--- snapshot-1791032837+++ snapshot-1791054438@@ -6,7 +6,7 @@ v1.44.0 -logto-changelog-2026-09

Highlights

New features & enhancements

MFA trusted devices

Users who complete MFA can now choose to trust their browser and skip repeated MFA prompts there.

A trusted device only fulfills the MFA step of a sign-in. It does not satisfy identity verification, account recovery, or other sensitive account operations. See MFA trusted devices.

Keep existing user IDs when migrating

Bot protection

Cap as a self-hosted CAPTCHA provider

Cap is an open-source, self-hosted proof-of-work CAPTCHA. It needs no third-party service, so bot protection keeps working in regions where Cloudflare Turnstile and Google reCAPTCHA are unreachable or unreliable.

  1. Deploy a publicly reachable Cap Standalone instance and create a site key.
  2. Go to Console > Security > CAPTCHA and add Cap with the instance endpoint, site key, and secret key. The same configuration is available through PUT /api/captcha-provider with type: "Cap".

While Cap is the CAPTCHA provider, the sign-in page's Content Security Policy allows the Cap instance and dynamic JavaScript evaluation, which Cap's instrumentation challenge requires. Thanks to @imJack6 for the request (#9404).

reCAPTCHA Enterprise score threshold

Set the minimum accepted score (0.0 to 1.0) for reCAPTCHA Enterprise in Console > Security > CAPTCHA to control how strict verification is. The threshold was previously fixed at 0.5. It applies to invisible mode. Checkbox mode is unaffected.

Authentication policies for SAML applications

theme authentication parameter

Pass theme=light or theme=dark as an extra authentication parameter to render the sign-in experience in that theme instead of following the end user's OS setting. Applications with their own light/dark toggle can now keep Logto in sync.

The override lasts for the whole authentication flow, including page reloads, social and SSO callbacks, and the consent page. It is ignored when dark mode is disabled in the sign-in experience settings, and unsupported values are ignored.

Refresh tokens for dynamic app clients

This setting applies only to dynamic apps: clients that use an OAuth Client ID Metadata Document (CIMD) URL as their client_id. Applications registered in Logto are not affected.

MCP clients such as ChatGPT and Codex follow the MCP authorization spec, which only asks them to request the offline_access scope. They don't send prompt=consent, and without it Logto drops offline_access as OpenID Connect Core requires. These clients get no refresh token, so users have to sign in again whenever the access token expires.

Turn on Add consent prompt for offline access under Client compatibility in the dynamic app settings. Logto then adds consent to the prompt of dynamic app authorization requests that ask for offline_access without it. Requests with prompt=none are left unchanged. The setting is experimental and off by default, and audit logs show the added consent in prompt.

Management API SDK (@logto/api)

Bug fixes & stability

Sign-in experience

Enterprise SSO and OIDC

Console

Connectors

Self-hosting & OSS notes

Contributors

Huge thanks to the community members whose work shipped in this release:

Full Changelog: v1.43.0...v1.44.0

silverhand-bot tag:github.com,2008:Repository/378310716/@logto/phrases@1.32.0 2026-09-30T06:52:48Z +logto-changelog-2026-09

Highlights

New features & enhancements

MFA trusted devices

Users who complete MFA can now choose to trust their browser and skip repeated MFA prompts there.

A trusted device only fulfills the MFA step of a sign-in. It does not satisfy identity verification, account recovery, or other sensitive account operations. See MFA trusted devices.

Keep existing user IDs when migrating

Bot protection

Cap as a self-hosted CAPTCHA provider

Cap is an open-source, self-hosted proof-of-work CAPTCHA. It needs no third-party service, so bot protection keeps working in regions where Cloudflare Turnstile and Google reCAPTCHA are unreachable or unreliable.

  1. Deploy a publicly reachable Cap Standalone instance and create a site key.
  2. Go to Console > Security > CAPTCHA and add Cap with the instance endpoint, site key, and secret key. The same configuration is available through PUT /api/captcha-provider with type: "Cap".

While Cap is the CAPTCHA provider, the sign-in page's Content Security Policy allows the Cap instance and dynamic JavaScript evaluation, which Cap's instrumentation challenge requires. Thanks to @imJack6 for the request (#9404).

reCAPTCHA Enterprise score threshold

Set the minimum accepted score (0.0 to 1.0) for reCAPTCHA Enterprise in Console > Security > CAPTCHA to control how strict verification is. The threshold was previously fixed at 0.5. It applies to invisible mode. Checkbox mode is unaffected.

Authentication policies for SAML applications

theme authentication parameter

Pass theme=light or theme=dark as an extra authentication parameter to render the sign-in experience in that theme instead of following the end user's OS setting. Applications with their own light/dark toggle can now keep Logto in sync.

The override lasts for the whole authentication flow, including page reloads, social and SSO callbacks, and the consent page. It is ignored when dark mode is disabled in the sign-in experience settings, and unsupported values are ignored.

Refresh tokens for dynamic app clients

This setting applies only to dynamic apps: clients that use an OAuth Client ID Metadata Document (CIMD) URL as their client_id. Applications registered in Logto are not affected.

MCP clients such as ChatGPT and Codex follow the MCP authorization spec, which only asks them to request the offline_access scope. They don't send prompt=consent, and without it Logto drops offline_access as OpenID Connect Core requires. These clients get no refresh token, so users have to sign in again whenever the access token expires.

Turn on Add consent prompt for offline access under Client compatibility in the dynamic app settings. Logto then adds consent to the prompt of dynamic app authorization requests that ask for offline_access without it. Requests with prompt=none are left unchanged. The setting is experimental and off by default, and audit logs show the added consent in prompt.

Management API SDK (@logto/api)

Bug fixes & stability

Sign-in experience

Enterprise SSO and OIDC

Console

Connectors

Self-hosting & OSS notes

Contributors

Huge thanks to the community members whose work shipped in this release:

Full Changelog: v1.43.0...v1.44.0

silverhand-bot tag:github.com,2008:Repository/378310716/@logto/phrases@1.32.0 2026-09-30T06:52:48Z @logto/phrases@1.32.0