FIDO authentication release notes
26.1.0
What's new?
- Authenticator lockout: Authenticator policies now support lockout configuration. You can configure the system to automatically lock an authenticator after a specified number of failed authentication attempts within a defined time window, and set the lockout duration. You can check lockout status through the authenticator admin API.
Improvements and fixes
This release also includes new policy samples for lockout configuration, and general improvements and defect fixes.
25.3.0
What's new?
-
Tenant delete management: Admins can now remove a tenant via lifecycle APIs with guardrails (validation, soft-lock window) and full audit coverage to prevent accidental or partial deletion.
-
FIDO API availability: FIDO authentication APIs are now exposed in the OneWelcome Identity Platform (OIP), making it easier to integrate FIDO flows alongside your existing OIP services and credentials management.
Improvements and fixes
This release also includes general improvements and defect fixes that enhance logging, audit robustness, and configuration safety.
25.2.0
What's new?
This release delivers key enhancements to tenant and user lifecycle workflows. From streamlined tenant creation and updates to proper user data cleanup on deletion, these features help organizations manage identities more efficiently and securely.
-
Tenant lifecycle: Support for tenant lifecycle management is now available, enabling API-based creation and updates of tenant records. This simplifies onboarding and configuration changes in multi-tenant environments.
-
User lifecycle: In addition, user deletion lifecycle management is now available. When users are removed, associated data is properly cleaned up, helping you stay compliant with retention and privacy requirements.
25.1.0
What's new?
This release brings two key improvements: FIDO authentication policies for enhanced security compliance, and multi-user push notifications to ensure personalized notifications on shared devices.
-
FIDO authentication policies: Administrators can now define and enforce FIDO authentication policies to ensure compliance with security standards, offering granular control over which operations or accesses are allowed.
-
Multi-user push notifications: Users with different accounts on the same mobile device will now support receiving push notifications respectively without conflict.