BLASTA

Ory Hydra load testing template

Hydra public API (and admin introspection) endpoints.

Category IdentityStack Ory HydraJobs 44

About this Ory Hydra load test

Load tests Ory Hydra's public API and the admin introspection endpoint: discovery, keys, and the authorization and token endpoints with their error cases. It shows how the token endpoint scales as clients ask for tokens at the same time.

It holds 44 ready-made jobs: 25 single scenarios and an enterprise test plan of 19 stages to run in order, 16 of them with pass/fail targets (SLOs). Each job is a plain request pattern you can change before running.

Scenarios include OIDC discovery document, discovery document (cache bypass), JSON web key set, authorization endpoint (login page or redirect) and silent authentication (prompt=none).

How to load test Ory Hydra

  1. Open the template in BLASTA.
  2. Set url, clientId and redirectUri to point at your own Ory Hydra system, ideally a staging copy.
  3. Pick a job and choose the rate and duration.
  4. Start the run and watch requests per second, latency percentiles and errors live; the result is saved to your history.

What you set before running

url
Issuer / base URL, no trailing slash
clientId
A test client registered for load testing
clientSecret
A credential, supplied as an environment variable and never typed into the form. Client secret. Read from the OIDC_CLIENT_SECRET env var by the CLI.
redirectUri
A redirect URI registered on that client
scope
Space-separated scopes, URL-encoded
token
A credential, supplied as an environment variable and never typed into the form. A valid access token. Read from OIDC_ACCESS_TOKEN by the CLI.

Test scenarios (25)

OIDC discovery document

Read-only

Fetched by every relying party at start-up and on a timer. Cheap, but often served uncached.

JSON web key set

Read-only

Every API validating tokens locally refreshes keys from here, and a key rotation causes a thundering herd of fetches.

silent authentication (prompt=none)

Read-only

What SPAs do in a hidden iframe to renew a session. With no session it must answer with a login_required redirect, quickly, and without rendering a page.

authorization with a wrong redirect_uri

Read-only

Must be rejected with an error page, never redirected (open-redirect check): a 302 to the bad URI would be a vulnerability, so only 4xx and the error page count as success.

token: client credentials

Changes state: use a staging system

Machine-to-machine tokens. Signing a JWT is CPU bound, so this is where most providers saturate first. Creates tokens and sessions: staging only.

token: client credentials with HTTP Basic auth

Changes state: use a staging system

Same grant, client authenticated with an Authorization: Basic header. Replace the header value with base64(clientId:secret) when running from the UI.

token: wrong client secret

Read-only

Failed client authentication. Should be fast, rate limited and logged. Keep the rate low: some providers lock the client after repeated failures.

token: refresh token grant

Changes state: use a staging system

Token renewal, the most frequent token call in a long-lived app. If refresh tokens ROTATE, only the first request succeeds and the rest fail with invalid_grant: use a client without rotation.

token: exchange (RFC 8693)

Changes state: use a staging system

Swaps a token for another (service-to-service delegation). Not every provider supports it; a 400 unsupported_grant_type is counted as an error.

token endpoint capacity ramp

Changes state: use a staging system

Ramps client-credentials requests up to find the rate where latency or errors climb: your token-issuing capacity. Staging only.

token revocation

Writes data

Logout and security flows. Revoking an unknown token must still return 200 (RFC 7009).

userinfo soak (10 min)

Read-only

Steady load for ten minutes: finds cache expiry, connection and memory problems in token validation.

device authorization (device flow)

Changes state: use a staging system

Starts a TV or CLI login. Creates a pending device code per request, so it also tests the cleanup of abandoned ones. Staging only.

logout (end session)

Read-only

RP-initiated logout without a session: shows a confirmation page or redirects. Redirects are not followed.

dynamic client registration

Writes data

Creates a client per request. Only enable this endpoint where you need it: it is an unauthenticated write. Staging only; clean the clients up afterwards.

admin: introspect (port 4445)

Read-only

Resource servers call the ADMIN api to introspect. Point url at the admin port for this job only, and never expose it publicly.

