Available for selected product partnerships and engineering engagements.Start a project →
Version history

OpenProof changelog.

Every published release, important change and upgrade note in one readable timeline.

Synced from official GitHub releases Cached for performance · GitHub remains the source of truth
← All changelogs Identity infrastructure

OpenProof

Authentication, account model, providers, security and deployment changes.

OpenProof 1.1.0-rc5 — October 9, 2026 reissue

> Reissued release tag: An earlier `v1.1.0-rc5` tag and successful Release workflow existed on September 22, 2026 but were subsequently removed. This is a new, intentionally reissued RC5 build from Git commit `256f970aba84a406d4f7bb906dbb011252719f2e`. If you obtained a historic RC5 artifact, do not assume it is byte-for-byte identical to this release. Verify the artifact against this release's `SHA256SUMS` before use.

Security and correctness improvements

  • JavaScript OAuth SDK hardening: Rejects unsafe or ambiguous callback redirect URIs, aligns redirect URI validation with the identity server, validates the OIDC `azp` claim and rejects ambiguous duplicate OAuth callback parameters.
  • Documentation MCP hardening: The latest source masks internal exception details behind a stable HTTP `internal_error` response. The hosted documentation MCP was separately updated and verified.
  • Safer account flows: Browser account security and TOTP enrollment, robust password recovery with one-time proof handling, better stale-session recovery and safer Device Authorization approval surfaces.
  • Migration-integrity protection: Packaging now validates that every expected migration is present, byte-identical and checksummed in both Debian and bundle artifacts. The Farcaster profile seed migration `0019_farcaster_profile_seed.sql` is included and applies only display-only fields to missing profile values; email/phone ownership remains untouched.
  • Native / browser integrations: Genycaster native OAuth client and production environment definitions and Tegra CMS browser client support.
  • Constrained owner recovery: Maintenance operation for narrowly defined incomplete initial-owner bootstrap states, with IAL2 verification and audited transaction protections.

Verification

  • Tagged commit: `256f970aba84a406d4f7bb906dbb011252719f2e`.
  • GitHub CI on that exact commit: successful Build and Test + Static Checks, run `37891378458`.
  • Local regression checks passed: JavaScript SDK tests, OpenAPI coverage (87 paths / 111 operations), migration artifact verifier (7 tests), and documentation MCP syntax.
  • On the existing OpenProof production instance, migration inventory is consistent (22/22), public endpoint health checks passed and email configuration persistence was verified. Production state is not a substitute for testing a newly built release package.
  • Binary artifacts: `amd64` and `arm64` Debian packages and Linux tarball bundles, with a `SHA256SUMS` file. Verify all downloaded artifacts before installation.

Pre-release: This is a release candidate, not a general-availability/stable release. Existing production installations are not automatically upgraded by creating this GitHub Release.

Open release on GitHub ↗

OpenProof 1.1.0-rc4

Farcaster profile bootstrap

  • Farcaster SIWF presentation metadata now seeds missing canonical profile fields after the signed identity proof is verified, so first-time Farcaster users receive their display name, preferred username and avatar automatically.
  • Provider presentation refreshes remain display-only: they do not import email or phone ownership claims, and existing user-chosen canonical name, username and picture values are preserved.
  • Added migration `0019_farcaster_profile_seed.sql` to backfill empty canonical profile fields from already stored Farcaster connection metadata without overwriting populated profile values.

Upgrade

sudo openproof upgrade --version 1.1.0-rc4
Open release on GitHub ↗

OpenProof 1.1.0-rc2

Fixed

  • Fixed duplicate canonical identities when a user first authenticated through a trusted federated provider and later enrolled local email/password with the same verified email. OpenProof now converges onto the single active canonical identity instead of creating a second account.
  • Verified-email convergence now fails closed when that email maps ambiguously to multiple active identities, or belongs to a suspended/non-authenticating identity, rather than guessing an owner.
  • Completing signup email verification now establishes an IAL1 browser session, removing the unnecessary second sign-in immediately after proving control of the address. The OpenAPI response now includes `session_id` and `assurance`.

Documentation and developer tooling

  • Added the end-to-end Deployment & Developer Handbook for installation, production configuration, OAuth/OIDC, Node.js, PHP, C++ and generic HTTP integration.
  • Added machine-readable LLM documentation surfaces and the public, read-only OpenProof documentation MCP server with reproducible source.
Open release on GitHub ↗

OpenProof v1.1.0-rc1

What's Changed

  • Improve account sessions and provider profile refresh by @thecompez in https://github.com/genyleap/openproof/pull/1
  • Fix/account session profile sync by @thecompez in https://github.com/genyleap/openproof/pull/2
  • Add multi-chain mobile wallet authentication by @thecompez in https://github.com/genyleap/openproof/pull/3
  • Restore federated conflict handling and document WalletConnect integration by @thecompez in https://github.com/genyleap/openproof/pull/4
  • Add hardened Postfix verification delivery adapter by @thecompez in https://github.com/genyleap/openproof/pull/5
  • Enable verified email sign-in management by @thecompez in https://github.com/genyleap/openproof/pull/6
  • Fix OpenAPI gate and Linux GCC toolchain by @thecompez in https://github.com/genyleap/openproof/pull/7
  • Support Apple OIDC form-post callbacks by @thecompez in https://github.com/genyleap/openproof/pull/8
  • Document federated provider environment setup by @thecompez in https://github.com/genyleap/openproof/pull/9
  • Enable one-time recovery codes for local MFA by @thecompez in https://github.com/genyleap/openproof/pull/10
  • Avoid GitGuardian password false positives by @thecompez in https://github.com/genyleap/openproof/pull/11
  • feat: add self-service TOTP enrollment and recovery codes by @thecompez in https://github.com/genyleap/openproof/pull/12
  • fix: require TOTP for recovery code issuance by @thecompez in https://github.com/genyleap/openproof/pull/13
  • feat: harden external OIDC providers by @thecompez in https://github.com/genyleap/openproof/pull/14
  • fix: preserve Apple first-login profile name by @thecompez in https://github.com/genyleap/openproof/pull/15
  • fix: encode OIDC basic client credentials by @thecompez in https://github.com/genyleap/openproof/pull/16
  • fix: bound enterprise LDAP operations by @thecompez in https://github.com/genyleap/openproof/pull/17
  • fix: validate SAML HTTPS endpoints by @thecompez in https://github.com/genyleap/openproof/pull/18
  • feat: enrich OIDC profile display names by @thecompez in https://github.com/genyleap/openproof/pull/19
  • fix: validate GitHub HTTPS callback URLs by @thecompez in https://github.com/genyleap/openproof/pull/20
  • fix: bind passkey RP IDs to origins by @thecompez in https://github.com/genyleap/openproof/pull/21
  • fix: validate Web3 RPC HTTPS endpoints by @thecompez in https://github.com/genyleap/openproof/pull/22
  • fix: sanitize Web3 presentation metadata by @thecompez in https://github.com/genyleap/openproof/pull/23
  • fix: normalize OIDC profile claims by @thecompez in https://github.com/genyleap/openproof/pull/24
  • fix: normalize enterprise presentation claims by @thecompez in https://github.com/genyleap/openproof/pull/25
  • fix: validate LDAP URI and base DN by @thecompez in https://github.com/genyleap/openproof/pull/26
  • fix: enforce local subject invariant by @thecompez in https://github.com/genyleap/openproof/pull/27
  • fix: make passkey auth challenges single-use by @thecompez in https://github.com/genyleap/openproof/pull/28
  • fix: enforce siwe challenge expiry by @thecompez in https://github.com/genyleap/openproof/pull/29
  • fix: harden Web3 authentication challenges by @thecompez in https://github.com/genyleap/openproof/pull/30
  • fix: make enterprise authentication challenges single-use by @thecompez in https://github.com/genyleap/openproof/pull/31
  • fix: make redirect authentication challenges single-use by @thecompez in https://github.com/genyleap/openproof/pull/32
  • fix: keep provider challenge handling cluster-safe by @thecompez in https://github.com/genyleap/openproof/pull/33
  • fix: make local authentication cluster-safe by @thecompez in https://github.com/genyleap/openproof/pull/34

New Contributors

  • @thecompez made their first contribution in https://github.com/genyleap/openproof/pull/1
Open release on GitHub ↗
Release clarity

Downloads show the artifact. Changelog explains the change.

This keeps product pages focused, documentation durable, and release-specific information easy to find.