Last release 2 days ago
25 Aug 2026
Ships on a steady schedule
a new release about every 8 days
Rarely documented
notes for 2 of 50 stable releases
Nothing withdrawn
no release was ever pulled
1 years old
459 releases ยท first in 2025
Release timeline
459 releases since 2025Releases
- v1.0.0-beta2.0.20260810120915-ba37ccd8c63110 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta2.0.20260810095229-2d1df9d2c57a10 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta2.0.20260810064043-b3736ff51c1f10 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta2.0.20260810052126-628754e317c010 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta2.0.20260809174324-efc9ddf950ab9 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta2.0.20260809104425-f5c1f701166e9 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta2.0.20260808070026-d7796d2467c08 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta2.0.20260807200356-8aecefbac5dd7 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta27 Aug 2026pre-release
Release notes
Open source โThunderID is a lightweight, open-source IAM stack built to secure access for humans, AI agents, and machines.
Designed for the agentic era, ThunderID provides a developer-first IAM stack and supporting tools for securing applications, APIs, services, and agent-driven workflows. It works across traditional and decentralized identity ecosystems, with post-quantum-ready security built in from the start.
Core design goals of ThunderID include:
- Agent-native identity: Manage AI agents as first-class identities with delegated authority, consent-aware access, traceability, and support for issuing verifiable credentials to agents. ThunderID also aims to expose IAM capabilities through interfaces that agents can use safely and programmatically.
- Post-quantum-safe by design: Build on a crypto-agile foundation where algorithms, key types, signing methods, and token protection mechanisms can evolve over time, including support for post-quantum-safe algorithms and hybrid transition approaches across key management, credential issuance, assertions, and secure service-to-service communication.
- Decentralized identity: Bridge the adoption gap for relying parties by making it practical for service providers to consume, verify, and trust decentralized identity in real-world applications, including DIDs, verifiable credentials, digital wallets, trust registries, and issuer-verifier-holder interaction models.
- Lightweight runtime with GitOps support: Provide a lightweight, containerized runtime that can run across on-premises and cloud environments, with declarative identity flows, policies, and configuration suitable for automation, versioning, and GitOps practices.
Getting Started
Get started by exploring how ThunderID can be used to secure:
- Applications - by following Securing B2C Application Guide
- AI Agents - by following Securing AI Agents Guide
- MCP - by following Securing MCP Guide
To learn more about overall requirements, solution patterns of these scenarios, refer to the Use Cases section.
Visit Get ThunderID to learn more about installation methods.
What's Changed
โจ Improvements
- Introduce CSP baseline with file based config by @Osara-B in #4523
- Introduce support to add custom SMS providers by @NipuniBhagya in #4537
- Enable Docusaurus docs and API versioning by @himeshsiriwardana in #4558
- Add support for tracking unsaved changes in token settings by @NipuniBhagya in #4577
- Add overview tab to Applications by @brionmario in #4490
- Add an Overview tab Agents by @brionmario in #4598
- Restructure B2C use-case docs into a problem-to-implementation funnel by @himeshsiriwardana in #4395
- Validate duplicate application names early in the console creation wizard by @pasindubalasooriya in #3924
- Added runtimeCryptoProvider option method by @anushasunkada in #4603
- Offer the default resource server from the wizard and the list by @ImalshaD in #4635
- Add criteria-based revocation administration flows by @indeewari in #4591
- Add agent type export support by @sahandilshan in #4630
- Add per request CSP nonces for script and style src by @Osara-B in #4632
- Bump google.golang.org/grpc from 1.82.0 to 1.82.1 in /backend by @dependabot[bot] in #4664
- Fix UI consistency issues by @brionmario in #4648
- Run console user deletion through a configurable administration flow by @indeewari in #4669
- Add usages endpoints for SMS gateway, Twilio, and Vonage connections by @NipuniBhagya in #4656
- Add nested groups support to the group members UI by @ZiyamSanthosh in #4681
- Introduce user group assignment policies by @ZiyamSanthosh in #4496
- Restrict OpenID4VCI credential issuance to wallet applications by @thiva-k in #4676
- Replace default sign out flow with conditional confirmation by @ZiyamSanthosh in #4628
- Improve OIDC scope-claim mapping and console token UI by @thiva-k in #4631
- Update OC resources and docs by @ayeshajay in #4641
๐ Bug Fixes
- Recover the gate sign-in page from an expired flow execution by @PasinduYeshan in #4492
- Update Nuxt application template to default
tokenEndpointAuthMethodtoclient_secret_basicby @janithjay in #4573 - Remove the Allow Cross OU provisioning property from federated Executors by @ImalshaD in #4583
- Replace Wayfinder sample SQLite storage with in-memory data by @PasinduYeshan in #4586
- Extend authorization request and auth flow expiry to 60 minutes by @PasinduYeshan in #4539
- Fix the DSN string of SQLite to use modernc pragma syntax so busy_timeout applies by @Sadeesha-Sath in #4536
- Match resource_type only as a plain key when importing sample resources by @PasinduYeshan in #4593
- Conformance Bug Fix: Token endpoint returns unauthorized_client (should be invalid_client/invalid_request) by @KashiwalHarsh in #4482
- Default permission consent toggles to unselected. by @ImalshaD in #4619
- Polish visual issues on the Console Home Page by @brionmario in #4617
- Provide seamless login for OIDC/github connections by defualt. by @ImalshaD in #4543
- Fix attribute library property names and drop phone_number from the default Person schema by @PasinduYeshan in #4615
- Replace automatic Google Font fetching with explicit font import by @Osara-B in #4614
- Fix deployment.yaml override of bool config fields defaulting to true by @rajithacharith in #4602
- Fix cursor positioning in the Import Configuration environment variable editor by @rajithacharith in #4601
- Fix OAuth error propagation by @ThumulaPerera in #4604
- Fix b2c try it out for staff onboarding by @ThaminduDilshan in #4650
- Fix rich-text link wiring in the flow builder by @PasinduYeshan in #4636
- Change Wayfinder Registration Flows to AutoLogin by @Sadeesha-Sath in #4638
- Allow declarative flows to be opened from the flow listing. by @ImalshaD in #4668
- Show Magic Link as an alternative first factor in generated flows by @PasinduYeshan in #4670
- Route registration credential failures back to the credentials prompt by @Dilusha-Madushan in #4674
- Allow translation writes in composite and mutable store modes by @rajithacharith in #4655
- Complete a timed out consent prompt without recording it. by @ImalshaD in #4653
- Add replay protection to private_key_jwt client assertions by @thiva-k in #4673
- Add deny list of credentials accepted by creds auth service by @ThumulaPerera in #4666
- Fix resending OTP in SMS and EmailOTP flows by @ZiyamSanthosh in #4651
- Align React SDK sample URLs with HTTP by @ImalshaD in #4682
- Remove unused callbackType property from auth_assert nodes by @ThumulaPerera in #4684
- Add support for ID-JAG authorization grant profile in OIDC metadata by @sajitha-tj in #4677
- Restore executor-declared outcome handles when loading a flow by @PasinduYeshan in #4675
- Fix CIBA Page rendering by @Thumimku in #4665
- Remove app authorization filtering from token exchange by @ImalshaD in #4687
New Contributors
- @NipuniBhagya made their first contribution in #4537
- @pasindubalasooriya made their first contribution in #3924
- @sajitha-tj made their first contribution in #4677
Full Changelog: v1.0.0-beta...v1.0.0-beta2
License
Licenses this source under the Apache License, Version 2.0 (LICENSE), You may not use this file except in compliance with the License.
- v1.0.0-beta.0.20260807144136-b0ae6ff7418a7 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta.0.20260807133216-aa2d481f53617 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta.0.20260807122843-ee04122c50267 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta.0.20260807104458-057f70c335517 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta.0.20260807083324-a98a7fd5841e7 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta.0.20260807064216-7a16a1ed8bb67 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta.0.20260807054113-827f2c987c8b7 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta.0.20260807043737-06403f1af9597 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta.0.20260807025833-d02097a2af1d7 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta.0.20260806125307-59e2f881fb656 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta.0.20260806110954-5e7daefabfbb6 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta.0.20260806092328-a1f8e0256e366 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta.0.20260806084137-a4311a0fa89b6 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta.0.20260806051301-7425160d38cb6 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta.0.20260806034149-d5b052d00dd36 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta.0.20260805172455-2a9a1c611eea5 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta.0.20260805142109-798b83d2ea2b5 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta.0.20260805120703-d80cadcbd4cd5 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta.0.20260805102930-f0262ee0731d5 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta.0.20260805091137-69f44e12fe1f5 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta.0.20260805055842-27ccd1788efa5 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta.0.20260805033248-a8a6ba61bacd5 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta.0.20260804180628-1545fa3f36e84 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta.0.20260804144540-02b7bb7a59c14 Aug 2026pre-release
Nothing published for this version
- v1.0.0-beta4 Aug 2026pre-release
Release notes
Open source โThunderID is a lightweight, open-source Identity and Access Management (IAM) engine built to secure access for humans, AI agents, and machines.
Designed for the agentic era, ThunderID provides a developer-first IAM platform and supporting tools for securing applications, APIs, services, and agent-driven workflows. It works across traditional and decentralized identity ecosystems, with post-quantum-ready security built in from the start.
Core design goals of ThunderID include:
- Agent-native identity: Manage AI agents as first-class identities with delegated authority, consent-aware access, traceability, and support for issuing verifiable credentials to agents. ThunderID also aims to expose IAM capabilities through interfaces that agents can use safely and programmatically.
- Decentralized identity: Bridge the adoption gap for relying parties by making it practical for service providers to consume, verify, and trust decentralized identity in real-world applications, including DIDs, verifiable credentials, digital wallets, trust registries, and issuer-verifier-holder interaction models.
- Cloud-native IAM: Provide a lightweight, containerized identity product that can run across on-premises and cloud environments, with declarative identity flows, policies, and configuration suitable for automation, versioning, and GitOps practices.
- Post-quantum-safe security: Build on a crypto-agile foundation where algorithms, key types, signing methods, and token protection mechanisms can evolve over time, including support for post-quantum-safe algorithms and hybrid transition approaches across key management, credential issuance, assertions, and secure service-to-service communication.
Getting Started
Get started by exploring how ThunderID can be used to secure:
- Applications - by following Securing B2C Application Guide
- AI Agents - by following Securing AI Agents Guide
- MCP - by following Securing MCP Guide
To learn more about overall requirements, solution patterns of these scenarios, refer to the Use Cases section.
Visit Get ThunderID to learn more about installation methods.
What's Changed
โ ๏ธ Breaking Changes
- Remove exporting a zip file by @rajithacharith in #4443
โจ Improvements
- Support grid layouts in the STACK flow element by @DonOmalVindula in #4365
- Consolidate login-flow into the flows feature and flatten flow routes by @DonOmalVindula in #4398
- Add optional logo URL to agents with console fallback by @Dilusha-Madushan in #4390
- Resolve patch coverage from Codecov first and name the source of every verdict by @DonOmalVindula in #4397
- Seed @thunderid/configure-verifiable-presentations by @DonOmalVindula in #4404
- Scope the E2E dependency install to the E2E package by @DonOmalVindula in #4421
- Run only the Chromium E2E projects on pull requests by @DonOmalVindula in #4429
- Stop the pnpm store and Turbo caches from freezing at their first write by @DonOmalVindula in #4427
- Fix laggy typing in flow builder executor property fields by @DonOmalVindula in #4422
- Add mcp application type for MCP client applications by @Malith-19 in #4399
- Revamp application creation flow by @brionmario in #4415
- Update token endpoint auth method in frontend by @thiva-k in #4430
- Throttle SSO session activity touch to cut write load by @madurangasiriwardena in #4257
- Forward the SSO-Check node's session and checkpoint reads to the Session node by @madurangasiriwardena in #4401
- End the SSO session when signing out of the samples by @madurangasiriwardena in #4433
- Seed @thunderid/configure-applications by @DonOmalVindula in #4445
- Fixes current implemented E2E tests including MFA login by @Sadeesha-Sath in #4317
- Add a compact view mode to the flow builder canvas by @DonOmalVindula in #4450
- Sign out without a confirmation prompt by @madurangasiriwardena in #4455
- Turn the button Type selector into an Action selector with a sign-out option by @DonOmalVindula in #4456
- Flag sign-out buttons that do not lead to the session sign-out step by @DonOmalVindula in #4460
- Keep the flow builder canvas still when a node is deleted by @DonOmalVindula in #4470
- Improve the flow builder validation notifications panel design by @DonOmalVindula in #4471
- Add '/users/me/meta' endpoint to retrieve user's schema metadata by @janithjay in #4117
- Measure frontend package coverage in CI by @DonOmalVindula in #4467
- Make Organization Picker & Random name picker consistent by @brionmario in #4444
- Round-trip the prompt action type through the flow builder by @madurangasiriwardena in #4481
- Moved RuntimeCryptoProvider interface to pkg/thunderidengine by @anushasunkada in #4463
- Signal sign-out confirmation with the prompt action type by @madurangasiriwardena in #4480
- Remove dead SCSS and unused validation indicator from flow builder by @DonOmalVindula in #4488
- In-app documentation links support by @brionmario in #4252
- Add dev mode flag for mobile app attestation by @Malith-19 in #4434
- Replace flow builder SCSS with theme-driven styled components by @DonOmalVindula in #4489
- Support OAuth token subject mapping by @ThumulaPerera in #4419
- Replace nested token tabs with an audience selector by @Dilusha-Madushan in #4479
- Rewrite vanilla sample as a Next.js backend-for-frontend app by @Malith-19 in #4418
- Use attributes consistently in token settings by @Dilusha-Madushan in #4533
- Added new classifier methods on jweService by @anushasunkada in #4495
๐ Bug Fixes
- Allow editing entities after schema tightening by filtering undeclared attributes by @PasinduYeshan in #4253
- [Bug-fix] Improve i18n for input error messages by @NutharaNR in #4266
- Fix home page add button by @jeradrutnam in #4411
- Add Backend Validations for Applications PUT by @Sadeesha-Sath in #4157
- Change Rollback changes labels to 'Reset' by @Sadeesha-Sath in #4249
- Fix missing attestation mapping in declarative app parser by @Malith-19 in #4375
- Strip undeclared user attributes on inbound client update by @PasinduYeshan in #4358
- Improve signing/encryption related token configurations by @thiva-k in #4423
- Validate access token typ header in token exchange grant by @thiva-k in #4437
- Add support to encrypt attribute cache by @ThumulaPerera in #4436
- Fix Reset Bahaviour on All Edit Pages by @Sadeesha-Sath in #4162
- Conformance Bug Fix : Token endpoint returns invalid_request (should be invalid_grant) by @KashiwalHarsh in #4439
- Disable PAR for non-authorization code grant types in console by @thiva-k in #4438
- Remove theme and layout foreign keys from inbound client by @rajithacharith in #4532
- Fix adding users when deployed as federated login to console by @rajithacharith in #4527
- Wire rich text links nested inside flow blocks by @PasinduYeshan in #4550
- Include ID-token-only scope claims in issued ID tokens for code and CIBA flows by @thiva-k in #4554
- Make jwt assertion aud validated as string by @thiva-k in #4544
New Contributors
- @KashiwalHarsh made their first contribution in #4439
- @janithjay made their first contribution in #4117
Full Changelog: v1.0.0-alpha2...v1.0.0-beta
License
Licenses this source under the Apache License, Version 2.0 (LICENSE), You may not use this file except in compliance with the License.
- v1.0.0-alpha2.0.20260804113520-8c8ae0cfa31f4 Aug 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260804095218-9f0f14edb1bb4 Aug 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260804074033-9fe394b181f44 Aug 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260803145527-952ca086f33e3 Aug 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260803124546-7dcfbbba321e3 Aug 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260803122246-a8b2b45513763 Aug 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260803111050-b876cd06cfde3 Aug 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260803092059-a2a4aee0e67c3 Aug 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260803075859-12378cd111733 Aug 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260803061941-7d9bc8f593a43 Aug 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260803043301-a3e93503cdc53 Aug 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260803021835-0d5a00852cc83 Aug 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260802162117-0ed00bb92bf02 Aug 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260802123920-ab6b67c828902 Aug 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260802095559-dd1dcfca4b102 Aug 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260801141906-1b65c96c79121 Aug 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260801093054-44eca277366c1 Aug 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260731141818-630ad905d0fd31 Jul 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260731131035-4a8a72492e6631 Jul 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260731113345-6a8313069f5831 Jul 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260731095648-1533aea75e7e31 Jul 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260731092015-bcaf3aec331731 Jul 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260731074726-8f80ac92e64631 Jul 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260731044647-97229ac1f3fb31 Jul 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260730201558-7fe984186bc230 Jul 2026pre-release
Nothing published for this version
- v1.0.0-alpha2.0.20260730174141-f537e2704ac930 Jul 2026pre-release
Nothing published for this version