Security and privacy · Edition No. 38 · 2 Oct 2026

ory/polis

Translates a company's own single sign-on into the ordinary modern login your application already understands.

← Security and privacyRead the whole edition →

2,260 stars · Apache-2.0 (read from /blob/main/LICENSE, unmodified, 'Copyright 2025 Ory Corp') · v26.2.0 (20 Mar 2026, read from /releases/latest; the version number carries its own year) · Track this in Scout

Translates a company's own single sign-on into the ordinary modern login your application already understands.

▶Repo detailsthe review · specs · pros & cons · install

What it is

A service that sits between a customer's corporate identity system and your application. It accepts SAML, the standard large organisations use, and also OpenID Connect, and it presents the result to your application as an OAuth 2.0 or OpenID Connect login. It also supports SCIM, a standard for a company to create and remove user accounts in your system automatically when staff join or leave.

What it is good for. Anyone selling software to businesses who has been asked for "SSO" and found out what that means. It removes the need to learn SAML, which is the whole value. It also brings a supporting standard with it, so the customer's staff list stays correct without anyone sending spreadsheets.

Stars2,260
LicenceApache-2.0 (read from /blob/main/LICENSE, unmodified, 'Copyright 2025 Ory Corp')
Latestv26.2.0 (20 Mar 2026, read from /releases/latest; the version number carries its own year)
Good
  • Plain unmodified Apache-2.0, read from the LICENSE file. Nothing is added and nothing is carved out.
  • It brings its own database choice. The README says it supports MySQL, MariaDB, PostgreSQL, MongoDB, Redis and PlanetScale, so it fits beside most existing setups.
  • A very quiet board for a project of this size: 25 open issues and 9 open pull requests.
Watch for
  • The project changed hands and the only place that says so is the repository. Its own README reads: "Ory Polis - formerly known as BoxyHQ Jackson - bridges or proxies a SAML login flow to OAuth 2.0 or OpenID Connect." The licence file carries "Copyright 2025 Ory Corp". The practical effect is that every tutorial, blog post and search result written before the change uses the old name, and anyone looking for "SAML Jackson" has to work this out for themselves.
  • Release v26.2.0 is dated 20 March 2026, more than six months ago, although code landed on 27 July 2026. The version number carries its own year, which is how we settled the date.
  • The install instructions in the repository are for local development only. The README points at the company's own documentation site for running it in earnest, and the company sells a hosted version of the same thing. That is an honest arrangement, not a trap, but the free route is the less signposted one.
Similar repositories
  • keycloak/keycloak

    37,100 stars and far larger. It is a complete identity system you host, so it can replace your logins entirely rather than translating someone else's, and it is a much bigger thing to run.

    Track this in Scout
  • ory/hydra

    17,495 stars, from the same company. It issues OAuth 2.0 and OpenID Connect tokens and expects you to supply the user management, which is the opposite half of the job.

    Track this in Scout
  • authelia/authelia

    Covered in Edition 32. It puts one login and a second factor in front of services you run, which is about protecting your own things rather than accepting a customer's company login.

    Track this in Scout
Install
git clone https://github.com/ory/polis.git
cd polis
npm install
npm run dev
Screenshots
ory/polis: GitHub preview card

Get the next edition in your inbox

A dozen repositories, opened and checked. The licence read, the last release dated, and the ones that did not make it named with the reason. It is the half most lists leave out.

No tracking pixels. One click to leave. The archive stays free either way.

We use your address to send the edition and nothing else. Confirm by email, leave in one click. How we handle it.