NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #4137 most downloaded on Packagist
A Craft CMS module to make working with authentication for third-parties a breeze.
Last release 6 days ago
02 Oct 2026
Ships fairly regularly
a new release about every 2 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
4 years old
98 releases · first in 2023
One column per quarter.
Fix Client Credentials API requests discarding provider response values required to resolve API URLs.
Fixed a high-severity external identity verification vulnerability.
Changed Switch to RFC 3986 URI parser.
Return token persistence failures instead of reporting a successful save, and report missing stored tokens before constructing OAuth API requests.
Add Tokens::EVENT_TOKEN_REFRESH_FAILED , fired when a refresh token is permanently rejected (e.g. Google invalid_grant ).
Tokens::EVENT_TOKEN_REFRESH_FAILED, fired when a refresh token is permanently rejected (e.g. Google invalid_grant).OAuthTokenRefreshException so consumers can detect “reconnect required” without parsing provider error bodies.invalid_grant (and similar permanent refresh failures), delete the stored OAuth token and throw instead of retrying API calls with a dead access token. Fixes integrations that appeared “Connected” for ~a week then failed until reconnect (common when a Google OAuth app is still in Testing publishing status).Add PKCE (S256) support for Salesforce OAuth authorization-code flows.
Fix OAuth 401 retries skipping token refresh for providers that omit access-token expiry (for example Salesforce), which caused repeated INVALID_SESSI
INVALID_SESSION_ID failures until reconnecting.Fix client_credentials API requests discarding the request payload (empty body), introduced in 2.0.41.
client_credentials API requests discarding the request payload (empty body), introduced in 2.0.41.Fix client_credentials API requests sending an empty scope parameter for providers like Marketo that reject it.
client_credentials API requests sending an empty scope parameter for providers like Marketo that reject it.Fix Apple sign-in fatal when is_private_email claim is omitted from the id_token.
Update lcobucci/jwt to support 5.x .
lcobucci/jwt to support 5.x.Fix RedirectUri::getCallbackUri() using a CP URL for detached installs ( cpTrigger = null ) when front-end login plugins expect a site URL.
RedirectUri::getCallbackUri() using a CP URL for detached installs (cpTrigger = null) when front-end login plugins expect a site URL.Fix intermittent 401 errors for OAuth integrations when multiple queue workers refresh the same token concurrently.
invalid_grant (rotated refresh tokens).Update client_credentials clients handling of scopes.
client_credentials clients handling of scopes.Update pkceVerifier check logic.
pkceVerifier check logic.Add RedirectUri helper to assist with redirection handling.
Update firebase/php-jwt to support 7.x.
firebase/php-jwt to support 7.x.paragonie/random-lib dependency and use native PHP randomness for Twitter PKCE verifier generation.Update Marketo to use access_token params.
access_token params.Fix client credentials based grants throwing an error for scopes for some providers.
Update Marketo to use client_credentials grant.
client_credentials grant.Fix Client Credentials grants to using getAccessTokenOptions() and scopes in request.
getAccessTokenOptions() and scopes in request.Fix GithubResourceOwner typing.
GithubResourceOwner typing.Fix Client Credentials grants to using getAccessTokenOptions() and scopes in request.
getAccessTokenOptions() and scopes in request.AuthorizationUrlEvent.Fix PSR autoloading issue for Procurios due to typo.
Add the ability for providers to modify the options for a request.
Fix a merge issue with AzureResourceOwner.
AzureResourceOwner.Add support for psr/http-message "^1.0 || ^2.0".
psr/http-message "^1.0 || ^2.0".Add email for Azure provider resources for common scenarios.
email for Azure provider resources for common scenarios.Update GitHub, GitLab and PayPal provider classes to be proper case.
Update league/oauth2-client dependency with refresh token fix. Provides official compatibility with PHP 8.3+.
league/oauth2-client dependency with refresh token fix. Provides official compatibility with PHP 8.3+.Lock league/oauth2-client to 2.7.0 to prevent an issue with refresh token scopes on some providers.
league/oauth2-client to 2.7.0 to prevent an issue with refresh token scopes on some providers.Add CA domain to Zoho provider.
Update handling for getBaseApiUrl() when a token doesn’t yet exist.
getBaseApiUrl() when a token doesn’t yet exist.Update handling for getBaseApiUrl() when a token doesn’t yet exist.
getBaseApiUrl() when a token doesn’t yet exist.Fix an error when making a request with a query string, and refreshing an expired token in the same request.
### Added - Add Microsoft Entra provider.
Fix Constant Contact client not working.
Add conditional for Twitter code_verifier check to prevent errors when already supplied.
code_verifier check to prevent errors when already supplied.Fix an issue with the Generic provider.
Fix an issue with the Generic provider and duplicate baseApiUrl.
baseApiUrl.Add the ability to set baseApiUrl for providers as part of their config. This can be a string, or a callback function.
baseApiUrl for providers as part of their config. This can be a string, or a callback function.useDeveloper setting.Updated Amazon Cognito provider.
Fix an error for IdentityServer4 getBaseApiUrl().
getBaseApiUrl().getBaseApiUrl().### Added - Add Amazon Cognito provider.
Fix an error with Azure/Entra with login approval.
Fix Slack provider not setting correct auth token for requests.
Fix LinkedIn client to support v2 API.
Fix LinkedIn client to support v2 API.
Fix an error with Google provider
Add improved session-storage and restoration between authorization and callback methods, to improve failed sessions in some cases.
8.2.0+.5.0.0+.Nothing published for this version
Nothing published for this version
Nothing published for this version
Update firebase/php-jwt to support 7.x.
firebase/php-jwt to support 7.x.paragonie/random-lib dependency and use native PHP randomness for Twitter PKCE verifier generation.Fix Client Credentials grants to using getAccessTokenOptions() and scopes in request.
getAccessTokenOptions() and scopes in request.Fix GithubResourceOwner typing.
GithubResourceOwner typing.Fix Client Credentials grants to using getAccessTokenOptions() and scopes in request.
getAccessTokenOptions() and scopes in request.AuthorizationUrlEvent.Unlock league/oauth2-client from 2.7.0.
league/oauth2-client from 2.7.0.Add support for psr/http-message "^1.0 || ^2.0".
psr/http-message "^1.0 || ^2.0".Add email for Azure provider resources for common scenarios.
email for Azure provider resources for common scenarios.Your coding agent can read these notes before it upgrades. Set up the MCP server →