DNSControl
DNSControl is rewriting its record internals in public, one release candidate at a time
A side-by-side editorial comparison of Auth0 and Ory Hydra — release velocity, themes, recent moves, and the top alternatives to consider.
Auth0 is rebuilding identity around actors that operate on someone else's behalf.
Auth0 is shipping delegation primitives faster than anything else in its feed. Custom Token Exchange now reaches browser sessions, agents are getting first-class identities, and Token Vault workers can pull a user's third-party tokens with nobody signed in. The dashboard work — organization search filters, a Cmd+K palette — is steady but clearly secondary to the delegation push.
Hydra's 2.2 candidates rebuilt the OAuth2 flow store, then reached for verifiable credentials
Ory Hydra is a self-hosted OAuth2 and OpenID Connect server. Its visible release record is the v2.2.0 candidate series from 2023, which did two substantial things: rc.2 moved authorization-code flow state out of the database and into AEAD-encrypted cookies and request parameters, a change shipped with an explicit breaking-change notice; rc.3 then added initial OIDC verifiable-credential issuance and wired logout propagation into Ory Kratos. The feed stops at a v2.2.0-pre.1 tag in February 2024.
Auth0 is shipping delegation primitives faster than anything else in its feed. Custom Token Exchange now reaches browser sessions, agents are getting first-class identities, and Token Vault workers can pull a user's third-party tokens with nobody signed in. The dashboard work — organization search filters, a Cmd+K palette — is steady but clearly secondary to the delegation push.
The through-line is machine and proxy actors. Nearly every Early Access release this cycle answers the same question — who acted on whose behalf, and can you prove it — via act claims, per-agent credentials, and scope-pinned worker tokens. Enterprise Connect runs in a different direction: Auth0 as a modular layer over an authorization server the customer already operates, rather than a replacement for it.
The scattered Early Access pieces — Agents as Principal, Token Vault Privileged Worker, Session Delegation — are close enough in shape that the next consolidation is a single GA agent-identity product with one audit surface across all three.
Ory Hydra is a self-hosted OAuth2 and OpenID Connect server. Its visible release record is the v2.2.0 candidate series from 2023, which did two substantial things: rc.2 moved authorization-code flow state out of the database and into AEAD-encrypted cookies and request parameters, a change shipped with an explicit breaking-change notice; rc.3 then added initial OIDC verifiable-credential issuance and wired logout propagation into Ory Kratos. The feed stops at a v2.2.0-pre.1 tag in February 2024.
The through-line is reducing per-request database work in the hot authorization path — first by relocating flow state into encrypted client-side material, then by parallelizing JSON web key set generation and adding scope-claim strategies. Running underneath is tighter coupling to the rest of the Ory stack: the Kratos admin URL config and session-termination hook make Hydra less of a standalone component and more of one piece of an integrated identity suite. The verifiable-credentials work is the one thread pointing somewhere genuinely new, and it shipped against a draft specification.
The candidate series points toward a v2.2.0 general release consolidating the AEAD flow change and the credential-issuance work. The feed's silence after February 2024 gives no basis for judging when, or whether the draft-stage VC support advanced.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Auth0 or Ory Hydra.
DNSControl is rewriting its record internals in public, one release candidate at a time
Fission's release feed carries only RC tags, and none of them say what shipped
Kaniko's release feed stops dead in June 2024 after a patch that undid its own change
mod_auth_openidc audited itself, found eight holes, and broke every session on the way out
Kubernetes CNI maintaining four release branches at once, mostly to carry CVE fixes back.
KeePass-compatible password manager frozen mid-patch-run since 2021.
See all Auth0 alternatives → · See all Ory Hydra alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Auth0 is currently shipping more aggressively (velocity 10.0 vs 0.0), with 2 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Auth0 is currently shipping more aggressively (velocity 10.0 vs 0.0), with 2 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top Auth0 alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Auth0 alternatives" section above for the current picks, or visit /alternatives/auth0 for the full list with editorial commentary on each.
Top Ory Hydra alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Ory Hydra alternatives" section above for the current picks, or visit /alternatives/ory-hydra for the full list with editorial commentary on each.