Enterprise test plan (19)

Run in order: smoke, baseline, load, stress, spike, soak, breakpoint and failover window, each with pass/fail targets.

Ory Hydra: 01 smoke

Read-only

Enterprise plan, step 1 of 10. One request a second for 30 seconds. Run this first, every time: it proves the address, credentials and headers are right and that the environment is up before any real load is applied. Gate: zero errors. Reference request: authorization endpoint (login page or redirect).

Ory Hydra: 02 baseline (20% load)

Read-only

Step 2 of 10. About a fifth of normal traffic for 5 minutes: the uncontended latency of this request. Every later result is judged against it, so record p50 and p95. Gate: at most 0.5% errors and the default latency targets. Reference request: authorization endpoint (login page or redirect).

Ory Hydra: 03 average load (SLO check)

Read-only

Step 3 of 10. Normal busy-hour traffic for 10 minutes. The rate is the reference job's rate: raise it to your measured production peak-hour rate. This is the run that proves (or breaks) your SLO. Gate: at most 1% errors, p95 and p99 inside the targets. Reference request: authorization endpoint (login page or redirect).

Ory Hydra: 04 peak load (2x average)

Read-only

Step 4 of 10. Twice the average for 10 minutes: the busiest hour of the year plus headroom. Latency may rise, but must stay in SLO; if it does not, you have no headroom. Gate: at most 2% errors, latency targets doubled. Reference request: authorization endpoint (login page or redirect).

Ory Hydra: 05 stress (ramp to 4x)

Read-only

Step 5 of 10. Ramps to four times average over 10 minutes, then holds for 2. Finds where it degrades and HOW: gracefully (latency rises, errors stay low) or badly (errors, timeouts, crashes, restarts). Observation only, no gate. Reference request: authorization endpoint (login page or redirect).

Ory Hydra: 06 spike (10x in 10 s)

Read-only

Step 6 of 10. Reaches ten times average within 10 seconds and holds for 2 minutes: a campaign email, a news link, a failover. Checks autoscaling, queue limits and load shedding. Gate: at most 5% errors, because shedding load is acceptable and crashing is not. Reference request: authorization endpoint (login page or redirect).

Ory Hydra: 07 recovery after the spike

Read-only

Step 7 of 10. Run IMMEDIATELY after the spike, at average load for 5 minutes. Latency and errors must return to the baseline from step 2. If they do not, something is stuck: queues, connection pools, GC, an autoscaler cool-down. Gate: same as average load. Reference request: authorization endpoint (login page or redirect).

Ory Hydra: 08 soak (1 hour at 60%)

Read-only

Step 8 of 10. One hour of steady load. Finds leaks and slow decay in memory, connections, file descriptors, disk, log volume and cache churn. Watch the resource graphs: any line that climbs and never flattens is a finding. Gate: at most 0.5% errors. Reference request: authorization endpoint (login page or redirect).

Ory Hydra: 09 breakpoint (find the ceiling)

Read-only

Step 9 of 10. Ramps to twenty times average over 20 minutes. Stop it when errors pass about 5%: the rate at that moment is your ceiling, and ceiling divided by peak is your capacity margin. Use a production-like environment, never production. Reference request: authorization endpoint (login page or redirect).

Ory Hydra: 10 resilience window (failover / deploy)

Read-only

Step 10 of 10. Average load for 15 minutes. About 5 minutes in, cause the event you are testing: kill a pod or node, fail over the database, roll out a new version, drain a zone. Errors in the window are your real availability loss. Gate: at most 1% errors overall; read the time series for how long the dip lasted. Reference request: authorization endpoint (login page or redirect).

Ory Hydra: no keep-alive (new connection per request)

Read-only

Sends Connection: close, so every request pays for a new TCP and TLS handshake: the cost for clients that do not reuse connections (scripts, some mobile SDKs, health checkers). Shows load balancer and TLS termination limits. Reference request: authorization endpoint (login page or redirect).

Ory Hydra: crawler traffic (Googlebot user agent)

Read-only

Same request identified as a search crawler. Tests WAF and bot-management rules and whether crawlers get cached or origin responses. Crawlers can easily be a third of all traffic. Reference request: authorization endpoint (login page or redirect).

Ory Hydra: large cookies (~4 KB header)

Read-only

Adds a 4 KB Cookie header, like a logged-in user with many tracking cookies. Proxies and servers reject headers around 8 KB, so this shows how close you are to that limit. Reference request: authorization endpoint (login page or redirect).

Ory Hydra: uptime monitors (HEAD from many locations)

Read-only

A fleet of synthetic monitors checking the URL with HEAD requests every 30 seconds from 20 locations, plus load balancer probes. Cheap each, constant in total. Reference request: authorization endpoint (login page or redirect).

Ory Hydra: Monday 9am login storm

Read-only

Everyone in the company signs in within a minute of starting work. Ramps login starts to eight times normal over 60 seconds. The identity provider is the one system every other system depends on, so this is the most important identity test. Reference request: authorization endpoint (login page or redirect).

Ory Hydra: token expiry herd

Changes state: use a staging system

Many services were started together, so their tokens expire together and they all ask for new ones in the same second. Jumps token requests to ten times normal in 10 seconds. Reference request: token: client credentials. This job WRITES or creates data on every request: staging only, and expect a lot of rows.

Ory Hydra: signing-key rotation herd

Read-only

After a signing key rotates, every service that validates tokens refetches the key set at once. Twenty times normal for 90 seconds; this should be a cache hit at the edge. Reference request: JSON web key set.

Ory Hydra: userinfo peak

Read-only

Apps call userinfo after login and on every page load. Three times normal for 10 minutes. Reference request: userinfo with a valid token.

Ory Hydra: credential-stuffing resilience

Read-only

Ten times the normal rate of failed client authentication for 2 minutes, the shape of a credential-stuffing attack. The provider must stay responsive for real users, rate-limit or lock the attacker, and not spend expensive hashing on each attempt. Run a normal login in parallel to confirm it keeps working. Staging only: it can lock the client. Reference request: token: wrong client secret.

Frequently asked questions

What does the Ory Hydra load test cover?

The Ory Hydra template has 44 jobs: 25 single scenarios and an enterprise test plan of 19 stages (smoke, baseline, load, stress, spike, soak, breakpoint and failover window). Scenarios include OIDC discovery document, discovery document (cache bypass), JSON web key set and authorization endpoint (login page or redirect). 16 of them have pass/fail targets (SLOs), so a run can be judged against limits you set.

How do I load test Ory Hydra with BLASTA?

Open the template in BLASTA and set url, clientId and redirectUri, then pick a job and start it. Results stream live: requests per second, latency percentiles and errors, and the run is kept in your history. To run from the command line, use blasta preset new ory-hydra with your address.

Is it safe to run the Ory Hydra load test against production?

Of the 44 jobs, 35 are read-only, 2 write data and 7 change state. Run the writing and state-changing jobs against a staging system, never against production data. Only test systems you own or have permission to test.

Related templates

Run a load test

Point BLASTA at something you own, choose how hard to hit it, and press Start test. Results stream in live.

1 What do you want to test? Use a template

Request headers

2 How hard should it hit?

Advanced limits
Pass / fail targets (SLO) optional
The result is marked SLO met or SLO missed. The same targets live in a job file, where blasta run exits 2 on a miss so CI or Kubernetes can gate a release.

Set up this job

Quick check

Please confirm you are not a robot to start your free test.

Clear history

Delete every finished test in your history. Tests still running are kept. This cannot be undone.

Add identity provider

Add user

The account is active at once. Share the password with them securely; they can change it from their menu.

Sign in to use templates

Templates and test history are part of the full app. Sign in, or create a free account, to use them.

Sign inCreate account

Change password