Last 7 days
0
Features: 0
Changes: 0
Fixes: 0
Deprecations: 0
Managed secrets, certificates, key management, and privileged access platform.
Latest Infisical changelog updates, official release notes, breaking changes, security patches, pricing changes, and developer reactions in one product feed.
Follow this Infisical release-notes page to spot useful features, risky migrations, noisy announcements, and source links before they hit your backlog.
Changes.Watch links back to official changelog and release-note sources so summaries stay easy to verify.
Use channels to follow groups of tools around a stack, workflow, or topic.
Rolling windows show how many product updates landed in the last 7, 30, 90, and 365 days, grouped by existing changelog semantics.
0
7
43
131
Added upgrade impact notes and updated the create sub‑organization modal to version 3.
Updated Docker integration documentation
Added new PAM features (auto‑fill account fields, Redis account type/web access) and PKI support for AWS Private CA; introduced extraArgs to the gateway Helm chart.
Added new PAM capabilities: auto‑populate account fields from a pasted connection string, Redis account type and web access, and AWS Private CA support for PKI certificates.
- UI/UX enhancements and fixes: normalize iOS input font, restore default styling, add selected action bar, dedicated 403 page, migrate gateway/relay UI, revamp personal settings, improve onboarding form spacing and verification code input
UI and UX upgrades: improved machine‑identity template visibility, full secret path tooltip, and added SCEP support for Microsoft Intune.
Added new service templates (Google Workspace) and expanded PAM capabilities (domain detection, Windows rotation) along with UI enhancements like product activation coloring, refined signup flow, and admin console migration.
Added auto‑rotation for Azure app connections and LDAP credentials; allowed user‑defined GCP replication regions
Added PKI sync for KEMP Loadbalancer and made certificate properties optional for ADCS CAs.
Added new secret rotation integrations (Datadog API keys, Snowflake user key) and support for pre‑hashed RSA signing for HSM PKCS#11 signers.
Added Nutanix Prism Central as a PKI sync destination and domain support for the CLI access command
Return secretPath in imported secrets
Added dynamic secret integrations (Fold, Tailscale, proxied services) and HMAC key support in KMS; enhanced PAM SSH logging, Unix discovery, and gateway Helm properties.
Revamped 2FA UI with account‑wide recovery codes and introduced secrets brokering via proxied services and an agent proxy CA.
Added metrics collection for secrets
Fix LDAP group CN matching to be case‑insensitive per LDAP semantics.
Cache identity token revocation checks and tighten marker expiry for improved security and performance.
Staggered daily resource cleanup jobs and improved safety of request updates.
Added a revamp of the PAM feature.
Add PAM access request/approval flows, GCP service‑account access type, and revamp PAM rotation
Revamped PAM user experience and added secret sync support for Rundeck.
Add native Windows ADCS support
Revamped the add‑member‑to‑group modal and introduced HSM‑backed internal certificate authorities with exposed sync identifiers in API/UI.
Added cross‑project secret sharing support
Migrated various modals and UI sections to the new v3 component library, renamed the Overview tab to Secrets, and refreshed audit logs, change request, and secret insights interfaces.
Refactored secret project settings and moved the remove product button to the management sheet UI.
Added extensive PAM enhancements including MongoDB, MS SQL, MySQL data explorers, MFA flow, command blocking, session log masking, Windows RDP, and S3 recording overrides
Added API endpoints for managing application memberships
Updated license client to include organization identity (name, slug, region) in entitlements calls
Expanded identity and secret management with AWS workload identity federation support, SAN validation, new PAM account types (MongoDB, MS SQL), registry-driven template policies, HSM connector for PKI code signing, and Trigger.dev integr...
Updated Migrate app connections UI to v3 components and added document upgrade tool link in self‑hosted upgrade guides
- Added new features: shadow mode enhancements, project resource count on secret insights, FQDN support for PKI syncs, empty‑value checks for secret references, and ability to invite users when SSO enforcement is enabled.
Added MySQL account support, a new endpoint to retrieve project roles by ID, dual entitlement reads with discrepancy logging, and a license‑server billing UI.
Added security and management features: PAM sessions, audit logs, access control pages, KMS key rotation, TLS client‑cert authentication, and improved certificate handling
Added new security and integration capabilities such as configurable GCP IAM scopes, unexportable KMS keys, certificate revocation via thumbprints, and a PKI signer helper.
Migrated several UI components (invite modal, service token modal, toast, settings tabs) to v3 with improved flows and validation UI.
Added async project deletion with a soft‑delete workflow and paced hard‑delete worker.
Updated UI components and added new detail and search views (Migrate project modal v3, certificate metadata search, profile/policy details).
Fix app connection to pass projectId and version for AWS AssumeRole external ID
Added extensive telemetry events, DigiCert revocation support, ACME order hardening, post‑quantum DSA signing algorithms, and a new enforceIdentityLimit flag for identity limits.
Added upgrade impact notes for v0.160.6 (docs)
Fix redlock release edge case and address authorization bugs in PKI and licensing handling
Added new security and integration features such as LDAP mTLS client certificate support, Azure Key Vault certificate authentication, resource identity auth for relays, and Salesforce OAuth secret rotation
Added telemetry events for organization creation, RBAC role changes, and enriched self‑hosted stats; introduced permission audit for project machine identities.
Improved certificate management: export project fixes, CA CRL rotation and DigiCert polling now run via cron jobs.
Add permission audit feature to project users page and revamp PKI migration updates
Added browser‑based RDP client with session recording, duplicate‑secret support across environments, PVC for session‑recording persistence, and extensible error tracking in the API.
UI improvements: added organization overview product category tiles, navbar type selector, and redirected users to their last visited project on login.
Added extensive new features: Oracle DB support for PAM, Valkey memory DB for dynamic secrets, secret rotation for Datadog with verification button, distributed Redis‑backed cron jobs, gateway pool across platform, RDP session replay pla...
Added new UI components (tab and stepper) and announcements feature for both cloud and self‑hosted deployments.
Added new PAM capabilities: export with cell scroll and RDP access for Active Directory domain accounts; improved audit‑log queue messaging.
Added custom CRL distribution points for PKI CAs and made TLS verification configurable for identity Kubernetes auth, plus a limit on ACME requests for external CAs.
Added logout to the create organization modal.
Added many new features including a 7‑day grace period for secret deletion, secret rotation support for Supabase, HA gateway pools, Venafi TPP CA integration, PAM‑isolated Postgres connections, audit‑log filtering, user‑controlled SSL re...
Added Gitpod support to secret sync feature.
Fixed group handling to run filters, ordering, and pagination on the backend
- Fixed multiple UI and backend issues including table re‑render debounce, lockout handling, modal overflow, and migration queue bugs.
Introduced several new features including dedicated AD server domains for PAM, PKI PQC readiness charts, AWS ACM Public CA support, frontend systemd CLI display, and updated default request config.
Prevent duplicated 'v' in on‑prem version badge (frontend bug fix)
Added ghost accordion variant, new accordion stories, and removed the unstable v3 prefix in components.
Introduced multiple new features: revamped Certificate Manager navigation, project permission caching, PAM gateway auth for Kubernetes, auth system adaptation, login‑V2 user flagging, and webhook edit/event selection.
Redesigned the audit‑logs date range picker UI
Added deployment, instance, and region telemetry; OCI labeling; dynamic SCEP challenges; bulk tag modal; and gateway enrollment token flow
Added documentation for event‑based cache refresh in the proxy module
Fixed validation issue in PKI certificate profile creation form.
Updated documentation to replace team@infisical.com with support or sales contact.
Added new features such as real‑time PAM session log sync, SQL runner in data explorer, request‑scoped memoization, cache helper, AI session insights, and UI enhancements like version display and sync status icons.
Fixed multiple issues: PAM routing, secret value dirty state in atomic mode, vault migration org ownership checks, audit log retention, Kubernetes auth DNS, ID mismatches, and added API host to PostHog config.
Fixed multiple bugs: UA identity orgSlug verification, old route redirect compatibility, boolean display in Data Explorer, and missing project permissions.
Added ability for sub‑organization projects to grant secret access to the root organization when permissions are valid.
- Custom roles are now exclusive to Enterprise plans, ending temporary Pro availability (breaking/deprecation).
Added SSH PAM exec and SFTP support and ability to terminate active PAM sessions
Added several new features: vertical navbar in dashboard, magic‑number validation for secret sharing, and a revamped secret access insights sheet.
Migrated numerous UI tables (org roles, service tokens, memberships, roles, groups, machine identities) to new v3 components and added role filtering.
Added PAM rotation revamp (including Windows rotation and UI), browser data explorer for Postgres, webhook support for secret rotations, and new SCEP enrollment method.
Hide project type on edit template to prevent noop updates
Added manual gateway health check trigger, new PKI alert types, request expiration for approval policies, MFA token exchange fix, and project name inclusion in secret approval notifications.
Add MSSQL PAM support (new feature)
Add custom role selection in organization invites, IP address SAN support for ACME certificates, and an option to disable certificate import during Azure Key Vault sync.
Added automated intermediate CA signing and renewal, Infisical secret sync, and single‑env secret selection features
Added RBAC policy conditions for certificate metadata and HP iLO local account password rotation (security feature).
Fixed operator subset check, audit‑log ordering, and ACME fields to prevent undefined org IDs and missing data.
Added PostHog identifyUser hook, new telemetry events and SDK updates for analytics
Enhanced identity permissions handling
Fixed backend token renewal to include decoded identity auth property
Added machine‑identity support with PostHog telemetry, actorType indicator, Redis deduplication, and automatic tidy of expired certificates.
Fixed JSON insertion error when writing to ClickHouse
Add PostHog event tracking for approval workflows and remove OAuth sources from attribution events
Added DNS configuration support for ACME external CAs and PostHog tracking for secret sync events.
Implemented PostHog event tracking for dynamic secrets.
Added new features: PostHog identify() calls for user/person and org name enrichment, Claude context support, and extraEnv option in the Infisical Helm chart.
Added metadata support, RBAC, and Windows discovery for PAM, plus SSH web access and dynamic operation IDs.
Added multiple new features including auto KMIP setup, wildcard/regex support for Kubernetes auth, sub‑organization login selection, navigation from reference tree, PKI metadata and daily expiration alerts.
Added support for adding environments, secret import, and GTM on the overview page, including CSP update for GTM
Added new membership API for org and sub‑org groups, Azure DNS provider for ACME, and AWS PCA integration for PKI
Adds validation for conflicts before rotating external credentials during secret rotation.
Added many new features: wildcard OIDC email domains, PKI network discovery, durable Redis queue persistence, secret version redaction, secret sharing API, Fly.io auto‑redeploy, reusable Vault gateway, secret reminder, PAM browser termin...
Fixed AWS Secrets Manager sync to correctly handle key schema in many‑to‑one mappings and resolved ENOTFOUND errors for HCP Vault connections
Introduced a revamped event architecture with improved cleanup and new event service capabilities.
Added PKI enhancements: default TTL for certificate profiles, certificate details page, policy creation option from profile form, and ACME enrollment option to skip EAB validation.
Added numerous new features: orphan membership cleanup queries, PKI approval workflows, project template groups and machine identities, user account recovery, organization role API, and Azure SAML sign‑assertion‑only support;
Added custom Unify script support to Mintlify docs.
Fix unhide all API paths in dev mode
Updated Dockerfile to exclude development dependencies from the final image
Added granular PII filtering with configurable entity types in the agent sentinel.
Added support for issuing intermediate CAs via certificate profiles, Cassandra dynamic secret handling, and name‑based RBAC permission conditions for MCP endpoints; improved host validation errors.
Added Unix/Linux password rotation and enhanced OAuth handling for servers lacking RFC 9728 metadata and MCP Inspector compatibility.
Added custom branding for secret sharing and Bearer Token authentication support for Agent Sentinel (MCP servers).
Added SSH app connection feature.
Added docs sections for supported K8s versions, activity‑log screenshots after Agent Sentinel rebrand, and Databricks rotation guidance
Introduced numerous features such as PAM UI enhancements, WebAuthn MFA, Redis access for PAM, SCIM event support, dynamic secret migrations, Databricks secret rotation, KMS key export, and added telemetry for KMIP operations.
Updated project group membership UI and added new v3 components
Introduced many new features including PAM Kubernetes support, ACME DNS challenge and skip‑DNS validation, certificate request UI, SCIM external group mapping API, machine identity groups, optional CDN URL configuration, Octopus Deploy i...
Fixed gateway Helm permission errors
- Added tooltip for unknown user actors in audit logs and refined PKI access control permissions
Added external CA support to PKI and background HTTP‑01 challenge with retries
Added expiring SCIM token notifications and switched SAML to user‑alias verification (new features).
Added DNS Made Easy support for external CA/ACME and related documentation.
Added multiple new authentication and PKI features such as SSH PAM, AWS/Chef PKI sync, self‑signed certificate support, group projects table, and SPA cache‑control.
Added extensive PKI enhancements: export certificates in PKCS12, ACME external CA support, template presets, license check, and updated documentation.
Added new PKI capabilities (ACME enrollment, legacy template option, alerting v2) and Azure certificate authentication for app connections.
Added Terraform EC2 support to the interactive setup and new text/user‑agent filters to the audit log UI.
Added new app connections (Northflank, Chef data bag) and extended PKI capabilities (UI creation of subscribers/templates, certificate syncs, Azure PKI rename, AWS ARN option).
Fixed omnibus automatic releases that were failing.
Introduced several new features: interactive CLI for gateway/relay deployment, PKI auto‑renewal, PAT support for GitHub, group access token support for GitLab, MySQL PAM, dynamic secret Vault migration, and extended TTL validation up to ...
Implemented new frontend navigation structure and UI fixes for Tailwind upgrade.
Add Laravel Forge integration and Vault policy migration tooling, plus new Kubernetes operator documentation
Added extensive secret management features including temporary AWS IAM role credentials, Azure Key Vault/SQL secrets, Redis rotation, PKI sync, and project‑scoped app connections
Fix several permissioning and secret handling bugs (commit permissions, host resolution for Postgres, SQL Server dynamic secrets, secret reference formatting, SSO seat limit check)
Add HC Vault Gateway support, custom vault migration UI, and Redis cluster/replica support, plus primary forwarding mode completion.
Added numerous new features including role description UI, machine identities endpoint, InstantUpdates for K8s operator, environment groups rendering, secret approval reviewer read access, Checkly group variables, Microsoft ADCS PKI conn...
Introduced multiple new features including CSV secret import, policy limits on access request times, editing of access requests by admins, GitHub app connection pagination, Couchbase dynamic secrets, and API path returns for folder opera...
Fix duplicate Helm labels bug in the k8s operator
Added release channels with nightly builds and removed the “postgres” suffix from Docker tags.
Added new features such as bulk‑commit value handling, MSSQL server name support, last‑logged‑in auth method field, and improved identity auth template upgrade logic.
Added multiple new features including audit‑log storage disable flag, timeout, secret‑reminder date filter, GitHub Enterprise Server support, LDAP auth for the K8s operator, Machine Auth templates, Helm imagePullSecrets support, and exte...
Added new app connection features: Cloudflare DNS provider, Netlify secrets sync, and an events system implementation.
