Release notes

How Ferriskey has been taking shape, release after release.

A curated timeline of stable Ferriskey releases, condensed from the public GitHub history into product-level notes.

Based on the public release history of ferriskey/ferriskey on GitHub.

Stable release timeline

Newest first. Milestone releases ship new capabilities; patch releases are quick fixes to an existing line.

v0.9.0 October 3, 2026
Milestone release Latest release

Token exchange, back-channel logout, and realm isolation enforced by the type system

FerrisKey 0.9.0 adds RFC 8693 token exchange with delegation policies, OIDC Back-Channel Logout and a consent screen, and carries password hashes over from other systems. Underneath, every repository port now takes a realm scope, which closed a whole class of cross-realm access bugs.

  • Implements RFC 8693 token exchange for downscoping, targeting another service, and delegation: per-client opt-in, delegation policies with a scope ceiling and separate impersonation and delegation switches, actor tokens, the act claim with chained actors, a console tab to manage policies, and an entry in the discovery document.
  • Adds OIDC Back-Channel Logout with its console settings, the prompt and max_age parameters, a remember-me setting that now changes the SSO cookie lifetime, an SSO session handed out on the MFA login steps, and a themable consent screen for a client's optional scopes.
  • Makes migrations from other identity systems keep their users: bcrypt password hashes are imported and re-encoded as argon2id on first sign-in, and a user can be created with a caller-supplied id so the sub claim survives. With the CLI, this lets teams import users from Supabase together with their passwords.
  • Rebuilds webhook delivery on a persisted outbox with retry policies per realm and per webhook, delivery history, manual replay and signing secret regeneration, and translates the console into English and Simplified Chinese with API errors localised from a stable reason code.
  • Threads the realm through every repository port with a RealmScope type, which turned a series of cross-realm access bugs into compile errors, and fixes around fifteen of them: login sessions, passkeys, roles, credentials, maintenance whitelists and delegated realm-admin roles are now confined to the realm in the URL, and the access token is no longer handed out in a cookie.

Where 0.8 turned inward to build foundations that could be verified, 0.9 spends them: the realm boundary is now checked by the compiler, and the protocol surface grows with token exchange, back-channel logout and consent on top of it.

v0.8.0 September 15, 2026
Milestone release

SAML 2.0, a rebuilt administration console, and a reworked codebase

FerrisKey 0.8.0 adds a complete SAML 2.0 identity provider next to OIDC and rebuilds the entire administration interface, but most of the cycle went into the foundations: the workspace was split from 10 crates into 36 and the test suite grew from 395 to 1245 tests.

  • Ships a complete SAML 2.0 identity provider alongside OIDC: AuthnRequest parsing, HTTP bindings, exclusive XML canonicalisation, enveloped XML-DSig signatures, a self-signed X509 certificate derived from the realm signing key, and service provider configuration from the console.
  • Rebuilds the whole administration interface in the FerrisKey style, covering 15 IAM screens and 5 console sections, replaces the two user interfaces that used to coexist, and adds light, dark, and system themes.
  • Splits the workspace from 10 crates into 36 with explicit boundaries, grows the test suite from 395 to 1245 tests, and wires the integration suites that continuous integration had never actually run.
  • Anchors SSO on the user session rather than the access token so revoking a session also invalidates its refresh tokens, chains the SeaWatch audit log with hashes to make tampering visible, and lands around twenty security fixes including PKCE, refresh token rotation with reuse detection, account lockout, and signed webhook deliveries.

Where 0.7 pushed outward on protocol coverage and branding, 0.8 turns inward. The release spends as much effort on crate boundaries, tests, and continuous integration as on features, so the surface built up over the previous releases now rests on something that can be verified.

v0.7.2 July 30, 2026
Patch release

Realm roles restored in issued tokens on the 0.7 line

A patch for the 0.7 line that backports a token assembly fix: realm roles assigned directly to a user were dropped while claims were built, so realm_access.roles came back empty even with the default roles client scope and a realm role mapper in place.

  • Backports the claim assembly fix for realm roles assigned directly to a user, which were silently skipped and never reached the realm role mapper.
  • Restores realm_access.roles for users whose roles come from a direct assignment rather than from a group, which previously required inheriting the role through a group to work at all.
  • Realigns the workspace, Helm chart, and operator chart versions so the published artifacts stay consistent.

A single backported commit onto the 0.7 line, so deployments that rely on realm roles inside tokens did not have to wait for the 0.8 cycle to land.

v0.7.1 July 3, 2026
Patch release

Nginx packaging fix for the 0.7 line

A small patch that cherry-picks an Nginx configuration fix into the 0.7 release line so the packaged web application image keeps serving correctly.

  • Cherry-picks the Nginx fix into 0.7.1 so the packaged webapp is served correctly in the shipped image.
  • Bumps workspace, Helm chart, and operator chart versions together to keep artifacts aligned.
  • Keeps the 0.7 branch production-ready without requiring a larger upgrade.

A narrow follow-up to 0.7.0 that ensures the release ships cleanly in containerized environments.

v0.7.0 June 30, 2026
Milestone release

Device authorization flow and the portal theming builder

FerrisKey 0.7.0 brings the OAuth 2.0 Device Authorization Grant (RFC 8628) end to end and a full portal theming builder, letting teams onboard input-constrained devices and fully brand their login experience.

  • Implements the complete OAuth 2.0 Device Authorization Flow (RFC 8628): device authorization endpoint, device_code token grant, verification page, and CIAM console configuration.
  • Ships a portal theming builder with per-page layouts, design tokens, live preview, and an iframe-based editor to fully customize the hosted login portal.
  • Adds CIAM application management, resume-OAuth-after-password-reset, basic auth support, and several OIDC discovery and nonce compliance fixes.

With operational control settled in 0.6, the 0.7 line turns toward developer-facing protocol coverage and end-user branding, making FerrisKey both more standards-complete and more customizable.

v0.6.1 June 8, 2026
Patch release

Authentication flow fixes and passkey configuration polish

A patch release for the 0.6 line that bundles a set of authentication-flow fixes across passkey configuration, OTP challenge handling, identity-provider brokering, and redirect URI handling.

  • Refines the passkey configuration experience and hardens the OTP challenge flow on the login journey.
  • Fixes the GitHub identity-provider broker login flow and cleans up redirect URI handling.
  • Smooths the login and post-authentication callback path across the frontend.

Right after 0.6.0's operational features, this patch tightens the day-to-day authentication experience before the larger 0.7 work.

v0.6.0 May 6, 2026
Milestone release

Maintenance mode, user attributes, and OpenTelemetry tracing

FerrisKey 0.6.0 introduces two major platform capabilities, a built-in maintenance mode and extensible user attributes, alongside full OpenTelemetry tracing support for production observability.

  • Ships a first-class maintenance mode across the full stack, letting administrators halt user-facing operations gracefully during upgrades or incidents while retaining admin access.
  • Adds user attributes support so realms can store arbitrary key-value metadata on users and propagate them into tokens via protocol mappers.
  • Integrates OpenTelemetry tracing and an OTLP log bridge, so traces and logs land in observability stacks such as Grafana Tempo and Jaeger without extra glue.

Building on the passwordless and multi-tenant foundations of 0.5.0, this release shifts focus to operational control and extensibility, giving platform teams the tools to manage identity infrastructure with more confidence.

v0.5.0 April 12, 2026
Milestone release

Passwordless authentication, organizations, and email theming

Ferriskey 0.5.0 moves the product beyond core IAM administration with native passwordless sign-in, multi-tenant organization management, and customizable transactional emails.

  • Adds native WebAuthn passkeys for passwordless authentication without heavy external infrastructure.
  • Introduces Magic Link sign-in for teams that want a simpler passwordless user experience.
  • Ships organizations and email builder theming so tenants and transactional emails can be managed directly from Ferriskey.

After the 0.4 line focused on observability, recovery, and token control, 0.5.0 turns that foundation into a more complete end-user and multi-tenant experience.

v0.4.3 March 24, 2026
Patch release

Authentication URL hardening and release alignment

A focused patch that hardens authentication and registration URL generation, especially when Ferriskey runs behind a root path or a webapp URL with trailing slashes.

  • Normalizes login URL construction to avoid double slashes in authentication redirects.
  • Applies root-path aware base URLs to authenticate, registration, and token exchange handlers.
  • Bumps workspace and Helm chart versions together so the shipped artifacts stay aligned.

This closes the 0.4 line with a practical production fix: cleaner redirects, safer URL composition, and properly aligned release metadata.

v0.4.2 March 13, 2026
Patch release

Dockerfile and Nginx packaging fixes

A packaging-focused patch release that fixes the delivery layer around the web application, with corrections in the Docker entrypoint, Dockerfile flow, and Nginx configuration.

  • Fixes the Dockerfile path so the packaged web application boots with the expected assets.
  • Corrects the container entrypoint behavior in the release build.
  • Updates Nginx configuration so the shipped image serves the app correctly.

It is a narrow release, but an important one: it turns the 0.4 branch into something easier to ship and verify in containers.

v0.4.1 March 12, 2026
Patch release

Authentication callback flow refinement

A patch release centered on the authentication callback path, tightening refresh-token behavior and smoothing the post-login handoff.

  • Fixes the authentication callback flow after the broader 0.4.0 changes.
  • Adjusts refresh-token logic so sign-in completion behaves more predictably.
  • Stabilizes the handoff between the login journey and token lifecycle.

This patch serves as the functional correction right after 0.4.0 before the packaging fixes that landed in 0.4.2.

v0.4.0 March 12, 2026
Milestone release

Client scopes, Compass observability, and account recovery foundations

Version 0.4.0 is a major step forward for platform teams: token shaping improves, authentication flows become observable, and user recovery starts to land as a complete subsystem.

  • Introduces client scopes, mappings, migrations, and API support for better token composition.
  • Launches Compass runtime, database layer, API endpoints, and UI to inspect authentication flows.
  • Adds password reset and SMTP management building blocks, including UI and infrastructure.

Once federation was established in 0.3.0, the next logical move was to improve policy control, visibility, and recovery across the sign-in journey.

v0.3.0 February 2, 2026
Milestone release

Federation becomes real

Ferriskey expands beyond local identity management with federation primitives, social login, LDAP support, and SSO endpoints.

  • Adds the Abyss federation module and user federation entities and migrations.
  • Ships social auth APIs, LDAP provider CRUD, sync and connection test endpoints.
  • Improves login UX, error detail quality, and permissions hydration in the app.

At this point the project stops being only an internal IAM console and starts addressing real-world enterprise identity integration problems.

v0.2.1 January 16, 2026
Patch release

Maintenance patch for the 0.2 line

A small release that backports the necessary fixes to keep the 0.2 branch versioned and consumable while larger federation work continues on main.

  • Cherry-picks targeted fixes from main into the 0.2 release line.
  • Corrects release versioning before the next milestone.
  • Keeps existing adopters on a stable branch without forcing a larger upgrade.

It is a short stop on the timeline, but it shows the project already treating release management as part of the product.

v0.2.0 December 30, 2025
Milestone release

Operations, webhooks, and admin surface expansion

Ferriskey broadens its operator story with webhooks, required actions, stronger admin pages, and the first serious steps toward event-driven integrations.

  • Introduces webhook notifications and required actions in the authentication journey.
  • Expands admin UX with realm settings, login settings, IdP overview, and UI polish across clients and roles.
  • Lays groundwork for SeaWatch and strengthens deployment support with TLS and Docker improvements.

From here the roadmap opens up: not just authenticating users, but integrating identity events into the rest of the platform.

v0.1.1 August 11, 2025
Patch release

First post-launch hardening pass

The first patch release focuses on correctness and release hygiene right after the initial public milestone.

  • Fixes session cookie handling to make authentication flows safer.
  • Corrects Docker Compose execution context issues.
  • Cleans up the Helm release workflow so tags are published more predictably.

This is where the team starts closing the gap between a fast-moving launch and a project people can trust to upgrade.

v0.1.0 August 7, 2025
Milestone release

The first public Ferriskey baseline

The first stable release establishes the platform core: realms, clients, users, roles, OpenID endpoints, admin UI, packaging, and deployment tooling.

  • Delivers the foundational IAM surface: realms, clients, roles, permissions, users, and authentication endpoints.
  • Ships the first admin portal flows, including login, client management, role management, and user management.
  • Adds Helm, operator, Docker, metrics, and documentation so Ferriskey can be evaluated as a real platform.