NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #245 by repository stars
Last release 2 months ago
29 Jul 2026
Ships on a steady schedule
a new release about every 9 days
Nearly every release is documented
notes for 10 of 10 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
2821 releases · first in 2019
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
b2b0eb0 ci: add CVE-2022-30065 to trivy ignore
The 2022 winter release of Ory Kratos is here, and we are extremely excited to share with you some of the highlights included:
oauth2_provider.url configuration value.Please read the changelog carefully to identify changes which might affect you. Always test upgrading with a copy of your production system before applying the upgrade in production.
This patch changes the behavior of the recovery flow. It introduces a new strategy for account recovery that sends out short "one-time passwords" (code) that a user can use to prove ownership of their account and recovery access to it. This PR also updates the default recovery strategy to code.
This patch invalidates recovery flows initiated using the Admin API. Please re-generate any admin-generated recovery flows and tokens.
This is a breaking change, as it removes the courier.message_ttl config key and replaces it with a counter courier.message_retries.
SDK Method getJsonSchema was renamed to getIdentitySchema.
Active attribute based off IsActive checks (#2901) (bcbf68e)
Add issuerURL for apple id (#2565) (2aeb0a2):
No issuer url was specified when using the Apple ID provider,
this forced usersers to manually enter it in the provider config.
This PR adds the Apple ID issuer url to the provider simplifying the setup.
Add missing go.mod to docker build (7c4964e)
Add support for verified Graph API calls for facebook oidc provider (#2547) (1ba7c66)
Admin recovery CSRF & duplicate form elements (#2846) (de80b7f)
Bump graceful to deal with http header timeouts (9ce2d26)
Check return code of ms graphapi /me request. (#2647) (3f490a3)
Correct name of span on recovery code deletion (#2823) (44f775f)
Correctly calculate expired_at timestamp for FlowExpired errors (#2836) (ddde43e)
Disappearing title label on verification and recovery flow (#2613) (29aa3b6), closes #2591
Distinguish credential types properly when collecting identifiers (#2873) (705f7b1)
Do not crash process on invalid smtp url (#2890) (c5d3ebc):
Closes ory-corp/cloud#3321
Do not double-commit webhooks on registration (#2888) (88e75d9)
docker: Update images (b5f80c1)
Express e2e tests for new account experience (#2708) (84ea0cf)
Format (0934def)
Gosec false positives (e3e7ed0)
Identity sessions list response includes pagination headers (#2763) (0c2efa2), closes #2762
identity: Migrate identity_addresses to lower case (#2517) (c058e23), closes #2426
Ignore commata in HIBP response (0856bd7)
Ignore CSRF for session extension on public route (866b472)
Ignore error explicitly (772d596)
Include flow id in use recovery token query (#2679) (d56586b):
This PR adds the selfservice_recovery_flow_id to the query used when "using" a token in the recovery flow.
This PR also adds a new enum field for identity_recovery_tokens to distinguish the two flows: admin versus self-service recovery.
Include metadata_admin in admin identity list response (#2791) (aa698e0), closes #2711
Incorrect swagger annotation for getSession (#2891) (797ea68)
lint: Fixed lint error causing ci failures (4aab5e0)
Make hydra consistently localhost (70211a1)
Make ID field in VerifiableAddress struct optional (#2507) (0844b47), closes #2506
Make servicelocator explicit (4f841da)
Make swagger/openapi go 1.19 compatible (fec6772)
Mark gosec false positives (13eaddb)
Metadata should not be required (05afd68)
Migration error detection (a115486)
Missing usage to recovery_code_invalid template (#2798) (5ac7553)
Panic (1182278)
Patch invalidates credentials (#2721) (c4d95af), closes ory/cloud#148
Re-add service to quickstart (8c52c33)
Re-issue outdated cookie in /whoami (#2598) (bf6f27e), closes #2562
Remove jsonnet import support (d708c81)
Remove rust workaround (355ec43)
Replace io/util usage by io and os package (e2d805b)
Resolve bug where 500s in web hooks are not properly retried (e572e81)
Respect more http sources for computing request URL (66a9448)
Return browser to 'return_to' when logging in without registered account using oidc. (#2496) (a4194f5), closes #2444
Return empty array not null when there are no sessions (#2548) (fffba47)
Revert Go 1.19 formatting changes (7fb085b)
Revert removal of required field in uiNodeInputAttributes (#2623) (fee154b)
sdk: Identity metadata is nullable (#2841) (4c70578):
Closes ory/sdk#218
sdk: Make InputAttributes.Type an enum (ff6190f)
sdk: Rust compile issue with required enum (#2619) (8800085)
Send out correct verification invalid email in code strategy (#2908) (d2bb67a)
Take over return_to param from unauthorized settings to login flow (#2787) (504fb36)
Use correct download location for golangci-lint (c36ca53)
Use errors instead of fatal for serve cmd (02f7e9c)
Use full URL for webhook payload (72595ad)
Verification redirect & continue label (#2905) (e1119e8):
This PR resolves an issue with the redirect after a successful verification, if not specified.
Wrong config key in admin recovery documentation (#2815) (154b61b)
Hot reloading (b0d8f38)
Make embedding easier with internal sdk (e9aa21f)
SDK v1 naming (11f9d30):
Find the full upgrade guide in our documentation.
sdk: Rename getJsonSchema to getIdentitySchema (#2606) (8dc2ecf)
Use gotemplates for command usage (baa84c6)
Add api endpoint to fetch messages (#2651) (5fddcbf):
Closes #2639
Add codecov yaml (90da0bb)
Add flow id check to use verification token (#2695) (54c64fc)
Add handler with openapi def for admin revoke session (#2867) (2438ca0)
Add identity id to "account disabled" error (#2557) (f09b1b3)
Add missing config entry (8fe9de6)
Add missing cookie headers to SDK methods (#2720) (32e32d1):
See #2583
Add pre-hooks to settings, verification, recovery (c0ceaf3)
Add session cache header feature flag (#2899) (02a92b4), closes ory-corp/cloud#3283
Add support for firebase scrypt hashes on identity import and login hash upgrade (#2734) (3852eb4), closes #2422
Add verification via code (#2838) (a82ee92), closes #2824:
The new code strategy is now supported as a verification strategy. If enabled, the strategy sends a code, instead of a magic link to the user's address, which they can use to verify their address.
Adding device information to the session (#2715) (82bc9ce):
Closes #2091
See ory-corp/cloud#3011
Co-authored-by: Patrik zepatrik@users.noreply.github.com
Allow importing scrypt hashing algorithm (#2689) (3e3b59e), closes #2422:
It is now possible to import scrypt-hashed passwords.
Allow setting public and admin metadata with the jsonnet data mapper (#2569) (aa6eb13), closes #2552
cli: Helper for cleaning up stale records (#2406) (29d6376), closes #952
Forward parsed request cookies to webhook Jsonnet snippet (#2917) (70ed068):
Request cookies were already available in raw form in
the ctx.request_headers top-level argument to the Jsonnet snippet.
Parsing cookies in Jsonnet is tedious and error-prone, though, so
we parse them internally for convenience.
Handler for update API with credentials (#2423) (561187d), closes #2334
Immutable cookie session values (#2761) (a6f2793), closes #2701
Implement blocking webhooks (#1585) (e48e9fa), closes #1724 #1483
Improve cache handling (6e8579b)
Improve state generation logic (546ee3d)
Ingest hydra bugfix (3c11216)
OAuth2 integration (#2804) (7c6eb2a):
This feature allows Ory Kratos to act as a login provider for Ory Hydra using the oauth2_provider.url configuration value.
Closes #273
Closes #2293
See ory/kratos-selfservice-ui-node#50
See ory/kratos-selfservice-ui-node#68
See ory/kratos-selfservice-ui-node#108
See ory/kratos-selfservice-ui-node#111
See ory/kratos-selfservice-ui-node#149
See ory/kratos-selfservice-ui-node#170
See ory/kratos-selfservice-ui-node#198
See ory/kratos-selfservice-ui-node#207
Parse all id token claims into raw_claims (#2765) (1da0cf6), closes #2528:
All ID Token claims resulting from the Social Sign In flow are now available in raw_claims and can be used in the Social Sign In JsonNet Mapper.
Replace magic links with one time codes in recovery flow (#2645) (a1532ba), closes #1451:
This feature introduces a new code strategy to recover an account.
Currently, if a user needs to initiate a recovery flow to recover a lost password/MFA/etc., they’ll receive an email containing a “magic link”. This link contains a flow_id and a recovery_token. This is problematic because some antivirus software opens links in emails to check for malicious content, etc.
Instead of the magic link, we send an 8-digit code that is clearly displayed in the email or SMS. A user can now copy/paste or type it manually into the text-field that is shown after the user clicks “submit” on the initiate flow page.
Replace message_ttl with static max retry count (#2638) (b341756):
This PR replaces the courier.message_ttl configuration option with a courier.message_retries option to limit how often the sending of a message is retried before it is marked as abandoned.
Support ip exceptions (de46c08)
Trace WebHooks (#2911) (665605b):
Previously the context was not propagated to the http client. As a result the (instrumented) client did not find the existing span and the sapns for outgoing http request have been orphains.
With this simple Fix they are now children of the corresponding webhook spans.
Upgrade hydra to v2 (fdb108f)
Revert "autogen(openapi): regenerate swagger spec and internal client" (24eddfb):
This reverts commit 4159b93.
Revert "refactor: use gotemplates for command usage (#2770)" (#2778) (d612612), closes #2770 #2778:
This reverts commit 1d22b23.
Note truncated.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This is a breaking change, as it removes the courier.message_ttl config key and replaces it with a counter courier.message_retries.
autogen: pin v0.11.0-alpha.0.pre.2 release commit
This patch changes the behavior of the recovery flow. It introduces a new
strategy for account recovery that sends out short "one-time passwords" (code)
that a user can use to prove ownership of their account and recovery access to
it. This PR also updates the default recovery strategy to code.
This patch invalidates recovery flows initiated using the Admin API. Please re-generate any admin-generated recovery flows and tokens.
This is a breaking change, as it removes the courier.message_ttl config key
and replaces it with a counter courier.message_retries.
Closes https://github.com/ory/kratos/issues/402 Closes https://github.com/ory/kratos/issues/1598
SDK Method getJsonSchema was renamed to getIdentitySchema.
Active attribute based off IsActive checks (#2901) (bcbf68e)
Add issuerURL for apple id (#2565) (2aeb0a2):
No issuer url was specified when using the Apple ID provider, this forced usersers to manually enter it in the provider config.
This PR adds the Apple ID issuer url to the provider simplifying the setup.
Add missing go.mod to docker build (7c4964e)
Add support for verified Graph API calls for facebook oidc provider (#2547) (1ba7c66)
Admin recovery CSRF & duplicate form elements (#2846) (de80b7f)
Bump graceful to deal with http header timeouts (9ce2d26)
Cache migration status (#2631) (9020738):
See https://github.com/ory-corp/cloud/issues/2691
Check return code of ms graphapi /me request. (#2647) (3f490a3)
Correct name of span on recovery code deletion (#2823) (44f775f)
Correctly calculate expired_at timestamp for FlowExpired errors
(#2836)
(ddde43e)
Disappearing title label on verification and recovery flow (#2613) (29aa3b6), closes #2591
Distinguish credential types properly when collecting identifiers (#2873) (705f7b1)
Do not crash process on invalid smtp url (#2890) (c5d3ebc):
Closes https://github.com/ory-corp/cloud/issues/3321
Do not double-commit webhooks on registration (#2888) (88e75d9)
docker: Update images (b5f80c1)
Express e2e tests for new account experience (#2708) (84ea0cf)
Format (0934def)
Gosec false positives (e3e7ed0)
Identity sessions list response includes pagination headers (#2763) (0c2efa2), closes #2762
identity: Migrate identity_addresses to lower case (#2517) (c058e23), closes #2426
Ignore commata in HIBP response (0856bd7)
Ignore CSRF for session extension on public route (866b472)
Ignore error explicitly (772d596)
Include flow id in use recovery token query (#2679) (d56586b):
This PR adds the selfservice_recovery_flow_id to the query used when "using"
a token in the recovery flow.
This PR also adds a new enum field for identity_recovery_tokens to
distinguish the two flows: admin versus self-service recovery.
Include metadata_admin in admin identity list response (#2791) (aa698e0), closes #2711
Incorrect swagger annotation for getSession
(#2891)
(797ea68)
lint: Fixed lint error causing ci failures (4aab5e0)
Make hydra consistently localhost (70211a1)
Make ID field in VerifiableAddress struct optional (#2507) (0844b47), closes #2506
Make servicelocator explicit (4f841da)
Make swagger/openapi go 1.19 compatible (fec6772)
Mark gosec false positives (13eaddb)
Metadata should not be required (05afd68)
Migration error detection (a115486)
Missing usage to recovery_code_invalid template (#2798) (5ac7553)
Panic (1182278)
Patch invalidates credentials (#2721) (c4d95af), closes ory/cloud#148
Re-add service to quickstart (8c52c33)
Re-issue outdated cookie in /whoami (#2598) (bf6f27e), closes #2562
Remove jsonnet import support (d708c81)
Remove rust workaround (355ec43)
Replace io/util usage by io and os package (e2d805b)
Resolve bug where 500s in web hooks are not properly retried (e572e81)
Respect more http sources for computing request URL (66a9448)
Return browser to 'return_to' when logging in without registered account using oidc. (#2496) (a4194f5), closes #2444
Return empty array not null when there are no sessions (#2548) (fffba47)
Revert Go 1.19 formatting changes (7fb085b)
Revert removal of required field in uiNodeInputAttributes (#2623) (fee154b)
sdk: Identity metadata is nullable (#2841) (4c70578):
Closes https://github.com/ory/sdk/issues/218
sdk: Make InputAttributes.Type an enum (ff6190f)
sdk: Rust compile issue with required enum (#2619) (8800085)
Send out correct verification invalid email in code strategy (#2908) (d2bb67a)
Take over return_to param from unauthorized settings to login flow (#2787) (504fb36)
Use correct download location for golangci-lint (c36ca53)
Use errors instead of fatal for serve cmd (02f7e9c)
Use full URL for webhook payload (72595ad)
Verification redirect & continue label (#2905) (e1119e8):
This PR resolves an issue with the redirect after a successful verification, if not specified.
Wrong config key in admin recovery documentation (#2815) (154b61b)
Hot reloading (b0d8f38)
Make embedding easier with internal sdk (e9aa21f)
SDK v1 naming (11f9d30):
Find the full upgrade guide in our documentation.
