NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #245 by repository stars
Last release 2 months ago
29 Jul 2026
Ships on a steady schedule
a new release about every 9 days
Nearly every release is documented
notes for 10 of 10 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
2821 releases · first in 2019
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
autogen: pin v0.8.0-alpha.4.pre.0 release commit
autogen: pin v0.8.0-alpha.4.pre.0 release commit
To celebrate this change, we cleaned up the ways you install Ory software, and will roll this out to all other projects soon:
There is now one central brew / bash curl repository:
-brew install ory/kratos/kratos
+brew install ory/tap/kratos
-bash <(curl https://raw.githubusercontent.com/ory/kratos/master/install.sh)
+bash <(curl https://raw.githubusercontent.com/ory/meta/master/install.sh) kratos
Add subdomain configuration in csrf page (#1896) (681750f):
Add some instructions as to how kratos can be configured to work across subdomains.
Remove unintended characters in subdomain section in csrf page (#1897) (dfb9007)
Add new goreleaser build chain (#1932) (cf1714d):
This patch adds full compatibility with ARM architectures, including Apple Silicon (M1). We additionally added cryptographically signed signatures verifiable using cosign for both binaries as well as docker images.
Add quickstart mimicking hosted ui (813fb4c)
Advanced e-mail templating support (#1859) (54b97b4), closes #834 #925
Allow wildcard domains for redirect_to checks (#1528) (349cdcf), closes #943:
Support wildcard domains in redirect_to checks.
Configurable health endpoints access logging (#1934) (1301f68):
This PR introduces a new boolean configuration parameter that allows turning off logging of health endpoints requests in the access log. The implementation is basically a rip-off from Ory Hydra and the configuration parameter is the same:
serve.public.request_log.disable_for_health
serve.admin.request_log.disable_for_health
The default value is false.
Make admin recovery to work without emails #1419 (#1750) (db00e85)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Resolves issues in the quickstart.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Resolves an issue in the SDK release pipeline.
Resolves an issue in the SDK release pipeline.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Docker Image vulnerability checking as part of the release pipeline.
We are extremely excited to share this next generation of Ory Kratos! The project is truly maturing and the community is getting larger by the hour.
On this special occasion, we would like to bring to your attention that the Ory Summit is happening tomorrow and on Friday! You will hear gripping talks from the Ory Community and Ory maintainers! And the best part, tickets are free and we are covering multiple time zones!
This release is truly the best version of Ory Kratos to date and we want to give you a tl;dr of the 345 commits and 1152 files changed, and what you can expect from this release:
return_to across flows (e.g. OIDC) and in custom UIs.As you can see, much has happened and we are grateful for all the great interactions we have with you, every day!
Let's take a look at some of the breaking changes. Even though much was added, little has changed in breaking ways! This is a testament that Ory Kratos' internals and APIs are becoming more stable!
This release requires you to run SQL migrations. Please, as always, create a backup of your database first!
The SDKs are now generated with tag v0alpha2 to reflect that some signatures
have changed in a breaking fashion. Please update your imports from v0alpha1
to v0alpha2.
The SMTPS scheme used in courier config URL with cleartext/StartTLS/TLS SMTP connection types is now only supporting implicit TLS. For StartTLS and cleartext SMTP, please use the SMTP scheme instead.
Example:
smtp://foo:bar@my-mailserver:1234/?disable_starttls=truesmtps://foo:bar@my-mailserver:1234/ ->
smtp://foo:bar@my-mailserver:1234/smtps://foo:bar@my-mailserver:1234/?legacy_ssl=true
-> `smtps://foo:bar@my-mailserver:1234/We are extremely excited to share this
next generation of Ory Kratos! The project is truly maturing and the community
is getting larger by the hour.On this special occasion, we would like to bring to your attention that the Ory Summit is happening tomorrow and on Friday! You will hear gripping talks from the Ory Community and Ory maintainers! And the best part, tickets are free and we are covering multiple time zones!
This release is truly the best version of Ory Kratos to date and we want to give you a tl;dr of the 345 commits and 1152 files changed, and what you can expect from this release:
return_to across flows (e.g. OIDC) and in custom UIs.As you can see, much has happened and we are grateful for all the great interactions we have with you, every day!
Let's take a look at some of the breaking changes. Even though much was added, little has changed in breaking ways! This is a testament that Ory Kratos' internals and APIs are becoming more stable!
This release requires you to run SQL migrations. Please, as always, create a backup of your database first!
The SDKs are now generated with tag v0alpha2 to reflect that some signatures
have changed in a breaking fashion. Please update your imports from v0alpha1
to v0alpha2.
The SMTPS scheme used in courier config URL with cleartext/StartTLS/TLS SMTP connection types is now only supporting implicit TLS. For StartTLS and cleartext SMTP, please use the SMTP scheme instead.
Example:
smtp://foo:bar@my-mailserver:1234/?disable_starttls=truesmtps://foo:bar@my-mailserver:1234/ ->
smtp://foo:bar@my-mailserver:1234/smtps://foo:bar@my-mailserver:1234/?legacy_ssl=true
-> `smtps://foo:bar@my-mailserver:1234/We are extremely excited to share this
next generation of Ory Kratos! The project is truly maturing and the community
is getting larger by the hour.On this special occasion, we would like to bring to your attention that the Ory Summit is happening tomorrow and on Friday! You will hear gripping talks from the Ory Community and Ory maintainers! And the best part, tickets are free and we are covering multiple time zones!
This release is truly the best version of Ory Kratos to date and we want to give you a tl;dr of the 345 commits and 1152 files changed, and what you can expect from this release:
return_to across flows (e.g. OIDC) and in custom UIs.As you can see, much has happened and we are grateful for all the great interactions we have with you, every day!
Let's take a look at some of the breaking changes. Even though much was added, little has changed in breaking ways! This is a testament that Ory Kratos' internals and APIs are becoming more stable!
This release requires you to run SQL migrations. Please, as always, create a backup of your database first!
The SDKs are now generated with tag v0alpha2 to reflect that some signatures
have changed in a breaking fashion. Please update your imports from v0alpha1
to v0alpha2.
The SMTPS scheme used in courier config URL with cleartext/StartTLS/TLS SMTP connection types is now only supporting implicit TLS. For StartTLS and cleartext SMTP, please use the SMTP scheme instead.
Example:
smtp://foo:bar@my-mailserver:1234/?disable_starttls=truesmtps://foo:bar@my-mailserver:1234/ ->
smtp://foo:bar@my-mailserver:1234/smtps://foo:bar@my-mailserver:1234/?legacy_ssl=true
-> smtps://foo:bar@my-mailserver:1234/The location of the homebrew tap has changed from ory/ory/kratos to
ory/tap/kratos.
To stay consistent with other query parameter's, the self-service login flow's
forced key has been renamed to refresh.
The SDKs are now generated with tag v0alpha2 to reflect that some signatures
have changed in a breaking fashion. Please update your imports from v0alpha1
to v0alpha2.
To support 2FA on non-browser (e.g. native mobile) apps we have added the Ory
Session Token as a possible parameter to both
initializeSelfServiceLoginFlowWithoutBrowser and submitSelfServiceLoginFlow.
Depending on the SDK generator, the order of the arguments may have changed. In
JavaScript:
- .submitSelfServiceLoginFlow(flow.id, payload)
+ .submitSelfServiceLoginFlow(flow.id, sessionToken, payload)
+ // or if the user has no session yet:
+ .submitSelfServiceLoginFlow(flow.id, undefined, payload)
To improve the overall API design we have changed the result of
POST /self-service/settings. Instead of having flow be a key, the flow is now
the response. The updated identity payload stays the same!
{
- "flow": {
- "id": "flow-id-..."
- ...
- },
+ "id": "flow-id-..."
+ ...
"identity": {
"id": "identity-id-..."
}
}
The SMTPS scheme used in courier config url with cleartext/StartTLS/TLS SMTP connection types is now only supporting implicit TLS. For StartTLS and cleartext SMTP, please use the smtp scheme instead.
Example:
smtp://foo:bar@my-mailserver:1234/?disable_starttls=truesmtps://foo:bar@my-mailserver:1234/ ->
smtp://foo:bar@my-mailserver:1234/smtps://foo:bar@my-mailserver:1234/?legacy_ssl=true
-> smtps://foo:bar@my-mailserver:1234/This patch changes the naming and number of prometheus metrics (see:
https://github.com/ory/x/pull/379). In short: all metrics will have now http_
prefix to conform to Prometheus best practices.
Add error id (1442784)
Add mfa e2e test scenarios and resolve found issues (436992d)
Allow refresh and aal upgrade at the same time (2ec801f)
API client leaks stack trace with an error (#1772) (d3aff6d), closes #1771
Better const handling for internal context (1e457e3)
Correct swagger path for /identities/:id/session endpoint (#1756) (d614f2a)
Decoder regression in registration (febf75a)
Deterministic clidoc dates (e48d90a)
Disable totp per default (7278589)
Docs autogen should not use time.Now
(a830f5b)
Ensure correct error propagation (77ce709)
Ensure refresh issues a new session when the identity changes (a10b385)
Ensure return_to works for OIDC flows (d615734), closes #1773
Explicit validation for return to in new flows (284cf29)
Follow chrome webauthn best practice recommendation (0a7c812)
Handle return errors on the frontend and break early (0e8d481):
Closes https://github.com/ory-corp/cloud/issues/1426
Identity credential identifiers are now unique per method (57fd99a)
Improve schema validation error tracing (f793fe5)
Incorrect JSON response for browser flows (1501f56)
Kill modd as well (e5a98e5)
link: Resolve incorrect response types when opening API recovery link in browser (35ea8db)
login: Properly handle refresh (8dc7059)
lookup: Ensure correct fields are set (5ed4c55)
lookup: Resolve reuse scenarios (dbfe475)
lookup: Set up codes correctly (2f373f3)
oidc: Ensure nested keys work on login (71583c5)
Omitempty for VerifiedAt and StateChangedAt (#1736) (bf2ec6e):
Closes https://github.com/ory/sdk/issues/95
Only respect required modules for SDK (4c5677f)
Panic when recovering deactivated user (0a49f27), closes #1794 #1826
Potentially resolve hanging postgres connection closing (693a928)
Properly encode aal error (49b6288)
Properly open recovery endpoints in browser if flow was initiated via API (23c12e5)
Remove duplicate schema error (4e69123)
Remove initial_value again as it was not useful outside of booleans (0cc984b)
Remove obsolete openapi patch (11618ec)
Remove unnecessary cmd reference (351760e)
Replace 302 with 303 (2e2b0f8)
Resolve clidoc generation issue (1aaaa03)
Resolve merge issues (1dc7497)
Resolve openapi issues and regenerate clients (f7d60c0)
Resolve swagger regression (02b9d47)
Run format on ts files (f55f6f6)
Slow CLI start-up time (ae20c17):
Found a deeply nested dependency which was importing
https://github.com/markbates/pkger, causing unreasonable CPU consumption and
significant delay at start up time. With this patch, start up time was reduced
from almost 3s to ~0.01s.
$ time kratos
kratos 2.55s user 2.46s system 508% cpu 0.986 total
$ time ./kratos-patch
./kratos-patch 0.00s user 0.00s system 64% cpu 0.001 total
totp: Reorder QR (d096df7)
Try and reduce cookie flakyness (e7ae8d6)
Typo (8c4d8a2)
ui: Use correct type for anchor (a6595e4)
Update schema config location (539ae73)
Use parallelism of 1 in go test (8736334)
webauthn: Support react-based webauth (b6123b4)
X-session-token must not be mandatory (05d73be)
courier: Support SMTP schemes for implicit TLS, explicit StartTLS, and cleartext SMTP (#1831) (4cb082c), closes #1770 #1769
Homogenize error messages (421a319)
Improved prometheus metrics (#1830) (0be993b), closes #1735:
This will add new prometheus metrics for Kratos that are more useful for alerting and increase overall observability.
Login flow forced renamed to refresh
(92087e5)
login: Rename forced -> refresh (8d1e54b)
login: Support 2FA for non-browser SDKs (df4846d)
Move expired error into top-level flow module (01a2602)
Move homebrew tap to ory/tap (0ee67c3)
Move node identifiers to node package (b0a86dc)
Revert decision to return 422 errors and streamline 401/403 (8aa5318)
Sdk API is no v0alpha2 (3f06738)
session: CreateAndIssueCookie is now UpsertAndIssueCookie (a6d134d)
session: CreateSession is now UpsertSession (3ec81a2)
settings: Change settings success response (12f98f2)
Add intended_for_someone_else error code
(572a131)
Add aal fallback for existing sessions (a5c7b11)
Add authenticators after set up (035c276)
Add DeleteCredentialsType to identity struct including tests (b12bf52)
Add e2e tests for react native 2fa (a3ac253)
Add error ids for csrf-related errors (dc2adbf)
Add error ids for redirect-related errors (246a045)
Add error ids for session-related errors (087d907)
Add explicit return_to to flow objects and API parameters (50d04ea), closes #1605 #1121:
This patch adds a return_to field to the flow objects which contains the
original ?return_to=... value. It uses the Flow's request_url for that
purpose.
Add ids for user-facing errors for login, registration, settings (787558b):
This patch adds a new field id to JSON error payloads. This helps
tremendously in implementing better client-side (native / SPA) apps as the API
now returns error IDs like no_active_session, orbidden_return_to,
no_verified_address and more. UIs can use these IDs to decide what to do
next in the application - for example redirecting to a particular endpoint or
showing an error message.
Add initial value to bool checkboxes (63dba73)
Add internal context to login and registration (723e6ee)
Add internal context to settings flow (afb6895)
Add lookup node to disable lookup (d0836be):
See https://github.com/ory/cloud/issues/12
Add lookup to config (14119b6)
Add lookup to identity (ead3833)
Add lookup to migrations (dac4f75)
Add MFA enforcment option to whoami and settings (554d725)
Add mfa for non-browser (4096fd3)
Add missing migrations (ccc64d8)
Add option to disable recovery codes (9d3daa6):
Closes https://github.com/ory/cloud/issues/12
Add ory cli config (5b959be)
Add schema patch for new initial_value field (131e380):
The field sets a node input's initial value. This is primarily used for fields which are e.g. checkboxes or buttons (active/inactive). If this field is set on a button, it implies that clicking the button should trigger the "value" to be set.
Add script type and discriminator for attributes (de0af95):
See https://github.com/ory/sdk/issues/72
Add smtp headers config option (#1747) (7ffe0e9), closes #1725
Add support for onclick javascript in ui nodes (7cc7efa)
Add totp strategy for settings flow (d1d6617):
This patch allows adding a TOTP device in the settings, and also removing it when no longer needed.
Add webauthn identity credential (f8b9582)
Adjust to new aal error handling (b8956bc)
API to return access, refresh, id tokens from social sign in (#1818) (198991a), closes #1518 #397:
This patch introduces the new include_credential query parameter to the
GET /identities endpoint which allows administrators to receive the initial
access, refresh, and ID tokens from Social Sign In (OpenID Connect / OAuth
2.0) flows.
These tokens can be stored in an encrypted format (XChaCha20Poly1305 or AES-GCM) in the database if an appropriate encryption secret is set. To get started easily these values are not encrypted per default.
For more information head over to the docs.
Endpoint to list all identity schemas (#1703) (aa23d5d), closes #1699
Generate sdks and update versions (c9d22d9)
hash: PBKDF2 password hash verification (#1774) (33cc7e0), closes #1659
Identity schema validation on startup (#1779) (99db3f0), closes #701
identity: Add AAL constants (882573d)
Implement AAL for login and sessions (45467e0)
Implement endpoint for invalidating all sessions for a given identity (#1740) (dbd1689), closes #655:
This PR introduces endpoint to destroy all sessions for a given identity which effectively logouts user from all devices/sessions. This is useful when for some security concern we want to make sure there are no "old" sessions active or other "staff" related actions (such as force logout after password change etc.).
Implement lookup code settings and login (8f3ce7b)
Improve detection of AAL errors and return 422 instead of 403 (e2bfbea)
Improve labels for totp and lookup (b92e00e)
Improve session device annotations (87907b8)
logout: Add logout token to browser response (#1758) (d3f1177)
Mark recovery email address verified (#1665) (e3efc5d), closes #1662
Mark required fiels as required (34cd5e8):
Closes https://github.com/ory-corp/cloud/issues/1328 Closes https://github.com/ory/kratos/issues/400 Closes https://github.com/ory/kratos/issues/1058 See https://ory-community.slack.com/archives/C012RJ2MQ1H/p1631825476159000
Natively support social sign in for single-page apps (1a1a350)
persistence: Add new columns for mfa (6184fe3)
Potentially add arm64 docker support (68112de)
Proper enum and type assertions for openapi (c4d8516)
Publish webauthn as loadable script instead of eval (2717c59)
Redirect on login if session aal is not matched (8feff8d)
Respect webauthn in session aal (869b4a5)
session: Respect 2fa enforcement in whoami (3a82c88)
Sign in with apple (#1833) (16ed123), closes #1782:
Adds an adapter and configuration options for enabling Social Sign In with Apple.
Sort totp nodes (5c9a494)
Stubable time in text package (22e4ed1)
Support apple m1 (54b4fb6)
Support setting the identity state via the admin API (#1805) (29c060b), closes #1767
Support strategy return to ui for settings (74670bb)
Support webauthn for mfa (e8f4d3c)
totp: Add width and height to QR code (a648ba3)
totp: Support account name setting from schema (19a6bcc)
Treat lookup as aal2 in session (3269028)
Use discriminators for ui node types in spec (59e808e)
Use initial_value in lookup strategy (efe272f)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →