github.com/thunder-id/thunderid
v1.0.0
#2338 most downloaded on Go modules
thunder-id/thunderid
What this package is like to depend on
Last release today
23 Aug 2026
Ships on a steady schedule
a new release about every 8 days
Rarely documented
notes for 1 of 49 stable releases
Nothing withdrawn
no release was ever pulled
1 years old
450 releases · first in 2025
443 releases in the last 12 months
see the full history below
Release timeline
450 releases · May 2025 to Aug 2026Releases
latest 60 of 450-
v1.0.1-0.20260823233352-7d3a46afd0db23 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260821110906-4e69e014300921 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260821064150-ec15cd2cc65d21 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260820121311-3e657101f79220 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260820073156-f3d27813c1c820 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260820052038-a6b5b5ad934920 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260819190944-f08110b635c719 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260819164121-0cd4a4f42b9119 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260819141243-327f435a240919 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260819113716-02d052ba3bba19 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260819073955-f6d70ee459da19 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260819043326-2b2cace7e48519 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260818165419-7e72d5a4119b18 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260818153636-6ccde7388c7018 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260818120244-9472486aa85a18 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260818081015-489ebdb1e35818 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260818070313-d16ac285294818 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260818053908-2b05d60812c518 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260818031316-394140c2800818 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260817175807-0077914badd617 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260817120242-1097ced3b2dd17 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260817095623-793d41968a8a17 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260817071815-8f7075cdcbf917 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260817052307-cd5f3bc9f88617 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260817025028-2432d40c663517 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260815192843-3edfbc769c5a15 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260815152801-4ac2bdee169e15 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260815081946-9e3217d0d9bb15 Aug 2026 pre-releaseNothing published for this version
-
v1.0.1-0.20260814182620-7069e0532ee414 Aug 2026 pre-releaseNothing published for this version
-
v1.0.013 Aug 2026Release notes
Open source →ThunderID is a lightweight, open-source IAM stack built to secure access for humans, AI agents, and machines.
Designed for the agentic era, ThunderID provides a developer-first IAM stack and supporting tools for securing applications, APIs, services, and agent-driven workflows. It works across traditional and decentralized identity ecosystems, with post-quantum-ready security built in from the start.
Core design goals of ThunderID include:
- Agent-native identity: Manage AI agents as first-class identities with delegated authority, consent-aware access, traceability, and support for issuing verifiable credentials to agents. ThunderID also aims to expose IAM capabilities through interfaces that agents can use safely and programmatically.
- Post-quantum-safe by design: Build on a crypto-agile foundation where algorithms, key types, signing methods, and token protection mechanisms can evolve over time, including support for post-quantum-safe algorithms and hybrid transition approaches across key management, credential issuance, assertions, and secure service-to-service communication.
- Decentralized identity: Bridge the adoption gap for relying parties by making it practical for service providers to consume, verify, and trust decentralized identity in real-world applications, including DIDs, verifiable credentials, digital wallets, trust registries, and issuer-verifier-holder interaction models.
- Lightweight runtime with GitOps support: Provide a lightweight, containerized runtime that can run across on-premises and cloud environments, with declarative identity flows, policies, and configuration suitable for automation, versioning, and GitOps practices.
Getting Started
Get started by exploring how ThunderID can be used to secure:
- Applications - by following Securing B2C Application Guide
- AI Agents - by following Securing AI Agents Guide
- MCP - by following Securing MCP Guide
To learn more about overall requirements, solution patterns of these scenarios, refer to the Use Cases section.
Visit Get ThunderID to learn more about installation methods.
Full Changelog: v1.0.0-rc...v1.0.0
License
Licenses this source under the Apache License, Version 2.0 (LICENSE), You may not use this file except in compliance with the License.
-
v1.0.0-rc.0.20260815062213-b35061baa69815 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-rc.0.20260814122607-1942fa7a077914 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-rc.0.20260814101654-f5593a23fab014 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-rc.0.20260814065026-5531239ee83514 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-rc.0.20260814033701-3e69b403614714 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-rc.0.20260813183257-d6a161d3ba7913 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-rc.0.20260813164807-23b5fd010fb413 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-rc.0.20260813104806-283cae82f0c513 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-rc13 Aug 2026 pre-releaseRelease notes
Open source →ThunderID is a lightweight, open-source IAM stack built to secure access for humans, AI agents, and machines.
Designed for the agentic era, ThunderID provides a developer-first IAM stack and supporting tools for securing applications, APIs, services, and agent-driven workflows. It works across traditional and decentralized identity ecosystems, with post-quantum-ready security built in from the start.
Core design goals of ThunderID include:
- Agent-native identity: Manage AI agents as first-class identities with delegated authority, consent-aware access, traceability, and support for issuing verifiable credentials to agents. ThunderID also aims to expose IAM capabilities through interfaces that agents can use safely and programmatically.
- Post-quantum-safe by design: Build on a crypto-agile foundation where algorithms, key types, signing methods, and token protection mechanisms can evolve over time, including support for post-quantum-safe algorithms and hybrid transition approaches across key management, credential issuance, assertions, and secure service-to-service communication.
- Decentralized identity: Bridge the adoption gap for relying parties by making it practical for service providers to consume, verify, and trust decentralized identity in real-world applications, including DIDs, verifiable credentials, digital wallets, trust registries, and issuer-verifier-holder interaction models.
- Lightweight runtime with GitOps support: Provide a lightweight, containerized runtime that can run across on-premises and cloud environments, with declarative identity flows, policies, and configuration suitable for automation, versioning, and GitOps practices.
Getting Started
Get started by exploring how ThunderID can be used to secure:
- Applications - by following Securing B2C Application Guide
- AI Agents - by following Securing AI Agents Guide
- MCP - by following Securing MCP Guide
To learn more about overall requirements, solution patterns of these scenarios, refer to the Use Cases section.
Visit Get ThunderID to learn more about installation methods.
What's Changed
✨ Improvements
- Fix UI consistency issues by @brionmario in #4693
- Update Google logo to the new gradient mark by @brionmario in #4702
- Add CSP documentation and CSP origin hint component by @Osara-B in #4640
- Add support to handle OTP length configuration in flows by @NipuniBhagya in #4688
- Theme builder fixes by @jeradrutnam in #4809
- Enable AI agent and MCP client options on the Get Started page by @Dilusha-Madushan in #4839
- Enhance CORS management with support to configure regexes by @NipuniBhagya in #4833
- Show organization unit details in application overview by @Dilusha-Madushan in #4845
- Make the user profile endpoint optional for OAuth 2.0 connections by @thiva-k in #4824
- Remove Subject Attribute from API layer by @senthalan in #4892
- Rename default connections displayNames by @jeradrutnam in #4899
- Restore the Delegated mode toggle on the agent Advanced tab by @Dilusha-Madushan in #4923
- Rename google/github flow display names by @ThaminduDilshan in #4925
🐛 Bug Fixes
- Allow SELECT and RESEND elements to be dropped in the flow builder by @PasinduYeshan in #4685
- Fix registration flow template by @Yathusiga27 in #4703
- Set the SMS template on generated MFA OTP send nodes by @PasinduYeshan in #4733
- Roll back the generated sign-in flow when application creation fails by @PasinduYeshan in #4724
- Bootstrap the centered layout and remove the Add Layout action by @ImalshaD in #4760
- Stop the attributes tab from looping renders by @PasinduYeshan in #4765
- Disable adding and deleting resources for read-only resource servers by @rajithacharith in #4786
- Keep the execution node when a button targeting it is deleted by @PasinduYeshan in #4744
- Fix declarative resource server actions listed as server level actions by @rajithacharith in #4785
- Add missing completion screens to email self-invite flow template by @samadhisakunika in #4788
- Remove the unsupported oidc logout endpoint from connections by @thiva-k in #4808
- Apply default flow element variants by @Yathusiga27 in #4784
- Update agent token edit section's monaco setup by @thiva-k in #4804
- Correct allowed user types copy to describe sign-up by @PasinduYeshan in #4766
- Render OTP and magic link expiry as a human readable duration by @ZiyamSanthosh in #4797
- Add authorization executor to generated application sign-in flows by @ImalshaD in #4812
- Fix agent use case setup in the npx CLI by @Dilusha-Madushan in #4818
- Fix Self Sign-Up walkthrough copy in the console application tryout by @PasinduYeshan in #4819
- Hide the non-functional column filter in Console list pages by @Dilusha-Madushan in #4820
- Show the seeded admin in the home Add Users card by @PasinduYeshan in #4823
- Hide existing group members from add tabs by @Yathusiga27 in #4731
- Clear resource permissions when a child action is unselected by @thiva-k in #4816
- Name the issued credential on the one-time secret screen by @ZiyamSanthosh in #4790
- Apply one length rule to all resource names and handles by @PasinduYeshan in #4813
- Gate the edit page Set as default action on resource server type. by @ImalshaD in #4844
- Remove app's registration/ recovery flow when it's disabled by @ThaminduDilshan in #4840
- Resolve bindingMessage in SMS executor for CIBA flows by @thiva-k in #4843
- Fix groups listing pagination by @Yathusiga27 in #4782
- Fix Magic Link widget connection by @PasinduYeshan in #4851
- Sanitize export template variable names by @ZiyamSanthosh in #4794
- Add support for alphanumeric OTP input handling by @NipuniBhagya in #4817
- Prompt for mobile number before generating SMS OTP in signup and signin by @samadhisakunika in #4647
- Hide empty connection category filters by @PasinduYeshan in #4849
- Retain dynamic prompt inputs when a paused prompt is re-rendered by @ZiyamSanthosh in #4837
- Cascade resource, action and resource server deletions to role permissions by @thiva-k in #4834
- Fix retry button label and message pluralization on import summary by @ZiyamSanthosh in #4846
- Hide the recovery flow section from the agent edit page by @Dilusha-Madushan in #4850
- Fix user creation for user types with boolean and number attributes by @thiva-k in #4852
- Fix OTP numeric-only checkbox to match backend default by @ThaminduDilshan in #4860
- Fix incorrect GitHub connection scopes hint by @floze-the-genius in #4783
- Fix Groups/Roles/VC production crash from un-externalized logger subpath by @brionmario in #4863
- Show specific error messages for user onboarding flow failures by @Dilusha-Madushan in #4866
- Add authorization and credential state check on refresh grant by @thiva-k in #4861
- Include roles in the consent prompt attribute list by @thiva-k in #4876
- Remove b2c try it out coming soon tiles by @ThaminduDilshan in #4890
- Fix some UI inconsistencies by @jeradrutnam in #4900
- Revoke the access token on sign out in Console by @brionmario in #4894
- Enable refresh token rotation by default and bound the grant lifetime by @thiva-k in #4926
- Template missing configurations in helm chart by @rajithacharith in #4927
New Contributors
- @lashinijay made their first contribution in #4815
- @floze-the-genius made their first contribution in #4783
- @ShanChathusanda93 made their first contribution in #4534
Full Changelog: v1.0.0-beta2...v1.0.0-rc
License
Licenses this source under the Apache License, Version 2.0 (LICENSE), You may not use this file except in compliance with the License.
-
v1.0.0-beta2.0.20260813060353-570b46cd6d4013 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-beta2.0.20260813043606-f482ede8557a13 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-beta2.0.20260812170922-668c17199cba12 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-beta2.0.20260812132410-51be3c98b1c512 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-beta2.0.20260812095154-4a6a1537a82212 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-beta2.0.20260812072022-a1a88482191912 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-beta2.0.20260812064217-85e3531ca28312 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-beta2.0.20260812055831-136bea80a9e112 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-beta2.0.20260811191617-06c671a0abf511 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-beta2.0.20260811191525-5befa08ef79e11 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-beta2.0.20260811180934-1175d9bdd53411 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-beta2.0.20260811151047-e1a198d96dde11 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-beta2.0.20260811141402-b6f2a124d5d711 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-beta2.0.20260811124443-4a204c94671511 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-beta2.0.20260811091323-990e5ca24cb111 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-beta2.0.20260811082333-c6d000c43a2a11 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-beta2.0.20260811070400-5d87fef4705711 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-beta2.0.20260810120915-ba37ccd8c63110 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-beta2.0.20260810095229-2d1df9d2c57a10 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-beta2.0.20260810064043-b3736ff51c1f10 Aug 2026 pre-releaseNothing published for this version
-
v1.0.0-beta2.0.20260810052126-628754e317c010 Aug 2026 pre-releaseNothing published for this version