Softwr

Cloud · head to head

Infracost vs Ory Kratos

Infracost logo

Infracost

Cloud

Cloud cost estimates in pull requests, with governance in the paid tier

From
Free
Rated
-
Ory Kratos logo

Ory Kratos

Cybersecurity

Headless identity and user management API

From
Free
Rated
-

The short version

  • Each has a real cost: Infracost usage-based resources such as object storage, serverless functions and data transfer have no cost without monthly usage figures supplied by hand, and the documentation warns plainly that engineers otherwise read them as free.; Ory Kratos headless means you build every screen, which is significant work compared with a hosted login page
  • They diverge on capability: Infracost covers Pull request cost diffs, Ory Kratos covers Headless API.
  • Prices and features above were last checked on 31 August 2026.

Where they differ

Only the attributes on which Infracost and Ory Kratos actually diverge.

Attributes where Infracost and Ory Kratos differ
AttributeInfracostOry Kratos
Pricing modelFree open source tool, then per month by run volumeOpen-source self-hosted, with a paid managed network
PlatformsWeb, macOS, Linux, Windows, DockerLinux, Docker, Kubernetes, Self-hosted
CategoryCloudCybersecurity

Identical on both: starting price (Free), free tier (Yes), user rating (Not yet rated).

What each one covers

Drawn from each product's published feature list. An absence here means we hold no record of it - not that the product lacks it.

Only in Infracost

  • Pull request cost diffs
  • Multi-format parsing
  • Apache-2.0 CLI
  • FinOps policies
  • Automated remediation
  • IDE integration

Only in Ory Kratos

  • Headless API
  • Self-service flows
  • Multi-factor authentication
  • Pluggable identity schemas

What people use each for

The jobs each tool is most often brought in to do.

Infracost

  • Teams that want an expensive infrastructure change questioned at review rather than discovered on an invoicenot Ory Kratos
  • Platform groups enforcing tagging so cloud spend can be attributed to a team at allnot Ory Kratos
  • Organisations adopting FinOps practice without buying a full cloud management platformnot Ory Kratos
  • Engineers who want a cost figure in the editor while writing the Terraformnot Ory Kratos

Ory Kratos

  • Products needing complete control over the look and flow of authenticationnot Infracost
  • Applications that must not hand user identity data to a third partynot Infracost
  • Teams building identity as infrastructure across several servicesnot Infracost

Where each one falls short

Documented limitations, not opinions. Every one is a constraint you would hit in normal use.

Infracost

  • Usage-based resources such as object storage, serverless functions and data transfer have no cost without monthly usage figures supplied by hand, and the documentation warns plainly that engineers otherwise read them as free.
  • Splitting production from non-production usage assumptions is not supported in the free usage file, which the docs attribute to a missing project filter, so that separation requires the paid product.
  • The step from 250 to 1,000 dollars a month is large and the Cloud tier includes only ten admin seats, with developer seats charged at a figure that is not published, so the cost for a large organisation cannot be computed from the pricing page.
  • Estimates are list price. Negotiated agreements, committed use discounts and reserved instance economics require SKU-level overrides available only on Enterprise, so the number in the pull request is not the number on the bill.
  • The share of the product covered by the Apache-2.0 licence is shrinking. Checks, automated fixes, policies and agent integrations are all hosted-only, so the permissive licence increasingly protects the estimation engine rather than the product.

Ory Kratos

  • Headless means you build every screen, which is significant work compared with a hosted login page
  • More moving parts than a monolithic IAM: Kratos handles identity, and OAuth2 needs Ory Hydra alongside
  • Documentation assumes real familiarity with identity concepts and is not a gentle introduction
  • Self-hosting identity carries the security and availability burden that hosted providers absorb

Pricing, plan by plan

Infracost

Free
  • FreeFree
    • 1,000 runs a month
    • Terraform, CloudFormation and CDK estimates
    • Community support
  • Starter$250/month
    • 10,000 runs a month
    • Email support
  • Cloud$1000/month
    • Ten admin seats, developer seats charged separately
    • FinOps policies and cost guardrails
    • Dashboards and audit trails
  • Enterprise$undefined/year
    • SKU-level price overrides for negotiated rates
    • Business unit reporting
    • SSO with SAML group mapping

Ory Kratos

Free
  • Self-hostedFree
    • Full identity server
    • All flows
    • Community support

Which should you pick?

Choose Infracost if

  • You need pull request cost diffs.
  • You want to start without paying.
  • You work on Web, macOS, Linux, Windows, Docker.
  • You also want multi-format parsing.

Choose Ory Kratos if

  • You need headless api.
  • You want to start without paying.
  • You work on Linux, Docker, Kubernetes, Self-hosted.
  • You also want self-service flows.

Questions people ask

Is Infracost or Ory Kratos better?
Neither clearly leads. Infracost starts at Free and Ory Kratos at Free, and user ratings are close enough to be indistinguishable. Choose on capability and platform support.
Which is cheaper, Infracost or Ory Kratos?
Infracost starts at Free and Ory Kratos at Free.
Does Infracost or Ory Kratos run on more platforms?
Infracost runs on Web, macOS, Linux, Windows, Docker. Ory Kratos runs on Linux, Docker, Kubernetes, Self-hosted.
Can I use Infracost for free?
Both have a free tier, so you can try either at no cost before committing.
What is Infracost best used for?
Infracost is most often used for teams that want an expensive infrastructure change questioned at review rather than discovered on an invoice, platform groups enforcing tagging so cloud spend can be attributed to a team at all, organisations adopting finops practice without buying a full cloud management platform, engineers who want a cost figure in the editor while writing the terraform. Of those, teams that want an expensive infrastructure change questioned at review rather than discovered on an invoice and platform groups enforcing tagging so cloud spend can be attributed to a team at all are not what Ory Kratos is typically brought in for.
What can Infracost do that Ory Kratos cannot?
Infracost covers Pull request cost diffs, Multi-format parsing, Apache-2.0 CLI, FinOps policies. Ory Kratos covers Headless API, Self-service flows, Multi-factor authentication, Pluggable identity schemas.

Answered from the vendors’ own pages

Infracost: Is the open source version genuinely useful on its own?

Yes, for estimation. It parses your definitions and produces breakdowns and diffs locally. What it does not do is comment on pull requests, enforce policy or report across an organisation, all of which are hosted-only.

Ory Kratos: Is Ory Kratos free?

Yes, open source and free to self-host. Ory Network is a paid managed service.

Infracost: Will the estimate match my cloud bill?

No. It is list price. Committed use discounts, enterprise agreements and reserved instances need SKU-level overrides that sit in the Enterprise tier.

Ory Kratos: What does headless mean here?

Kratos provides identity flows as APIs and no user interface. You build the login, registration and recovery screens yourself.

Infracost: Why do my S3 and Lambda resources show no cost?

Usage-based resources need monthly usage values supplied in a usage file or defined centrally. Without them they estimate at zero, which is the documented behaviour and the most common way the tool misleads.

Ory Kratos: Does Kratos do OAuth2?

No. Kratos handles user identity; OAuth2 and OpenID Connect provider functionality is Ory Hydra, a separate component.

Infracost: Has the licence ever changed?

No. The command line tool has been Apache 2.0 throughout, with no Business Source or AGPL episode, which is unusual in this category.

Infracost: What is a run?

Not defined on the public pricing page, and the run allowance is what separates the free and Starter tiers, so establish the definition before choosing between them.

Share

Related pages

Other head to heads