Skip to content

zitadel

v4.16.0 Feature

This release adds 2 notable features for engineering teams evaluating rollout.

Published 16d Secrets & Credentials
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

2fa authentication authorization fido2 fips-140-3 identity
+11 more
login mfa multitenancy oauth2 oidc openid-connect passkeys saml scim sso user

Affected surfaces

auth rbac

Summary

AI summary

Updates Bug Fixes, 4.16.0, and 2026-07-10 across a mixed release.

Changes in this release

Feature High

Add FIPS 140-3 compliant build and runtime checks in crypto module.

Add FIPS 140-3 compliant build and runtime checks in crypto module.

Source: llm_adapter@2026-07-16

Confidence: high

Feature Low

Allow custom protocols for native apps again in login.

Allow custom protocols for native apps again in login.

Source: llm_adapter@2026-07-16

Confidence: high

Feature Low

Allow managing invite code in secret generators.

Allow managing invite code in secret generators.

Source: llm_adapter@2026-07-16

Confidence: high

Performance Medium

Increase performance of ListUser by login name ignore case.

Increase performance of ListUser by login name ignore case.

Source: llm_adapter@2026-07-16

Confidence: high

Bugfix Medium

Correct scope validation in token exchange.

Correct scope validation in token exchange.

Source: llm_adapter@2026-07-16

Confidence: high

Bugfix Medium

Correctly remove adjacent roles on user grants.

Correctly remove adjacent roles on user grants.

Source: llm_adapter@2026-07-16

Confidence: high

Bugfix Low

Improve contrast of IDP processing message in login.

Improve contrast of IDP processing message in login.

Source: granite4.1:30b@2026-07-16-audit

Confidence: low

Bugfix Low

Improve error handling for user registration in login.

Improve error handling for user registration in login.

Source: granite4.1:30b@2026-07-16-audit

Confidence: low

Bugfix Low

Migrate legacy Tailwind v4 opacity utilities and fix checkbox contrast color in login.

Migrate legacy Tailwind v4 opacity utilities and fix checkbox contrast color in login.

Source: granite4.1:30b@2026-07-16-audit

Confidence: low

Bugfix Low

Preserve org domain suffix through account chooser navigation in login.

Preserve org domain suffix through account chooser navigation in login.

Source: granite4.1:30b@2026-07-16-audit

Confidence: low

Bugfix Low

Prevent IDP auto-creation failure when name fields are missing in login.

Prevent IDP auto-creation failure when name fields are missing in login.

Source: granite4.1:30b@2026-07-16-audit

Confidence: low

Bugfix Low

Redirect to loginname instead of empty accounts page when org scope filters all sessions in login.

Redirect to loginname instead of empty accounts page when org scope filters all sessions in login.

Source: granite4.1:30b@2026-07-16-audit

Confidence: low

Bugfix Low

Use correct requestId with oidc_ prefix in Prompt.LOGIN + loginHint flow in login.

Use correct requestId with oidc_ prefix in Prompt.LOGIN + loginHint flow in login.

Source: granite4.1:30b@2026-07-16-audit

Confidence: low

Bugfix Low

Prevent double triggering of verification emails.

Prevent double triggering of verification emails.

Source: granite4.1:30b@2026-07-16-audit

Confidence: low

Full changelog

4.16.0 (2026-07-10)

Bug Fixes

  • correct scope validation in token exchange (#12312) (02d07e9), closes #12319 #12322 #12319 #12322
  • Correctly remove adjacent roles on user grants (dc89900)
  • increase performance of ListUser by login name ignore case (#12350) (8fed358)
  • login: allow custom protocols for native apps again (#12332) (5b3c10e)
  • login: improve contrast of IDP processing message (#12309) (30ad9ab)
  • login: improve error handling for user registration (#12338) (fa916e7)
  • login: migrate legacy Tailwind v4 opacity utilities and fix checkbox contrast color (#12360) (70850db)
  • login: preserve org domain suffix through account chooser navigation (#12304) (3311fb9), closes #12024
  • login: Prevent IDP auto-creation failure when name fields are missing (#11070) (ab2e099)
  • login: redirect to loginname instead of empty accounts page when org scope filters all sessions (#12346) (f21f95c), closes #11914
  • login: use correct requestId with oidc_ prefix in Prompt.LOGIN + loginHint flow (#12376) (57eb145), closes #11946 #11946
  • prevent double triggering of verification emails (#11995) (9ae9bf3)

Features

  • allow managing invite code in secret generators (#12109) (915586a)
  • crypto: FIPS 140-3 compliant build and runtime checks (#12233) (c03d9f4)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track zitadel

Get notified when new releases ship.

Sign up free

About zitadel

ZITADEL - Identity infrastructure, simplified for you.

All releases →

Beta — feedback welcome: [email protected]