NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #245 by repository stars
Last release 2 months ago
29 Jul 2026
Ships on a steady schedule
a new release about every 9 days
Nearly every release is documented
notes for 10 of 10 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
2821 releases · first in 2019
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
7ae1271 chore: ignore CVE-2023-4806
Ory Kratos v1.1 is the most complete, most scalable, and most secure open-source identity server on the planet, and we are thrilled to announce its release! This release comes with over 270 commits and an incredible amount of new features and capabilities!
Don't forget to leave a GitHub star and check out our other open source projects while you're here :)
Note: To ensure a seamless upgrade experience with minimal impact, some of these features are gated behind the feature_flags config parameter, allowing controlled deployment and testing.
return_to parameter set in the API call.The following features have been shipped exclusively to Ory Network for this version:
strong, eventual).Ory Kratos 1.1 is a major release that marks a significant milestone in our journey.
We sincerely hope that you find these new features and improvements in Ory Kratos 1.1 valuable for your projects. To experience the power of the latest release, we encourage you to get the latest version of Ory Kratos here or leverage Ory Kratos in Ory Network — the easiest, simplest, and most cost-effective way to run Ory.
For organizations seeking to upgrade their self-hosted solution, Ory offers enterprise support services to ensure a smooth transition. Our team is ready to assist you throughout the migration process, ensuring uninterrupted access to the latest features and improvements. Additionally, we provide various support plans specifically tailored for self-hosting organizations. These plans offer comprehensive assistance and guidance to optimize your Ory deployments and meet your unique requirements.
We extend our heartfelt gratitude to the vibrant and supportive Ory Community. Without your constant support, feedback, and contributions, reaching this significant milestone would not have been possible. As we continue on this journey, your feedback and suggestions are invaluable to us. Together, we are shaping the future of identity management and authentication in the digital landscape.
Contributors to this release in no particular order: moose115, K3das, sidartha, efesler, BrandonNoad ,Saancreed, jpogorzelski, dreksx, martinloesethjensen, cpoyatos1, misamu, tristankenney, nxy7, anhnmt
Are you passionate about security and want to make a meaningful impact in one of the biggest open-source communities? Join the Ory community and become a part of the new ID stack. Together, we are building the next generation of IAM solutions that empower organizations and individuals to secure their identities effectively.
Want to check out Ory Kratos yourself? Use these commands to get your Ory Kratos project running on the Ory Network:
brew install ory/tap/cli
scoop bucket add ory <https://github.com/ory/scoop.git>
scoop install ory
bash <(curl <https://raw.githubusercontent.com/ory/meta/master/install.sh>) -b . ory
sudo mv ./ory /usr/local/bin/
ory auth login
ory create project --name "My first Kratos project"
ory open account-experience registration
ory patch identity-config \
--replace '/identity/default_schema_id="preset://username"' \
--replace '/identity/schemas=[{"id":"preset://username","url":"preset://username"}]' \
--format yaml
ory open account-experience registration
Pagination parameters for the list identities CLI command have changed from arguments to flags --page-token and page-size:
- kratos list identities 1 100
+ kratos list identities --page-size 100 --page-token ...
Furthermore, the JSON / JSON pretty output of list identities has changed:
-[
- { "id": "..." },
- { /* ... */ },
- // ...
-]
+{
+ "identities": [
+ {"id": "..."},
+ { /* ... */ },
+ // ...
+ ],
+ "next_page_token": "..."
+}Closes ory/sdk#284
Closes #3480
oidc does not require a method in the payload (#3564) (b299abc):
fix: oidc does not require a method in the payload
refactor: only update strategies order in test
chore: update audit messages and comments
Accept all 200 responses as OK in courier (#3401) (88237e2), closes #3399:
Accept login_challenge after verification (#3427) (6b02350):
Part of ory/network#320
Add caching to Jsonnet snippet during session JWT tokenization (#3699) (1da8180)
Add missing tracing & attributes in oidc strategy (#3429) (09bcb71)
Add return_to parameter to API spec of createRecoveryLinkForIdentity (#3711) (757a5e4)
Add value code to authentication method enum (#3546) (95dc7a2):
fix: add value code to authentication method enum
chore: generate sdk
Additional_id_token_audiences key in config schema (#3622) (9396bb0)
Adjust tracing verbosity (976cd0d)
Allow post recovery hooks to interrupt the flow (#3393) (6c1d2f1)
Allow updating admin metadata from webhook responses (#3569) (22f61f0)
Always return relative URLs in the Link header for pagination (fb229c9)
Auto migrate old accounts to use code credential (#3581) (569b14a)
Carry oauth2_login_challenge over to registration flow (#3419) (76241be):
Fixes #3321
Change ListIdentities to keyset pagination (e16fed1)
Change shebangs and makefile from /bin/bash to /usr/bin/env bash (#3597) (1343bbb):
makefile fix
shebangs changed to /usr/bin/env bash
Signed-off-by: nxy7 lolnoxy@gmail.com
Check whoami aal before accepting hydra login request (#3669) (a2f79c3)
Consider OIDC registration flows errored with duplicate credential to be completed by strategy (#3525) (3e3c789):
Returning anything else here may cause Kratos to respond with two concatenated JSON objects: new login flow with actual error message as the first one and a very confusing '500, aborted registration hook execution' as the second one.
Csrf token regenerate on browser flows (#3706) (e4908db), closes #3705
Data race in test (ab6dc31)
Do not encode full config in multiple places (#3500) (57a3273)
Do not initialize parts of the registry in parallel (#3534) (ff177db)
Don't require code credential for MFA flows (#3753) (40ed809)
Don't require session for OIDC verification (#3443) (e08f831)
Don't return 500 on conflict for POST /admin/identities (#3437) (1429949)
Don't return nil if code is invalid (#3662) (df8ec2b):
fix: don't return nil if code is invalid
chore: add test
Error handling on identity import (#3520) (83bfb2d):
When importing identities without any traits, or with malformed traits, 500s are returned. This improves the error handling and messaging.
False-positives for requiring re-authentication on update (#3421) (ce8139f)
Http courier using should use lower case json (#3740) (84149c4)
Identity list pagination in CLI command and SDK (#3482) (1e8b1ae):
Adds correct pagination parameters to the SDK methods for listing identities and sessions.
Ignore CSRF middleware on Apple OIDC callback (309c506)
Improved SSRF protection (#3629) (6d08576):
This also improves tracing in the OIDC strategy.
Incorrect swagger spec for filter parameter (#3684) (2c1470a), closes #3676 #3675
Increase connection-level timeouts and shutdown timeouts (#3570) (200b413):
The admin API is generally expected to require longer timeouts, for example during bulk identity import.
Issue session after verification after registration with OIDC SSO (#3467) (a28b523)
Lint (e8740c3)
Lower-case recovery & verification emails on import (#3571) (e2ac9ff):
Emails that contained upper-case characters would be overwritten by the identity schema extension runner, because there all emails are lower-cased.
Mark identity as optional in session struct (#3463) (7ae02ba), closes #3461:
The identity is not always available in the session struct, for example when AAL2 is required.
Omit irrelevant OIDC providers in forced refresh login flows (#3608) (912dccd):
Whenever an user is asked to reauthenticate (e.g. because they wish to execute settings flow touching their credentials and their session is no longer privileged) they are asked to provide their credentials again. The forced-refresh login flow generated for such cases already excludes some strategies that are enabled in Kratos but cannot be used to authenticate as current identity, and for example the form presented to the user will not have a password field if the identity does not have a password credential.
This, however, does not currently apply to OIDC providers; the user will always see the full set even if some of them can't be used to sign in as current identity. This change causes forced refresh login flows to also omit irrelevant OIDC providers in generated form in order to avoid confunding the user about which strategies/providers are valid and can actually be used to reauthenticate.
On verification required after registration, preserve return_to (#3589) (6a0a914):
fix: on verification required after registration, preserve return_to
test: return_to on verification flow
chore: refactor
Redirect to verification URL even if login_challenge is set (#3412) (cd9e6a0):
Fixes ory/network#320
Reduce db lookups in whoami for aal check (#3372) (d814a48):
Significantly improves performance by reducing the amount of queries we need to do when checking for the different AAL levels.