sdk: Rename getJsonSchema to getIdentitySchema
(#2606)
(8dc2ecf)
Use gotemplates for command usage (baa84c6)
Add api endpoint to fetch messages (#2651) (5fddcbf):
Closes https://github.com/ory/kratos/issues/2639
Add codecov yaml (90da0bb)
Add flow id check to use verification token (#2695) (54c64fc)
Add handler with openapi def for admin revoke session (#2867) (2438ca0)
Add identity id to "account disabled" error (#2557) (f09b1b3)
Add missing config entry (8fe9de6)
Add missing cookie headers to SDK methods (#2720) (32e32d1):
See https://github.com/ory/kratos/discussions/2583
Add pre-hooks to settings, verification, recovery (c0ceaf3)
Add session cache header feature flag (#2899) (02a92b4), closes ory-corp/cloud#3283
Add support for firebase scrypt hashes on identity import and login hash upgrade (#2734) (3852eb4), closes #2422
Add verification via code
(#2838)
(a82ee92),
closes #2824:
The new code strategy is now supported as a verification strategy. If
enabled, the strategy sends a code, instead of a magic link to the user's
address, which they can use to verify their address.
Adding device information to the session (#2715) (82bc9ce):
Closes https://github.com/ory/kratos/issues/2091 See https://github.com/ory-corp/cloud/issues/3011
Co-authored-by: Patrik zepatrik@users.noreply.github.com
Allow importing scrypt hashing algorithm (#2689) (3e3b59e), closes #2422:
It is now possible to import scrypt-hashed passwords.
Allow setting public and admin metadata with the jsonnet data mapper (#2569) (aa6eb13), closes #2552
cli: Helper for cleaning up stale records (#2406) (29d6376), closes #952
Handler for update API with credentials (#2423) (561187d), closes #2334
Immutable cookie session values (#2761) (a6f2793), closes #2701
Implement blocking webhooks (#1585) (e48e9fa), closes #1724 #1483
Improve cache handling (6e8579b)
Improve state generation logic (546ee3d)
Ingest hydra bugfix (3c11216)
OAuth2 integration (#2804) (7c6eb2a):
This feature allows Ory Kratos to act as a login provider for Ory Hydra using
the oauth2_provider.url configuration value.
Closes https://github.com/ory/kratos/issues/273 Closes https://github.com/ory/kratos/discussions/2293 See https://github.com/ory/kratos-selfservice-ui-node/pull/50 See https://github.com/ory/kratos-selfservice-ui-node/pull/68 See https://github.com/ory/kratos-selfservice-ui-node/pull/108 See https://github.com/ory/kratos-selfservice-ui-node/pull/111 See https://github.com/ory/kratos-selfservice-ui-node/pull/149 See https://github.com/ory/kratos-selfservice-ui-node/pull/170 See https://github.com/ory/kratos-selfservice-ui-node/pull/198 See https://github.com/ory/kratos-selfservice-ui-node/pull/207
Parse all id token claims into raw_claims (#2765) (1da0cf6), closes #2528:
All ID Token claims resulting from the Social Sign In flow are now available
in raw_claims and can be used in the Social Sign In JsonNet Mapper.
Replace magic links with one time codes in recovery flow (#2645) (a1532ba), closes #1451:
This feature introduces a new code strategy to recover an account.
Currently, if a user needs to initiate a recovery flow to recover a lost password/MFA/etc., they’ll receive an email containing a “magic link”. This link contains a flow_id and a recovery_token. This is problematic because some antivirus software opens links in emails to check for malicious content, etc.
Instead of the magic link, we send an 8-digit code that is clearly displayed in the email or SMS. A user can now copy/paste or type it manually into the text-field that is shown after the user clicks “submit” on the initiate flow page.
Replace message_ttl with static max retry count (#2638) (b341756):
This PR replaces the courier.message_ttl configuration option with a
courier.message_retries option to limit how often the sending of a message
is retried before it is marked as abandoned.
Support ip exceptions (de46c08)
Trace WebHooks (#2911) (665605b):
Previously the context was not propagated to the http client. As a result the (instrumented) client did not find the existing span and the sapns for outgoing http request have been orphains.
With this simple Fix they are now children of the corresponding webhook spans.
Upgrade hydra to v2 (fdb108f)
Revert "autogen(openapi): regenerate swagger spec and internal client" (24eddfb):
This reverts commit 4159b93ae3f8175cf7ccf77d34e4a7a2d0181d4f.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →