NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #245 by repository stars
Last release 2 months ago
29 Jul 2026
Ships on a steady schedule
a new release about every 9 days
Nearly every release is documented
notes for 10 of 10 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
2821 releases · first in 2019
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Please note that can_interrupt is now deprecated in favor of response.parse.
We’re excited to announce the release of Ory Kratos v0.13.0! This update brings many enhancements and fixes, improving the user experience and overall performance. In general, Ory Kratos is reaching complete API stability and we're adding some missing features next, paving the road to v1.0.
Ory Kratos serves over 500M users monthly in various companies, and is the backbone of the Ory Network (the best, cheapest, easiest way to run Ory).
Here are the highlights:
We hope you enjoy these new features and improvements in Ory Kratos v0.13.0! All features are already live on the Ory Network - the simplest, fastest and most scalable way to run Ory.
Please note that the v0.12.0 release was skipped due to CI issues.
Head over to the changelog at https://github.com/ory/kratos/blob/master/CHANGELOG.md to read all the details. As always, we appreciate your feedback and support!
By default, Kratos no longer sends out these Emails. If you want to keep notifying unknown addresses (keep the current behavior), set selfservice.flows.recovery.notify_unknown_recipients to true for recovery, or selfservice.flows.verification.notify_unknown_recipients for verification flows.
Account experience redirects to verification page (#3195) (2e96d75)
Account settings broken on OIDC removal (#3185) (61ae531), closes ory-corp/cloud#3514
Add after_verification_return_to to sdk and api docs (#3097) (c70704c), closes #3096
Add HydraLoginRequest on flow creation (#3152) (09312dd), closes #3108:
The oauth2_login_request field was missing when initially creating the login flow.
Add missing code discriminator in updateVerificationFlow (#3213) (21576be)
Add mutex to test SMTP server setup/teardown (20c2359)
Avoid unchecked casts from IdentityPool to PrivilegedIdentityPool (71d35dd)
Correctly apply patches to identity metadata (#3103) (1193a56), closes #2950
Don't return 500 if active strategy is disabled (#3197) (3a734c2)
Don't treat missing session as error in tracing (290d28a)
Error messages in OpenAPI/Swagger / improve error messages from failed webhooks and client timeouts (#3218) (b1bdcd3)
Handle upstream errors in patreon provider (#3032) (39fa31f)
Identity.CopyWithoutCredentials (989c99d)
Implement offline scope in the way google expects (#3088) (39043d4)
Improve webhook resilience (#3200) (0a05d99):
Invalid SQL syntax in ListIdentities (#3202) (162ab9b):
PostgresQL does not support ... WHERE x IN ( ) with an empty argument list.
Issuer missing from netid claims (#3080) (dec7cbc):
The NetID provider omits the issuer claim in the userinfo response. To resolve this issue, the ID token returned by NetID is now validated and its sub and iss values are used.
Lint errors and unused code (ae49ef0)
Make session AAL satisfaction check resilient against a nil identity in the session (5ab1a56):
Also fix tracing.
Nolint comment (93e6501)
Only return one result set for credentials_identifier (#3107) (59f35d1), closes #3105
Orphaned webhook spans (a7f9414)
Re-use existing CSRF token in verification flows (#3188) (08a3447):
fix: re-use existing CSRF token in verification flows
chore: fix if/else
Reduce SQL tracing noise (1650426)
Remove http.Redirect from show_verification_ui hook (#3238) (054705b)
Report correct errors for json schema validation (#3085) (9477ea4):
jsonschema.ValidationError to errors codes documented here| Validation | Name | ID |
|---|---|---|
maxLength |
ErrorValidationMaxLength | 4000017 |
minimum |
ErrorValidationMinimum. | 4000018 |
exclusiveMinimum |
ErrorValidationExclusiveMinimum | 4000019 |
maximum |
ErrorValidationMaximum | 4000020 |
exclusiveMaximum |
ErrorValidationExclusiveMaximum | 4000021 |
multipleOf |
ErrorValidationMultipleOf | 4000022 |
maxItems |
ErrorValidationMaxItems | 4000023 |
minItems |
ErrorValidationMinItems | 4000024 |
uniqueItems |
ErrorValidationUniqueItems | 4000025 |
type |
ErrorValidationWrongType | 4000026 |
Respect the after recovery return to URL from config (#3141) (3467fd3):
Fixes ory-corp/cloud#1405
Set DB connection max idle time (8d4762c)
Set proper maxAge for session cookies (#3209) (1180c05), closes #3208
Test contract names (e9ac00b)
Add a new admin API to remove a specific 2nd factor credential (#2962) (44556a4), closes #2505
Add API to batch insert identities (#3157) (829bda7), closes ory/network#266
Add Inspect option to driver (8aa75e9)
Add test to verify GetIdentityConfidential expands everything (#3217) (f088ccd)
Add token prefixes to session and logout tokens (#3132) (8210cd0):
This feature adds token prefixes to Ory session and logout tokens:
ory_st_: Ory session token prefixory_lt_: Logout token prefixAdd upstream parameters to oidc provider (#3138) (b6b1679), closes #3127 #2069:
This PR introduces the upstream OIDC query parameters login_hint and hd.
To send additional upstream parameters the form can post this on a login, registration or settings link submit.
For example the form below does an OIDC flow to Google. We can now add additional parameters such as login_hint and hd to the upstream request to Google login with a pre-filled email email@example.com:
<form action="https://kratos/self-service/login?flow=">
<input type="submit" name="provider" value="google" />
<input
type="hidden"
name="upstream_parameters.login_hint"
value="email@example.com"
/>
<input type="hidden" name="upstream_parameters.hd" value="example.com" />
</form>Allow importing (salted) SHA hashing algorithms (#2741) (132255e), closes #2422
Allow passing transient data from registration to webhook (#3104) (4a3a076)
Don't pre-generate UUIDs for transient objects (e17f307)
Even more tracing of hidden HTTP requests (9d8b1e2)
Improve tracing span naming in hooks (bf828d3)
Improve webhook diagnostics (d4eb2f6)
Improved oidc flow on duplicate account registration (#3151) (4d2fda4):
This PR improves the OIDC registration flow when a duplicate account error happens.
Currently the flow looks as follows:
Instead of causing a confusing redirect loop we should show the user the error with a fresh login flow (since the account exists). This also gives the user the option to do a recovery flow.
Let DB generate ID for session devices (62402c7)
Make notification to unknown recipients configurable (#3075) (1a5ead4), closes #2345 #2585:
Added the ability to configure whether the system should notify unknown recipients, if some tries to recover their account or verify their address ("anti-account-enumeration measures").
Make password validator (HIBP check) cancelable and add tracing (28f8914)
Parallelize get identity and session calls (#3023) (6393519)
Refactor credentials fetching (#3183) (590269f):
This change revamps the way we fetch identity credentials. We no longer need most of the helper fields for gobuffalo/pop inside the Identity and Credentials structures, and we collect all the credentials in one joined query rather than using pop's EagerPreload functionality.
Return hydra error messages (b3d037b)
Return verification flow ID after registration flow (#3144) (eb854be), closes #2975
Show "continue" screen after successful verification (#3090) (fb6b160), closes /github.com/ory-corp/cloud#3925 /github.com/ory/network#228:
The link strategy for verification now shows a confirmation screen with a "continue" link after successful verification, aligning its behavior to the code strategy.
Also fixes a bug, where the default_browser_return_url of the verification flow was not respected when using the code strategy.
Social sign in via linkedin (#3079) (5de6bf4), closes #2856:
Adds LinkedIn as a social sign in provider.
Webhooks that update identities (2cbee3e), closes #2161:
Introduces a new configuration response.parse in webhooks. This enables updating of identity data during registration, including admin/public metadata, identity traits, enabling/disabling identity, and modifying verified/recovery addresses.
Please note that can_interrupt is being deprecated in favor of response.parse.
Revert "fix: do not omit last page on identity list (#3169)" (#3184) (73b5f13), closes #3169 #3184:
This reverts commit f95f48a.
HydraLoginRequest on flow creation (Note truncated.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →