Skip to content

Release history

zitadel releases

ZITADEL - Identity infrastructure, simplified for you.

All releases

21 shown

v4.15.0 Bug fix
Notable features
  • Improved client details dialog UX in console
Full changelog

4.15.0 (2026-05-04)

Bug Fixes

Features

Performance Improvements

v4.14.0 New feature
Security fixes
  • OIDC opaque token encryption
  • Invalid JWT assertion error handling
Notable features
  • x.509 certificate system-api-user tokens
  • ECDSA and ED25519 public keys
  • PKCS#1 key support
Full changelog

4.14.0 (2026-04-24)

Bug Fixes

Features

v4.13.1 Bug fix

Fixed admin initialization emails not being sent, enabled recovery codes to be active on creation, and reverted feature key naming for backward compatibility.

v4.13.0 New feature
Security fixes
  • tar and rollup vulnerabilities
Notable features
  • Webkeys v2 API migration
  • LDAP flow updates
  • HTTP/2 memory leak fix
v3.4.9 Security relevant patches GHSA-g2pf-ww5m-2r9m

Fixed organization scope enforcement to prevent cross-organization access vulnerabilities.

v4.12.3 Security relevant patches GHSA-g2pf-ww5m-2r9m

Fixed organization scope enforcement to prevent cross-organization access and prevented potential nil pointer panics in command handling logic.

v3.4.8 Bug fix

Fixed management API endpoint permission checks, improved auth middleware path encoding handling, and corrected webauthn invite code expiration validation logic.

v4.12.2 Bug fix

Fixed management API endpoint permission checks, improved auth middleware path encoding handling, and corrected webauthn invite code expiration validation logic.

v4.12.1 Security relevant patches GHSA-25rw-g6ff-fmg8 patches GHSA-25rw-g6ff-fmg8

Fixed request handling panic recovery and secured server action invocations to prevent unauthorized server-side page rendering in registration flows.

v4.12.0 New feature patches GHSA-6rx5-m2rc-hmf7 patches GHSA-6rx5-m2rc-hmf7 patches GHSA-pr34-2v5x-6qjq +1 more
Notable features
  • login_hint parameter support for IdP routing
  • Framework listing improvements
  • Email notification link fixes
v3.4.7 Security relevant patches GHSA-282g-fhmx-xf54 patches GHSA-6mq3-xmgp-pjm5

Fixed user update permission checks based on provided data and improved token subject validation logic.

v4.11.1 Security relevant patches GHSA-282g-fhmx-xf54
Notable features
  • Action target URL denylist
v4.11.0 Security relevant patches GHSA-6mq3-xmgp-pjm5
Notable features
  • xOAuth for SMTP authentication
  • OIDC back-channel logout URI management
  • Cross-app distributed tracing
v4.10.1 Bug fix

Fixed NX build caching issues and updated OpenAPI protoc plugin to versioned release for improved build reliability and documentation generation.

v4.10.0 New feature
Notable features
  • SMS country code selector for OTP
  • Arabic language support
  • App filtering by client ID
v4.9.2 Bug fix

Incremented feature version to handle removed event types correctly during upgrades.

v3.4.6 Security relevant patches GHSA-pvm5-9frx-264r

Fixed membership role synchronization from projections and generalized error messages on code verification endpoints for better user experience.

v4.9.1 Security relevant patches GHSA-pvm5-9frx-264r

Fixed SMTP configuration to allow optional passwords, added missing admin list filters to management API, and improved ID token hint handling in authentication.

v4.9.0 New feature
Notable features
  • Recovery code MFA support
  • Ukrainian language support
  • French and Dutch localization
v4.8.1 Bug fix

Fixed SMTP email handling to properly accept SMTPUTF8 encoded international email addresses with non-ASCII characters.

Beta — feedback welcome: [email protected]