NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #245 by repository stars
Last release 2 months ago
29 Jul 2026
Ships on a steady schedule
a new release about every 9 days
Nearly every release is documented
notes for 10 of 10 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
2821 releases · first in 2019
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Ory Kratos v1.2 is the most complete, scalable, and secure open-source identity server available. We are thrilled to announce its release!
Ory Kratos v1.2 is the most complete, scalable, and secure open-source identity server available. We are thrilled to announce its release!
This release introduces two major features: two-step registration and full PassKey with resident key support.
Passkeys provide a secure and convenient authentication method, eliminating the need for passwords while ensuring strong security. With this release, we have added support for resident keys, enabling offline authentication. Credential discovery allows users to link existing passkeys to their Ory account seamlessly.
passkeys.webmTwo-step registration improves the user experience by dividing the registration process into two steps. Users first enter their identity traits, and then choose a credential method for authentication, resulting in a streamlined process. This feature is especially useful when enabling multiple authentication strategies, as it eliminates the need to repeat identity traits for each strategy.
The 107 commits since v1.1 include several improvements:
Two-Step Registration Enabled by Default: This is now the default setting. To disable, set selfservice.flows.registration.enable_legacy_one_step to true.
return_to parameter is now respected in OIDC API flows.verification and verification_ui hooks are now available in the login flow.We are doing this survey to find out how we can support self-hosted Ory users better. We strive to provide you with the best product and service possible and your feedback will help us understand what we're doing well and where we can improve to better meet your needs. We truly value your opinion and thank you in advance for taking the time to share your thoughts with us!
Fill out the survey now!
This feature enables two-step registration per default. Two-step registration is a significantly improved sign up flow and recommended when using more than one sign up methods. To disable two-step registration, set selfservice.flows.registration.enable_legacy_one_step to true. This value defaults to false.
Add login succeeded event to post registration hook (#3739) (b685fa5)
Add missing env vars to set up guide (#3855) (da90502):
Closes #3828
Add missing indexes and remove unused index (6d7372e)
Add missing indexes and remove unused index (#3756) (c905f02)
Allow updating just the verified_at timestamp of addresses (#3880) (696cc1b)
Always issue session last (#3876) (e942507):
In post persist hooks, the session issuance hook always needs
to come last. This fixes the getHooks function to ensure this.
Db index and duplicate credentials error (#3896) (9f34a21):
Do not require method to be passkey in settings schema (#3862) (660f330)
Execute verification & verification_ui properly in login flows (#3847) (5aad1c1)
Ignore decrypt errors in WithDeclassifiedCredentials (#3731) (8f5192f)
Include all creds in duplicate credential err (#3881) (e06c241)
Make sure emails can still be sent with SMS enabled (#3795) (7c68c5a)
oidc: Grace period for continuity container on oidc callbacks (#3915) (1a9a096)
Respect return_to in OIDC API flow error case (#3893) (e8f1bcb):
This fix ensures that we redirect the user to the return_to URL
when an error occurs during the OIDC login for native flows.
Native flows are initialized through the API, and the browser
URL is retrieved from a 422 response after a POST to submit the
login flow. Successful OIDC flows already returned the code to
the return_to URL. Now, unsuccessful flows return the flow with
the current flow ID (which might have changed), so that the caller
can retrieve the full flow and act accordingly.
Bump in distroless is still open
sdk: Expand identity in session extension (#3843) (04f0231), closes #3842
sdk: Improve discriminators for node and Go (#3821) (9ddf7cc)
Test assertions on declassifying OIDC tokens (#3773) (7f8a7f1)
Tolerate more "truthy" values when creating new flows (#3841) (49d93c0), closes #3839:
Use strconv.ParseBool to accept multiple "truthy" values for the
refresh and return_session_token_exchange_code query parameters when
creating a new login flow.
For some SDKs (e.g.: Python), these stringification of booleans is not
user-controlled and these endpoints could not be used fully due to the
backend ignoring any value other than true (all lowercase).
Use correct post-verification identity state in post-hooks (#3863) (6e63d06)
Webhook transient payload in OIDC login flows (#3857) (2cdfc70):
Add include_credential query param to /admin/identities list call (#3343) (d94530a)
Allow admin to create API code recovery flows (#3939) (25d1ecd)
Linkedin v2 provider (#3804) (a6ad983):
feat: add linkedin-v2 provider
docs: document linkedin special-case
PassKeys with Resident Keys and two-step registration (#3748) (3621411)
Use authenticate endpoint for x (#3833) (3d9ba5d):
Improves the "Log in with X" experience by not asking the user to re-authenticate every time.
Resolve flaky e2e tests (#3935) (a14927d):
test: resolve flaky code registration tests
chore: don't fail logout if cookie is not found
chore: remove .only
chore: reduce wait
chore: u
chore: u
chore: u
include_credential query param to /admin/identities list call (#3343)Note truncated.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →