---
title: "Where Kratos fits in an identity system"
description: "Which parts of login belong to Kratos, and which remain in the application?"
status: "coming-soon"
language: "en"
canonical: "https://bulnik.dev/en/articles/topics/T05.01/"
topicId: "T05.01"
---

> Coming soon — this article is being prepared. Below are its question, intended outcome, and place in the story.

## The question

Which parts of login belong to Kratos, and which remain in the application?

## What we will work through

Draw a Kratos login flow and identify responsibility boundaries.

## Before you begin

Previously covered: Authentication, authorization, and sessions: separate responsibilities; OAuth participants and delegated access.

- [Authentication, authorization, and sessions: separate responsibilities](/en/articles/topics/T02.01/)
- [OAuth participants and delegated access](/en/articles/topics/T04.01/)