Registration code ui nodes group (#3505) (6220184):
fix: registration code ui nodes group
style: format
Registration should accept hydra login (#3592) (7a47827):
fix: registration should accept hydra login
fix: oauth2 registration flow with session
wip: registration oauth flow tests
wip: refactor oauth flows test
wip: refactor op_registration_test
wip: oauth provider registration test
wip: refactor oauth flows test
fix(test): oauth provider login
style: format
Reject obviously invalid email addresses from courier (8cb9e4c)
Remove earliest_possible_extend default in schema (#3464) (7e05b7d)
Remove slow queries from update identities (#3553) (d138abb)
Respond with 422 when SPA identity requires AAL2 (#3572) (df18c09):
If you submit a browser login flow with an Accept header of application/json, but the login flow requires AAL2, then there is no way for the code to know it needs to redirect the user to the 2FA page. Instead of responding with the Session in this scenario, this PR changes the behaviour to respond with a browser_location_change_required error (status 422) to indicate that the browser needs to open a specific URL, /self-service/login/browser?aal=aal2.
Return 400 bad request for invalid login challenge (#3404) (ca34e9b)
Return HTTP 400 if key unmarshal fails (#3594) (fdf4956):
fix: return HTTP 400 if key unmarshal fails
fix: apply reviewer's suggestion, prepare for bump
fix: follow up reviewer suggestion from ory/x
chore: bump ory/x
Specify correct minimum versions in migratest (18b89ea)
Tracing context passing in /sessions/whoami (1254bf5)
Tracing improvements (c804cb2)
Type-assert all interfaces that WebHook implements (ffda1a0)
Ui node input attributes key added (#3561) (9eff0f3):
fix: ui node InputAttributes.Key added
fix: selfservice recovery flow add React unique key and numeric pattern
fix: remove React related key addition
test: update snapshot
Use ID label on login with multiple identifiers (#3657) (be907db)
Use org ID from session if available in login flow (#3545) (1b3647c)
Add example for allowed_return_urls to include wildcard url (#3533) (39b0c3c), closes #1528
Remove experimental warnings (#3406) (d4d26e6):
See #3388
Add ability to convert session to JWT when calling whoami (#3472) (57b7bb8), closes #2487:
This patch adds a query parameter tokenize_as to /session/whoami which encodes the session to a JWT. It is possible to customize the JWT claims by using a JsonNet template, and furthermore change the expiry of the token.
The tokenize feature supports multiple templates, which makes it easy to use the resulting JWT in a variety of use cases.
Add GetID member functions to RecoveryAddress and Credentials (#3474) (085d500)
Add ID Token sign in with Google Android/iOS SDK (#3515) (055ed92)
Add OpenTelemetry span for password hash comparison (#3383) (e3fcf0c)
Add request URL to email and SMS templates (bf5f8c3)
Add WebhookSucceeded event (aa8c936)
Added various new text messages (ea91483):
To improve i18n and message customization, we added a bunch of new messages. Integrations that do message customization should probably handle those new message codes:
Additionally, these messages got more context:
Allow extra migrations in NewPersister (96c1ff7)
Allow fuzzy-search on credential identifiers (#3526) (2cb3ea2):
This PR adds the ability to search for sub-strings and similar strings in credential identifiers.
Note that the postgres and CRDB migrations create special indexes useful for this feature. To use online schema changes with cockroach, we recommend to manually copy the index definition and run it before applying migrations. The migration will then be a no-op.
If you run on mysql (or sqlite), no special index is created. If desired, you can create such an index manually, and it would be highly appreciated if you could contribute its definition.
This feature is a preview and will change in behavior! Similarity search is not expected to return deterministic results but are useful for humans.
Allow importing hmac hashed passwords (#3544) (0a0e1f7), closes #2422:
The basic format is $hmac-<hashfunction>$<base64 encoded hash>$<base64 encoded key>:
# password = test; key=key; hash function=sha
$hmac-sha1$NjcxZjU0Y2UwYzU0MGY3OGZmZTFlMjZkY2Y5YzJhMDQ3YWVhNGZkYQ==$a2V5
Allow marking OIDC provider-verified addresses as verified during registration (#3448) (e7b33a1), closes #3445 #3424 #1057:
This feature allows marking emails provided by social sign in providers as verified.
Batch list identities (#3598) (8ad54f1), closes #2448:
This change allows to filter GET /admin/identities by ID with the following syntax:
/admin/identities?ids=id1&ids=id2&ids=id3
changelog: Add support for native recovery (#3624) (492808c):
Adds the ability to complete the recovery flow properly on API flows. This PR also streamlines the behavior for SPA flows to not return 422 errors anymore. To enable this new behavior, set the features.use_continue_with_transitions flag in the config to true.
See also #3273
Claims from userinfo endpoint (#3718) (90bdc61):
feat: claims from userinfo endpoint
chore: update libraries
test: improve coverage
Emit error details when we find stray cookies in an API flow (#3496) (df74339)
Eventually consistency API controls (#3558) (00cf11c):
Adds a feature used in Ory Network which enables trading faster reads for slightly stale data.
This feature depends on Cockroach functionality and configuration, and is not possible for MySQL or PostgreSQL.
Extend Microsoft Graph API capabilities (#3609) (4a7bcc9):
This change queries for all user information available with the User.Read scope
during OIDC, and populates the RawClaims field.
Extract identifier label for login from default identity schema (#3645) (180828e)
Fine-grained hooks for all available flow methods (#3519) (a37f6bd):
Adds fine-grained hook configurations to the post-settings flow for methods totp, webauthn, lookup_secret and the post-login flow for totp, lookup_secret, and code.
Hook to revoke sessions after password changed (#3514) (e6af6db), closes #3513:
Currently, the Kratos system does not automatically log out or invalidate other active sessions when a user changes their password. This poses a significant security risk as it allows potentially unauthorized individuals to maintain access to the account even after the password has been updated.
This PR provides the option to add the revoke_active_sessions hook to the actions sections of the selfservice settings.
Improve performance by computing password hashes while validating (#3508) (a9786c5)
Jsonnet caching for OIDC claims mapper, webhooks, JWT session tokenizer (#3701) (1d26e09)
Link oidc credentials when login (#3563) (b784949), closes #2727 #3222:
When user tries to login with OIDC for the first time but has already registered before with email/password a credentials identifier conflict may be detected by Kratos. In this case user needs to login with email/password first and then link OIDC credentials on a settings screen.
This PR simplifies UX and allows user to link OIDC credentials to existing account right in the login flow, without
switching to settings flow.
Login with code on any credential type (#3549) (ceed7d5):
Should be able to login with the code credential even if the user did not register on the code credential.
Only identifier matching is done and validation based on the identity schema.
Parametrize courier worker (#3601) (0e4be57):
Allows one to parametrize how many messages the courier will fetch and how often it will fetch messages.
Passwordless browser login and registration via code to email (#3378) (eaaf375), closes #2029 ory-corp/cloud#3573:
This feature adds passwordless email code login. When a user signs up, or signs in, a code is sent to their email address which they can use to complete the authentication process.
This feature is currently only working for browser facing APIs.
Pooled process-isolated Jsonnet VM (9a52ddf)
Provide login hints when registration fails due to duplicate credentials/addresses (#3430) (8b28469):
feat: provide login hints when registration fails due to duplicate credentials or identifiers
feat: identify edge cases and write tests
chore: synchronize workspaces
feat: make login hints configurable
chore: synchronize workspaces
chore: synchronize workspaces
chore: synchronize workspaces
chore: synchronize workspaces
Support auth_type parameter (#3487) (fc30304):
The Facebook OIDC provider supports an auth_type parameter that
when set to "reauthenticate" will force the user to
reauthenticate (similar to prompt=login for other Providers).
Support multiple origins for WebAuthN (#3380) (013f335):
Users can now supply a list of origins for webauthn in the configuration.
Support native social sign using apple sdk (#3476) (f561013)
Transmit current session ID to Hydra when accepting the login (#3426) (610c76d):
chore: change react-native port to 19006
feat: transmit current session ID when accepting login
fix: upgrade hydra in tests
Webhook analytic events (9c8a25e)
Revert "feat: extend Microsoft Graph API capabilities (#3609)" (#3717) (549308d), closes #3609 #3717:
This reverts commit 4a7bcc9.
Note truncated.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →