Try our Chrome extension
Easily add the current web-page from your browser directly into your changedetection.io tool, more great features coming soon!Changedetection.io needs your support!
You can help us by supporting changedetection.io on these platforms;
- Rate us at AlternativeTo.net
- Star us on GitHub
- Follow us at Twitter/X
- G2 Software reviews
- Check us out on LinkedIn
- And tell your friends and colleagues :)
The more popular changedetection.io is, the more time we can dedicate to adding amazing features!
Many thanks :)
changedetection.io team
Not yet seconds ago
False
Not yet seconds ago
Triggered text Ignored text Blocked text
25 minutes ago
tag:github.com,2008:https://github.com/logto-io/logto/releases
Release notes from logto
2026-09-30T06:52:45Z tag:github.com,2008:Repository/378310716/v1.44.0 2026-09-30T07:40:17Z
v1.44.0
<a target="_blank" rel="noopener noreferrer" href="https://private-user-images.githubusercontent.com/10806653/661952531-16b11f26-0c2a-4601-8562-174e5015519b.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3OTEwNTQ3MzgsIm5iZiI6MTc5MTA1NDQzOCwicGF0aCI6Ii8xMDgwNjY1My82NjE5NTI1MzEtMTZiMTFmMjYtMGMyYS00NjAxLTg1NjItMTc0ZTUwMTU1MTliLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNjEwMDMlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjYxMDAzVDE5MDcxOFomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTczZjM4M2ZhZDY0ZDUzM2NjNzY2OTRhODM1MDhkYjU1N2UxM2I3YWJhMDk1NTFhNzlhMWRmOTFjNjVkZTUwMGMmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0JnJlc3BvbnNlLWNvbnRlbnQtdHlwZT1pbWFnZSUyRnBuZyJ9.4Fi7CFUYbqnadsZgIdF8t4SP-XQnIhoejP2sZHJ-f6A"><img width="1060" height="596" alt="logto-changelog-2026-09" src="https://private-user-images.githubusercontent.com/10806653/661952531-16b11f26-0c2a-4601-8562-174e5015519b.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3OTEwNTQ3MzgsIm5iZiI6MTc5MTA1NDQzOCwicGF0aCI6Ii8xMDgwNjY1My82NjE5NTI1MzEtMTZiMTFmMjYtMGMyYS00NjAxLTg1NjItMTc0ZTUwMTU1MTliLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNjEwMDMlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjYxMDAzVDE5MDcxOFomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTczZjM4M2ZhZDY0ZDUzM2NjNzY2OTRhODM1MDhkYjU1N2UxM2I3YWJhMDk1NTFhNzlhMWRmOTFjNjVkZTUwMGMmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0JnJlc3BvbnNlLWNvbnRlbnQtdHlwZT1pbWFnZSUyRnBuZyJ9.4Fi7CFUYbqnadsZgIdF8t4SP-XQnIhoejP2sZHJ-f6A" content-type-secured-asset="image/png" style="max-width: 100%; height: auto; max-height: 596px;"></a> <h2>Highlights</h2> <ul> <li><strong>MFA trusted devices</strong>: After completing MFA, users can trust their browser and skip repeated MFA prompts on it. Admins set the policy for the whole tenant, restrict it per organization, and manage devices from Console, Account Center, and the APIs.</li> <li><strong>Keep your user IDs when migrating</strong>: User IDs can now be up to 128 characters, and self-hosted Logto accepts a custom <code>id</code> when creating a user, so IDs such as <code>auth0|abc123</code> survive a migration. The Management API can also look up users by their external identity.</li> <li><strong>Cap, a self-hosted CAPTCHA</strong>: Use <a href="https://capjs.js.org" rel="nofollow">Cap</a> for bot protection where Cloudflare Turnstile and Google reCAPTCHA are unreachable or unreliable. reCAPTCHA Enterprise also gets a configurable score threshold.</li> <li><strong>Authentication policies for SAML applications</strong>: Let a SAML application reuse an existing Logto session, require signed authentication requests, and get the actual authentication time in assertions.</li> <li><strong><code>theme</code> authentication parameter</strong>: Pass <code>theme=light</code> or <code>theme=dark</code> to keep the sign-in experience in sync with your app's own theme toggle.</li> <li><strong>Refresh tokens for dynamic app clients</strong>: A new client compatibility setting for dynamic apps (CIMD) lets MCP clients such as ChatGPT and Codex receive refresh tokens, so users stop having to sign in again every time the access token expires. Applications registered in Logto are not affected.</li> </ul> <h2>New features & enhancements</h2> <h3>MFA trusted devices</h3> <p>Users who complete MFA can now choose to trust their browser and skip repeated MFA prompts there.</p> <ul> <li><strong>Tenant policy</strong>: Enable trusted devices in <strong>Console > Multi-factor authentication</strong> and set a trust duration from 1 to 365 days (default: 30). The policy is off by default.</li> <li><strong>Organization restrictions</strong>: An organization can disallow trusted devices for its members. This only tightens the tenant policy.</li> <li><strong>Trust this device page</strong>: After an eligible MFA verification or setup, users see a dedicated page at the end of sign-in or sign-up, where they can trust the browser for the configured duration or skip.</li> <li><strong>Device management</strong>: Admins view and remove a user's trusted devices in <strong>Console > User management</strong> or through <code>GET /api/users/{userId}/trusted-devices</code> and <code>DELETE /api/users/{userId}/trusted-devices/{trustedDeviceId}</code>. Users manage their own devices in Account Center (field control: Off, Read-only, or Edit) or through the Account API at <code>/api/my-account/trusted-devices</code> with the <code>urn:logto:scope:trusted_devices</code> scope.</li> <li><strong>Webhooks and audit logs</strong>: Subscribe to <code>TrustedDevice.Created</code> and <code>TrustedDevice.Deleted</code> webhooks. Audit logs record <code>TrustedDevice.Created</code> and <code>TrustedDevice.Used</code>.</li> </ul> <p>A trusted device only fulfills the MFA step of a sign-in. It does not satisfy identity verification, account recovery, or other sensitive account operations. See <a href="https://docs.logto.io/end-user-flows/mfa/trusted-devices" rel="nofollow">MFA trusted devices</a>.</p> <h3>Keep existing user IDs when migrating</h3> <ul> <li><strong>Longer user IDs</strong>: <code>users.id</code> and every column that references it were limited to 12 or 21 characters. They now accept up to 128 characters.</li> <li><strong>Custom user ID on create</strong> (Logto OSS only): <code>POST /api/users</code> accepts an optional <code>id</code> of up to 128 characters (letters, numbers, and <code>_ - . @ : + = |</code>). Use it to preserve IDs such as <code>auth0|abc123</code> or UUIDs when migrating from another identity provider. If the ID is taken, the request fails with <code>user.id_already_in_use</code>. Logto Cloud does not support this. See <a href="https://docs.logto.io/user-management/user-migration#keep-existing-user-ids" rel="nofollow">Keep existing user IDs</a>.</li> <li><strong>Look up users by external identity</strong>: <code>GET /api/users</code> accepts <code>identityType</code>, <code>identityProvider</code>, and <code>identityId</code> for exact lookup. Use <code>identityType=social</code> with a connector target (such as <code>dingtalk</code>), or <code>identityType=sso</code> with an enterprise SSO issuer, together with the user identifier issued by that provider. The identity filter combines with other search filters using AND logic. See <a href="https://docs.logto.io/user-management/advanced-user-search#look-up-by-external-identity" rel="nofollow">Look up by external identity</a>. Thanks to <a href="https://github.com/JunWang666">@JunWang666</a> (<a href="https://github.com/logto-io/logto/pull/9572" data-hovercard-type="pull_request" data-hovercard-url="/logto-io/logto/pull/9572/hovercard">#9572</a>).</li> </ul> <h3>Bot protection</h3> <h4>Cap as a self-hosted CAPTCHA provider</h4> <p><a href="https://capjs.js.org" rel="nofollow">Cap</a> is an open-source, self-hosted proof-of-work CAPTCHA. It needs no third-party service, so bot protection keeps working in regions where Cloudflare Turnstile and Google reCAPTCHA are unreachable or unreliable.</p> <ol> <li>Deploy a publicly reachable <a href="https://capjs.js.org/guide/standalone/" rel="nofollow">Cap Standalone</a> instance and create a site key.</li> <li>Go to <strong>Console > Security > CAPTCHA</strong> and add Cap with the instance endpoint, site key, and secret key. The same configuration is available through <code>PUT /api/captcha-provider</code> with <code>type: "Cap"</code>.</li> </ol> <p>While Cap is the CAPTCHA provider, the sign-in page's Content Security Policy allows the Cap instance and dynamic JavaScript evaluation, which Cap's instrumentation challenge requires. Thanks to <a href="https://github.com/imJack6">@imJack6</a> for the request (<a href="https://github.com/logto-io/logto/issues/9404" data-hovercard-type="issue" data-hovercard-url="/logto-io/logto/issues/9404/hovercard">#9404</a>).</p> <h4>reCAPTCHA Enterprise score threshold</h4> <p>Set the minimum accepted score (0.0 to 1.0) for reCAPTCHA Enterprise in <strong>Console > Security > CAPTCHA</strong> to control how strict verification is. The threshold was previously fixed at 0.5. It applies to invisible mode. Checkbox mode is unaffected.</p> <h3>Authentication policies for SAML applications</h3> <ul> <li><strong>Session reuse</strong>: SAML applications still force fresh authentication by default. To let an application reuse an existing Logto session, turn off <strong>Always force authentication</strong> in the application settings, or set <code>authnRequestConfig.forceAuthn</code> to <code>false</code> through the SAML application Management API. The service provider can still require fresh authentication for a single sign-in with <code>ForceAuthn="true"</code>.</li> <li><strong>Actual authentication time</strong>: SAML assertions now report when the user actually authenticated.</li> <li><strong>Signed authentication requests</strong>: Set <code>authnRequestConfig.requireSignedAuthnRequests</code> to <code>true</code> and provide the service provider's PEM-encoded RSA X.509 certificate in <code>authnRequestConfig.signingCertificate</code>. Both HTTP-POST and HTTP-Redirect signatures are verified, and the IdP metadata advertises the requirement. Unsigned requests remain accepted by default.</li> </ul> <h3><code>theme</code> authentication parameter</h3> <p>Pass <code>theme=light</code> or <code>theme=dark</code> as an extra authentication parameter to render the sign-in experience in that theme instead of following the end user's OS setting. Applications with their own light/dark toggle can now keep Logto in sync.</p> <p>The override lasts for the whole authentication flow, including page reloads, social and SSO callbacks, and the consent page. It is ignored when dark mode is disabled in the sign-in experience settings, and unsupported values are ignored.</p> <h3>Refresh tokens for dynamic app clients</h3> <p>This setting applies only to dynamic apps: clients that use an OAuth Client ID Metadata Document (CIMD) URL as their <code>client_id</code>. Applications registered in Logto are not affected.</p> <p>MCP clients such as ChatGPT and Codex follow the MCP authorization spec, which only asks them to request the <code>offline_access</code> scope. They don't send <code>prompt=consent</code>, and without it Logto drops <code>offline_access</code> as OpenID Connect Core requires. These clients get no refresh token, so users have to sign in again whenever the access token expires.</p> <p>Turn on <strong>Add consent prompt for offline access</strong> under <strong>Client compatibility</strong> in the dynamic app settings. Logto then adds <code>consent</code> to the <code>prompt</code> of dynamic app authorization requests that ask for <code>offline_access</code> without it. Requests with <code>prompt=none</code> are left unchanged. The setting is experimental and off by default, and audit logs show the added <code>consent</code> in <code>prompt</code>.</p> <h3>Management API SDK (<code>@logto/api</code>)</h3> <ul> <li> <p><strong>Pagination iterator</strong>: <code>paginate()</code> returns a typed async iterator over paginated <code>GET</code> endpoints, following the Management API pagination headers.</p> <div class="highlight highlight-source-ts notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="for await (const user of apiClient.paginate('/api/users')) { console.log(user); }"><pre><span class="pl-k">for</span> <span class="pl-k">await</span> <span class="pl-kos">(</span><span class="pl-k">const</span> <span class="pl-s1">user</span> <span class="pl-k">of</span> <span class="pl-s1">apiClient</span><span class="pl-kos">.</span><span class="pl-en">paginate</span><span class="pl-kos">(</span><span class="pl-s">'/api/users'</span><span class="pl-kos">)</span><span class="pl-kos">)</span> <span class="pl-kos">{</span> <span class="pl-smi">console</span><span class="pl-kos">.</span><span class="pl-en">log</span><span class="pl-kos">(</span><span class="pl-s1">user</span><span class="pl-kos">)</span><span class="pl-kos">;</span> <span class="pl-kos">}</span></pre></div> </li> <li> <p><strong>Reliability</strong>:</p> <ul> <li>Token requests reject redirects, support custom abort signals and a configurable 10-second timeout, and concurrent requests share one token fetch.</li> <li>A rejected cached token is invalidated once, without fetching tokens over and over for permanent <code>401</code> responses.</li> <li>Management API network requests get a configurable 10-second timeout while keeping per-request cancellation.</li> <li>Scope mismatch warnings are emitted once per distinct scope, and token request failures keep their cause.</li> </ul> </li> <li> <p><strong>Ergonomics</strong>:</p> <ul> <li>Object-style Management API client configuration with a tenant ID, or an explicit base URL and API indicator.</li> <li>Lowercase client methods such as <code>.get()</code> and <code>.post()</code>, with the uppercase methods still available.</li> <li>Trailing slashes in custom base URLs are normalized.</li> </ul> </li> </ul> <h2>Bug fixes & stability</h2> <h3>Sign-in experience</h3> <ul> <li><strong>Browser auto-translation no longer blanks the page</strong>: When a browser auto-translated the sign-in page, React's DOM updates could fail and leave the user on a blank page mid sign-in. The experience is already localized per tenant, so the page now opts out of browser auto-translation with <code>translate="no"</code> and <code><meta name="google" content="notranslate"></code>.</li> <li><strong>Social account linking</strong>: When a required secondary identifier (such as a phone number) is already used by another account during social sign-up, the "link and continue" option now only appears if that identifier can sign in with a verification code. Previously, linking failed with <code>user.sign_in_method_not_enabled</code> and left the user stuck.</li> </ul> <h3>Enterprise SSO and OIDC</h3> <ul> <li><strong>Trailing slash in OIDC SSO issuers</strong>: <code>https://idp.example.com/</code> and <code>https://idp.example.com</code> now resolve to the same discovery URL. The stored issuer stays exactly as configured, so existing SSO identities keep resolving. Failed outbound requests from OIDC SSO connectors now report a concise reason.</li> <li><strong><code>none</code> prompt validation</strong>: OIDC configuration no longer allows combining the <code>none</code> prompt with other prompt values.</li> <li><strong>API error message language</strong>: API error messages fall back to the base language when the requested regional language is unavailable.</li> </ul> <h3>Console</h3> <ul> <li><strong>Webhook test results</strong>: Test results are now stored per webhook, so a result from one webhook no longer appears on another webhook's details page.</li> </ul> <h2>Connectors</h2> <ul> <li><strong>Apple</strong>: The identifier field is now labeled <strong>Services ID</strong> and explains that an App ID (bundle ID) is rejected by Apple with <code>invalid_client</code>. Setup instructions cover the Apple Developer portal, so Sign in with Apple no longer appears to require Xcode. Troubleshooting covers <code>invalid_client</code> and <code>invalid_request</code>, including Apple's identifier configuration cache, which can take up to 24 hours to refresh.</li> <li><strong>DingTalk (web)</strong>: <code>corpId</code> from the DingTalk token response is now preserved in the social user information <code>rawData</code>.</li> <li><strong>Twilio SMS</strong>: New optional API host configuration, for example to send through a Twilio region other than the default <code>api.twilio.com</code>.</li> </ul> <h2>Self-hosting & OSS notes</h2> <ul> <li><strong>Database migration required</strong>: This release ships two schema alterations. One adds an authentication request configuration column to SAML application configs. The other widens <code>users.id</code> and every column that references it to <code>varchar(128)</code>. After upgrading, run the database alteration command (<code>npm run alteration deploy</code> in the <code>@logto/cli</code>/core image, or <code>logto db alteration deploy</code>) before starting the new version. See the <a href="https://docs.logto.io/logto-oss/upgrading-oss-version" rel="nofollow">upgrade guide</a>.</li> <li><strong>Rolling back the user ID alteration</strong>: Reverting the user ID alteration fails if any stored user ID is longer than the previous 12 or 21 character limit.</li> <li><strong>Custom user IDs are OSS only</strong>: Passing <code>id</code> to <code>POST /api/users</code> works in self-hosted Logto only.</li> <li><strong>Cap requires your own instance</strong>: Cap needs a publicly reachable Cap Standalone instance. The Content Security Policy is relaxed only while Cap is the active CAPTCHA provider.</li> <li><strong>Database seeding checks for leftover roles</strong>: <code>logto db seed</code> now checks for the PostgreSQL roles it needs before creating tables. If roles from a previous Logto database remain in the cluster, the command reports the conflict and explains why dropping the database did not remove them, so you can clean them up safely before retrying.</li> </ul> <h2>Contributors</h2> <p>Huge thanks to the community members whose work shipped in this release:</p> <ul> <li><a href="https://github.com/JunWang666">@JunWang666</a> - user lookup by external identity (<a href="https://github.com/logto-io/logto/pull/9572" data-hovercard-type="pull_request" data-hovercard-url="/logto-io/logto/pull/9572/hovercard">#9572</a>) (first contribution)</li> <li><a href="https://github.com/Igor-Techsee">@Igor-Techsee</a> - authentication policies for SAML applications (<a href="https://github.com/logto-io/logto/pull/9563" data-hovercard-type="pull_request" data-hovercard-url="/logto-io/logto/pull/9563/hovercard">#9563</a>) (first contribution)</li> <li><a href="https://github.com/konlanx">@konlanx</a> - <code>theme</code> authentication parameter (<a href="https://github.com/logto-io/logto/pull/9645" data-hovercard-type="pull_request" data-hovercard-url="/logto-io/logto/pull/9645/hovercard">#9645</a>)</li> <li><a href="https://github.com/Kathircpe">@Kathircpe</a> - reCAPTCHA Enterprise score threshold (<a href="https://github.com/logto-io/logto/pull/9323" data-hovercard-type="pull_request" data-hovercard-url="/logto-io/logto/pull/9323/hovercard">#9323</a>)</li> <li><a href="https://github.com/nicolaj0">@nicolaj0</a> - browser auto-translation opt-out (<a href="https://github.com/logto-io/logto/pull/9591" data-hovercard-type="pull_request" data-hovercard-url="/logto-io/logto/pull/9591/hovercard">#9591</a>) (first contribution)</li> <li><a href="https://github.com/Tyagiquamar">@Tyagiquamar</a> - OIDC <code>none</code> prompt validation (<a href="https://github.com/logto-io/logto/pull/9596" data-hovercard-type="pull_request" data-hovercard-url="/logto-io/logto/pull/9596/hovercard">#9596</a>) and DingTalk <code>corpId</code> in <code>rawData</code> (<a href="https://github.com/logto-io/logto/pull/9622" data-hovercard-type="pull_request" data-hovercard-url="/logto-io/logto/pull/9622/hovercard">#9622</a>) (first contribution)</li> <li><a href="https://github.com/ryanchou1994">@ryanchou1994</a> - leftover PostgreSQL role check before database seeding (<a href="https://github.com/logto-io/logto/pull/9573" data-hovercard-type="pull_request" data-hovercard-url="/logto-io/logto/pull/9573/hovercard">#9573</a>) (first contribution)</li> <li><a href="https://github.com/toyeshhm">@toyeshhm</a> - Kakao and Naver connector README fixes (<a href="https://github.com/logto-io/logto/pull/9666" data-hovercard-type="pull_request" data-hovercard-url="/logto-io/logto/pull/9666/hovercard">#9666</a>) (first contribution)</li> <li><a href="https://github.com/darcyYe">@darcyYe</a> - per-webhook test results (<a href="https://github.com/logto-io/logto/pull/9664" data-hovercard-type="pull_request" data-hovercard-url="/logto-io/logto/pull/9664/hovercard">#9664</a>)</li> </ul> <p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/logto-io/logto/compare/v1.43.0...v1.44.0"><tt>v1.43.0...v1.44.0</tt></a></p> silverhand-bot tag:github.com,2008:Repository/378310716/@logto/phrases@1.32.0 2026-09-30T06:52:48Z
@logto/phrases@1.32.0
<p>@logto/phrases@1.32.0</p> silverhand-bot tag:github.com,2008:Repository/378310716/@logto/experience@1.23.0 2026-09-30T06:52:47Z
@logto/experience@1.23.0
<p>@logto/experience@1.23.0</p> silverhand-bot tag:github.com,2008:Repository/378310716/@logto/core@1.44.0 2026-09-30T06:52:44Z
@logto/core@1.44.0
<p>@logto/core@1.44.0</p> silverhand-bot tag:github.com,2008:Repository/378310716/@logto/console@1.41.0 2026-09-30T06:52:47Z
@logto/console@1.41.0
<p>@logto/console@1.41.0</p> silverhand-bot tag:github.com,2008:Repository/378310716/@logto/connector-twilio-sms@1.5.0 2026-09-30T06:52:46Z
@logto/connector-twilio-sms@1.5.0
<p>@logto/connector-twilio-sms@1.5.0</p> silverhand-bot tag:github.com,2008:Repository/378310716/@logto/connector-kit@5.1.2 2026-09-30T06:52:48Z
@logto/connector-kit@5.1.2
<p>@logto/connector-kit@5.1.2</p> silverhand-bot tag:github.com,2008:Repository/378310716/@logto/connector-dingtalk-web@0.4.7 2026-09-30T06:52:46Z
@logto/connector-dingtalk-web@0.4.7
<p>@logto/connector-dingtalk-web@0.4.7</p> silverhand-bot tag:github.com,2008:Repository/378310716/@logto/connector-apple@1.6.10 2026-09-30T06:52:45Z
@logto/connector-apple@1.6.10
<p>@logto/connector-apple@1.6.10</p> silverhand-bot tag:github.com,2008:Repository/378310716/@logto/account@0.7.0 2026-09-30T06:52:45Z
@logto/account@0.7.0
<p>@logto/account@0.7.0</p> silverhand-bot
For now, Differences are performed on text, not graphically, only the latest screenshot is available.
Screenshot requires a Content Fetcher ( Sockpuppetbrowser, selenium, etc ) that supports screenshots.