--- snapshot-1791032837+++ snapshot-1791054438@@ -6,7 +6,7 @@
v1.44.0
-
id when creating a user, so IDs such as auth0|abc123 survive a migration. The Management API can also look up users by their external identity.theme authentication parameter: Pass theme=light or theme=dark to keep the sign-in experience in sync with your app's own theme toggle.Users who complete MFA can now choose to trust their browser and skip repeated MFA prompts there.
GET /api/users/{userId}/trusted-devices and DELETE /api/users/{userId}/trusted-devices/{trustedDeviceId}. Users manage their own devices in Account Center (field control: Off, Read-only, or Edit) or through the Account API at /api/my-account/trusted-devices with the urn:logto:scope:trusted_devices scope.TrustedDevice.Created and TrustedDevice.Deleted webhooks. Audit logs record TrustedDevice.Created and TrustedDevice.Used.A trusted device only fulfills the MFA step of a sign-in. It does not satisfy identity verification, account recovery, or other sensitive account operations. See MFA trusted devices.
users.id and every column that references it were limited to 12 or 21 characters. They now accept up to 128 characters.POST /api/users accepts an optional id of up to 128 characters (letters, numbers, and _ - . @ : + = |). Use it to preserve IDs such as auth0|abc123 or UUIDs when migrating from another identity provider. If the ID is taken, the request fails with user.id_already_in_use. Logto Cloud does not support this. See Keep existing user IDs.GET /api/users accepts identityType, identityProvider, and identityId for exact lookup. Use identityType=social with a connector target (such as dingtalk), or identityType=sso with an enterprise SSO issuer, together with the user identifier issued by that provider. The identity filter combines with other search filters using AND logic. See Look up by external identity. Thanks to @JunWang666 (#9572).Cap is an open-source, self-hosted proof-of-work CAPTCHA. It needs no third-party service, so bot protection keeps working in regions where Cloudflare Turnstile and Google reCAPTCHA are unreachable or unreliable.
PUT /api/captcha-provider with type: "Cap".While Cap is the CAPTCHA provider, the sign-in page's Content Security Policy allows the Cap instance and dynamic JavaScript evaluation, which Cap's instrumentation challenge requires. Thanks to @imJack6 for the request (#9404).
Set the minimum accepted score (0.0 to 1.0) for reCAPTCHA Enterprise in Console > Security > CAPTCHA to control how strict verification is. The threshold was previously fixed at 0.5. It applies to invisible mode. Checkbox mode is unaffected.
authnRequestConfig.forceAuthn to false through the SAML application Management API. The service provider can still require fresh authentication for a single sign-in with ForceAuthn="true".authnRequestConfig.requireSignedAuthnRequests to true and provide the service provider's PEM-encoded RSA X.509 certificate in authnRequestConfig.signingCertificate. Both HTTP-POST and HTTP-Redirect signatures are verified, and the IdP metadata advertises the requirement. Unsigned requests remain accepted by default.theme authentication parameterPass theme=light or theme=dark as an extra authentication parameter to render the sign-in experience in that theme instead of following the end user's OS setting. Applications with their own light/dark toggle can now keep Logto in sync.
The override lasts for the whole authentication flow, including page reloads, social and SSO callbacks, and the consent page. It is ignored when dark mode is disabled in the sign-in experience settings, and unsupported values are ignored.
This setting applies only to dynamic apps: clients that use an OAuth Client ID Metadata Document (CIMD) URL as their client_id. Applications registered in Logto are not affected.
MCP clients such as ChatGPT and Codex follow the MCP authorization spec, which only asks them to request the offline_access scope. They don't send prompt=consent, and without it Logto drops offline_access as OpenID Connect Core requires. These clients get no refresh token, so users have to sign in again whenever the access token expires.
Turn on Add consent prompt for offline access under Client compatibility in the dynamic app settings. Logto then adds consent to the prompt of dynamic app authorization requests that ask for offline_access without it. Requests with prompt=none are left unchanged. The setting is experimental and off by default, and audit logs show the added consent in prompt.
@logto/api)Pagination iterator: paginate() returns a typed async iterator over paginated GET endpoints, following the Management API pagination headers.
for await (const user of apiClient.paginate('/api/users')) { console.log(user); }Reliability:
401 responses.Ergonomics:
.get() and .post(), with the uppercase methods still available.translate="no" and .user.sign_in_method_not_enabled and left the user stuck.https://idp.example.com/ and https://idp.example.com now resolve to the same discovery URL. The stored issuer stays exactly as configured, so existing SSO identities keep resolving. Failed outbound requests from OIDC SSO connectors now report a concise reason.none prompt validation: OIDC configuration no longer allows combining the none prompt with other prompt values.invalid_client. Setup instructions cover the Apple Developer portal, so Sign in with Apple no longer appears to require Xcode. Troubleshooting covers invalid_client and invalid_request, including Apple's identifier configuration cache, which can take up to 24 hours to refresh.corpId from the DingTalk token response is now preserved in the social user information rawData.api.twilio.com.users.id and every column that references it to varchar(128). After upgrading, run the database alteration command (npm run alteration deploy in the @logto/cli/core image, or logto db alteration deploy) before starting the new version. See the upgrade guide.id to POST /api/users works in self-hosted Logto only.logto db seed now checks for the PostgreSQL roles it needs before creating tables. If roles from a previous Logto database remain in the cluster, the command reports the conflict and explains why dropping the database did not remove them, so you can clean them up safely before retrying.Huge thanks to the community members whose work shipped in this release:
theme authentication parameter (#9645)none prompt validation (#9596) and DingTalk corpId in rawData (#9622) (first contribution)Full Changelog: v1.43.0...v1.44.0
silverhand-bot tag:github.com,2008:Repository/378310716/@logto/phrases@1.32.0 2026-09-30T06:52:48Z +
id when creating a user, so IDs such as auth0|abc123 survive a migration. The Management API can also look up users by their external identity.theme authentication parameter: Pass theme=light or theme=dark to keep the sign-in experience in sync with your app's own theme toggle.Users who complete MFA can now choose to trust their browser and skip repeated MFA prompts there.
GET /api/users/{userId}/trusted-devices and DELETE /api/users/{userId}/trusted-devices/{trustedDeviceId}. Users manage their own devices in Account Center (field control: Off, Read-only, or Edit) or through the Account API at /api/my-account/trusted-devices with the urn:logto:scope:trusted_devices scope.TrustedDevice.Created and TrustedDevice.Deleted webhooks. Audit logs record TrustedDevice.Created and TrustedDevice.Used.A trusted device only fulfills the MFA step of a sign-in. It does not satisfy identity verification, account recovery, or other sensitive account operations. See MFA trusted devices.
users.id and every column that references it were limited to 12 or 21 characters. They now accept up to 128 characters.POST /api/users accepts an optional id of up to 128 characters (letters, numbers, and _ - . @ : + = |). Use it to preserve IDs such as auth0|abc123 or UUIDs when migrating from another identity provider. If the ID is taken, the request fails with user.id_already_in_use. Logto Cloud does not support this. See Keep existing user IDs.GET /api/users accepts identityType, identityProvider, and identityId for exact lookup. Use identityType=social with a connector target (such as dingtalk), or identityType=sso with an enterprise SSO issuer, together with the user identifier issued by that provider. The identity filter combines with other search filters using AND logic. See Look up by external identity. Thanks to @JunWang666 (#9572).Cap is an open-source, self-hosted proof-of-work CAPTCHA. It needs no third-party service, so bot protection keeps working in regions where Cloudflare Turnstile and Google reCAPTCHA are unreachable or unreliable.
PUT /api/captcha-provider with type: "Cap".While Cap is the CAPTCHA provider, the sign-in page's Content Security Policy allows the Cap instance and dynamic JavaScript evaluation, which Cap's instrumentation challenge requires. Thanks to @imJack6 for the request (#9404).
Set the minimum accepted score (0.0 to 1.0) for reCAPTCHA Enterprise in Console > Security > CAPTCHA to control how strict verification is. The threshold was previously fixed at 0.5. It applies to invisible mode. Checkbox mode is unaffected.
authnRequestConfig.forceAuthn to false through the SAML application Management API. The service provider can still require fresh authentication for a single sign-in with ForceAuthn="true".authnRequestConfig.requireSignedAuthnRequests to true and provide the service provider's PEM-encoded RSA X.509 certificate in authnRequestConfig.signingCertificate. Both HTTP-POST and HTTP-Redirect signatures are verified, and the IdP metadata advertises the requirement. Unsigned requests remain accepted by default.theme authentication parameterPass theme=light or theme=dark as an extra authentication parameter to render the sign-in experience in that theme instead of following the end user's OS setting. Applications with their own light/dark toggle can now keep Logto in sync.
The override lasts for the whole authentication flow, including page reloads, social and SSO callbacks, and the consent page. It is ignored when dark mode is disabled in the sign-in experience settings, and unsupported values are ignored.
This setting applies only to dynamic apps: clients that use an OAuth Client ID Metadata Document (CIMD) URL as their client_id. Applications registered in Logto are not affected.
MCP clients such as ChatGPT and Codex follow the MCP authorization spec, which only asks them to request the offline_access scope. They don't send prompt=consent, and without it Logto drops offline_access as OpenID Connect Core requires. These clients get no refresh token, so users have to sign in again whenever the access token expires.
Turn on Add consent prompt for offline access under Client compatibility in the dynamic app settings. Logto then adds consent to the prompt of dynamic app authorization requests that ask for offline_access without it. Requests with prompt=none are left unchanged. The setting is experimental and off by default, and audit logs show the added consent in prompt.
@logto/api)Pagination iterator: paginate() returns a typed async iterator over paginated GET endpoints, following the Management API pagination headers.
for await (const user of apiClient.paginate('/api/users')) { console.log(user); }Reliability:
401 responses.Ergonomics:
.get() and .post(), with the uppercase methods still available.translate="no" and .user.sign_in_method_not_enabled and left the user stuck.https://idp.example.com/ and https://idp.example.com now resolve to the same discovery URL. The stored issuer stays exactly as configured, so existing SSO identities keep resolving. Failed outbound requests from OIDC SSO connectors now report a concise reason.none prompt validation: OIDC configuration no longer allows combining the none prompt with other prompt values.invalid_client. Setup instructions cover the Apple Developer portal, so Sign in with Apple no longer appears to require Xcode. Troubleshooting covers invalid_client and invalid_request, including Apple's identifier configuration cache, which can take up to 24 hours to refresh.corpId from the DingTalk token response is now preserved in the social user information rawData.api.twilio.com.users.id and every column that references it to varchar(128). After upgrading, run the database alteration command (npm run alteration deploy in the @logto/cli/core image, or logto db alteration deploy) before starting the new version. See the upgrade guide.id to POST /api/users works in self-hosted Logto only.logto db seed now checks for the PostgreSQL roles it needs before creating tables. If roles from a previous Logto database remain in the cluster, the command reports the conflict and explains why dropping the database did not remove them, so you can clean them up safely before retrying.Huge thanks to the community members whose work shipped in this release:
theme authentication parameter (#9645)none prompt validation (#9596) and DingTalk corpId in rawData (#9622) (first contribution)Full Changelog: v1.43.0...v1.44.0
silverhand-bot tag:github.com,2008:Repository/378310716/@logto/phrases@1.32.0 2026-09-30T06:52:48Z @logto/phrases@1.32.0