Kratos or Hydra required for SSO? #24
-
I've gone through the docs but it is not clear to me whether Kraton is sufficient when you want to login once for multiple domains, or that you'd need Hydra for this. Any suggestions? |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 1 reply
-
Ah found it: ory/kratos#662 |
Beta Was this translation helpful? Give feedback.
-
As far i understand ory's architecture, SSO for different domains is limited by kratos using cookies heavily for authentication - sending tokens explicitly between domains instead implicit cookies was the answer to this by OAuth2 (ie. ory's
and set kratos session/csrf cookies for the domain The general flow could be:
|
Beta Was this translation helpful? Give feedback.
Ah found it: ory/kratos#662
So not yet possible with just Kratos. Need Hydra currently.