NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #681 by repository stars
Last release 10 months ago
20 Nov 2025
Ships fairly regularly
a new release about every 5 weeks
Nearly every release is documented
notes for 58 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
1103 releases · first in 2015
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
feat: new factory with default issuer for JWT tokens
Nothing published for this version
Nothing published for this version
Nothing published for this version
feat: added support for ES256 token strategy and client authentication
feat: added support for ES256 token strategy and client authentication (#439)
I added to DefaultOpenIDConnectClient a field TokenEndpointAuthSigningAlgorithm to be able to configure what GetTokenEndpointAuthSigningAlgorithm returns. I also cleaned some other places where there were assumptions about only RSA keys.
Closes #429
arguments: Fixes a logic bug in MatchesExact and adds documentation (#433) (10fd67b):
Double-decoding of client credentials in request body (#434) (48c9b41):
I noticed that client credentials are URL-decoded after being extracted from the POST body form, which was already URL-decoded by Go. The accompanying error message suggests this was copied and pasted from the HTTP basic authorization header handling, which is the only place where the extra URL-decoding was needed (as per the OAuth 2.0 spec). The result is that client credentials containing %-prefixed sequences, whether valid sequences or not, are going to fail validation.
Remove the extra URL decoding. Add tests that ensure client credentials work with special characters in both the HTTP basic auth header and in the request body.
Added support for ES256 token strategy and client authentication (#439) (36eb661), closes #429:
I added to DefaultOpenIDConnectClient a field TokenEndpointAuthSigningAlgorithm to be able to configure what GetTokenEndpointAuthSigningAlgorithm returns. I also cleaned some other places where there were assumptions about only RSA keys.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
feat(pkce): add EnforcePKCEForPublicClients config flag
feat(pkce): add EnforcePKCEForPublicClients config flag (#431)
Alternative proposal for the issue discussed in #389 and #391, where enforcement of PKCE is wanted only for certain clients.
Add a new flag EnforcePKCEForPublicClients which enforces PKCE only for public clients. The error hint is slightly different, as it mentions PKCE is enforced for "this client" rather than "clients". (It intentionally does not mention why it's enforced, as I think basing it on public clients is an implementation detail that servers may want to change without adding to the error hints).
Closes #389 Closes #391
Nothing published for this version
fix: introduce better linting pipeline and resolve Go issues
Nothing published for this version
fix: return invalid_grant instead of invalid_request in refresh flow
fix: return invalid_grant instead of invalid_request in refresh flow (#427)
Return invalid_grant instead of invalid_request when in authorization code flow when the user is not the owner of the authorization code or if the redirect uri doesn't match from the authorization request.
Co-authored-by: Damien Bravin damienbr@users.noreply.github.com
List all response types in example memory store (#413) (427d40d), closes #304
Return invalid_grant instead of invalid_request in refresh flow (#427) (f5a0e96):
Return invalid_grant instead of invalid_request when in authorization code flow when the user is not the owner of the authorization code or if the redirect uri doesn't match from the authorization request.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Merge pull request from GHSA-v3q9-2p3m-7g43
Merge pull request from GHSA-v3q9-2p3m-7g43
u
u
Merge pull request from GHSA-v3q9-2p3m-7g43 (0c9e0f6):
u
u
fix: handle serialization errors that can be thrown by call to 'Commit'
Nothing published for this version
fix: handle concurrent transactional errors in the refresh token grant handler
fix: handle concurrent transactional errors in the refresh token grant handler (#402)
This commit provides the functionality required to address https://github.com/ory/hydra/issues/1719 & https://github.com/ory/hydra/issues/1735 by adding error checking to the RefreshTokenGrantHandler's PopulateTokenEndpointResponse method so it can deal with errors due to concurrent access. This will allow the authorization server to render a better error to the user-agent.
No longer returns fosite.ErrServerError in the event the storage. Instead a wrapped fosite.ErrNotFound is returned when fetching the refresh token fails due to it no longer being present. This scenario is caused when the user sends two or more request to refresh using the same token and one request gets into the handler just after the prior request finished and successfully committed its transaction.
Adds unit test coverage for transaction error handling logic added to the RefreshTokenGrantHandler's PopulateTokenEndpointResponse method
Handle concurrent transactional errors in the refresh token grant handler (#402) (b17190b):
This commit provides the functionality required to address https://github.com/ory/hydra/issues/1719 & https://github.com/ory/hydra/issues/1735 by adding error checking to the RefreshTokenGrantHandler's PopulateTokenEndpointResponse method so it can deal with errors due to concurrent access. This will allow the authorization server to render a better error to the user-agent.
No longer returns fosite.ErrServerError in the event the storage. Instead a wrapped fosite.ErrNotFound is returned when fetching the refresh token fails due to it no longer being present. This scenario is caused when the user sends two or more request to refresh using the same token and one request gets into the handler just after the prior request finished and successfully committed its transaction.
Adds unit test coverage for transaction error handling logic added to the RefreshTokenGrantHandler's PopulateTokenEndpointResponse method
fix: add ability to specify amr values natively in id_token payload
fix: add ability to specify amr values natively in id_token payload (#401)
See ory/hydra#1756
Old .Exact() remains for compatibility and marked as deprecated
fix: Support RFC8252#section-7.3 Loopback Interface Redirection (#400)
Closes #284
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Return state parameter in authorization error conditions
Return state parameter in authorization error conditions (#388)
Related to ory/hydra#1642
Nothing published for this version
Nothing published for this version
pkce: Enforce verifier formatting
handler/pkce: Enable PKCE for private clients
handler/pkce: Enable PKCE for private clients (#382)
Nothing published for this version
Nothing published for this version
handler/revoke: respecting ErrInvalidRequest code
handler/revoke: respecting ErrInvalidRequest code (#380)
This commit modifies the case for ErrInvalidRequest in WriteRevocationResponse to respect the 400 error code and not fallthrough to ErrInvalidClient.
Author: DefinitelyNotAGoat baldrich@protonmail.com
handler/revoke: respecting ErrInvalidRequest code (#380) (cc34bfb), closes #380:
This commit modifies the case for ErrInvalidRequest in WriteRevocationResponse to respect the 400 error code and not fallthrough to ErrInvalidClient.
Author: DefinitelyNotAGoat baldrich@protonmail.com
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →