---
title: "theAuth changelog: TypeScript and Go release notes"
description: "Recent theAuth releases for TypeScript and theauth-go in one place, summarized from each changelog, with links to the full release notes on GitHub."
canonical: https://theauth.dev/changelog/
lastmod: 2026-10-08
---

Changelog

# What shipped, library by library.

Short summaries of recent releases of the TypeScript library and theauth-go, taken from their changelogs. The repositories hold the full record, including every item trimmed here.

Snapshot of 2026-10-08, refreshed with npm run sync:changelog. The TypeScript timeline is curated by hand and can trail the newest npm release, so check GitHub Releases for the latest.

## theauth-go

Latest: v2.7.1. [Full Go changelog](https://github.com/glincker/theauth-go/blob/main/CHANGELOG.md) and [releases](https://github.com/glincker/theauth-go/releases). See also the [Go overview](https://theauth.dev/go/).

**v2.7.1 (2026-10-07)**

#### Upgrade notes

- JWKS URLs must use `https`. Plain `http` is refused unless `JWTBearerConfig.AllowPrivateJWKSNetworks` is set.
- JWKS hosts that resolve to loopback, private, link-local, CGNAT or cloud metadata addresses are refused. Local development and tests that serve a JWKS from `localhost` need `AllowPrivateJWKSNetworks: true`, or an (more in the full changelog)
- Redirects are not followed. A JWKS URL must serve the document directly.
- Rotated keys are picked up after the cache TTL (`JWKSCacheTTL`, default 5 minutes) instead of never.

1 more in the full changelog.

#### Security

- JWKS fetching for `private_key_jwt` client `jwks_uri` and `TrustedJWTIssuer.JWKSURL` is now SSRF-guarded.
- The in-process JWKS cache now expires entries (`JWTBearerConfig.JWKSCacheTTL`, default 5 minutes) so rotated keys are picked up, is bounded (`JWKSCacheMaxEntries`, default 256) and never caches failed fetches.
- The address guard now lives in a shared `internal/safehttp` package used by both CIMD and JWKS fetching.

**v2.7.0 (2026-10-05)**

#### Added

- `OAuthConfig.RedirectURI`, `RedirectURIAllowedHosts` and `AllowInsecureRedirectURI` to override and validate the OAuth redirect URI, plus `(*TheAuth).OAuthStart` and `OAuthCallback` for apps hosting their own routes.
- `WebAuthnConfig.UserHandleResolver`: lets imported passkeys whose authenticator holds a foreign user handle sign in; the credential's stored owner stays authoritative and the resolver must agree with it.

#### Changed

- Default logs no longer contain email addresses (password signin/signup/reset, magic link, `email.Noop`); lines carry `user_id` or a 12-hex `email_ref` hash instead.

#### Fixed

- `PasswordPolicy.OnLegacyHashAccepted` is now invoked (in a goroutine, after the new Argon2id hash is persisted) on signin and step-up; it was declared but never called.
- `ResetPasswordAdmin` now also clears the email's per-IP login backoff entries (new optional `LoginThrottleEntryDeleter` store capability; implemented by the memory, sqlite, postgres and mysql stores).

**v2.6.0 (2026-10-05)**

#### Upgrade notes

- Module path is now `github.com/glincker/theauth-go/v2`; update imports. The v2.x tags were never resolvable by the Go toolchain because the module path lacked the `/v2` suffix, so (more in the full changelog)
- Login throttle is on by default. Password signin is gated by per (client IP, normalized email) backoff and a per-user lockout.
- JSON error bodies. Handlers that returned plain-text `http.Error` bodies now return `{"code","message"}` JSON with a stable code (`bad_request`, `unauthorized`, `forbidden`, `not_found`, `conflict`, `rate_limited`, (more in the full changelog)
- TOTP verify and recovery routes rotate the session cookie. They set a new cookie and revoke the pending token, so clients must keep the cookie from the response.

11 more in the full changelog.

#### Added

- `Config.PathPrefix`. Serve the auth routes under a custom prefix (default `/auth`, validated) with no `http.StripPrefix`.
- **`(*TheAuth).Handler()`.** Returns an `http.Handler` serving every route `Mount` registers, so `net/http` ServeMux users need no chi import.
- Storage capability interfaces and `Config.CoreStorage`. `Storage` is now the embedding of small capability interfaces (`UserStorage`, `SessionStorage`, `MagicLinkStorage`, `PasswordStorage`, `OAuthAccountStorage`, (more in the full changelog)
- `storage/sqlite` adapter (separate module). Pure Go (`modernc.org/sqlite`) storage for `CoreStorage` plus the OAuthAccount, WebAuthn, TOTP and Audit capabilities.

28 more in the full changelog.

#### Changed

- Repository layout. The module root now holds only the public face of the library.
- Module path is now `github.com/glincker/theauth-go/v2` (see Upgrade notes).
- JSON error bodies replace plain-text `http.Error` bodies (see Upgrade notes).
- OAuth login CSRF closed with a real browser binding. The `/start` cookie now carries a secret distinct from the `state` parameter; the server stores its hash and verifies it in constant time at `/callback`.

3 more in the full changelog.

#### Fixed

- Synced-passkey login failure (backup-eligible flag). WebAuthn login failed with a generic "verification failed" for any credential whose authenticator reports the backup-eligible (BE) flag, which is the overwhelming (more in the full changelog)
- `PasswordPolicy.AllowLegacyBcrypt` is now honored at signin, step-up and password change, with rehash to Argon2id on success.
- Existing accounts are no longer linked by an unverified provider email: a callback whose email matches an existing user fails unless the provider marks it verified, and provider emails are lower-cased and trimmed before (more in the full changelog)
- MySQL `CreateUser` defaults zero `CreatedAt` and `UpdatedAt` instead of failing.

#### Security

- Login throttle. Password signin is now gated before any credential work by per (client IP, normalized email) exponential backoff after a grace period, plus a per-user lockout that auto-expires and can be cleared (more in the full changelog)
- MFA hardening. TOTP codes are single use: the last accepted time-step is recorded per user and replays are rejected (RFC 6238 section 5.2).
- First-run bootstrap. `Config.Bootstrap` closes public signup and requires a one-time setup token (generated and logged at startup, or supplied) to create the first user.
- Email canonicalization. Every email entry point (password, magic link, rate-limit key, SAML, SCIM) trims and lowercases, and folds Unicode compatibility forms when `Config.EmailNFKC` is set.

4 more in the full changelog.

**v2.5.0 (2026-07-14)**

#### Added

- `Config.LifecycleHooks` fully wired (#76). `OnSignup` now also fires from SAML signup and a user's first WebAuthn credential (passkey registration has no true account-creation moment, so the first credential is the (more in the full changelog)
- `AuthorizationServerConfig.Clock` (#38). Injectable time source for the introspection cache and agent-chain cache, so tests can assert revocation propagation deterministically instead of sleeping past (more in the full changelog)
- Password policy documented in README (#39). Minimum length, Argon2id hashing, and the anti-enumeration dummy-verify behavior.

#### Fixed

- `a.Mount()` bypassed `LifecycleHooks` for password, TOTP, and WebAuthn. `passwordhandlers`/`totphandlers`/`webauthnhandlers` held the raw internal `Service` directly instead of a hook-aware adapter, unlike OAuth/ (more in the full changelog)
- SCIM `PATCH /Groups/{id}` silently discarded member-write errors, always returning 200 even when the storage write failed.
- Admin `GET /audit` classified bad-cursor errors by substring-matching `err.Error()` instead of `errors.Is`.
- `storage/mysql.MoveTOTPSecret` treated any error from its existence check (not just "no rows") as "primary already has a secret," which could silently delete a secondary user's real TOTP secret on a transient DB (more in the full changelog)

3 more in the full changelog.

**v2.5.0-rc.1 (2026-06-22)**

#### Added

- `Config.LifecycleHooks` surface (#76, partial). New optional hook bundle lets consumers react to authentication-lifecycle events without forking handlers or wrapping endpoints at the HTTP boundary.
- `Auth.UserByID` (#77). Public lookup that previously forced consumers to reach into storage directly.
- `Config.Tenancy` auto-provisioning (#77). New `TenancyConfig` lets consumers opt into automatic personal-organization creation on signup.

#### Fixed

- `RequireAuth` now emits RFC 7807 problem+json on 401 (#78). Previously `RequireAuth` and `RequirePendingOrFull` wrote plain-text bodies (`"unauthorized"`) while `RequirePermission` already emitted RFC 7807, forcing (more in the full changelog)

**v2.4.0 (2026-06-22)**

#### Added

- MySQL 8.x storage backend (#62). `storage/mysql` implements `theauth.Storage` and `OAuthServerStorage` with full parity with the existing postgres backend.
- Cognito + Auth0 migration CLI (#63). New `cmd/theauth-migrate/` binary with sub-commands `cognito` and `auth0` exports users from AWS Cognito (CSV or JSON input) and Auth0 (Management API or bulk export) into an (more in the full changelog)
- PAR (RFC 9126) + JAR (RFC 9101) for FAPI-adjacent profile (#64). Pushed Authorization Requests and JWT-Secured Authorization Requests are now supported by the OAuth 2.1 AS.
- JWT-Bearer client auth + grant + token exchange polish (#65, RFC 7523). The AS now accepts JWT client assertions (`client_assertion_type= urn:ietf:params:oauth:client-assertion-type:jwt-bearer`) as a client (more in the full changelog)

4 more in the full changelog.

#### Changed

- `AuthorizationServerConfig` extended with new optional sub-configs (additive). `PAR *PARConfig`, `JAR *JARConfig`, `JWTBearer *JWTBearerConfig`, `CIBA *CIBAConfig`.
- Token exchange response now sets `issued_token_type` explicitly (#65). Previously the field was omitted.

#### Fixed

- `gofmt` fixup on `jwtbearer.go` and `par_serialise.go` (#68). Two files landed in #64 and #65 with minor formatting inconsistencies.

#### Security

- Supply chain: goreleaser + cosign + SLSA (#57). Every release artifact (source archive, SBOM) is now signed with Sigstore keyless signing via the GitHub Actions OIDC identity.
- Trust documentation (#61). `docs/THREAT-MODEL.md` (STRIDE analysis across all subsystems), `docs/COMPLIANCE-SOC2.md` (AICPA TSC 2017 criteria mapping), and `docs/COMPLIANCE-GDPR.md` (GDPR data handling reference and (more in the full changelog)

## theAuth for TypeScript

Core package @glinr/theauth. [Full changelog](https://github.com/glincker/theauth/blob/main/CHANGELOG.md) and [releases](https://github.com/glincker/theauth/releases). See [get started](https://theauth.dev/get-started/).

**v0.5.0, July 2026**

#### Summary

- No breaking change. All `legacy` exported identifiers now have `TheAuth*` canonical equivalents.

**@glinr/theauth-nextjs-auth v0.1.0, May 2, 2026**

#### Summary

- New package. A focused Next.js (14/15/16) adapter for apps whose auth backend lives outside Next.js (Spring, Rails, Hono, Go, etc.).

**v0.4.2, April 18, 2026**

#### Summary

- Fix on a missed barrel in 0.4.0. The ten new OAuth providers were added to `providers/index.ts` but the top-level `auth/index.ts` still pointed at the old nine-provider list, so `import { notion } from "@glinr/theauth/auth"` did not resolve.

**v0.4.1, April 18, 2026**

#### Summary

- `@glinr/theauth/standards` shipped in 0.4.0 but was missing from the `exports` field in `package.json` and from the tsup build entries, which meant `import { AGENTIC_JWT_CLAIMS } from "@glinr/theauth/standards"` failed at resolve time.

**v0.4.0, April 18, 2026**

#### Summary

- Four things shipped together.

**v0.3.0, April 17, 2026**

#### Summary

- Two adapter additions and a schema defaults change.

## Related

[How releases work](https://theauth.dev/open/releases/) [Stability policy](https://theauth.dev/open/stability/) [Roadmap](https://theauth.dev/open/roadmap/) [Guides](https://theauth.dev/guides/)
