megachangelog
ZITADEL logo

ZITADEL Changelog

ZITADEL — Auth, Security product updates and releases, tracked on megachangelog.


Update4.19.0

v4.19.0 Release

This release includes a bug fix for eventstore that omits owners on empty unique constraint inserts, and a feature to remove application constraints by app owner in the eventstore.

eventstorebugfixconstraintsdatabase
Announcement4.18.0

v4.18.0

Release 4.18.0 includes bug fixes for eventstore unique constraints and projection event skipping, login improvements with external IdP support and startup API credential verification, new database metrics publishing, telemetry enhancements for Google attributes, and query performance improvements for user list operations.

eventstoreloginperformancetelemetrydatabase
Fix4.17.3

v4.17.3 Bug Fixes

This release includes critical bug fixes for encryption of IDP intent tokens, IDP linking authorization logic, translation of authentication strings, and organization-level auth method permissions.

securityauthenticationidpcryptobugfix
Fix4.17.2

v4.17.2

This release includes bug fixes for caching and relations of well-known app link files, cross-instance caching prevention, console support for Zitadel Support IDP, login flow improvements including proper IdP URL handling and account selection after logout, OIDC token exchange enhancements, and TOTP reuse prevention for improved security.

apioidcloginsecurityidp
Fix3.4.15

Bug fixes for passkey enrollment and MFA prompt

Fixed permission checks when issuing passkey enrollment codes and updated the login flow to require MFA prompt step before 2FA enrollment to improve security.

securitypasskeymfaauthenticationbugfix
Fix4.17.1

v4.17.1 Bug Fixes

This release fixes multiple security and authentication issues: blocks Login V2 auth for deactivated organizations, enforces permission checks for passkey enrollment, prevents unwanted OTP requests, and requires MFA prompt before 2FA enrollment.

securityauthmfaloginbugfix
Feature4.17.0

ZITADEL v4.17.0

This release adds support for Zitadel as an identity provider with full CRUD operations, dynamic OIDC client registration and management per RFC 7591/7592, native passkey app links, and numerous bug fixes including improvements to login flows, metadata handling, and database operations.

idpoidcsecurityloginapi
Fix4.16.2

v4.16.2 Bug Fixes and Performance Improvements

This release includes critical security fixes for login flows including prevention of external-IDP account hijacking and required authentication before enrollment, plus improvements to random string generation and ListUsers query performance.

securityloginperformanceidpauth
Fix4.16.1

v4.16.1 Bug Fixes

Bug fixes including prevention of disk access via require in actions, improved password complexity messaging, fixed submit button state during password set operations, and prevented crash from stale session cookies.

bug-fixsecurityloginconsolestability
Announcement4.16.0

v4.16.0

ZITADEL v4.16.0 includes multiple bug fixes for token exchange scope validation, user grants management, login UI improvements, and IDP handling, plus new features for invite code management in secret generators and FIPS 140-3 compliant crypto builds.

authloginidpperformancesecurity
Fix4.15.3

Bug fixes in token exchange, email verification, and login flows

This release includes fixes for client and scope validation in token exchange, ensures external users' emails are verified before auto-linking, centers text for IDP buttons without icons, and guards the default redirect URI in OIDC/SAML failure paths.

securityauthoidcsamlbug-fix
Fix3.4.12

JWT IdP validation improvements and client_id verification

Fixed JWT IdP token validation to always check exp and iat claims, added client_id verification during code exchange and refresh token flows, and improved JWT IdP audience management and validation.

securityjwtidpauthvalidation
Fix4.15.2

v4.15.2

Bug fixes including JWT IdP claim validation, client ID verification during OAuth flows, connection handling after migrations, PKCE application for OAuth/OIDC providers, and JWT audience management. Also improves login handling for passkey registration and custom font loading in branding.

securityoauthjwtidplogin
Fix3.4.11

Check permission based on provided data on user updates

Fixed a permission check issue where user update operations were not correctly validating permissions based on the actual provided data, which could have allowed unauthorized modifications.

apipermissionssecurityusers

Sign up to see more

15 more changes from ZITADEL. Sign up to read the whole changelog.

Sign up free

GitHub or email — no card needed.