NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #245 by repository stars
Last release 2 months ago
29 Jul 2026
Ships on a steady schedule
a new release about every 9 days
Nearly every release is documented
notes for 10 of 10 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
2821 releases · first in 2019
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Resolves an issue in the quickstart.
Resolves an issue in the quickstart.
Calling /self-service/recovery without flow ID or with an invalid flow ID while authenticated will now respond with an error instead of redirecting to the default page.
Closes https://github.com/ory-corp/cloud/issues/2173
Co-authored-by: aeneasr 3372410+aeneasr@users.noreply.github.com
Accept recovery link from authenticated users (#2195) (0fa64dd):
When a recovery link is opened while the user already has a session cookie (possibly for another account), the endpoint will now correctly complete the recovery process and issue new cookies.
Quickstart (73b461c):
Closes https://github.com/ory/kratos/issues/2339
Resolve issue where CF cookies would mingle with CSRF detection in API flows (011219a)
version schema: Require version or fall back to latest (52c9824)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Resolves an issue in the SDK release pipeline.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
We moved the admin API from / to admin. This is a breaking change. Please read the explanation and proceed with caution!
Ory Kratos v0.9 is here! We're extremely happy to announce that the new release is out and once again it's been made even better thanks to the incredible contributions from our awesome community. <3
Enjoy!
Here's an overview of things you can expect from the v0.9 release:
/ to admin. This is a breaking change.
Please read the explanation and proceed with caution!As you can see, this release introduces breaking changes. We tried to keep the HTTP API as backward-compatible as possible by introducing HTTP redirects and other measures, but this update requires you to take extra care. Make sure you've read the release notes and understand the risk before updating.
You must apply SQL migrations for this release. Make sure to create backup before you start!
Configuration key selfservice.whitelisted_return_urls has been renamed to
allowed_return_urls.
All endpoints at the Admin API are now exposed at /admin/. For example,
endpoint https://kratos:4434/identities is now exposed at
https://kratos:4434/admin/identities. This change makes it easier to configure
reverse proxies and API Gateways. Additionally, it introduces 1:1 compatibility
between Ory Cloud's APIs and self-hosted Ory Kratos. Please note that nothing
has changed in terms of the port. To make the migration less painful, we have
set up redirects from the old endpoints to the new /admin endpoints, so your
APIs, SDKs, and clients should continue working as they were working before.
This change is marked as a breaking change as it touches many endpoints and
might be confusing when encountering the redirect for the first time.
If you are using two or more secrets for the secrets.session, this patch might
break existing Ory Session Cookies. This has the effect that users will need to
re-authenticate when visiting your app.
The password_identifier form field of the password login strategy has been
renamed to identifier to make compatibility with passwordless flows possible.
Field name password_identifier will still be accepted. Please note that the UI
node for displaying the "username" / "email" field has this name="identifier"
going forward. Additionally, the traits of the password strategy are no longer
within group password but instead in group profile going forward!
The following OpenID Connect configuration keys have been renamed to better explain their purpose:
- private_key_id
+ apple_private_key_id
- private_key
+ apple_private_key
- team_id
+ apple_team_id
- tenant
+ microsoft_tenant
A major issue has been lingering in the configuration for a while. What happens to your identities when you update a schema? The answer was, it depends on the change. If the change is incompatible, some things might break!
To resolve this problem we changed the way you define schemas. Instead of having
a global default_schema_url which developers used to update their schema, you
now need to define the default_schema_id which must reference schema ID in
your config. To update your existing configuration, check out the patch example
below:
identity:
- default_schema_url: file://stub/identity.schema.json
+ default_schema_id: default
+ schemas:
+ - id: default
+ url: file://stub/identity.schema.json
Ideally, you would version your schema and update the default_schema_id with
every change to the new version:
identity:
default_schema_id: user_v1
schemas:
- id: user_v0
url: file://path/to/user_v0.json
- id: user_v1
url: file://path/to/user_v1.json
Add DispatchMessage to interface (df2ca7a)
Add missing enum (#2223) (4b7d7d0):
Closes https://github.com/ory/sdk/issues/147
Added malformed config test (5a3c9c1)
Appropriately pass context around (#2241) (668f6b2):
Closes https://github.com/ory/cloud/issues/56
Base redirect URL decoding (acdefa7)
Base64 encode identity schema URLs (ad44e4d):
Previously, identity schema IDs with special characters could lead to broken URLs. This patch introduces a change where identity schema IDs are base64 encoded to address this issue. Schema IDs that are not base64 encoded will continue working.
Broken links API spec (e1e7516)
Cloud config issue (135b29c)
Correct recovery hook (c7682a8)
courier: Improve composability (d47150e)
Do not error when HIBP behaves unexpectedly (#2251) (a431c1e), closes #2145
Do not remove all credentials when remove all security keys (#2233) (ecd715a)
Don't inherit flow type in recovery and verification flows (#2250) (c5b444a), closes #2049
embed: Disallow additional props (b2018ce)
embed: Do not require plaintext/html in email config (dfe4140)
Ensure no internal networks can be called in SMS sender (65e42e5)
identity: Slow query performance on MySQL (731b3c7), closes #2278
Improve password error resilience on settings flow (e614f6e)
Improve soundness of credential identifier normalization (e475163)
login: Put passwordless login before password (df9245f)
lookup: Resolve credentials counting regression (50782c6)
Lower-case jsonnet context for sms (8c58e94)
Mark struct as used (33f3dfe)
Mark width and height as required (#2322) (37f2f22):
Closes https://github.com/ory/sdk/issues/157
Mr comment fix (96c917e)
oidc: Improve empty credential handling (124d4ce)
oidc: Incorrect error handling (c8d789c)
Order regression (2cb5d2b)
Pass context to registration flow (c8d55b3)
Pass docs output dir as a separate argument (78c69a2)
password: Schema regressions (271d5fa)
Properly check for not found (77ac199)
Provide access to root path and error page (#2317) (f360ee8)
Rebase regressions (d1c5085)
registration: Order for passwordless webauthn (8427322)
Remove non-hermetic sprig functions (#2201) (17e0acc):
Closes https://github.com/ory/kratos/issues/2087
Resolve issues with the CI pipeline (d15bd90)
Resolve merge regression (d8ca4f3)
Resolve prettier issues (32bf052)
Resolve remaining passwordless regressions (151c8cf)
Resovle lint errors (afb7aaf)
Return 400 instead of 404 on admin recovery (ae2509c), closes #1664
sdk: Add all available discriminators (5d70f9c), closes #2287 #2288
sdk: Add webauth and lookup_secret to identityCredentialsType (#2276) (61ce3c0)
selfservice: Cannot login after remove security keys and all other 2FA settings (#2181) (5ff6773), closes #2180
selfservice: Login self service flow with TOTP does not pass on return_to URL (#2175) (3eaa88e), closes #2172
session: Correctly calculate aal for passwordless webauthn (c7eb970)
session: Properly declare session secrets (6312afd), closes #2272:
Previously, a misconfiguration of Gorilla's session store caused incorrect handling of the configured secrets. From now on, cookies will also be properly encrypted at all times.
Snapshot regression (6481441)
Static analysis (a1d3254)
test: Parallelization issues (dbcf3fb)
text: Incorrect IDs for different messages (0833321), closes #2277
totp: Resolve credentials counting regression (737bb3f)
Typo (fbc8b4f)
Typo (3bb0d41)
Unstable ordering (bee26c6)
Unstable webauthn order (6262160)
URL with hash sign in after_verification_return_to stays encoded (#2173) (fb1cb8a), closes #2068
Use actions/checkout for ui repos (f0136ca)
Use correct dir for clidoc (8c8a1ab)
Use HTTP 303 instead of 302 for selfservice redirects (#2215) (50b6bd8), closes #1969
Use latest hydra version (ffb3f20)
webauthn: Resolve missing identifier bug (93a1ae4)
webauthn: Schema regressions (970e861)
webauth: SPA regressions for login (be378ff)
Yq version (41b6f18)
/admin/ on the admin port
(8acb4cf)identity.default_schema_id
(#1964)
(e4f205d)password_identifier field to identifier
(4dbe0ea)whitelisted_return_urls to allowed_return_urls
(#2299)
(686c9ba)Abandon courier messages after configurable timeout (#2257) (bff92f7)
Add webauthn to list of identifiers
(1a8b256):
This patch adds the key webauthn to the list of possible identifiers in the
Identity JSON Schema. Use this key to specify what field is used to find the
WebAuthn credentials on passwordless login flows.
Add credential migrator pattern (77afc6f)
Add message for missing webauthn credentials (303dc6b)
Add new messages (09e6fd1)
Add npm install step (3d253e5)
Add versioning and improve compatibility for credential migrations (78ce668)
Added sms sending support to courier (687eca2)
Allow empty version string (419f94b)
Cancelable web hooks (44a5323):
Introduces the ability to cancel web hooks by calling error "cancel" in
JsonNet.
config: Add option to mark webauthn as passwordless-able (0455e3f):
Adds option passwordless to selfservice.methods.webauthn.config, making it
possible to use WebAuthn for first-factor authentication, or so-called
"passwordless" authentication.
Courier template configs (#2156) (799b6a8), closes #2054:
It is now possible to override individual courier email templates using the configuration system!
courier: Expose setters again (598dc3a)
e2e: Add passwordless flows and fix bugs (ef3871b)
identity: Add identity credentials helpers (b7be327)
identity: Add versioning to credentials (aaf779a)
Ignore web hook response (ae87914):
Introduces the ability to ignore responses from web hooks in favor of faster and non-blocking execution.
Make sensitive log value redaction text configurable (#2321) (9b66e43)
oidc: Customizable base redirect uri (fa1f234):
Closes https://github.com/ory-corp/cloud/issues/2003
Password, social sign, verified email in import (41a27b1), closes #605:
This patch introduces the ability to import passwords (cleartext, PKBDF2, Argon2, BCrypt) and Social Sign In connections when creating identities!
recovery: Allow invalidation of existing sessions (5029884), closes #1077:
You can now use the revoke_active_sessions hook in the recovery flow. It
invalidates all of an identity's sessions on successful account recovery.
schema: Add functionality to disallow internal HTTP requests (6e08416):
See https://github.com/ory-corp/cloud/issues/1261
security: Add e2e tests for various private network SSRF defenses (b049bc3)
security: Add SSRF defenses in OIDC (d37dc5d)
session: Add webauthn to extension validation (049fd8e)
session: Webauthn can now be a first factor as well (861bee0)
webauthn: Add error preventing deleting last webauthn credential (1209eda)
webauthn: Add new decoder schemas (c3e1501)
webauthn: Add passwordless credentials indicator (6e3057a)
webauthn: Add swagger type (14c2b74)
webauthn: Count passwordless credentials (145af23)
webauthn: Implement refresh using webauth (bf10868), closes #2284:
This change introduces the ability to refresh a session (for example when entering "sudo" mode") using WebAuthn credentials. In this case, it does not matter whether the WebAuthN credentials are for MFA or passwordless flows.
webauthn: Improve schema (790dcf3)
webauthn: Manage webauthn passwordless keys (5a62ced)
webauthn: Passwordless login (b4c4fd2)
webauthn: Update messages and nodes (22534d8)
webauthn: Use plain bytes for wrapped user (97c8c9e)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →