PackageTrack
Sign in Get early access

workos/workos-php

WorkOS PHP Library

v9.2.0 3.3M downloads/mo #2096 most downloaded on Packagist workos/workos-php

What this package is like to depend on

Last release 12 days ago

11 Aug 2026

Ships fairly regularly

a new release about every 3 weeks

Rarely documented

notes for 21 of 100 stable releases

Nothing withdrawn

no release was ever pulled

6 years old

100 releases · first in 2020

26 releases in the last 12 months

see the full history below

Release timeline

100 releases · Apr 2020 to Aug 2026
2021 2022 2023 2024 2025 2026
Release Pre-release

Releases

latest 60 of 100
  1. v9.2.0 11 Aug 2026
    Release notes
    • #428 feat(generated)!: regenerate from spec (2 changes)

      ⚠️ Breaking

      • events:
        • Changed required status for parameter Events.list.events

      Features

      • groups:
        • Added parameter Groups.list.search
      • connect:
        • Added client_id to ConnectedAccount
        • Added client_secret_last_4 to ConnectedAccount
        • Added config to ConnectedAccount
      • pipes:
        • Added client_id to DataIntegrationsListResponseDataConnectedAccount
        • Added client_secret_last_4 to DataIntegrationsListResponseDataConnectedAccount
        • Added config to DataIntegrationsListResponseDataConnectedAccount
        • Changed errors for endpoint POST /data-integrations/{slug}/credentials
        • Made CustomProviderDefinition.authorization_url optional
        • Made CustomProviderDefinition.token_url optional
        • Added model DataIntegrationsUpsertClientCredentialsRequest
        • Added client_credentials to CreateDataIntegrationAuthMethods
        • Added endpoint PUT /data-integrations/{slug}/client-credentials
      • sso:
        • Added XOAuth to ConnectionType
        • Added XOAuth to ProfileConnectionType
        • Added XOAuth to ConnectionsConnectionType
        • Added GrokOAuth to ConnectionType
        • Added GrokOAuth to ProfileConnectionType
        • Added GrokOAuth to ConnectionsConnectionType
      • user_management:
        • Changed errors for endpoint DELETE /user_management/users/{id}
        • Added password_salt_position to CreateUser
        • Added password_salt_position to UpdateUser
        • Made RadarSmsChallengeCodeSessionAuthenticateRequest.verification_id optional
        • Made RadarSmsChallengeCodeSessionAuthenticateRequest.phone_number optional
        • Added enum CreateUserPasswordSaltPosition
        • Added enum UpdateUserPasswordSaltPosition
        • Added XOAuth to AuthenticateResponseAuthenticationMethod
        • Added XOAuth to UserIdentitiesGetItemProvider
        • Added GrokOAuth to AuthenticateResponseAuthenticationMethod
        • Added GrokOAuth to UserIdentitiesGetItemProvider
      • webhooks:
        • Added agent.registration.refreshed to CreateWebhookEndpointEvents
        • Added agent.registration.refreshed to UpdateWebhookEndpointEvents

      Fixes

      • pipes:
        • Changed the type of DataIntegration.credentials
      • user_management:
        • Changed errors for endpoint POST /user_management/authenticate
        • Changed errors for endpoint POST /user_management/users
        • Changed errors for endpoint PUT /user_management/users/{id}
    Open source →
    Release notes
    • #428 feat(generated)!: regenerate from spec (2 changes)

      ⚠️ Breaking

      • events:
        • Changed required status for parameter Events.list.events

      Features

      • groups:
        • Added parameter Groups.list.search
      • connect:
        • Added client_id to ConnectedAccount
        • Added client_secret_last_4 to ConnectedAccount
        • Added config to ConnectedAccount
      • pipes:
        • Added client_id to DataIntegrationsListResponseDataConnectedAccount
        • Added client_secret_last_4 to DataIntegrationsListResponseDataConnectedAccount
        • Added config to DataIntegrationsListResponseDataConnectedAccount
        • Changed errors for endpoint POST /data-integrations/{slug}/credentials
        • Made CustomProviderDefinition.authorization_url optional
        • Made CustomProviderDefinition.token_url optional
        • Added model DataIntegrationsUpsertClientCredentialsRequest
        • Added client_credentials to CreateDataIntegrationAuthMethods
        • Added endpoint PUT /data-integrations/{slug}/client-credentials
      • sso:
        • Added XOAuth to ConnectionType
        • Added XOAuth to ProfileConnectionType
        • Added XOAuth to ConnectionsConnectionType
        • Added GrokOAuth to ConnectionType
        • Added GrokOAuth to ProfileConnectionType
        • Added GrokOAuth to ConnectionsConnectionType
      • user_management:
        • Changed errors for endpoint DELETE /user_management/users/{id}
        • Added password_salt_position to CreateUser
        • Added password_salt_position to UpdateUser
        • Made RadarSmsChallengeCodeSessionAuthenticateRequest.verification_id optional
        • Made RadarSmsChallengeCodeSessionAuthenticateRequest.phone_number optional
        • Added enum CreateUserPasswordSaltPosition
        • Added enum UpdateUserPasswordSaltPosition
        • Added XOAuth to AuthenticateResponseAuthenticationMethod
        • Added XOAuth to UserIdentitiesGetItemProvider
        • Added GrokOAuth to AuthenticateResponseAuthenticationMethod
        • Added GrokOAuth to UserIdentitiesGetItemProvider
      • webhooks:
        • Added agent.registration.refreshed to CreateWebhookEndpointEvents
        • Added agent.registration.refreshed to UpdateWebhookEndpointEvents

      Fixes

      • pipes:
        • Changed the type of DataIntegration.credentials
      • user_management:
        • Changed errors for endpoint POST /user_management/authenticate
        • Changed errors for endpoint POST /user_management/users
        • Changed errors for endpoint PUT /user_management/users/{id}
    Open source →
  2. v9.1.0 30 Jul 2026
    Release notes

    Features

    • pkce: Default clientId to the client's configured client ID (#423) (f65713b)

    • support for guzzle 8 (#427) (81c2384)

    • #425 fix(generated): regenerate from spec

      Features

      • pipes:
        • Added config to DataIntegrationsGetDataIntegrationAuthorizeUrlRequest
        • Added client_credentials to DataIntegrationAuthMethods
        • Added client_credentials to DataIntegrationsListResponseDataAuthMethods
        • Added client_credentials to DataIntegrationsListResponseDataConnectedAccountAuthMethod
        • Added config to Pipes models
      • connect:
        • Added client_credentials to ConnectedAccountAuthMethod

      Fixes

      • user_management:
        • Changed errors for endpoint POST /user_management/invitations
        • Changed errors for endpoint POST /user_management/invitations/{id}/resend
        • Changed errors for endpoint POST /user_management/magic_auth
        • Changed errors for endpoint POST /user_management/authenticate
    • #426 fix(generated): regenerate from spec

      Fixes

      • sso:
        • Removed callback_endpoint from Connection
    Open source →
    Release notes

    Features

    • pkce: Default clientId to the client's configured client ID (#423) (f65713b)

    • support for guzzle 8 (#427) (81c2384)

    • #425 fix(generated): regenerate from spec

      Features

      • pipes:
        • Added config to DataIntegrationsGetDataIntegrationAuthorizeUrlRequest
        • Added client_credentials to DataIntegrationAuthMethods
        • Added client_credentials to DataIntegrationsListResponseDataAuthMethods
        • Added client_credentials to DataIntegrationsListResponseDataConnectedAccountAuthMethod
        • Added config to Pipes models
      • connect:
        • Added client_credentials to ConnectedAccountAuthMethod

      Fixes

      • user_management:
        • Changed errors for endpoint POST /user_management/invitations
        • Changed errors for endpoint POST /user_management/invitations/{id}/resend
        • Changed errors for endpoint POST /user_management/magic_auth
        • Changed errors for endpoint POST /user_management/authenticate
    • #426 fix(generated): regenerate from spec

      Fixes

      • sso:
        • Removed callback_endpoint from Connection
    Open source →
  3. v9.0.0 22 Jul 2026
    Release notes

    Miscellaneous Chores

    • deps: update actions/cache action to v5.1.0 (#419) (d963179)

    • prevent oagen generated files from being PR'ed (26d03a0)

    • scope SDK bot App token permissions (293b5ef)

    • #420 fix(generated): regenerate from spec

      Features

      • audit_logs:
        • Added expired to AuditLogExportState
    • #421 feat(generated)!: regenerate from spec (3 changes)

      Features

      • agents:
        • Added model ClaimViewResponse
        • Added model ClaimViewResponseOrganization
        • Added model AgentAdminLinkClaimAttemptToExternalUserRequest
        • Added model AgentAdminLinkClaimAttemptToExternalUserRequestUser
        • Added enum ClaimViewResponseStatus
        • Added endpoint PATCH /agents/claims/attempts
        • Added model AgentRegistration
        • Added model AgentCredentialValidation
        • Added model AgentRegistrationAgentIdentity
        • Added model AgentRegistrationClaim
        • Added model AgentAdminValidateCredentialRequest
        • Added model AgentRegistrationClaimClaimCompletion
        • Added enum AgentRegistrationStatus
        • Added enum AgentRegistrationKind
        • Added enum AgentAdminValidateCredentialRequestType
        • Added service Agents
      • api_keys:
        • Added agent_registration_id to ApiKeyValidationResponse
      • connect:
        • Added enum ApplicationsRegistrationTypes
        • Added parameter Applications.list.registration_types
      • directory_sync:
        • Added parameter DirectoryUsers.list.idp_id
        • Added parameter DirectoryUsers.list.email
      • organizations:
        • Added model OrganizationAuthorizedConnectApplicationList
        • Added model OrganizationAuthorizedConnectApplicationListData
        • Added model OrganizationAuthorizedConnectApplicationListListMetadata
        • Added service OrganizationsAuthorizedApplications
      • pipes:
        • Added model DataIntegrationInstallation
        • Added auth_methods to CreateDataIntegration
        • Added api_key to CreateDataIntegration
        • Added api_key to UpdateDataIntegration
        • Added auth_methods to DataIntegration
        • Added installation to DataIntegration
        • Added enum CreateDataIntegrationAuthMethods
        • Added enum DataIntegrationAuthMethods
        • Added model DataIntegrationCredentialsResponse
        • Added model DataIntegrationCredentialsResponseCredential
        • Added model DataIntegrationsUpsertApiKeyRequest
        • Added model DataIntegrationsVendCredentialsRequest
        • Added enum DataIntegrationCredentialsResponseError
        • Added endpoint PUT /data-integrations/{slug}/api-key
        • Added endpoint POST /data-integrations/{slug}/credentials
      • sso:
        • Added parameter SSO.authorize.prompt
      • user_management:
        • Added ssha256 to CreateUserPasswordHashType
        • Added ssha256 to UpdateUserPasswordHashType
        • Added endpoint GET /user_management/radar_challenges/{id}
      • webhooks:
        • Added agent.registration.revoked to CreateWebhookEndpointEvents
        • Added agent.registration.revoked to UpdateWebhookEndpointEvents
        • Added agent.registration.deleted to CreateWebhookEndpointEvents
        • Added agent.registration.deleted to UpdateWebhookEndpointEvents
        • Added radar.challenge_created to CreateWebhookEndpointEvents
        • Added radar.challenge_created to UpdateWebhookEndpointEvents
        • Added agent.registration.expired to CreateWebhookEndpointEvents
        • Added agent.registration.expired to UpdateWebhookEndpointEvents
      • widgets:
        • Made WidgetSessionToken.organization_id optional
    • #422 feat(generated)!: regenerate from spec (5 changes)

      ⚠️ Breaking

      • admin_portal:
        • SDK surface change: Symbol "IntentOptions" was removed
      • connect:
        • SDK surface change: Symbol "ConnectedAccountDto" was removed
      • organization_domains:
        • SDK surface change: Symbol "DomainVerificationIntentOptions" was removed
      • pipes:
        • SDK surface change: Symbol "DataIntegrationCredentialsDto" was removed
      • sso:
        • SDK surface change: Symbol "SSOIntentOptions" was removed
    Open source →
    Release notes

    Miscellaneous Chores

    • deps: update actions/cache action to v5.1.0 (#419) (d963179)

    • prevent oagen generated files from being PR'ed (26d03a0)

    • scope SDK bot App token permissions (293b5ef)

    • #420 fix(generated): regenerate from spec

      Features

      • audit_logs:
        • Added expired to AuditLogExportState
    • #421 feat(generated)!: regenerate from spec (3 changes)

      Features

      • agents:
        • Added model ClaimViewResponse
        • Added model ClaimViewResponseOrganization
        • Added model AgentAdminLinkClaimAttemptToExternalUserRequest
        • Added model AgentAdminLinkClaimAttemptToExternalUserRequestUser
        • Added enum ClaimViewResponseStatus
        • Added endpoint PATCH /agents/claims/attempts
        • Added model AgentRegistration
        • Added model AgentCredentialValidation
        • Added model AgentRegistrationAgentIdentity
        • Added model AgentRegistrationClaim
        • Added model AgentAdminValidateCredentialRequest
        • Added model AgentRegistrationClaimClaimCompletion
        • Added enum AgentRegistrationStatus
        • Added enum AgentRegistrationKind
        • Added enum AgentAdminValidateCredentialRequestType
        • Added service Agents
      • api_keys:
        • Added agent_registration_id to ApiKeyValidationResponse
      • connect:
        • Added enum ApplicationsRegistrationTypes
        • Added parameter Applications.list.registration_types
      • directory_sync:
        • Added parameter DirectoryUsers.list.idp_id
        • Added parameter DirectoryUsers.list.email
      • organizations:
        • Added model OrganizationAuthorizedConnectApplicationList
        • Added model OrganizationAuthorizedConnectApplicationListData
        • Added model OrganizationAuthorizedConnectApplicationListListMetadata
        • Added service OrganizationsAuthorizedApplications
      • pipes:
        • Added model DataIntegrationInstallation
        • Added auth_methods to CreateDataIntegration
        • Added api_key to CreateDataIntegration
        • Added api_key to UpdateDataIntegration
        • Added auth_methods to DataIntegration
        • Added installation to DataIntegration
        • Added enum CreateDataIntegrationAuthMethods
        • Added enum DataIntegrationAuthMethods
        • Added model DataIntegrationCredentialsResponse
        • Added model DataIntegrationCredentialsResponseCredential
        • Added model DataIntegrationsUpsertApiKeyRequest
        • Added model DataIntegrationsVendCredentialsRequest
        • Added enum DataIntegrationCredentialsResponseError
        • Added endpoint PUT /data-integrations/{slug}/api-key
        • Added endpoint POST /data-integrations/{slug}/credentials
      • sso:
        • Added parameter SSO.authorize.prompt
      • user_management:
        • Added ssha256 to CreateUserPasswordHashType
        • Added ssha256 to UpdateUserPasswordHashType
        • Added endpoint GET /user_management/radar_challenges/{id}
      • webhooks:
        • Added agent.registration.revoked to CreateWebhookEndpointEvents
        • Added agent.registration.revoked to UpdateWebhookEndpointEvents
        • Added agent.registration.deleted to CreateWebhookEndpointEvents
        • Added agent.registration.deleted to UpdateWebhookEndpointEvents
        • Added radar.challenge_created to CreateWebhookEndpointEvents
        • Added radar.challenge_created to UpdateWebhookEndpointEvents
        • Added agent.registration.expired to CreateWebhookEndpointEvents
        • Added agent.registration.expired to UpdateWebhookEndpointEvents
      • widgets:
        • Made WidgetSessionToken.organization_id optional
    • #422 feat(generated)!: regenerate from spec (5 changes)

      ⚠️ Breaking

      • admin_portal:
        • SDK surface change: Symbol "IntentOptions" was removed
      • connect:
        • SDK surface change: Symbol "ConnectedAccountDto" was removed
      • organization_domains:
        • SDK surface change: Symbol "DomainVerificationIntentOptions" was removed
      • pipes:
        • SDK surface change: Symbol "DataIntegrationCredentialsDto" was removed
      • sso:
        • SDK surface change: Symbol "SSOIntentOptions" was removed
    Open source →
  4. v8.1.0 06 Jul 2026
    Release notes
    • #416 fix(generated): regenerate from spec

      Features

      • user_management:
        • Added model UserRoleAssignmentSource
        • Added source to UserRoleAssignment
        • Added enum UserRoleAssignmentSourceType
        • Added parameter UserManagementAuthentication.authorize.max_age
        • Added endpoint GET /user_management/cors_origins
        • Added endpoint GET /user_management/redirect_uris

      Fixes

      • Restore mistakenly removed CreateMagicAuth logic from previous release
    Open source →
    Release notes
    • #416 fix(generated): regenerate from spec

      Features

      • user_management:
        • Added model UserRoleAssignmentSource
        • Added source to UserRoleAssignment
        • Added enum UserRoleAssignmentSourceType
        • Added parameter UserManagementAuthentication.authorize.max_age
        • Added endpoint GET /user_management/cors_origins
        • Added endpoint GET /user_management/redirect_uris

      Fixes

      • Restore mistakenly removed CreateMagicAuth logic from previous release
    Open source →
  5. v8.0.0 02 Jul 2026
    Release notes
    • #409 fix(generated): regenerate from spec

      Features

      • pipes:
        • Added model DataIntegrationCredentialsResponse
        • Added model DataIntegrationCredentialsResponseCredential
        • Added model DataIntegrationsUpsertApiKeyRequest
        • Added model DataIntegrationsVendCredentialsRequest
        • Added enum DataIntegrationCredentialsResponseError
        • Added endpoint PUT /data-integrations/{slug}/api-key
        • Added endpoint POST /data-integrations/{slug}/credentials
    • #411 feat(generated)!: regenerate from spec (1 change)

      ⚠️ Breaking

      • user_management:
        • Removed model SessionReauthenticated
        • Removed model SessionReauthenticatedData
        • Removed model SessionReauthenticatedDataImpersonator
        • Removed enum SessionReauthenticatedDataAuthMethod
        • Removed enum SessionReauthenticatedDataStatus

      Features

      • webhooks:
        • Added agent.registration.created to CreateWebhookEndpointEvents
        • Added agent.registration.claim.attempt.created to CreateWebhookEndpointEvents
        • Added agent.registration.claim.completed to CreateWebhookEndpointEvents
        • Added agent.registration.credential.issued to CreateWebhookEndpointEvents
        • Added agent.registration.organization.switched to CreateWebhookEndpointEvents
        • Added authentication.reauthentication_succeeded to CreateWebhookEndpointEvents
        • Added agent.registration.created to UpdateWebhookEndpointEvents
        • Added agent.registration.claim.attempt.created to UpdateWebhookEndpointEvents
        • Added agent.registration.claim.completed to UpdateWebhookEndpointEvents
        • Added agent.registration.credential.issued to UpdateWebhookEndpointEvents
        • Added agent.registration.organization.switched to UpdateWebhookEndpointEvents
        • Added authentication.reauthentication_succeeded to UpdateWebhookEndpointEvents
      • webhooks:
        • Added session.reauthenticated to CreateWebhookEndpointEvents
        • Added session.reauthenticated to UpdateWebhookEndpointEvents
      • webhooks:
        • Added pipes.connected_account.connection_failed to CreateWebhookEndpointEvents
        • Added pipes.connected_account.connection_failed to UpdateWebhookEndpointEvents
      • user_management:
        • Added model UserRoleAssignmentSource
        • Added source to UserRoleAssignment
        • Added enum UserRoleAssignmentSourceType
        • Added parameter UserManagementAuthentication.authorize.max_age
        • Added endpoint GET /user_management/cors_origins
        • Added endpoint GET /user_management/redirect_uris
      • audit_logs:
        • Changed the format of AuditLogExportCreation.range_start
        • Changed the format of AuditLogExportCreation.range_end
      • audit_logs:
        • Added expired to AuditLogExportState

      Fixes

      • admin_portal:
        • Removed intent_options from GenerateLink
      • webhooks:
        • Removed session.reauthenticated from CreateWebhookEndpointEvents
        • Removed session.reauthenticated from UpdateWebhookEndpointEvents
    • #413 feat(generated): regenerate from spec (1 change)

      Features

      • pipes:
        • Added model DataIntegrationCredentialsDto
        • Added model CustomProviderDefinition
        • Added model CreateDataIntegration
        • Added model UpdateCustomProviderDefinition
        • Added model UpdateDataIntegration
        • Added model DataIntegration
        • Added model DataIntegrationList
        • Added model DataIntegrationListListMetadata
        • Added model DataIntegrationCredential
        • Added model DataIntegrationCustomProvider
        • Added enum DataIntegrationCredentialsType
        • Added enum CustomProviderDefinitionAuthenticateVia
        • Added enum UpdateCustomProviderDefinitionAuthenticateVia
        • Added enum DataIntegrationState
        • Added enum DataIntegrationCredentialType
        • Added enum DataIntegrationCustomProviderAuthenticateVia
        • Added endpoint GET /data-integrations
        • Added endpoint POST /data-integrations
        • Added endpoint GET /data-integrations/{slug}
        • Added endpoint PUT /data-integrations/{slug}
        • Added endpoint DELETE /data-integrations/{slug}
        • Added endpoint POST /user_management/users/{user_id}/connected_accounts/{slug}
        • Added endpoint PUT /user_management/users/{user_id}/connected_accounts/{slug}
    • #414 feat(generated): regenerate from spec (2 changes)

