NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #245 by repository stars
Last release 2 months ago
29 Jul 2026
Ships on a steady schedule
a new release about every 9 days
Nearly every release is documented
notes for 10 of 10 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
2821 releases · first in 2019
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Resolves further issues in the SDK and release pipeline.
Resolves further issues in the SDK and release pipeline.
Primarily resolves issues in the SDK pipeline.
Primarily resolves issues in the SDK pipeline.
This release adds the GitHub-app provider, improves SQL instrumentation, resolves an expired flow bug, and resolves documentation issues.
This release adds the GitHub-app provider, improves SQL instrumentation, resolves an expired flow bug, and resolves documentation issues.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Ory Kratos was using gorilla/sessions prior to version v1.2 which had a dependency on gorilla/context, a deprecated library with known memory manageme…
This patch resolves a regression issue with Facebook login, a memory leak issue introduced by an external dependency, adds a "requires verification" login hook, and improves performance for some endpoints.
Also, Ory Kratos SDKs are now published in individual GitHub repositories for every language.
Add new message when refresh parameter is true (#1560) (0525623), closes #1117
Add session in spa registration if session cook is configured (#1657) (639a7dd), closes #1604
docs: Ensure config reference is updated (f6b3aa4), closes #1597
Facebook sign in regression (#1689) (85337bf), closes #1687 #1686
Http context memory leak (b21bd22):
Ory Kratos was using gorilla/sessions prior to version v1.2 which had a
dependency on gorilla/context, a deprecated library with known memory
management issues. Even though we used gorilla/context's clean up
middleware, it appears that r.Context() was not properly cleaned up, causing
memory leaks.
On average, the memory leak is pretty small, but depending on what gets added
to r.Context() it could significantly increase the memory leak.
By replacing gorilla/sessions with v1.2.1 we:
Closes https://github.com/ory-corp/cloud/issues/1292
Remove session cookie on logout (#1587) (cdb30bb), closes #1584:
Before, the logout endpoint would invalidate the session cookie, but not remove it. This was a regression introduced in 0.7.0. This patch resolves that issue.
sdk: Use proper annotation for genericError (#1611) (da214b2), closes #1609
Skip prompt on discord authorization by default (#1594) (a667255):
When a value for prompt is not provided, Discord defaults to
prompt="consent". This change makes it so that if the request is not forced,
prompt is explicitly set to "none".
Static parameter for warning message in config.baseURL(...) (#1673) (db54a1b), closes #1672
Update csrf token cookie name (#1601) (64c90bf):
See https://github.com/ory-corp/cloud/issues/1252
Use eager preloading for list identites endpoint (#1588) (de5fb3e)
Fix func naming for Logout flow (#1676) (bbeb613):
rename createSelfServiceLogoutUrlForBrowsers to createSelfServiceLogoutFlowUrlForBrowsers
Make qickstart URLs consistent (playground vs. localhost) (#1626) (bae1847):
Since the quick-start describes how to run Kratos locally the actual location
of the redirect is http://127.0.0.1:4433/self-service/login/browser.
Update docker.md - Outdated information (#1627) (dc32720), closes #1619:
Kratos does not automatically use a config file that exists at
$HOME/.kratos.yaml, or any other similar pattern. The documentation in the
Docker Images section of the guides could lead developers to believe that the
--config flag is unnecessary if they are binding the directory the
configuration file is in to $HOME or using a custom docker image to provide
the file.
Allow multiple webhook body sources (#1606) (51b1311):
This patch adds support for loading webhooks from the local filesystem, base64 encoded inline string, and remote (http/https) sources. Please note that support for relative/absolute paths without an URI scheme are deprecated and will eventually be removed.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release addresses regressions introduced in Ory Kratos v0.7.0 and resolves some bugs and documentation inconsistencies.
This release addresses regressions introduced in Ory Kratos v0.7.0 and resolves some bugs and documentation inconsistencies.
Correct meta schema (8d4f3ff)
Do not set csrf cookies on /sessions/whoami (#1580) (36bbd43)
Generate CSRF token on validation creation (#1549) (6612c5f), closes #1547
Identity extension meta schema (#1554) (ba5ca64):
Up until now the extension meta schema was only applied to top level keys. This fix now recursively checks the extension schema on any depth.
Resolve wrong openapi types (b07927c)
Update identity state openapi spec (0217737)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
For more details on breaking changes and patch notes, see below.
About two months ago we released Ory Kratos v0.6. Today, we are excited to announce the next iteration of Ory Kratos v0.7! This release includes 215 commits from 24 contributors with over 770 files and more than 100.000 lines of code changed!
Ory Kratos v0.7 brings massive developer experience improvements:
In the next iteration of Ory Kratos, we will focus on providing a NextJS example application for the SPA integration as well as the long-awaited MFA flows!
Please be aware that upgrading to Ory Kratos 0.7 requires you to apply SQL migrations. Make sure to back up your database before migration!
For more details on breaking changes and patch notes, see below.
Prior to this change it was not possible to specify the verification/recovery link lifetime. Instead, it was bound to the flow expiry. This patch changes that and adds the ability to configure the lifespan of the link individually:
selfservice:
methods:
link:
enabled: true
config:
+ # Defines how long a recovery link is valid for (default 1h)
+ lifespan: 15m
This is a breaking change because the link strategy no longer respects the recovery / verification flow expiry time and, unless set, will default to one hour.
This change introduces a better SDK. As part of this change, several breaking changes with regards to the SDK have been introduced. We recommend reading this section carefully to understand the changes and how they might affect you.
Before, the SDK was structured into tags public and admin. This stems from
the fact that we have two ports in Ory Kratos - one administrative and one
public port.
While serves as a good overview when working with Ory Kratos, it does not express:
This patch replaces the current admin and public tags with a versioned
approach indicating the maturity of the API used. For example,
initializeSelfServiceSettingsForBrowsers would no longer be under the public
tag but instead under the v0alpha1 tag:
import {
Configuration,
- PublicApi
+ V0Alpha1
} from '@ory/kratos-client';
- const kratos = new PublicApi(new Configuration({ basePath: config.kratos.public }));
+ const kratos = new V0Alpha1(new Configuration({ basePath: config.kratos.public }));
To avoid confusion when setting up the SDK, and potentially using the wrong
endpoints in your codebase and ending up with strange 404 errors, Ory Kratos now
redirects you to the correct port, given that serve.(public|admin).base_url
are configured correctly. This is a significant improvement towards a more
robust API experience!
Further, all administrative functions require, in the Ory SaaS, authorization
using e.g. an Ory Personal Access Token. In the open source, we do not know what
developers use to protect their APIs. As such, we believe that it is ok to have
admin and public functions under one common API and differentiate with an
admin prefix. Therefore, the following patches should be made in your
codebase:
import {
- AdminApi,
+ V0Alpha1,
Configuration
} from '@ory/kratos-client';
-const kratos = new AdminApi(new Configuration({ basePath: config.kratos.admin }));
+const kratos = new V0Alpha1(new Configuration({ basePath: config.kratos.admin }));
-kratos.createIdentity({
+kratos.adminCreateIdentity({
schema_id: 'default',
traits: { /* ... */ }
})
Further, we have introduced a style guide for writing SDKs annotations governing how naming conventions should be chosen.
We also streamlined how credentials are used. We now differentiate between:
Per-request credentials such as the Ory Session Token / Cookie
- public getSelfServiceRegistrationFlow(id: string, cookie?: string, options?: any) {}
+ public getSelfServiceSettingsFlow(id: string, xSessionToken?: string, cookie?: string, options?: any) {}
Global credentials such as the Ory (SaaS) Personal Access Token.
const kratos = new V0Alpha0(
new Configuration({
basePath: config.kratos.admin,
accessToken: "some-token",
}),
)
kratosAdmin.adminCreateIdentity({
schema_id: "default",
traits: {
/* ... */
},
})
We hope you enjoy the vastly improved experience! There are still many things that we want to iterate on. For full context, we recommend reading the proposal and discussion around these changes at kratos#1424.
Additionally, the Self-Service Error endpoint was updated. First, the endpoint
/self-service/errors is now located at the public port only with the admin
port redirecting to it. Second, the parameter ?error was renamed to ?id for
better SDK compatibility. Parameter ?error is still working but will be
deprecated at some point. Third, the response no longer contains an error array
in errors but instead just a single error under error:
{
"id": "60208346-3a61-4880-96ae-0419cde8fca8",
- "errors": [{
+ "error": {
"code": 404,
"status": "Not Found",
"reason": "foobar",
"message": "The requested resource could not be found"
- }],
+ },
"created_at": "2021-07-07T11:20:15.310506+02:00",
"updated_at": "2021-07-07T11:20:15.310506+02:00"
}
This patch introduces CSRF countermeasures for fetching all self-service flows. This ensures that users can not accidentally leak sensitive information when copy/pasting e.g. login URLs (see #1282). If a self-service flow for browsers is requested, the CSRF cookie must be included in the call, regardless if it is a client-side browser app or a server-side browser app calling. This does not apply for API-based flows.
As part of this change, the following endpoints have been removed:
GET <ory-kratos-admin>/self-service/login/flows;GET <ory-kratos-admin>/self-service/registration/flows;GET <ory-kratos-admin>/self-service/verification/flows;GET <ory-kratos-admin>/self-service/recovery/flows;GET <ory-kratos-admin>/self-service/settings/flows.Please ensure that your server-side applications use the public port (e.g.
GET <ory-kratos-public>/self-service/login/flows) for fetching self-service
flows going forward.
If you use the SDKs, upgrading is easy by adding the cookie header when
fetching the flows. This is only required when using browser flows on the
server side.
The following example illustrates a ExpressJS (NodeJS) server-side application fetching the self-service flows.
app.get('some-route', (req: Request, res: Response) => {
- kratos.getSelfServiceLoginFlow(flow).then((flow) => /* ... */ )
+ kratos.getSelfServiceLoginFlow(flow, req.header('cookie')).then((flow) => /* ... */ )
- kratos.getSelfServiceRecoveryFlow(flow).then((flow) => /* ... */ )
+ kratos.getSelfServiceRecoveryFlow(flow, req.header('cookie')).then((flow) => /* ... */ )
- kratos.getSelfServiceRegistrationFlow(flow).then((flow) => /* ... */ )
+ kratos.getSelfServiceRegistrationFlow(flow, req.header('cookie')).then((flow) => /* ... */ )
- kratos.getSelfServiceVerificationFlow(flow).then((flow) => /* ... */ )
+ kratos.getSelfServiceVerificationFlow(flow, req.header('cookie')).then((flow) => /* ... */ )
- kratos.getSelfServiceSettingsFlow(flow).then((flow) => /* ... */ )
+ kratos.getSelfServiceSettingsFlow(flow, undefined, req.header('cookie')).then((flow) => /* ... */ )
})
For concrete details, check out the changes in the NodeJS app.
This patch refactors the logout functionality for browsers and APIs. It adds increased security and DoS-defenses to the logout flow.
Previously, calling GET /self-service/browser/flows/logout would remove the
session cookie and redirect the user to the logout endpoint. Now you have to
make a call to GET /self-service/logout/browser which returns a JSON response
including a logout_url URL to be used for logout. The call to
/self-service/logout/browser must be made using AJAX with cookies enabled or
by including the Ory Session Cookie in the X-Session-Cookie HTTP Header. You
may also use the SDK method createSelfServiceLogoutUrlForBrowsers to do that.
Additionally, the endpoint DELETE /sessions has been moved to
DELETE /self-service/logout/api. Payloads and responses stay equal. The SDK
method revokeSession has been renamed to
submitSelfServiceLogoutFlowWithoutBrowser.
We listened to your feedback and have improved the naming of the SDK method
initializeSelfServiceRecoveryForNativeApps to better match what it does:
initializeSelfServiceRecoveryWithoutBrowser. As in the previous release you
may still use the old SDK if you do not want to deal with the SDK breaking
changes for now.
We listened to your feedback and have improved the naming of the SDK method
initializeSelfServiceVerificationForNativeApps to better match what it does:
initializeSelfServiceVerificationWithoutBrowser. As in the previous release
you may still use the old SDK if you do not want to deal with the SDK breaking
changes for now.
We listened to your feedback and have improved the naming of the SDK method
initializeSelfServiceSettingsForNativeApps to better match what it does:
initializeSelfServiceSettingsWithoutBrowser. As in the previous release you
may still use the old SDK if you do not want to deal with the SDK breaking
changes for now.
We listened to your feedback and have improved the naming of the SDK method
initializeSelfServiceregistrationForNativeApps to better match what it does:
initializeSelfServiceregistrationWithoutBrowser. As in the previous release
you may still use the old SDK if you do not want to deal with the SDK breaking
changes for now.
We listened to your feedback and have improved the naming of the SDK method
initializeSelfServiceLoginForNativeApps to better match what it does:
initializeSelfServiceLoginWithoutBrowser. As in the previous release you may
still use the old SDK if you do not want to deal with the SDK breaking changes
for now.
Add json detection to setting error subbranches (fb83dcb)
Add verification success message (#1526) (126698c), closes #1450
Change SMTP config validation from URI to a Regex pattern (#1436) (5ab1e8f), closes #1435
Check filesystem before fallback to bundled templates (#1401) (22d999e)
Continue button for oidc registration step (2aad5ac), closes #1422 #1320:
When signing up with an OIDC provider and the traits model is missing some fields, the submit button shows all OIDC options. Instead, it should show just one option called "Continue".
Do not run network migrations when booting (12bbab9), closes #1399
Format test files (0468aa1)
Incorrect openapi specification for verification submission (#1431) (ecb0a01), closes #1368
Link t docker guide (953c6d6)
Mark ui node message as optional (#1365) (7b8d59f), closes #1361 #1362
Mark verified_at as omitempty (77b258e):
Closes https://github.com/ory/sdk/issues/46
Panic if contextualizer is not set (760035a)
Recovery email case sensitive (#1357) (bce14c4), closes #1329
Remove changelog (7affb7a)
Remove typing from node.attribute.value (63a5e08):
Closes https://github.com/ory/sdk/issues/75 Closes https://github.com/ory/sdk/issues/74 Closes https://github.com/ory/sdk/issues/72
Rename client package for external consumption (cba8b00)
Resolve build issues on release (7c265a8)
Resolve driver issues (47b1c8d)
Resolve network regression (8f96b1f)
Resolve network regressions (8fc52c0)
Testhelper regressions (bf3b04f)
Use correct url in submitSelfServiceVerificationFlow (ab8a600)
Use session cookie path settings for csrf cookie (#1493) (c6d08ed), closes #1292:
This PR adds configuration option for CSRF cookies and improves the domain alias logic as well as adding tests for it.
Use STARTTLS for smtps connections (#1430) (c21bb80), closes #781
Version schema (#1359) (8c4bac7), closes #1331 #1101 ory/hydra#2427
Add examples for usage of go sdk (870c2bd)
Add GetContextualizer (ac32717)
Add instana as possible tracing provider (#1429) (abe48a9), closes #1385
Add vk and yandex providers to oidc providers and documentation (#1339) (22a3ef9), closes #1234
Anti-CSRF measures when fetching flows (#1458) (5171557), closes #1282
Configurable recovery/verification link lifetime (f80d4e3)
Disable HaveIBeenPwned validation when HaveIBeenPwnedEnabled is set to false (#1445) (44002f4), closes #316:
This patch introduces an option to disable HaveIBeenPwned checks in environments where outbound network calls are disabled.
identities: Add a state to identities (#1312) (d22954e), closes #598
Improve contextualization in serve/daemon (f83cd35)
Include Credentials Metadata in admin api (#1274) (c8b6219), closes #820
Include Credentials Metadata in admin api Missing changes in handler (#1366) (a71c220)
Natively support SPA for login flows (6ff67af), closes #1138 #668:
This patch adds the long-awaited capabilities for natively working with SPAs
and AJAX requests. Previously, requests to the /self-service/login/browser
endpoint would always end up in a redirect. Now, if the Accept header is set
to application/json, the login flow will be returned as JSON instead.
Accordingly, changes to the error and submission flow have been made to
support application/json content types and SPA / AJAX requests.
Natively support SPA for recovery flows (5461244):
This patch adds the long-awaited capabilities for natively working with SPAs
and AJAX requests. Previously, requests to the
/self-service/recovery/browser endpoint would always end up in a redirect.
Now, if the Accept header is set to application/json, the registration
flow will be returned as JSON instead. Accordingly, changes to the error and
submission flow have been made to support application/json content types and
SPA / AJAX requests.
Natively support SPA for registration flows (57d3c57), closes #1138 #668:
This patch adds the long-awaited capabilities for natively working with SPAs
and AJAX requests. Previously, requests to the
/self-service/registration/browser endpoint would always end up in a
redirect. Now, if the Accept header is set to application/json, the
registration flow will be returned as JSON instead. Accordingly, changes to
the error and submission flow have been made to support application/json
content types and SPA / AJAX requests.
Natively support SPA for settings flows (ea4395e):
This patch adds the long-awaited capabilities for natively working with SPAs
and AJAX requests. Previously, requests to the
/self-service/settings/browser endpoint would always end up in a redirect.
Now, if the Accept header is set to application/json, the registration
flow will be returned as JSON instead. Accordingly, changes to the error and
submission flow have been made to support application/json content types and
SPA / AJAX requests.
Natively support SPA for verification flows (c151500):
This patch adds the long-awaited capabilities for natively working with SPAs
and AJAX requests. Previously, requests to the
/self-service/verification/browser endpoint would always end up in a
redirect. Now, if the Accept header is set to application/json, the
registration flow will be returned as JSON instead. Accordingly, changes to
the error and submission flow have been made to support application/json
content types and SPA / AJAX requests.
Support api in settings error (23105db)
Support reading session token from X-Session-Token HTTP header (dcaefd9)
TLS support for public and admin endpoints (#1466) (7f44f81), closes #791
Update openapi specs and regenerate (cac507e)
Add tests for cookie behavior of API and browser endpoints (d1b1521)
e2e: Greatly improve test performance (#1421) (2ffad9e):
Instead of running the individual profiles as separate Cypress instances, we now use one singular instance which updates the Ory Kratos configuration depending on the test context. This ensures that hot-reloading is properly working while also signficantly reducing the amount of time spent on booting up the service dependencies.
e2e: Resolve flaky test issues related to timeouts and speed (b083791)
e2e: Resolve recovery regression (72c47d6)
e2e: Resolve test config regressions (eb9c4f9)
Remove obsolete console.log (3ecc869)
Resolve e2e regressions (b0d3b82)
Resolve migratest panic (89d05ae)
Resolve mobile regressions (868e82e)
Resolve oidc regressions (2403082)
Your coding agent can read these notes before it upgrades. Set up the MCP server →