FusionAuth
Developer-focused authentication, authorization, and user management platform available self-hosted or cloud-hosted
FusionAuth's feed publishes version numbers; whether they carry news is a coin flip.
◆Recent moves
- 15d ago
FusionAuth 1.69.0 ships with no published release notes
The 1.69.0 entry arrives in the feed with no release notes at all — just the standing advice to upgrade. Whatever shipped is not readable here, which is the second release in a row that way.
View source ↗ - 1mo ago
FusionAuth 1.68.0 (Intelligent Kamfa), notes not published
A named release — Intelligent Kamfa — published with the same boilerplate upgrade notice and no notes. The codename suggests a feature release rather than a patch, but the feed gives nothing to judge.
View source ↗ - 2mo ago
FusionAuth 1.67.1 patch, no notes published
A patch release with no notes in the feed. Consistent with FusionAuth's point releases, which rarely carry documented changes here.
View source ↗ - 2mo ago
RFC 8707 OAuth resource scoping for tokens
RFC 8707 support lets an application declare valid resource URIs and bind issued tokens to them via the authorization code flow. Standards conformance that matters most to deployments where one identity server fronts several APIs and a token should not be valid at all of them.
View source ↗ - 3mo ago
Webhook endpoints now require global API keys (breaking)
A breaking change extending the previous release's global API key requirement to webhook endpoints, which had been left out. Explicitly framed as correcting an omission rather than adding protection — the kind of follow-up that tells you the security pass was done in stages.
View source ↗ - 3mo ago
Breaking: IdP linking strategy locked, tenant-key access narrowed
The release that started the hardening run: identity provider linking strategy became immutable while enabled, and installation-scope endpoints began requiring global API keys. Breaking by design, and the reason the next release existed.
View source ↗