      Features

      • user_management:
        • Added model SendRadarSmsChallenge
        • Added model SendRadarSmsChallengeResponse
        • Added model UrnWorkosOAuthGrantTypeRadarEmailChallengeCodeSessionAuthenticateRequest
        • Added model UrnWorkosOAuthGrantTypeRadarSmsChallengeCodeSessionAuthenticateRequest
        • Added model MagicAuthSendMagicAuthCodeAndReturnResponse
        • Added model UserCreateResponse
        • Added ip_address to CreateMagicCodeAndReturn
        • Added user_agent to CreateMagicCodeAndReturn
        • Added radar_auth_attempt_id to CreateMagicCodeAndReturn
        • Added signals_id to CreateMagicCodeAndReturn
        • Added ip_address to CreateUser
        • Added user_agent to CreateUser
        • Added signals_id to CreateUser
        • Added signals_id to AuthorizationCodeSessionAuthenticateRequest
        • Added signals_id to PasswordSessionAuthenticateRequest
        • Added radar_auth_attempt_id to PasswordSessionAuthenticateRequest
        • Added radar_auth_attempt_id to UrnWorkosOAuthGrantTypeMagicAuthCodeSessionAuthenticateRequest
        • Added endpoint POST /user_management/radar_challenges
      • radar:
        • Added signals_id to RadarStandaloneAssessRequest

      Fixes

      • user_management:
        • Changed request body for UserManagementAuthentication.authenticate
        • Changed response of UserManagementUsers.create from User to UserCreateResponse
        • Changed response of UserManagementMagicAuth.sendMagicAuthCodeAndReturn from MagicAuth to MagicAuthSendMagicAuthCodeAndReturnResponse
    Open source →
    Release notes
    • #409 fix(generated): regenerate from spec

      Features

      • pipes:
        • Added model DataIntegrationCredentialsResponse
        • Added model DataIntegrationCredentialsResponseCredential
        • Added model DataIntegrationsUpsertApiKeyRequest
        • Added model DataIntegrationsVendCredentialsRequest
        • Added enum DataIntegrationCredentialsResponseError
        • Added endpoint PUT /data-integrations/{slug}/api-key
        • Added endpoint POST /data-integrations/{slug}/credentials
    • #411 feat(generated)!: regenerate from spec (1 change)

      ⚠️ Breaking

      • user_management:
        • Removed model SessionReauthenticated
        • Removed model SessionReauthenticatedData
        • Removed model SessionReauthenticatedDataImpersonator
        • Removed enum SessionReauthenticatedDataAuthMethod
        • Removed enum SessionReauthenticatedDataStatus

      Features

      • webhooks:
        • Added agent.registration.created to CreateWebhookEndpointEvents
        • Added agent.registration.claim.attempt.created to CreateWebhookEndpointEvents
        • Added agent.registration.claim.completed to CreateWebhookEndpointEvents
        • Added agent.registration.credential.issued to CreateWebhookEndpointEvents
        • Added agent.registration.organization.switched to CreateWebhookEndpointEvents
        • Added authentication.reauthentication_succeeded to CreateWebhookEndpointEvents
        • Added agent.registration.created to UpdateWebhookEndpointEvents
        • Added agent.registration.claim.attempt.created to UpdateWebhookEndpointEvents
        • Added agent.registration.claim.completed to UpdateWebhookEndpointEvents
        • Added agent.registration.credential.issued to UpdateWebhookEndpointEvents
        • Added agent.registration.organization.switched to UpdateWebhookEndpointEvents
        • Added authentication.reauthentication_succeeded to UpdateWebhookEndpointEvents
      • webhooks:
        • Added session.reauthenticated to CreateWebhookEndpointEvents
        • Added session.reauthenticated to UpdateWebhookEndpointEvents
      • webhooks:
        • Added pipes.connected_account.connection_failed to CreateWebhookEndpointEvents
        • Added pipes.connected_account.connection_failed to UpdateWebhookEndpointEvents
      • user_management:
        • Added model UserRoleAssignmentSource
        • Added source to UserRoleAssignment
        • Added enum UserRoleAssignmentSourceType
        • Added parameter UserManagementAuthentication.authorize.max_age
        • Added endpoint GET /user_management/cors_origins
        • Added endpoint GET /user_management/redirect_uris
      • audit_logs:
        • Changed the format of AuditLogExportCreation.range_start
        • Changed the format of AuditLogExportCreation.range_end
      • audit_logs:
        • Added expired to AuditLogExportState

      Fixes

      • admin_portal:
        • Removed intent_options from GenerateLink
      • webhooks:
        • Removed session.reauthenticated from CreateWebhookEndpointEvents
        • Removed session.reauthenticated from UpdateWebhookEndpointEvents
    • #413 feat(generated): regenerate from spec (1 change)

      Features

      • pipes:
        • Added model DataIntegrationCredentialsDto
        • Added model CustomProviderDefinition
        • Added model CreateDataIntegration
        • Added model UpdateCustomProviderDefinition
        • Added model UpdateDataIntegration
        • Added model DataIntegration
        • Added model DataIntegrationList
        • Added model DataIntegrationListListMetadata
        • Added model DataIntegrationCredential
        • Added model DataIntegrationCustomProvider
        • Added enum DataIntegrationCredentialsType
        • Added enum CustomProviderDefinitionAuthenticateVia
        • Added enum UpdateCustomProviderDefinitionAuthenticateVia
        • Added enum DataIntegrationState
        • Added enum DataIntegrationCredentialType
        • Added enum DataIntegrationCustomProviderAuthenticateVia
        • Added endpoint GET /data-integrations
        • Added endpoint POST /data-integrations
        • Added endpoint GET /data-integrations/{slug}
        • Added endpoint PUT /data-integrations/{slug}
        • Added endpoint DELETE /data-integrations/{slug}
        • Added endpoint POST /user_management/users/{user_id}/connected_accounts/{slug}
        • Added endpoint PUT /user_management/users/{user_id}/connected_accounts/{slug}
    • #414 feat(generated): regenerate from spec (2 changes)

      Features

      • user_management:
        • Added model SendRadarSmsChallenge
        • Added model SendRadarSmsChallengeResponse
        • Added model UrnWorkosOAuthGrantTypeRadarEmailChallengeCodeSessionAuthenticateRequest
        • Added model UrnWorkosOAuthGrantTypeRadarSmsChallengeCodeSessionAuthenticateRequest
        • Added model MagicAuthSendMagicAuthCodeAndReturnResponse
        • Added model UserCreateResponse
        • Added ip_address to CreateMagicCodeAndReturn
        • Added user_agent to CreateMagicCodeAndReturn
        • Added radar_auth_attempt_id to CreateMagicCodeAndReturn
        • Added signals_id to CreateMagicCodeAndReturn
        • Added ip_address to CreateUser
        • Added user_agent to CreateUser
        • Added signals_id to CreateUser
        • Added signals_id to AuthorizationCodeSessionAuthenticateRequest
        • Added signals_id to PasswordSessionAuthenticateRequest
        • Added radar_auth_attempt_id to PasswordSessionAuthenticateRequest
        • Added radar_auth_attempt_id to UrnWorkosOAuthGrantTypeMagicAuthCodeSessionAuthenticateRequest
        • Added endpoint POST /user_management/radar_challenges
      • radar:
        • Added signals_id to RadarStandaloneAssessRequest

      Fixes

      • user_management:
        • Changed request body for UserManagementAuthentication.authenticate
        • Changed response of UserManagementUsers.create from User to UserCreateResponse
        • Changed response of UserManagementMagicAuth.sendMagicAuthCodeAndReturn from MagicAuth to MagicAuthSendMagicAuthCodeAndReturnResponse
    Open source →
  6. v7.3.0 30 Jun 2026
    Release notes
    Open source →
    Release notes
    Open source →
  7. v7.2.0 18 Jun 2026
    Release notes

    Bug Fixes

    • Fix empty body serializing as JSON array instead of object (#403) (29d0099)

    Miscellaneous Chores

    • commit publishing fixes (c7ba478)
    • #401 feat(generated)!: regenerate from spec (11 changes)

      ⚠️ Breaking

      • pipes:
        • SDK surface change: Pipes.createDataIntegrationToken was renamed to Pipes.getAccessToken

      Features

      • authorization:
        • Added model ReplaceGroupRoleAssignmentEntry
        • Added model ReplaceGroupRoleAssignments
        • Added model DeleteGroupRoleAssignmentsByCriteria
        • Added endpoint POST /authorization/groups/{group_id}/role_assignments
        • Added endpoint PUT /authorization/groups/{group_id}/role_assignments
        • Added endpoint DELETE /authorization/groups/{group_id}/role_assignments
        • Added endpoint GET /authorization/groups/{group_id}/role_assignments/{role_assignment_id}
        • Added endpoint DELETE /authorization/groups/{group_id}/role_assignments/{role_assignment_id}
      • client:
        • Added model ClientApiToken
        • Added model ClientApiTokenResponse
        • Added service Client
      • connect:
        • Added auth_method to ConnectedAccount
        • Added api_key_last_4 to ConnectedAccount
        • Added enum ConnectedAccountAuthMethod
      • groups:
        • Added model CreateGroupRoleAssignment
        • Added model GroupRoleAssignment
        • Added model GroupRoleAssignmentList
        • Added model GroupRoleAssignmentResource
      • organization_membership:
        • Added model UserOrganizationMembershipList
        • Added model UserOrganizationMembershipListListMetadata
      • pipes:
        • Added model DataIntegrationCredentials
        • Added model DataIntegrationConfigurationResponse
        • Added model DataIntegrationConfigurationListResponse
        • Added model ConfigureDataIntegrationBody
        • Added auth_methods to DataIntegrationsListResponseData
        • Added auth_method to DataIntegrationsListResponseDataConnectedAccount
        • Added api_key_last_4 to DataIntegrationsListResponseDataConnectedAccount
        • Added enum DataIntegrationCredentialsCredentialsType
        • Added enum DataIntegrationsListResponseDataAuthMethods
        • Added enum DataIntegrationsListResponseDataConnectedAccountAuthMethod
        • Added service PipesProvider
      • user_management:
        • Added model UserInviteList
        • Added model UserInviteListListMetadata
        • Made AuthorizationCodeSessionAuthenticateRequest.client_secret optional
        • Made RefreshTokenSessionAuthenticateRequest.client_secret optional
      • widgets:
        • Added widgets:pipes:manage to WidgetSessionTokenScopes

      Fixes

      • organization_membership:
        • Changed response of UserManagementOrganizationMembership.list from UserOrganizationMembership to UserOrganizationMembershipList
      • user_management:
        • Changed response of UserManagementInvitations.list from UserInvite to UserInviteList
    Open source →
    Release notes

    Bug Fixes

    • Fix empty body serializing as JSON array instead of object (#403) (29d0099)

    Miscellaneous Chores

    • commit publishing fixes (c7ba478)
    • #401 feat(generated)!: regenerate from spec (11 changes)

      ⚠️ Breaking

      • pipes:
        • SDK surface change: Pipes.createDataIntegrationToken was renamed to Pipes.getAccessToken

      Features

      • authorization:
        • Added model ReplaceGroupRoleAssignmentEntry
        • Added model ReplaceGroupRoleAssignments
        • Added model DeleteGroupRoleAssignmentsByCriteria
        • Added endpoint POST /authorization/groups/{group_id}/role_assignments
        • Added endpoint PUT /authorization/groups/{group_id}/role_assignments
        • Added endpoint DELETE /authorization/groups/{group_id}/role_assignments
        • Added endpoint GET /authorization/groups/{group_id}/role_assignments/{role_assignment_id}
        • Added endpoint DELETE /authorization/groups/{group_id}/role_assignments/{role_assignment_id}
      • client:
        • Added model ClientApiToken
        • Added model ClientApiTokenResponse
        • Added service Client
      • connect:
        • Added auth_method to ConnectedAccount
        • Added api_key_last_4 to ConnectedAccount
        • Added enum ConnectedAccountAuthMethod
      • groups:
        • Added model CreateGroupRoleAssignment
        • Added model GroupRoleAssignment
        • Added model GroupRoleAssignmentList
        • Added model GroupRoleAssignmentResource
      • organization_membership:
        • Added model UserOrganizationMembershipList
        • Added model UserOrganizationMembershipListListMetadata
      • pipes:
        • Added model DataIntegrationCredentials
        • Added model DataIntegrationConfigurationResponse
        • Added model DataIntegrationConfigurationListResponse
        • Added model ConfigureDataIntegrationBody
        • Added auth_methods to DataIntegrationsListResponseData
        • Added auth_method to DataIntegrationsListResponseDataConnectedAccount
        • Added api_key_last_4 to DataIntegrationsListResponseDataConnectedAccount
        • Added enum DataIntegrationCredentialsCredentialsType
        • Added enum DataIntegrationsListResponseDataAuthMethods
        • Added enum DataIntegrationsListResponseDataConnectedAccountAuthMethod
        • Added service PipesProvider
      • user_management:
        • Added model UserInviteList
        • Added model UserInviteListListMetadata
        • Made AuthorizationCodeSessionAuthenticateRequest.client_secret optional
        • Made RefreshTokenSessionAuthenticateRequest.client_secret optional
      • widgets:
        • Added widgets:pipes:manage to WidgetSessionTokenScopes

      Fixes

      • organization_membership:
        • Changed response of UserManagementOrganizationMembership.list from UserOrganizationMembership to UserOrganizationMembershipList
      • user_management:
        • Changed response of UserManagementInvitations.list from UserInvite to UserInviteList
    Open source →
  8. v7.1.0 17 Jun 2026
    Release notes

    Miscellaneous Chores

    • deps: update github actions non-major (#398) (79fc78c)
    • #397 feat(generated)!: regenerate from spec (5 changes)

      ⚠️ Breaking

      • api_keys:
        • Made expires_at required in API key models
      • directory_sync:
        • Removed model DsyncDeactivated
        • Removed model DsyncDeactivatedData
        • Removed model DsyncDeactivatedDataDomain
        • Removed enum DsyncDeactivatedDataType
        • Removed enum DsyncDeactivatedDataState
      • radar:
        • Removed domain_sign_up_rate_limit from RadarStandaloneResponseControl
      • user_management:
        • Removed return_to from RevokeSession

      Features

      • api_keys:
        • Added model ExpireApiKey
        • Added model ApiKeyUpdated
        • Added model ApiKeyUpdatedData
        • Added model ApiKeyUpdatedDataOwner
        • Added model UserApiKeyUpdatedDataOwner
        • Added model ApiKeyUpdatedDataPreviousAttribute
        • Added endpoint POST /api_keys/{id}/expire
      • audit_logs:
        • Added Snowflake to AuditLogConfigurationLogStreamType
      • connect:
        • Added name to UserObject
      • directory_sync:
        • Added model DsyncTokenCreated
        • Added model DsyncTokenCreatedData
        • Added model DsyncTokenRevoked
        • Added model DsyncTokenRevokedData
      • user_management:
        • Added name to user management models
      • webhooks:
        • Added api_key.updated to CreateWebhookEndpointEvents
        • Added api_key.updated to UpdateWebhookEndpointEvents
    Open source →
    Release notes

    Miscellaneous Chores

    • deps: update github actions non-major (#398) (79fc78c)
    • #397 feat(generated)!: regenerate from spec (5 changes)

      ⚠️ Breaking

      • api_keys:
        • Made expires_at required in API key models
      • directory_sync:
        • Removed model DsyncDeactivated
        • Removed model DsyncDeactivatedData
        • Removed model DsyncDeactivatedDataDomain
        • Removed enum DsyncDeactivatedDataType
        • Removed enum DsyncDeactivatedDataState
      • radar:
        • Removed domain_sign_up_rate_limit from RadarStandaloneResponseControl
      • user_management:
        • Removed return_to from RevokeSession

      Features

      • api_keys:
        • Added model ExpireApiKey
        • Added model ApiKeyUpdated
        • Added model ApiKeyUpdatedData
        • Added model ApiKeyUpdatedDataOwner
        • Added model UserApiKeyUpdatedDataOwner
        • Added model ApiKeyUpdatedDataPreviousAttribute
        • Added endpoint POST /api_keys/{id}/expire
      • audit_logs:
        • Added Snowflake to AuditLogConfigurationLogStreamType
      • connect:
        • Added name to UserObject
      • directory_sync:
        • Added model DsyncTokenCreated
        • Added model DsyncTokenCreatedData
        • Added model DsyncTokenRevoked
        • Added model DsyncTokenRevokedData
      • user_management:
        • Added name to user management models
      • webhooks:
        • Added api_key.updated to CreateWebhookEndpointEvents
        • Added api_key.updated to UpdateWebhookEndpointEvents
    Open source →
  9. v7.0.1 28 May 2026
    Release notes

    Bug Fixes

    • renamed misleading Object to VaultObject (c7cef60)
    • renovate: explicitly enable minor and patch updates (#393) (e1705f1)
    • sdk: omit defaulted screen_hint from auth URLs (#396) (d583c7c)
    Open source →
    Release notes

    Bug Fixes

    • renamed misleading Object to VaultObject (c7cef60)
    • renovate: explicitly enable minor and patch updates (#393) (e1705f1)
    • sdk: omit defaulted screen_hint from auth URLs (#396) (d583c7c)
    Open source →
  10. v7.0.0 26 May 2026
    Release notes

    Miscellaneous Chores

    • deps: update googleapis/release-please-action action to v5 (#389) (f973f21)

    • deps: update shivammathur/setup-php action to v2.37.0 (#388) (f9e113f)

    • use shared workos/renovate-config preset (99aad6c)

    • #392 feat(generated)!: regenerate from spec (10 changes)

      ⚠️ Breaking

      • user_management: Remove organization membership methods from UserManagement service
        • Removed listOrganizationMemberships, createOrganizationMembership, getOrganizationMembership, updateOrganizationMembership, deleteOrganizationMembership, deactivateOrganizationMembership, and reactivateOrganizationMembership methods
        • These methods have been moved to the new OrganizationMembershipService
        • Change to getAuthorizationUrl() parameter screenHint from UserManagementAuthenticationScreenHint to RadarStandaloneAssessRequestAction type
        • Removed UserManagementAuthenticationScreenHint enum
      • user_management: Remove UserManagementOrganizationMembershipGroups service
        • Removed $workos->userManagementOrganizationMembershipGroups() accessor
        • listOrganizationMembershipGroups() has been moved to the new OrganizationMembershipService
      • radar: Remove device fingerprint and bot score from RadarStandaloneAssessRequest
        • Removed deviceFingerprint parameter from Radar.createAttempt() method
        • Removed botScore parameter from Radar.createAttempt() method
        • Removed deviceFingerprint and botScore fields from RadarStandaloneAssessRequest model
        • Removed deprecated enum values from RadarStandaloneAssessRequestAction: Login, Signup, SignUp2, SignUp3, SignIn2, SignIn3
        • Changed enum values in RadarStandaloneAssessRequestAction: SignUp from 'sign up' to 'sign-up', SignIn from 'sign in' to 'sign-in'
        • Removed enum values from RadarStandaloneResponseControl: CredentialStuffing, IpSignUpRateLimit
      • radar: Rename Radar list enums
        • Renamed RadarAction to RadarListAction
        • Renamed RadarType to RadarListType
      • audit_logs: Rename audit log models for consistency
        • Renamed AuditLogActionJson to AuditLogAction
        • Renamed AuditLogExportJson to AuditLogExport
        • Renamed AuditLogExportJsonState to AuditLogExportState
        • Renamed AuditLogSchemaJson to AuditLogSchema
        • Renamed AuditLogSchemaJsonActor to AuditLogSchemaActorInput
        • Renamed AuditLogSchemaJsonTarget to AuditLogSchemaTargetInput
        • Renamed AuditLogsRetentionJson to AuditLogsRetention
        • createSchema() method parameter types changed: AuditLogSchemaActorAuditLogSchemaActorInput, AuditLogSchemaTargetAuditLogSchemaTargetInput
      • webhooks: Rename webhook endpoint models and update status field type
        • Renamed WebhookEndpointJson to WebhookEndpoint
        • Renamed WebhookEndpointJsonStatus to WebhookEndpointStatus
        • Changed UpdateWebhookEndpoint.status field type from WebhookEndpointJsonStatus to WebhookEndpointStatus
        • Updated webhook event enums: added PIPES_CONNECTED_ACCOUNT_CONNECTED, PIPES_CONNECTED_ACCOUNT_DISCONNECTED, PIPES_CONNECTED_ACCOUNT_REAUTHORIZATION_NEEDED events
      • authorization: Update Authorization API with new filters and remove search parameter
        • Added resourceId, resourceExternalId, resourceTypeSlug filter parameters to listRoleAssignments()
        • Added roleSlug filter parameter to listRoleAssignmentsForResourceByExternalId() and listRoleAssignmentsForResource()
        • Removed search parameter from listResources() method
      • vault: Replace hand-maintained WorkOS\Vault class with generated WorkOS\Service\Vault
        • The old WorkOS\Vault class (lib/Vault.php) with client-side encrypt/decrypt helpers has been removed
        • $workos->vault() now returns WorkOS\Service\Vault with a different API surface
        • New generated methods: createDataKey(), createDecrypt(), createRekey(), listKv(), createKv(), getName(), getKv(), updateKv(), deleteKv(), listKvMetadata(), listKvVersions()

      Features

      • organization_membership: Introduce OrganizationMembershipService with membership and group operations
        • New service OrganizationMembershipService with methods: listOrganizationMemberships(), createOrganizationMembership(), getOrganizationMembership(), updateOrganizationMembership(), deleteOrganizationMembership(), deactivateOrganizationMembership(), reactivateOrganizationMembership(), and listOrganizationMembershipGroups()
        • Accessible via $workos->organizationMembership()
        • Replaces functionality previously in UserManagement and UserManagementOrganizationMembershipGroups services
      • vault: Add new Vault service for encrypted key-value storage
        • New Vault service with methods: createDataKey(), createDecrypt(), createRekey(), listKv(), createKv(), getName(), getKv(), updateKv(), deleteKv(), listKvMetadata(), and listKvVersions()
        • Support for encrypted object storage and management with key rotation
        • New models: CreateDataKeyResponse, DecryptResponse, ObjectMetadata, ObjectModel, ObjectSummary, ObjectWithoutValue, ObjectVersion, VersionListResponse
        • New enum: VaultOrder for sort direction
        • Accessible via $workos->vault()
      • api_keys: Add expires_at field to API key models and creation methods
        • Added expires_at field to ApiKey, OrganizationApiKey, OrganizationApiKeyWithValue, UserApiKey, UserApiKeyWithValue models
        • Added expires_at field to ApiKeyCreatedData and ApiKeyRevokedData event data models
        • Added optional expiresAt parameter to createOrganizationApiKey() and createUserApiKey() methods
        • Support for setting API key expiration timestamps
      • applications: Update ApplicationCredentialsListItem and NewConnectApplicationSecret field types
        • Changed ApplicationCredentialsListItem.lastUsedAt field type from ?string to ?\DateTimeImmutable
        • Changed NewConnectApplicationSecret.lastUsedAt field type from ?string to ?\DateTimeImmutable
      • pipes: Add connected account event models and related types
        • New models for pipe events: PipeConnectedAccount, PipesConnectedAccountConnected, PipesConnectedAccountDisconnected, PipesConnectedAccountReauthorizationNeeded
        • New enum: PipeConnectedAccountState with values connected and needs_reauthorization
        • Support for monitoring data integration connection status changes
    Open source →
    Release notes

    Miscellaneous Chores

    • deps: update googleapis/release-please-action action to v5 (#389) (f973f21)

    • deps: update shivammathur/setup-php action to v2.37.0 (#388) (f9e113f)

    • use shared workos/renovate-config preset (99aad6c)

    • #392 feat(generated)!: regenerate from spec (10 changes)

      ⚠️ Breaking

      • user_management: Remove organization membership methods from UserManagement service
        • Removed listOrganizationMemberships, createOrganizationMembership, getOrganizationMembership, updateOrganizationMembership, deleteOrganizationMembership, deactivateOrganizationMembership, and reactivateOrganizationMembership methods
        • These methods have been moved to the new OrganizationMembershipService
        • Change to getAuthorizationUrl() parameter screenHint from UserManagementAuthenticationScreenHint to RadarStandaloneAssessRequestAction type
        • Removed UserManagementAuthenticationScreenHint enum
      • user_management: Remove UserManagementOrganizationMembershipGroups service
        • Removed $workos->userManagementOrganizationMembershipGroups() accessor
        • listOrganizationMembershipGroups() has been moved to the new OrganizationMembershipService
      • radar: Remove device fingerprint and bot score from RadarStandaloneAssessRequest
        • Removed deviceFingerprint parameter from Radar.createAttempt() method
        • Removed botScore parameter from Radar.createAttempt() method
        • Removed deviceFingerprint and botScore fields from RadarStandaloneAssessRequest model
        • Removed deprecated enum values from RadarStandaloneAssessRequestAction: Login, Signup, SignUp2, SignUp3, SignIn2, SignIn3
        • Changed enum values in RadarStandaloneAssessRequestAction: SignUp from 'sign up' to 'sign-up', SignIn from 'sign in' to 'sign-in'
        • Removed enum values from RadarStandaloneResponseControl: CredentialStuffing, IpSignUpRateLimit
      • radar: Rename Radar list enums
        • Renamed RadarAction to RadarListAction
        • Renamed RadarType to RadarListType
      • audit_logs: Rename audit log models for consistency
        • Renamed AuditLogActionJson to AuditLogAction
        • Renamed AuditLogExportJson to AuditLogExport
        • Renamed AuditLogExportJsonState to AuditLogExportState
        • Renamed AuditLogSchemaJson to AuditLogSchema
        • Renamed AuditLogSchemaJsonActor to AuditLogSchemaActorInput
        • Renamed AuditLogSchemaJsonTarget to AuditLogSchemaTargetInput
        • Renamed AuditLogsRetentionJson to AuditLogsRetention
        • createSchema() method parameter types changed: AuditLogSchemaActorAuditLogSchemaActorInput, AuditLogSchemaTargetAuditLogSchemaTargetInput
      • webhooks: Rename webhook endpoint models and update status field type
        • Renamed WebhookEndpointJson to WebhookEndpoint
        • Renamed WebhookEndpointJsonStatus to WebhookEndpointStatus
        • Changed UpdateWebhookEndpoint.status field type from WebhookEndpointJsonStatus to WebhookEndpointStatus
        • Updated webhook event enums: added PIPES_CONNECTED_ACCOUNT_CONNECTED, PIPES_CONNECTED_ACCOUNT_DISCONNECTED, PIPES_CONNECTED_ACCOUNT_REAUTHORIZATION_NEEDED events
      • authorization: Update Authorization API with new filters and remove search parameter
        • Added resourceId, resourceExternalId, resourceTypeSlug filter parameters to listRoleAssignments()
        • Added roleSlug filter parameter to listRoleAssignmentsForResourceByExternalId() and listRoleAssignmentsForResource()
        • Removed search parameter from listResources() method
      • vault: Replace hand-maintained WorkOS\Vault class with generated WorkOS\Service\Vault
        • The old WorkOS\Vault class (lib/Vault.php) with client-side encrypt/decrypt helpers has been removed
        • $workos->vault() now returns WorkOS\Service\Vault with a different API surface
        • New generated methods: createDataKey(), createDecrypt(), createRekey(), listKv(), createKv(), getName(), getKv(), updateKv(), deleteKv(), listKvMetadata(), listKvVersions()

      Features

      • organization_membership: Introduce OrganizationMembershipService with membership and group operations
        • New service OrganizationMembershipService with methods: listOrganizationMemberships(), createOrganizationMembership(), getOrganizationMembership(), updateOrganizationMembership(), deleteOrganizationMembership(), deactivateOrganizationMembership(), reactivateOrganizationMembership(), and listOrganizationMembershipGroups()
        • Accessible via $workos->organizationMembership()
        • Replaces functionality previously in UserManagement and UserManagementOrganizationMembershipGroups services
      • vault: Add new Vault service for encrypted key-value storage
        • New Vault service with methods: createDataKey(), createDecrypt(), createRekey(), listKv(), createKv(), getName(), getKv(), updateKv(), deleteKv(), listKvMetadata(), and listKvVersions()
        • Support for encrypted object storage and management with key rotation
        • New models: CreateDataKeyResponse, DecryptResponse, ObjectMetadata, ObjectModel, ObjectSummary, ObjectWithoutValue, ObjectVersion, VersionListResponse
        • New enum: VaultOrder for sort direction
        • Accessible via $workos->vault()
      • api_keys: Add expires_at field to API key models and creation methods
        • Added expires_at field to ApiKey, OrganizationApiKey, OrganizationApiKeyWithValue, UserApiKey, UserApiKeyWithValue models
        • Added expires_at field to ApiKeyCreatedData and ApiKeyRevokedData event data models
        • Added optional expiresAt parameter to createOrganizationApiKey() and createUserApiKey() methods
        • Support for setting API key expiration timestamps
      • applications: Update ApplicationCredentialsListItem and NewConnectApplicationSecret field types
        • Changed ApplicationCredentialsListItem.lastUsedAt field type from ?string to ?\DateTimeImmutable
        • Changed NewConnectApplicationSecret.lastUsedAt field type from ?string to ?\DateTimeImmutable
      • pipes: Add connected account event models and related types
        • New models for pipe events: PipeConnectedAccount, PipesConnectedAccountConnected, PipesConnectedAccountDisconnected, PipesConnectedAccountReauthorizationNeeded
        • New enum: PipeConnectedAccountState with values connected and needs_reauthorization
        • Support for monitoring data integration connection status changes
    Open source →
  11. v6.0.2 11 May 2026
    Release notes

    Bug Fixes

    • harden JWT signature verification and URL path encoding (#386) (aa64119)
    Open source →
  12. v6.0.1 07 May 2026
    Release notes

    Bug Fixes

    • Preserve full error response body on ApiException (#385) (57052ab)

    Miscellaneous Chores

    • release: include v prefix in tags (5517b8b)
    Open source →
  13. 6.0.0 06 May 2026
    Release notes

    ⚠ BREAKING CHANGES

    • user_management: Add user API keys and update ordering enum
    • api_keys: Restructure API key models and rename ordering enum
    • vault: Rename BYOK key provider enum and add vault key deleted event
    • authorization: Rename RoleAssignment to UserRoleAssignment

    Features

    • Add API docs generation and llms.txt index (#382) (ae03f03)
    • api_keys: Restructure API key models and rename ordering enum (1bb2fe4)
    • authorization: Rename EventsOrder to PaginationOrder (1bb2fe4)
    • authorization: Rename RoleAssignment to UserRoleAssignment (1bb2fe4)
    • directory_sync: Add name field to directory users (1bb2fe4)
    • sso: Add full name support to user profiles (1bb2fe4)
    • user_management: Add user API keys and update ordering enum (1bb2fe4)
    • user_management: Add user context to organization memberships (1bb2fe4)
    • vault: Rename BYOK key provider enum and add vault key deleted event (1bb2fe4)

    Bug Fixes

    • ci: install composer deps before building docs (8f439e3)
    • events: Add admin_portal to actor source enum (1bb2fe4)
    Open source →
  14. 5.2.1 28 Apr 2026
    Release notes

    Bug Fixes

    • generated: Add default values to optional object fields (#376) (1597af6)
    Open source →
  15. 5.2.0 27 Apr 2026
    Release notes

    Features

    • Add script/setup for pre-generation dependency installation (edc2543)
    • surface error metadata from API responses (#369) (ece118b)

    Bug Fixes

    • generated: update generated SDK from spec changes (#372) (0ee912a)
    Open source →
  16. 5.1.0 20 Apr 2026
    Release notes

    Features

    • add group, pipes, and authorization additive API support (#367) (c90a5d6)

    Bug Fixes

    • redesign authorization resource targeting and default order handling (b435ced)
    • Remove extractVersion from matchUpdateTypes rules (#365) (f4ad142)
    • type tweaks (780ee85)

    Miscellaneous Chores

    • deps: update minor and patch updates (#361) (7e439f7)
    Open source →
  17. 5.0.3 14 Apr 2026
    Release notes

    Bug Fixes

    • build redirect endpoint URLs locally instead of making HTTP requests (#358) (eae3949)
    • docs: add [@throws](https://github.com/throws) to PHPDoc when appropriate (#360) (ed68872)
    Open source →
  18. 5.0.2 14 Apr 2026
    Release notes

    Bug Fixes

    Miscellaneous Chores

    • mark non-spec service accessors with @oagen-ignore-start/end (#354) (084d0d1)
    Open source →
  19. 5.0.1 13 Apr 2026
    Release notes

    Bug Fixes

    • add default User-Agent header and optional override (#352) (8e202db)
    • one more regen (44906fd)
    Open source →
  20. 5.0.0 13 Apr 2026
    Release notes

    Top-Level Notices

    • v5 is a major SDK redesign centered on an instantiated WorkOS client with service accessors like $workos->sso(), $workos->userManagement(), and $workos->authorization(). Direct use of many legacy top-level service classes and transport internals has been removed or renamed.
    • The minimum runtime is now PHP 8.2. The SDK now depends on guzzlehttp/guzzle:^7, paragonie/halite:^5.1, and ext-curl:^8.2.
    • Responses and resources are now typed, generated models, pagination now uses PaginatedResponse, and named arguments are strongly recommended because many method signatures changed in v5.
    • The v5 release also expands and reorganizes the SDK surface across areas like Authorization, Audit Logs, Feature Flags, Organization Domains, Connect, Events, Pipes, Radar, API Keys, Session Manager, PKCE, Webhooks, and Vault helpers.

    Migration Guide

    • For upgrade steps, renamed APIs, and side-by-side examples for moving from v4 to v5, see V5_MIGRATION_GUIDE.
    Open source →
  21. 4.32.0 09 Mar 2026
    Release notes

    Features

    Bug Fixes

    • listEnvironmentRoles should not use PaginatedResource (#341) (52f0602)
    Open source →
  22. 4.30.1 17 Feb 2026

    Nothing published for this version

  23. 4.30.0 21 Jan 2026

    Nothing published for this version

  24. v4.29.0 03 Dec 2025

    Nothing published for this version

  25. v4.28.0 21 Nov 2025

    Nothing published for this version

  26. v4.27.0 24 Sep 2025

    Nothing published for this version

  27. v4.26.0 23 Jun 2025

    Nothing published for this version

  28. v4.25.0 17 Jun 2025

    Nothing published for this version

  29. v4.24.0 22 May 2025

    Nothing published for this version

  30. v4.23.0 25 Apr 2025

    Nothing published for this version

  31. v4.22.0 21 Mar 2025

    Nothing published for this version

  32. v4.21.0 14 Mar 2025

    Nothing published for this version

  33. v4.20.0 21 Feb 2025

    Nothing published for this version

  34. v4.19.0 20 Feb 2025

    Nothing published for this version

  35. v4.18.0 14 Jan 2025

    Nothing published for this version

  36. v4.17.0 27 Dec 2024

    Nothing published for this version

  37. v4.16.0 06 Dec 2024

    Nothing published for this version

  38. v4.15.0 15 Nov 2024

    Nothing published for this version

  39. v4.14.0 21 Oct 2024

    Nothing published for this version

  40. v4.13.0 07 Aug 2024

    Nothing published for this version

  41. v4.12.0 16 Jul 2024

    Nothing published for this version

  42. v4.11.1 11 Jul 2024

    Nothing published for this version

  43. v4.11.0 24 Jun 2024

    Nothing published for this version

  44. v4.10.0 04 Jun 2024

    Nothing published for this version

  45. v4.9.0 24 May 2024

    Nothing published for this version

  46. v4.8.1 22 May 2024

    Nothing published for this version

  47. v4.8.0 17 May 2024

    Nothing published for this version

  48. v4.7.0 14 May 2024

    Nothing published for this version

  49. v4.6.0 03 May 2024

    Nothing published for this version

  50. v4.5.0 02 May 2024

    Nothing published for this version

  51. v4.4.0 09 Apr 2024

    Nothing published for this version

  52. v4.3.0 20 Mar 2024

    Nothing published for this version

  53. v4.2.0 07 Feb 2024

    Nothing published for this version

  54. v4.1.0 14 Dec 2023

    Nothing published for this version

  55. v4.0.0 22 Nov 2023

    Nothing published for this version

  56. v3.4.0 20 Sep 2023

    Nothing published for this version

  57. v3.3.0 04 May 2023

    Nothing published for this version

  58. v3.2.0 13 Apr 2023

    Nothing published for this version

  59. v3.1.1 30 Mar 2023

    Nothing published for this version

  60. v3.1.0 07 Mar 2023

    Nothing published for this version

Every package, every release, already written down.

The archive is open and free. Watching your own project is what we are building next.

Browse the archive