# ZITADEL changelog > An identity and access management platform with multi-tenancy built in. - Vendor: ZITADEL - Category: Developer Tools - Official site: https://zitadel.com - Tracked by: What's New (https://whatsnew.fyi/product/zitadel) - Harvested from: GitHub (zitadel/zitadel) - Entries below: 10 (newest first) What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. ## Releases ### v4.16.3 - Date: 2026-08-07 - Version: v4.16.3 - Original notes: https://github.com/zitadel/zitadel/releases/tag/v4.16.3 - Permalink: https://whatsnew.fyi/product/zitadel/releases/v4.16.3 - **fixed** — Record route patterns instead of request paths on HTTP metrics ##### [4.16.3](https://github.com/zitadel/zitadel/compare/v4.16.2...v4.16.3) (2026-08-07) ###### Bug Fixes * **telemetry:** record route patterns instead of request paths on HTTP metrics ([#12557](https://github.com/zitadel/zitadel/issues/12557)) ([beffd5e](https://github.com/zitadel/zitadel/commit/beffd5e32e98a1518e5f6dc17acda93f7786cc1e)), closes [#9286](https://github.com/zitadel/zitadel/issues/9286) [#9523](https://github.com/zitadel/zitadel/issues/9523) [#11435](https://github.com/zitadel/zitadel/issues/11435) [#12315](https://github.com/zitadel/zitadel/issues/12315) [#12556](https://github.com/zitadel/zitadel/issues/12556) [#9286](https://github.com/zitadel/zitadel/issues/9286) [#9523](https://github.com/zitadel/zitadel/issues/9523) [#11435](https://github.com/zitadel/zitadel/issues/11435) ### v3.4.14 - Date: 2026-07-29 - Version: v3.4.14 - Original notes: https://github.com/zitadel/zitadel/releases/tag/v3.4.14 - Permalink: https://whatsnew.fyi/product/zitadel/releases/v3.4.14 - **fixed** — Prevent external-IDP account pre-hijack in Login V1 - **fixed** — Require authentication before WebAuthn/U2F and TOTP/OTP enrollment ##### [3.4.14](https://github.com/zitadel/zitadel/compare/v3.4.13...v3.4.14) (2026-07-29) ###### Bug Fixes * **login:** prevent external-IDP account pre-hijack in Login V1 ([da67750](https://github.com/zitadel/zitadel/commit/da677502e1d96c167dd9c630ef1295997b22c700)) * **login:** require authentication before WebAuthn/U2F and TOTP/OTP enrollment ([dd975b8](https://github.com/zitadel/zitadel/commit/dd975b8fc5bb20236b8ad535ebf4567d4e10f2f8)) ### v4.16.2 - Date: 2026-07-29 - Version: v4.16.2 - Original notes: https://github.com/zitadel/zitadel/releases/tag/v4.16.2 - Permalink: https://whatsnew.fyi/product/zitadel/releases/v4.16.2 - **fixed** — improve random string generation - **security** — prevent external-IDP account pre-hijack in Login V1 - **fixed** — redirect to external IdP after domain discovery regardless of registration policy - **security** — require authentication before WebAuthn/U2F and TOTP/OTP enrollment - **security** — use protected http client for org domain HTTP verification - **changed** — speed up ListUsers login name equality filters ##### [4.16.2](https://github.com/zitadel/zitadel/compare/v4.16.1...v4.16.2) (2026-07-29) ###### Bug Fixes * improve random string generation ([#12266](https://github.com/zitadel/zitadel/issues/12266)) ([34345ea](https://github.com/zitadel/zitadel/commit/34345ea8f6d98e7a7db58dac0ba106239caa8876)) * **login:** prevent external-IDP account pre-hijack in Login V1 ([917ade3](https://github.com/zitadel/zitadel/commit/917ade35af9c51e4b57ca8e57488ae95928182ad)) * **login:** redirect to external IdP after domain discovery regardless of registration policy ([#12369](https://github.com/zitadel/zitadel/issues/12369)) ([c4ba5a1](https://github.com/zitadel/zitadel/commit/c4ba5a1da5c56bac33b9f10e5e29fad39f0be05e)), closes [#12021](https://github.com/zitadel/zitadel/issues/12021) [#12023](https://github.com/zitadel/zitadel/issues/12023) * **login:** require authentication before WebAuthn/U2F and TOTP/OTP enrollment ([c20d613](https://github.com/zitadel/zitadel/commit/c20d6132965654bb761cd9009a5f013be2b5cf68)) * use protected http client for org domain HTTP verification ([35122e4](https://github.com/zitadel/zitadel/commit/35122e43974d542297018c57cc0fffb9db8a64ac)) ###### Performance Improvements * **query:** speed up ListUsers login name equality filters ([#12460](https://github.com/zitadel/zitadel/issues/12460)) ([b3b8da0](https://github.com/zitadel/zitadel/commit/b3b8da01b54fd1c698226cc261d7bca17dcd1478)) ### v3.4.13 - Date: 2026-07-17 - Version: v3.4.13 - Original notes: https://github.com/zitadel/zitadel/releases/tag/v3.4.13 - Permalink: https://whatsnew.fyi/product/zitadel/releases/v3.4.13 - **fixed** — prevent disk access via require in actions ##### [3.4.13](https://github.com/zitadel/zitadel/compare/v3.4.12...v3.4.13) (2026-07-17) ###### Bug Fixes * **actions:** prevent disk access via require ([e28d6bc](https://github.com/zitadel/zitadel/commit/e28d6bcc033368c3e9683ee15c195b8460b9305d)) ### v4.16.1 - Date: 2026-07-17 - Version: v4.16.1 - Original notes: https://github.com/zitadel/zitadel/releases/tag/v4.16.1 - Permalink: https://whatsnew.fyi/product/zitadel/releases/v4.16.1 - **security** — Prevent disk access via require in actions - **fixed** — Display minimum length in password complexity message - **fixed** — Keep submit button disabled/loading during password set - **fixed** — Prevent crash on a stale session cookie ##### [4.16.1](https://github.com/zitadel/zitadel/compare/v4.16.0...v4.16.1) (2026-07-17) ###### Bug Fixes * **actions:** prevent disk access via require ([afe1086](https://github.com/zitadel/zitadel/commit/afe108640cf57a17e8b743fbcdad9ae636eb3eb7)) * **console:** display minimum length in password complexity message ([#12419](https://github.com/zitadel/zitadel/issues/12419)) ([cc3812a](https://github.com/zitadel/zitadel/commit/cc3812a940d629984802fd1246f84fd91d07f6e8)), closes [#12390](https://github.com/zitadel/zitadel/issues/12390) * **login:** keep submit button disabled/loading during password set r… ([#12429](https://github.com/zitadel/zitadel/issues/12429)) ([0a355f7](https://github.com/zitadel/zitadel/commit/0a355f77db2f6dafc4e2d1b3254775d3a2c4a627)), closes [#12416](https://github.com/zitadel/zitadel/issues/12416) * **login:** prevent crash on a stale session cookie ([#12423](https://github.com/zitadel/zitadel/issues/12423)) ([6030a43](https://github.com/zitadel/zitadel/commit/6030a4316aceff23f9730bf8ccd3d1fa2411b293)), closes [#11130](https://github.com/zitadel/zitadel/issues/11130) ### v4.16.0 - Date: 2026-07-10 - Version: v4.16.0 - Original notes: https://github.com/zitadel/zitadel/releases/tag/v4.16.0 - Permalink: https://whatsnew.fyi/product/zitadel/releases/v4.16.0 - **fixed** — Correct scope validation in token exchange - **fixed** — Correctly remove adjacent roles on user grants - **fixed** — Increase performance of ListUser by login name ignore case - **fixed** — Allow custom protocols for native apps again - **fixed** — Improve contrast of IDP processing message - **fixed** — Improve error handling for user registration - **fixed** — Migrate legacy Tailwind v4 opacity utilities and fix checkbox contrast color - **fixed** — Preserve org domain suffix through account chooser navigation - **fixed** — Prevent IDP auto-creation failure when name fields are missing - **fixed** — Redirect to loginname instead of empty accounts page when org scope filters all sessions - **fixed** — Use correct requestId with oidc_ prefix in Prompt.LOGIN + loginHint flow - **fixed** — Prevent double triggering of verification emails - **added** — Allow managing invite code in secret generators - **added** — FIPS 140-3 compliant build and runtime checks #### [4.16.0](https://github.com/zitadel/zitadel/compare/v4.15.3...v4.16.0) (2026-07-10) ###### Bug Fixes * correct scope validation in token exchange ([#12312](https://github.com/zitadel/zitadel/issues/12312)) ([02d07e9](https://github.com/zitadel/zitadel/commit/02d07e951b0b6ff8d5fa5e74b65209a8e9efddfe)), closes [#12319](https://github.com/zitadel/zitadel/issues/12319) [#12322](https://github.com/zitadel/zitadel/issues/12322) [#12319](https://github.com/zitadel/zitadel/issues/12319) [#12322](https://github.com/zitadel/zitadel/issues/12322) * Correctly remove adjacent roles on user grants ([dc89900](https://github.com/zitadel/zitadel/commit/dc899002ec77eb30c1c2ab6326dcccf6f522d419)) * increase performance of ListUser by login name ignore case ([#12350](https://github.com/zitadel/zitadel/issues/12350)) ([8fed358](https://github.com/zitadel/zitadel/commit/8fed3582c47f01724bb70cf199570188f24a692d)) * **login:** allow custom protocols for native apps again ([#12332](https://github.com/zitadel/zitadel/issues/12332)) ([5b3c10e](https://github.com/zitadel/zitadel/commit/5b3c10ecd7cf4730071eab3acbd05afd2d470405)) * **login:** improve contrast of IDP processing message ([#12309](https://github.com/zitadel/zitadel/issues/12309)) ([30ad9ab](https://github.com/zitadel/zitadel/commit/30ad9ab8a1afc8fb9af00fd653b96560ff1a1d3d)) * **login:** improve error handling for user registration ([#12338](https://github.com/zitadel/zitadel/issues/12338)) ([fa916e7](https://github.com/zitadel/zitadel/commit/fa916e7659695d0e101d3af9c2b9afb155de7909)) * **login:** migrate legacy Tailwind v4 opacity utilities and fix checkbox contrast color ([#12360](https://github.com/zitadel/zitadel/issues/12360)) ([70850db](https://github.com/zitadel/zitadel/commit/70850db9d53ebdc96cdab40f6c04c654bbd2da78)) * **login:** preserve org domain suffix through account chooser navigation ([#12304](https://github.com/zitadel/zitadel/issues/12304)) ([3311fb9](https://github.com/zitadel/zitadel/commit/3311fb9ccdbcd232a59da148791bc906c04314c6)), closes [#12024](https://github.com/zitadel/zitadel/issues/12024) * **login:** Prevent IDP auto-creation failure when name fields are missing ([#11070](https://github.com/zitadel/zitadel/issues/11070)) ([ab2e099](https://github.com/zitadel/zitadel/commit/ab2e099514ff63ff39c3c36755301d461d237dd3)) * **login:** redirect to loginname instead of empty accounts page when org scope filters all sessions ([#12346](https://github.com/zitadel/zitadel/issues/12346)) ([f21f95c](https://github.com/zitadel/zitadel/commit/f21f95ce37699c5ed48618ccfa0839dfb09ee954)), closes [#11914](https://github.com/zitadel/zitadel/issues/11914) * **login:** use correct requestId with oidc_ prefix in Prompt.LOGIN + loginHint flow ([#12376](https://github.com/zitadel/zitadel/issues/12376)) ([57eb145](https://github.com/zitadel/zitadel/commit/57eb1453f26db3efdfcce26f294ad0436363e9db)), closes [#11946](https://github.com/zitadel/zitadel/issues/11946) [#11946](https://github.com/zitadel/zitadel/issues/11946) * prevent double triggering of verification emails ([#11995](https://github.com/zitadel/zitadel/issues/11995)) ([9ae9bf3](https://github.com/zitadel/zitadel/commit/9ae9bf3bc8bc55b9f47d72c48e51584fc935b814)) ###### Features * allow managing invite code in secret generators ([#12109](https://github.com/zitadel/zitadel/issues/12109)) ([915586a](https://github.com/zitadel/zitadel/commit/915586a40f1174014b116a2a653e4933468a2465)) * **crypto:** FIPS 140-3 compliant build and runtime checks ([#12233](https://github.com/zitadel/zitadel/issues/12233)) ([c03d9f4](https://github.com/zitadel/zitadel/commit/c03d9f4c6ecbd4af39e5c4dbd876244f3740e13a)) ### v4.15.3 - Date: 2026-06-22 - Version: v4.15.3 - Original notes: https://github.com/zitadel/zitadel/releases/tag/v4.15.3 - Permalink: https://whatsnew.fyi/product/zitadel/releases/v4.15.3 - **fixed** — Add client and scope validation for token exchange - **fixed** — Ensure external user's email is verified before auto-linking - **fixed** — Center text for generic IDP buttons without icons in login - **fixed** — Guard defaultRedirectUri in OIDC/SAML FailedPrecondition paths ##### [4.15.3](https://github.com/zitadel/zitadel/compare/v4.15.2...v4.15.3) (2026-06-22) ###### Bug Fixes * added client and scope validation for token exchange ([e2886a6](https://github.com/zitadel/zitadel/commit/e2886a61670ca8fd41c9434f87036546e5620bcc)) * ensure external user's email is verified before auto-linking ([c97012f](https://github.com/zitadel/zitadel/commit/c97012f0c5dc2fe960ae6e940cbea23229f0557f)) * **login:** center text for generic IDP buttons without icons ([#12211](https://github.com/zitadel/zitadel/issues/12211)) ([aadc664](https://github.com/zitadel/zitadel/commit/aadc664a206ebdf6bfd85145e9c6fcdc165a6cee)), closes [#12182](https://github.com/zitadel/zitadel/issues/12182) * **login:** guard defaultRedirectUri in OIDC/SAML FailedPrecondition paths ([0382659](https://github.com/zitadel/zitadel/commit/038265925a3b05ac1df8aad461ab071983e9eb85)) ### v3.4.12 - Date: 2026-06-17 - Version: v3.4.12 - Original notes: https://github.com/zitadel/zitadel/releases/tag/v3.4.12 - Permalink: https://whatsnew.fyi/product/zitadel/releases/v3.4.12 - **fixed** — Always validate exp and iat claims of JWT IdPs - **fixed** — Client_id verification during code exchange and refresh token flows - **fixed** — Manage and validate audience for JWT IdP ##### [3.4.12](https://github.com/zitadel/zitadel/compare/v3.4.11...v3.4.12) (2026-06-17) ###### Bug Fixes * always validate exp and iat claims of JWT IdPs ([d1c3aa8](https://github.com/zitadel/zitadel/commit/d1c3aa84af8fcb0f33910ada30b866f4afb551ac)) * client_id verification during code exchange and refresh token flows ([5b1708e](https://github.com/zitadel/zitadel/commit/5b1708e0e650398f0ebc3341714f0798b0118917)) * **jwt idp:** manage and validate audience ([42f629d](https://github.com/zitadel/zitadel/commit/42f629d8c8e63eb0721ece3aac9f88a62d6c04d5)) ### v4.15.2 - Date: 2026-06-17 - Version: v4.15.2 - Original notes: https://github.com/zitadel/zitadel/releases/tag/v4.15.2 - Permalink: https://whatsnew.fyi/product/zitadel/releases/v4.15.2 - **fixed** — Always validate exp and iat claims of JWT IdPs - **fixed** — Client_id verification during code exchange and refresh token flows - **fixed** — Connection handling in setup after migration steps 40, 64 and 70 - **fixed** — Allow overwriting resource owner of events in eventstore - **fixed** — Apply PKCE when building OAuth and OIDC providers - **fixed** — Manage and validate audience in JWT IdP - **fixed** — Accept IDP sessions on passkey registration in login - **fixed** — Load custom font from branding settings and allow in CSP in login - **fixed** — Remove unnecessary entry from default denylist - **fixed** — Use protected http client for outgoing connections ##### [4.15.2](https://github.com/zitadel/zitadel/compare/v4.15.1...v4.15.2) (2026-06-17) ###### Bug Fixes * always validate exp and iat claims of JWT IdPs ([4925fab](https://github.com/zitadel/zitadel/commit/4925fab849d39a88674485d937b79e54318b48a8)) * client_id verification during code exchange and refresh token flows ([5624030](https://github.com/zitadel/zitadel/commit/562403079a98cf2059cdac11865a45e2f285be71)) * connection handling in setup after migration steps 40, 64 and 70 ([#12293](https://github.com/zitadel/zitadel/issues/12293)) ([c53d977](https://github.com/zitadel/zitadel/commit/c53d9774d4272d3cebeee4131012c20bd77b9dfb)) * **eventstore:** allow overwriting resource owner of events ([#12261](https://github.com/zitadel/zitadel/issues/12261)) ([a939b84](https://github.com/zitadel/zitadel/commit/a939b847d90c3370bd162064e57764b89c01be46)) * **idp:** apply PKCE when building OAuth and OIDC providers ([#12247](https://github.com/zitadel/zitadel/issues/12247)) ([ab7c6c0](https://github.com/zitadel/zitadel/commit/ab7c6c09d3bb34ac3ec18fc9e0c72d810a614263)), closes [#12036](https://github.com/zitadel/zitadel/issues/12036) [#12054](https://github.com/zitadel/zitadel/issues/12054) * **jwt idp:** manage and validate audience ([999e2bb](https://github.com/zitadel/zitadel/commit/999e2bbc81b56fca693ccc87a863fdfc182b1316)) * **login:** accept IDP sessions on passkey registration ([#12275](https://github.com/zitadel/zitadel/issues/12275)) ([add46e0](https://github.com/zitadel/zitadel/commit/add46e0c8be3dbf014f77f4ca264f832e4ee49b0)) * **login:** load custom font from branding settings and allow in CSP ([#12279](https://github.com/zitadel/zitadel/issues/12279)) ([9f1561d](https://github.com/zitadel/zitadel/commit/9f1561dc8e56419bba816f5f003e96c606c9f5b1)), closes [#11200](https://github.com/zitadel/zitadel/issues/11200) * remove unnecessary entry from default denylist ([#12294](https://github.com/zitadel/zitadel/issues/12294)) ([1ca1fbd](https://github.com/zitadel/zitadel/commit/1ca1fbdab4aea43aac76e66abeda3dd3238afc84)) * use protected http client for outgoing connections ([b6f7808](https://github.com/zitadel/zitadel/commit/b6f78086913b8d916bce9ab2e049ab0d84f947fd)) ### v3.4.11 - Date: 2026-06-10 - Version: v3.4.11 - Original notes: https://github.com/zitadel/zitadel/releases/tag/v3.4.11 - Permalink: https://whatsnew.fyi/product/zitadel/releases/v3.4.11 - **fixed** — Check permission based on provided data on user updates in the API ##### [3.4.11](https://github.com/zitadel/zitadel/compare/v3.4.10...v3.4.11) (2026-06-10) ###### Bug Fixes * **api:** check permission based on provided data on user updates ([90f3102](https://github.com/zitadel/zitadel/commit/90f310212d3a5075084a603bf61fed549c92956d))