What Are the IAM Deployment Options Offered by Ory?
Ory offers three deployment paths for its identity and access management (IAM) stack: Open Source, Self-Hosted under the Ory Enterprise License (OEL), and Fully-Managed Cloud (Ory Network). They differ mainly in who runs the infrastructure, how much operational work you take on, and what level of support and compliance assurance you get. Choose Open Source to evaluate or build a proof of concept, OEL when you need to run in your own environment with enterprise support, and Ory Network when you want the fastest path to production without managing infrastructure.
The three deployment options at a glance
| Option | What it is | Where it runs | Support & assurance | Best fit |
|---|---|---|---|---|
| Open Source | Run and try Ory's open-source IAM components on your own infrastructure | Your infrastructure | Full transparency, no vendor lock-in | Testing specific use cases, proof-of-concept work |
| Self-Hosted (Ory Enterprise License) | Ory's optimized codebase with premium support for mission-critical environments | On-prem, private cloud, or air-gapped infrastructure | Enterprise SLAs, security patches, direct engineering support | Regulated or restricted environments needing control plus support |
| Fully-Managed Cloud (Ory Network) | Fully-managed cloud IAM delivered as SaaS | Ory's global identity infrastructure | Built-in compliance, automatic scaling, zero operational overhead | Fastest path to production without managing infrastructure |
Open Source deployment
With the open-source option, you run and try Ory's identity and access management components on your own infrastructure. The stated benefits are full transparency and no vendor lock-in. Ory positions this as ideal for testing specific use cases or building a proof of concept for your next project.
The trade-off is that you own the operational work: provisioning, upgrades, and running the components are on your side. There is no mention of enterprise SLAs or premium support at this tier.
Self-hosted with the Ory Enterprise License (OEL)
OEL gives you Ory's optimized codebase plus premium support for mission-critical environments. You can run it on-prem, in your private cloud, or in air-gapped infrastructure, with the assurance of enterprise SLAs, security patches, and direct engineering support.
This is the option to weigh when you need to keep data and workloads inside your own perimeter — including disconnected or air-gapped setups — but still want vendor-backed support and patching rather than relying on community resources alone.
Fully-managed cloud with Ory Network
Ory Network is a fully-managed cloud IAM solution: global identity infrastructure delivered as SaaS, with built-in compliance, automatic scaling, and zero operational overhead. Ory describes it as the fastest path to production without managing infrastructure yourself.
The trade-off is the inverse of self-hosting: you give up direct control of the underlying infrastructure in exchange for not operating it. If your requirements allow a SaaS identity layer, this removes the provisioning and scaling work entirely.
How to choose
- You are evaluating Ory or prototyping: start with Open Source. It lets you test your specific use cases with full transparency and no lock-in.
- You must keep IAM inside your own environment (on-prem, private cloud, air-gapped) and need SLAs and direct engineering support: Self-Hosted with OEL.
- You want production speed and are willing to run IAM as SaaS: Ory Network, which adds built-in compliance and automatic scaling with zero operational overhead.
The decision hinges on three axes the page makes explicit: control over infrastructure and data, compliance and support requirements, and how much operational burden you want to carry. Open Source maximizes transparency and minimizes lock-in but leaves operations to you; OEL keeps control in your environment while adding enterprise support; Ory Network minimizes operational burden at the cost of running on Ory's infrastructure.
What Ory covers across all three
Deployment choice is independent of which IAM capability you use. Ory describes three solution areas that run on any of the deployment models:
- Customer Identity (CIAM): secure, friction-free login and signup for customer-facing apps, built for scale and privacy.
- B2B Identity (B2B IAM): enterprise-grade single sign-on, SAML, SCIM, and granular permissions so business customers can onboard their teams in minutes.
- AI Agent Identity (Agent IAM): machine-scale identity and access management for AI agents, autonomous workflows, and machine-to-machine systems, with auth, audit, and authorization controls.
Ory also states its approach is cloud-native, API-first, and self-hostable, and that it provides in-the-loop, runtime enforcement for agent security across tools including Claude Code, Codex, and Gemini.
For current pricing and plan details across these deployment options, see Ory's pricing page, since the source material does not specify costs or which tiers are free.