Logto
In progress
β¨
Multiple custom domains
Support multiple custom domains and render different sign-in experience brandings according to the domain.
27
π€
Out-of-the-box account center
Instantly integrate a fully featured Account Settings page into your app.
20
Planned
ποΈ
Session management
Managing user sessions with multi-device session tracking, session controls, etc.
45
π
Passkey as a first authentication factor
Support passwordless authentication with passkey sign-in
41
π‘οΈ
Adaptive MFA
Trigger MFA according to the current risk level, e.g. a new device, IP, etc.
22
π¨οΈ
OAuth 2.0 device flow
Support RFC 8628: OAuth 2.0 Device Authorization Grant.
20
π€
Username policies
Adjust username case-sensitivity, length restrictions, allowed charset, etc.
14
π§
Friendly "continue" prompt
Simplify wording when no matching account is found during sign-in experience.
2
π
Support localization parameter in content URLs
Allow specifying a localization parameter in privacy policy and terms of use URLs.
2
Connectors: Sync unverified email
Choose whether to sync unverified emails from social or enterprise identity providers via OIDC.
1
π
Set up MFA for Logto Cloud
Manage MFA (passkeys, authenticator apps, backup codes) in your Logto Cloud console profile.
1
β©
Passkey experience improvements
Set passkey as a supplemental and custom passkey names.
0
Backlog
π¨
Account center elements
A set of framework-agnostic web components that can interact with Account API.
34
π
API authentication
Authenticate users via API. No redirect needed.
31
π
Redirect URI wildcards
Support for wildcard patterns in redirect URIs to improve authentication for dynamic environments like preview deployments.
25
π’
Authentication policy
Customize policies to control authentication, such as username rules, IP blacklist / whitelist, verification code expiration, etc.
17
π
RBAC as code
Allow to use code-based configuration to provision role-based access control, for example, a YAML file.
17
π°οΈ
Sign-in experience elements
A set of framework-agnostic web components that can interact with Experience API.
15
πΊ
Organization portal
An out-of-the-box solution that allows org admins to manage identities, organization profiles, and set up enterprise SSO themselves.
13
π
SCIM API
System for cross-domain identity management APIs.
12
π₯οΈ
Single sign-on dashboard
Making it easier for users to see all the apps theyβre connected to in one simple, centralized place.
10
β΅
Attribute-based access control (ABAC)
Define dynamic access policies using user or resource attributes for context-aware security.
7
π
Logto Management API key
Generate a secure key for programmatic access to the Logto Management API
7
β‘οΈ
Just-in-time user migration
Migrate users from your legacy system to Logto only when they sign in.
6
π§ββοΈ
Restrict user sign-ins to a specific app within a multi-app product
Block users at the login stage if they come from a specific app. This will essentially enable app-level authentication (beyond just branding).
5
β‘
Google One Tap for websites
Add Google One Tap to your website and authenticate users through Logto.
5
π
Custom claims for ID tokens
Add custom claims to ID tokens using JavaScript code snippet.
5
π
Support Dynamic Client Registration
RFC 7591: OAuth 2.0 Dynamic Client Registration Protocol
4
β²οΈ
Customize OIDC access token TTL & session TTL
Provide an option to override the default OIDC access token time-to-live (TTL) and session TTL.
4
π²οΈ
Support CIBA flow
Support Client Initiated Backchannel Authentication (CIBA) Flow.
3
β
Prevent search engine indexing
Provide an option to emit a noindex meta tag or X-Robots-Tag response header for sign-in pages.
3
π‘οΈ
Support machine-to-machine access policy
Limit access by IP address, user agent, and other policies.
2
Account API audit logs
Track all end-user activities performed through the Account API, including identifier, password, MFA, and profile updates.
2
βοΈ
Registration from forgot password
Directly register via forgot password instead of prompting for another round of verification.
2
β
Unverified email/phone number
Skip verifying email/phone number during sign-up.
1
M2M authentication IP allowlist
Restrict access to machine-to-machine applications only from allowed IP addresses or CIDR ranges.
1
π
Unverified SSO email verification
Allow verification code flow for SSO-provided unverified emails.
1
βοΈ
Allow concurrent Google Workspace and social login
Option to allow both Google Workspace and Google social logins for the same account.
1
πͺ
User role change webhook event
Invokes your API whenever a userβs role or organization role changes.
1
πͺ
Exchange organization token in authorization code flow
0
πΊοΈ
SAML social connector
Support SAML social connector for government-backed regional IdPs (e.g., SPID, eIDAS, Singpass).
0
π«§
RFC 9396: OAuth 2.0 Rich Authorization Requests
Implement RFC 9396 and provide some useful feature around it.
0
Smart country code detection
Auto-detect and select the right country code when users enter or paste full phone numbers with "+"
0
Application portal
Provide a centralized portal for end-users to view and launch all their authorized applications.
0
ποΈ
Customize account existence visibility
Show whether the account exists before code verification during sign-in or sign-up.
0
Country code restrictions for phone input
Limit selectable country codes in the phone number field to support region-specific apps
0
Email allowlist
Allow admins to define a list of email domains or addresses that can register.
0
Minimum age limit for sign-up
Configure a mandatory minimum age for the birthdate sign-up field to ensure compliance
0
π«
Opaque tokens for API resources
Issue opaque tokens instead of JWTs to allow real-time introspection for API resource access.
0
Completed
βοΈ
Profile fulfillment
Collect mandatory and optional profile fields during user registration.
41
π«
Block disposable email registration
Reject any sign-up attempts using a disposable email address to prevent spam and improve user quality.
20
π
SAML IdP
Use Logto as a SAML identity provider.
20
π§βπ
Account API
A set of APIs and rules that allow end-users to update their identifiers and profile.
19
π°
Captcha support
Add reCAPTCHA / Cloudflare Turnstile / hCaptcha for bot protection.
18
π©
Dev to Pro plan production tenant
Directly convert Dev tenant to a Pro tenant.
14
π
SOC 2 compliance
Achieve SOC 2 compliance and obtain certification.
4
π
Account API for MFA
Allow end users to update, delete, and verify TOTP via Account API.
3
π
Hide Logto branding
Remove "Powered by Logto" to spotlight your brand exclusively on the sign-in experience.
3
π
Email & SMS verification for MFA
Enable email or SMS passwordless verification for multi-factor authentication.
3
π§°
Typed library for Management API
Provide typed libraries for services (e.g., Node.js) to use Logto Management API.
3
ποΈ
Secret vault
Securely let users authorize third-party services, then store, manage, and use the tokens with Logto.
2
π
Account API for Passkey
Register, name, and manage multiple passkeys via Account API.
2
πͺ
Magic link
One-time token for organization member invitation, user invitation, password recovering, etc.
2
πΎ
Sign-up capability improvement
Multiple sign-up identifiers (e.g., email & username) and other improvements
2
π
Console UI for Account API
Directly manage access permissions for Account API in the console.
1
β»οΈ
Customize identifier lockout policy
Customize the policy to provisionally lock accounts after multiple failed sign-ins to prevent brute force access.
0
π
Add `ui_locales` authentication parameter
Use ui_locales to adjust the sign-in locale dynamically and expose it to email templates.
0
π¨
Custom CSS per organization
Customize organization's sign-in experience with exclusive logo, favicon, colors, and custom CSS.
0
π§΅
WordPress plugin integration
0
Powered by Productlane
New request
Powered by Productlane