acquirable
How much does SEO play a role in your customer acquisition? Do you have a lot of existing backlinks to the .net domain? Do you plan to continue building this product for a long time?
Depending on the answers to these questions, I would evaluate the tradeoffs of migrating. If SEO is not critical or if you already have a certain domain authority / backlinks or dont plan to continue for a long period of time - then it may not make sense to migrate.
Why not reach out to a domain broker to acquire it? Or even reach out yourself?
Yes we are a OAuth 2.0 client (and have SAML integrations too).
So if PingFederate is the provider, you can add "sign in with Ping" on an app that uses SuperTokens
Right - that makes sense. Unfortunately cant edit the title now
Haha, that was a straightforward purchase. I dont think i've ever been able to find another advaitruia (advait on its own is an uncommon name)
Correct. I've edited it to say that clearly (finally). Sorry about all the confusion here