NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #1925 most downloaded on NuGet
EntityFramework persistence layer for Duende IdentityServer
Last release 10 days ago
28 Sep 2026
Release timing varies
gaps range from 8 days to 3 months
Some releases are documented
notes for 15 of 43 stable releases
51 versions withdrawn
withdrawn after publishing
127 years old
94 releases · first in 1900
This is a security patch release of IdentityServer that hardens validation of pushed authorization requests (PAR). We recommend all 8.0.x users upgrad
This is a security patch release of IdentityServer that hardens validation of pushed authorization requests (PAR). We recommend all 8.0.x users upgrade.
client_id does not exactly match the authenticated client, as required by RFC 9126. Custom IPushedAuthorizationRequestValidator implementations remain responsible for enforcing this binding.AllowUnregisteredPushedRedirectUris. These clients do not authenticate at the PAR endpoint, so they must register their redirect URIs.AllowUnregisteredPushedRedirectUris is enabled, unregistered redirect URIs must now use the https scheme and must not match ValidationOptions.InvalidRedirectUriPrefixes. Registered redirect URIs, loopback handling, and custom redirect URI validators are unchanged.https PAR redirect URIs (for example http://localhost during local development) must be registered or moved to https.Full Changelog: is-8.0.8...is-8.0.9
Duende IdentityServer 8.0.9 Latest
Latest
Compare
One column per quarter.
A patch release containing some SAML bug fixes and improvements. Also, based on customer feedback regarding logging in Identity Server, we have reduc
A patch release containing some SAML bug fixes and improvements. Also, based on customer feedback regarding logging in Identity Server, we have reduced the severity of select log messages.
Note: We are currently auditing all Identity Server log levels and will roll out further adjustments in upcoming releases.
SAML: Adds configurable outbound AuthnRequest signing when IdentityServer acts as a SAML service provider. Both static and dynamic provider configurations can select Never or Always, with safe defaults, certificate-presence validation, consistent metadata, and persisted dynamic-provider behavior.
SAML logout sessions currently use the protected logout-message handle as their database lookup key. That protected value grows with serialized logout state and can exceed the nvarchar(200) column, causing SAML logout to fail with a truncation error.
Fixed issue when calling both AddInMemoryClients and AddInMemorySamlProviders that the last call overwrites the first call.
This is a patch release of IdentityServer that fixes the following issue:
This is a patch release of IdentityServer that fixes the following issue:
This is a patch release of IdentityServer that fixes the following issue:
This is a patch release of IdentityServer that fixes the following issue:
DiagnosticHostedService failed when certain delegate-based options were configured (e.g., dynamic provider path matching)This is a patch release of IdentityServer that fixes the following issue:
This is a patch release of IdentityServer that fixes the following issue:
This is a patch release of IdentityServer that adds support for IDP-initiated SSO when IdentityServer acts as a SAML Service Provider.
This is a patch release of IdentityServer that adds support for IDP-initiated SSO when IdentityServer acts as a SAML Service Provider.
AddSamlServiceProvider() or dynamic SAML providers), it can now receive unsolicited authentication responses from upstream identity providers. Configure AllowUnsolicitedAuthnResponse = true and set IdpInitiatedCallbackUrl to your external login callback endpoint.AuthenticationProperties.Items["relayState"], allowing your callback to use it for routing, tenant resolution, or other application logic.MaxRelayStateLength (default 1024 bytes) controls the maximum size of RelayState that will be persisted in authentication properties, preventing cookie bloat from oversized values.https://duendesoftware.com/Saml2. Users with active SAML SP sessions at the time of upgrade may experience failed single logout correlation until they re-authenticate. This only affects deployments using the SAML Service Provider feature (AddSamlServiceProvider() or dynamic SAML providers).Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This is a security patch release of IdentityServer that hardens validation of pushed authorization requests (PAR). We recommend all 7.4.x users upgrad
This is a security patch release of IdentityServer that hardens validation of pushed authorization requests (PAR). We recommend all 7.4.x users upgrade.
client_id does not exactly match the authenticated client, as required by RFC 9126. Custom IPushedAuthorizationRequestValidator implementations remain responsible for enforcing this binding.AllowUnregisteredPushedRedirectUris. These clients do not authenticate at the PAR endpoint, so they must register their redirect URIs.AllowUnregisteredPushedRedirectUris is enabled, unregistered redirect URIs must now use the https scheme and must not match ValidationOptions.InvalidRedirectUriPrefixes. Registered redirect URIs, loopback handling, and custom redirect URI validators are unchanged.https PAR redirect URIs (for example http://localhost during local development) must be registered or moved to https.Full Changelog: is-7.4.12...is-7.4.13
Based on customer feedback regarding logging in Identity Server, we have reduced the severity of select log messages:
Based on customer feedback regarding logging in Identity Server, we have reduced the severity of select log messages:
Note: We are currently auditing all Identity Server log levels and will roll out further adjustments in upcoming releases.
This is a patch release of IdentityServer that fixes the following issue:
This is a patch release of IdentityServer that fixes the following issue:
DiagnosticHostedService failed when certain delegate-based options were configured (e.g., dynamic provider path matching)This is a patch release of IdentityServer that fixes the following issue:
This is a patch release of IdentityServer that fixes the following issue:
This is a patch release of identity server that fixes the following issue:
This is a patch release of identity server that fixes the following issue:
Microsoft.Bcl.Memory dependency for net8.0 to resolve .NET 8 runtime failures at discovery and related endpoints.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This is a security patch release of IdentityServer that hardens validation of pushed authorization requests (PAR). We recommend all 7.3.x users upgrad
This is a security patch release of IdentityServer that hardens validation of pushed authorization requests (PAR). We recommend all 7.3.x users upgrade.
client_id does not exactly match the authenticated client, as required by RFC 9126. Custom IPushedAuthorizationRequestValidator implementations remain responsible for enforcing this binding.AllowUnregisteredPushedRedirectUris. These clients do not authenticate at the PAR endpoint, so they must register their redirect URIs.AllowUnregisteredPushedRedirectUris is enabled, unregistered redirect URIs must now use the https scheme and must not match ValidationOptions.InvalidRedirectUriPrefixes. Registered redirect URIs, loopback handling, and custom redirect URI validators are unchanged.https PAR redirect URIs (for example http://localhost during local development) must be registered or moved to https.Full Changelog: is-7.3.4...is-7.3.5
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This is a security patch release of IdentityServer that hardens validation of pushed authorization requests (PAR). We recommend all 7.2.x users upgrad
This is a security patch release of IdentityServer that hardens validation of pushed authorization requests (PAR). We recommend all 7.2.x users upgrade.
client_id does not exactly match the authenticated client, as required by RFC 9126. Custom IPushedAuthorizationRequestValidator implementations remain responsible for enforcing this binding.AllowUnregisteredPushedRedirectUris. These clients do not authenticate at the PAR endpoint, so they must register their redirect URIs.AllowUnregisteredPushedRedirectUris is enabled, unregistered redirect URIs must now use the https scheme and must not match ValidationOptions.InvalidRedirectUriPrefixes. Registered redirect URIs, loopback handling, and custom redirect URI validators are unchanged.https PAR redirect URIs (for example http://localhost during local development) must be registered or moved to https.Full Changelog: is-7.2.4...is-7.2.5
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This is a security patch release of IdentityServer that hardens validation of pushed authorization requests (PAR). We recommend all 7.1.x users upgrad
This is a security patch release of IdentityServer that hardens validation of pushed authorization requests (PAR). We recommend all 7.1.x users upgrade.
client_id does not exactly match the authenticated client, as required by RFC 9126. Custom IPushedAuthorizationRequestValidator implementations remain responsible for enforcing this binding.AllowUnregisteredPushedRedirectUris. These clients do not authenticate at the PAR endpoint, so they must register their redirect URIs.AllowUnregisteredPushedRedirectUris is enabled, unregistered redirect URIs must now use the https scheme and must not match ValidationOptions.InvalidRedirectUriPrefixes. Registered redirect URIs, loopback handling, and custom redirect URI validators are unchanged.https PAR redirect URIs (for example http://localhost during local development) must be registered or moved to https.Full Changelog: is-7.1.1...is-7.1.3
Nothing published for this version
Nothing published for this version
This is a security patch release of IdentityServer that hardens validation of pushed authorization requests (PAR). We recommend all 7.0.x users upgrad
This is a security patch release of IdentityServer that hardens validation of pushed authorization requests (PAR). We recommend all 7.0.x users upgrade.
client_id does not exactly match the authenticated client, as required by RFC 9126. Custom IPushedAuthorizationRequestValidator implementations remain responsible for enforcing this binding.AllowUnregisteredPushedRedirectUris. These clients do not authenticate at the PAR endpoint, so they must register their redirect URIs.AllowUnregisteredPushedRedirectUris is enabled, unregistered redirect URIs must now use the https scheme and must not match ValidationOptions.InvalidRedirectUriPrefixes. Registered redirect URIs, loopback handling, and custom redirect URI validators are unchanged.https PAR redirect URIs (for example http://localhost during local development) must be registered or moved to https.Full Changelog: f28cac9...is-7.0.10
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →