NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev · #1609 most downloaded on pub.dev
Serverpod core authentication client module.
Last release today
06 Oct 2026
Ships fairly regularly
a new release about every 2 weeks
Nearly every release is documented
notes for 29 of 29 stable releases
Nothing withdrawn
no release was ever pulled
1 years old
56 releases · first in 2025
One column per month.
Nothing published for this version
fix: Adds serverpod clean command to delete stale cached server kernels.
serverpod clean command to delete stale cached server kernels.SetNull and SetDefault relation actions against the foreign key column type.CLAUDE.md in favor of AGENTS.md.fix: Prints the reason why serverpod start stopped after the TUI ends with an error.
serverpod start stopped after the TUI ends with an error.futureCall.executionEnabled.futureCall.enabled flag to completely disable scheduling future calls.fix: Adds missing callbacks to ServerpodCloudEmailIdpConfig constructor.
ServerpodCloudEmailIdpConfig constructor.ServerpodCloudStorage custom storageIds.postgres library to improve performance and security.fix: Fixes github/workflows/tests.yml tests on the template project. (@dario-valles)
github/workflows/tests.yml tests on the template project. (@dario-valles)initialize() when the auth validation times out.maxFileSize.fix: BREAKING. Removes the deprecated authenticationKeyManager client parameter.
Serverpod 4 is a major overhaul of the development experience. It introduces a new development experience with an interactive command that boots your entire stack, makes Serverpod projects agent-ready out of the box, and lays the foundation for client-side databases with the new SQLite dialect.
Serverpod projects are now set up for AI-assisted development from the moment they are created. The CLI ships with an MCP server, skills and agent instructions installed for the IDEs/Agents you select. The MCP server exposes all tools from serverpod start to agents for an immersive agentic development experience. Try out the reworked serverpod create and the new serverpod quickstart commands.
serverpod start commandServerpod 4 introduces serverpod start, a single command that runs everything your project needs and keeps it in sync while you work. No more juggling docker compose, serverpod generate --watch, the server and the Flutter app in separate terminals.
Key features include:
Running a database locally no longer requires any setup. Serverpod now ships custom PostgreSQL multi-platform binaries built with pgvector and postgis support that can be run in embedded mode when running the server or started standalone with serverpod database start. Projects that do not configure the dataPath parameter on the database config get the docker compose started automatically by serverpod start instead.
The same models, ORM and migrations you already know can now generate a client-side SQLite database when using the new database keyword. Migrations for the client are separate and generated as Dart code for easy integration in Flutter apps without having to deal with assets.
To allow easily building offline-first Flutter apps, the experimental database: sync option will configure the models for synchronization with the server using the serverpod_offline_sync module. No other configuration is needed beyond annotating the models and adding the dependencies to the client and server. Check the serverpod_offline_sync README for more details on how to use it.
ServerpodClientException hierarchy to introduce a proper exception for network errors. Previous HTTP-related exceptions now extend the sealed ServerpodClientHttpException class.*withOptions methods on the CloudStorage interface.RateLimiter utility on the serverpod_auth_idp module..spy.yaml extension for model files.authenticationKeyManager client parameter.orderDescending parameter on ORM methods.ignoreEndpoint annotation from the CLI.SerializationManagerServer class.--mini option from the serverpod create command.database: sync models.table keyword on shared package models configured with database: all.upsert and upsertRow methods on the ORM. (@sedobrengocce)noReturn parameter to all ORM methods to allow skipping the returning the data.orderBy and orderByList in delete and deleteWhere methods. (@henycave)asc() / desc() convenience methods on orderable columns.databaseInterceptor parameter to Serverpod for intercepting database operations.dynamic fields on models, database and endpoints.jsonb columns and GIN indexes, with lossless json <-> jsonb column type migration. (@developerjamiu)Iterable and operator[] on vector types.serial on regular int columns on PostgreSQL.nulls_distinct key on unique indexes on PostgreSQL.unique keyword and unique(per=...) variant on models for simplified creation of unique indexes.column name on models, with proper migration support.fk flag for declaring the owner of the foreign key on a relation.field= on relations that require the explicit foreign key.deferred and deferrable flags on relations to postpone constraints evaluation inside transactions.tail keyword on models to configure the order of inherited fields.extends and sealed properties on Exception models.serverpod into the new serverpod_database package.ORDER BY in nested includeList queries with LIMIT.Order objects in favor of the new asc() / desc() methods.enableDatabaseAccess config.serverpod_cloud_storage package for native Serverpod Cloud provider support.withSession method on Serverpod for manual session usage with automatic teardown. (@nicowalter256)global cache fallback to local in development/testing.httpOnly cookie authentication for web clients.WidgetRoute.build method to return WebWidget? and easily throw a 404.httpClientOverride on the generated Client for HTTP client override.serverDirectory parameter on Serverpod to avoid depending on Directory.current.MessageCentral when streams are cancelled before session close.StateError instead of Exception for not configured features. (@realmeylisdev)private, no-cache for all files.Serverpod.shutdown not releasing ProcessSignal watchers after in-process shutdown/start calls.ServerpodCloudEmailIdpConfig as default email IDP using Serverpod Cloud.FlutterWebAuth2RedirectRoute for OAuth2 PKCE web sign-in flow.onAfterAccountCreated callbacks to all IDPs for custom post-account creation logic. (@kamil-matula)HmacSha256 JWT algorithm on the auth core package.kid to JWT header for ES512 tokens.UserProfile creation during first login if an exception occurs.onRefreshTokenCreated to JwtConfigFromPasswords constructor.SignInWidget and EmailSignInWidget not being transparent.Material wrapper to the SignInWidget for correct rendering when not using a Material app.TermsAndPrivacyText sign-in widget respond to app theming.serverpod create command to customize the created project.scloud through the new serverpod cloud command.ghcr.io/serverpod/postgres:16.dart test using withServerpod.Serverpod class for cleaner initialization.serverpod command.--empty flag to the create-migration command.serverpod upgrade, and prevents accidental downgrades.flutter_build during create command.serverpod_cli on CI.dart format clean respecting the project options.generate for the first time from a clean state.testObjectToJson return type from dynamic to Map<String, dynamic>. (@realmeylisdev)detach and detachRow for named list relations without order dependence.--watch flag by 15x and the regular generate command by 20%.generate command to avoid redundant work. Use --force to bypass.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
fix: BREAKING. Fixes Apple on legacy auth accepting unverified identities. Deployments using Sign in with Apple must set appleClientIds on AuthConfig
appleClientIds
on AuthConfig to their bundle and services ids. Backported to 2.9.5.UserInfo and, therefore, won't merge with other sign-in options. Backported to 2.9.5.StaticRoute and SpaRoute from env vars.fix: Fixes Google Sign-In accepting an access token minted for a different OAuth client that could be used to takeover an account.
FlutterRoute from env vars.fix: Adds missing export of DeepCollectionEquality for shared models.
DeepCollectionEquality for shared models.fix: Fixes malformed query when negating many-relation filters. (@realmeylisdev)
fix: Fixes joins with long column names and deeply nested relations not mapping the correct columns.
fix: Fixes Postgres throwing when using row-lock on find* methods with includes.
find* methods with includes.fix: Fixes constraints drop failing on Postgres due to already removed columns.
configOverride forward to the test server.chore: Bumps jose dependency on legacy auth to fix CVE-2026-34240. Also backported to 2.9.3.
PasswordMissingException..gitignore on created projects to ignore the .dart_tool of the workspace.serverpod create . in the current directory.insert with ignoreConflicts and !persist fields atomic.onSessionCreated to ServerSideSessionsConfigFromPasswords constructor.jose dependency on legacy auth to fix CVE-2026-34240. Also backported to 2.9.3.fix: Truncates logged error messages to prevent hanging on formatter issues during code generation.
flutter_secure_storage override from the workspace to the created Flutter package on a new project.fix: Fixes Google Sign-In not handling error when invoked directly from the controller.
refactor: Changes the session parameter type on repository methods to DatabaseSession.
session parameter type on repository methods to DatabaseSession._Undefined class when parent sealed classes have nullable fields and children have only non-nullable fields.Cache class import after relic upgrade to version 1.2.0.fix: Fixes wrong import URL to serverpod_service_client of shared models referenced as fields in other shared models.
serverpod_service_client of shared models referenced as fields in other shared models.Protocol class from an external package.DROP CONSTRAINT when referenced table is dropped via CASCADE.fix: Fixes shared models using inexistent toJsonForProtocol method if referenced as fields on models with !persist or serverOnly fields.
toJsonForProtocol method if referenced as fields on models with !persist or serverOnly fields.Serverpod 3.4 comes with two long-awaited features: shared models between server and client and allowing caching any type of object to the local/Redis
Serverpod 3.4 comes with two long-awaited features: shared models between server and client and allowing caching any type of object to the local/Redis cache. It also brings two new Identity Providers (Facebook and Microsoft), a complete revamp to the cloud storage system, ignore conflicts on inserts and row-level locking on the database, shell completion support to the CLI and more improvements to the developer experience.
ignoreConflicts parameter of the insert method. (@FXschwartz)find* and lockRows methods. (@FXschwartz)Session parameter.expired filter and limit parameter to ServerSideSessions.listSessions.AuthUsersConfig to AnonymousIdp. (@craiglabenz)serverpod_cloud_storage_s3_compat base package for S3-compatible storage integrations.serverpod_cloud_storage_gcp package with Application Default Credentials support.serverpod_cloud_storage_r2 package for Cloudflare R2.preventOverwrite, maxFileSize, contentLength, and expirationDuration for finer upload control.serverpod_cloud_storage_s3_compat package..vscode/launch.json with a composite project as default for full-stack debugging.fix: Fixes text of GitHub IDP button not aligning correctly when using the left alignment. (@vfiruz97)
tokenExpiresAt info on AuthSuccess for server-side sessions.Serverpod 3.3 brings a lot of new features and improvements to the framework, including two new identity providers (GitHub and Anonymous), virtual hos
Serverpod 3.3 brings a lot of new features and improvements to the framework, including two new identity providers (GitHub and Anonymous), virtual host routing, a robust Kubernetes-ready monitoring system, JSON key aliases and enum properties on models, and several improvements to logging.
The Anonymous IDP is currently experimental and can not be completely used yet due to the missing support for account linking. The missing parts will be added in the next releases.
livez, readyz, and startupz with support for custom health checks.jsonKey aliases in models to use in JSON serialization and deserialization. (@FXschwartz)fields key missing under indexes.const defaults for Duration and Uuid().v#obj() types.server.--serverId not being properly propagated to logs.async functions.VerificationCodeConfig in the serverpod_auth_idp_flutter package with no extra imports. (@NeroSong)fix: Fixes flutter_build script on the template project for Windows.
flutter_build script on the template project for Windows.fix: Fixes generated future calls producing import paths with backslashes on Windows.
serverpod generate timer frozen while command is running.fix: Moves the Firebase IDP into a separate package to avoid unexpected compilation issues for non-users of the IDP.
Firebase IDP into a separate package to avoid unexpected compilation issues for non-users of the IDP.feat: Propagates deprecated annotations from endpoint parameters to generated client code.
Serverpod 3.2 brings a completely reworked experience for future calls, enhanced platform support on serverpod run, the new Firebase identity provider and several minor improvements.
FutureCall experience with scheduling from generated type-safe classes (@Crazelu).getServerUrl function to the serverpod_flutter package.Serverpod class as deprecated in favor of the new type-safe API.Firebase identity provider to the authentication module.PasswordNotFoundException instead of null assertion in JWT and ServerSideSessions token managers.EmailSignInWidget default start screen to favor user conversion.UserProfile and AuthUser model variants.serverpod run command.dart install).fix: Fixes unknown encodings crashing the CLI when creating a new project.
Serverpod 3.1 focuses on improving the developer experience with new tooling, enhanced Flutter web support, and important bug fixes.
Serverpod 3.1 focuses on improving the developer experience with new tooling, enhanced Flutter web support, and important bug fixes.
FlutterRoute.serverpod run command for running scripts.WidgetRoute.validateHeaders config option for backward compatibility with Serverpod 2 clients.PasswordNotFoundException instead of null assertion in IDP *FromPassword config classes./**) is the default for StaticRoute.directory.serverOnly models.serverpod prefix.fix: Allows the server address to be specified without trailing slash on the client.
indexes key on non-table base models to allow inheritance of indexes.fix: BREAKING. Removes methods previously marked as deprecated.
Serverpod 3 is a major overhaul of the authentication system and the web server.
Serverpod 3 introduces a fully reworked web server with improved performance, additional features, and increased extensibility. Built on top of the Relic framework, it provides a more robust and flexible foundation for building web applications.
Key improvements include:
A new authentication module has been developed based on the authentication RFC. It provides a more flexible and robust foundation and significantly simplifies adding new identity providers.
Highlights:
AuthUser class representing the authenticated user, their scopes, and all associated authentication tokens — extensible with custom user dataNew packages:
serverpod_auth_core — Core authentication logic and session managementserverpod_auth_idp — Identity provider integrations (Email, Google, Apple, Passkey)serverpod_auth_bridge — Migration bridge for legacy auth (Email currently supported)serverpod_auth_migration — Tools and helpers for migrating auth data (Email currently supported)Serverpod now supports polymorphism on models and endpoints. This allows you to define a base class that can be extended by other classes using the extends keyword. The server will automatically handle the serialization and deserialization both to the database and in client server communication.
id field for table models for serverOnly models.--force flag.0 when no migrations are needed.byIndex to byName.Headers class for configuring headers in the Serverpod server.SerializableEntity class.userIdentifier parameter in AuthenticationInfo from Object to String.context parameter to request in Route.call and Route.handleCall methods.FlutterRoute and SpaRoute to simplify routing in single page applications.values to the TemplateWidget class.Request from all session Session object through the request getter.-d / --directory flag to the serverpod generate command.immutable keyword in models to generate immutable models. (obiwanzenobi, @kamil-matula)updateWhere and updateById methods.required field keyword on nullable fields in model and exception definitions.@unauthenticatedClientCall annotation for endpoints.~ operator on expressions to perform NOT expression.development mode.authKeyProvider interface to support multiple authentication key formats.generator.yaml configuration file.SessionLogEntry.time field now uses session start time.SIGTERM graceful shutdown.connectionTimeout final to prevent post-initialization mutation.session.authenticated synchronous.debug in development mode.@deprecated annotation was not propagated to test framework endpoints.{@template} markers were not removed from generated endpoint documentation.@internal.serverpod create execution.public parameter to file upload description (@LeonidVeremchuk)WebWidget now uses HTML instead of plainText as the default mimeType.AuthenticationKeyManager as deprecated in favour of the new ClientAuthKeyProvider interface.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →