Logto v1.44.0 is here. It adds MFA trusted devices, custom and longer user IDs for migrations, Cap as a self-hosted CAPTCHA, authentication policies for SAML applications, a `theme` authentication parameter, and refresh tokens for dynamic app clients such as ChatGPT and Codex.
YijunDeveloper
Stop wasting weeks on user auth
Launch secure apps faster with Logto. Integrate user auth in minutes, and focus on your core product.
Logto v1.44.0 adds MFA trusted devices, custom user IDs for migrations, Cap as a self-hosted CAPTCHA, and refresh tokens for dynamic app clients. Here's what's new.
Users who complete MFA can now trust their browser and skip MFA there until the trust expires.
Turn it on in Console > Multi-factor authentication and set the trust duration (1 to 365 days, 30 by default).
Organizations can disallow trusted devices for their members.
Admins manage a user's trusted devices in Console or through the Management API. Users manage their own in Account Center or through the Account API.
Subscribe to TrustedDevice.Created and TrustedDevice.Deleted webhooks.
A trusted device only covers the MFA step of sign-in. Identity verification and other sensitive operations still ask for proof. See the MFA trusted devices guide.
If Cloudflare Turnstile or Google reCAPTCHA is blocked or unreliable for your users, you can now use Cap, an open-source proof-of-work CAPTCHA you host yourself. Deploy a Cap Standalone instance, then add it in Console > Security > CAPTCHA.
reCAPTCHA Enterprise also gets a configurable score threshold (0.0 to 1.0) in place of the fixed 0.5.
MCP clients such as ChatGPT and Codex request offline_access without prompt=consent, so under OpenID Connect they get no refresh token and users have to sign in again when the access token expires. Turn on Add consent prompt for offline access under Client compatibility in the dynamic app settings, and Logto adds the prompt for them.
This applies only to dynamic apps (CIMD clients). The setting is experimental and off by default.
SAML applications can reuse an existing Logto session: turn off Always force authentication (fresh authentication stays the default). They can also require signed authentication requests, and assertions now report the actual authentication time.
theme authentication parameter: Pass theme=light or theme=dark to render the sign-in experience in that theme instead of following the OS setting, for the whole flow. See authentication parameters.
The @logto/api SDK adds paginate(), a typed async iterator over paginated endpoints, plus request timeouts and more reliable token handling.
The sign-in page no longer goes blank when a browser auto-translates it.
Social sign-up only offers "link and continue" when the conflicting identifier can sign in with a verification code.
OIDC enterprise SSO issuers with a trailing slash now resolve correctly.
OIDC configuration no longer allows combining the none prompt with other values.
API error messages fall back to the base language when a regional one isn't available.
Webhook test results no longer show up on other webhooks' pages.
Apple connector: clearer Services ID setup and troubleshooting.
DingTalk (web) connector: corpId is now kept in rawData.
Database migration required: Run logto db alteration deploy (or npm run alteration deploy in the core image) before starting v1.44.0. This release widens user ID columns to 128 characters and adds a SAML configuration column. Rolling back fails once any user ID exceeds the old limit.
Leftover PostgreSQL roles: logto db seed now checks for roles left by a previous Logto database before creating any tables, and explains why dropping the database didn't remove them. (Credit @ryanchou1994)