Added Azure Client Secrets authentication for Azure app connections and reduced token expiry for secret rotation
Added secrets detection in the secret manager and a new gateway for GitHub App connections & secret sync.
Fixed CVE related to form data handling
Fix Azure client secrets permissions issue
Add column resizing to the secret dashboard env view and enable automatic redeploy on secret sync
Added AWS attributes for ABAC machine identity and introduced project audit logs pages.
Fix oracle connection failure in the app
Added new app connection integrations (SQL gateway, Okta, DigitalOcean, Bitbucket) with secret rotation support and moved products out of projects
Added new secret sync integrations (AWS IRSA, Cloudflare Workers, Supabase, Checkly) and native FIPS support for enhanced security
Enhanced the CLI to correctly detect the latest available version
Added Bitbucket data source and app connection support for secret scanning.
Patch release v0.136.1 for the Postgres variant with unspecified changes; see the GitHub compare link for details.
Added autoplay to loading Lottie animation and fixed the project‑select tooltip.
Refactored utils.go to align with Gitleaks version 23b20ebda
Added multiple new features including telemetry aggregation, TLS cert identity authentication, Project UI v3, environment overrides for super admins, custom field labels for 1Password and Zabbix secret sync, weekly user re‑invite, audit‑...
Add GitLab secret sync support
Migrated dynamic secret handling to Postgres queue, added Cloudflare app connection, secret sync, Helm auto‑bootstrap, and projectSlug support for secrets v3.
Added Kubernetes client usage
Added extensive dynamic secret support (K8s, AWS, GCP, Azure, Oracle, Alibaba) and full gateway authentication with multiple auth methods, plus a Point‑In‑Time (PIT) revamp and new secret sync integrations (Fly.io, Heroku).
Updated CLI flags to use dash notation and added a project slug flag for dynamic secret commands
Fix handling of empty target URLs
Added support for multiple authentication methods in the gateway component.
Add Azure OIDC authentication documentation and several new features including AWS assume‑role for dynamic secrets, GCP sync support, K8s metadata in template policies, identityName in dynamic secret templates, and a project group detail...
Updated the connection.go file with recent changes
Added new Vertica dynamic secret option, project creation lock with invalidate function, and Kubernetes gateway token reviewer support; extended key schema with {{environment}} placeholder.
Fix gateway error handling for malformed URLs.
Added new gateway authentication methods to the CLI
Improved CLI error handling.
Workspace file is now required only when the project ID is omitted, simplifying CLI configuration.
Added auto login for bad user sessions
Added MySQL secret rotation v2, dynamic secret username templates, and an organizations overview UI.
Add automatic opening of the default web browser during CLI login flow.
Added PKI support for ACME & external CAs, Redis Sentinel, Kubernetes dynamic secrets, and certificate issuance against templates
Added numerous features including policy bypass permissions, custom SMTP CA certs, audit logging, OCI and 1Password secret sync, per‑page persistence for tables, and org‑ID logging
Updated license server functionality.
Disable ClusterGenerator watching in namespace‑scoped installations
Added secret sharing controls: enable/disable sharing, specify recipient emails, and set org‑level shared secret limits.
Updated the agent implementation in agent.go
Added support for underscores in key schemas and updated documentation.
Added duplicate org/project role capability, Oracle Cloud machine identity authentication, secret key schema, and identity support for audit log retention.
Added new features including OCI Vault secret sync, project role templates, PKI subscriber support, and cache‑control for index.html
Removed SSH functionality from the CLI, potentially breaking existing workflows.
Added rate limiting to all email‑sending API endpoints.
Fixed ESM import error in Octokit integration
Added several new features including admin cache invalidation, Kubernetes secret generator support, and a policy selection modal for project roles;
Added configurable allowed hosts via env var, SSH host group support, and PKI secret key storage with new fetch endpoints.
Introduced several new features including direct reference warnings, customizable auth token expiration, Azure client secret rotation, agent secret sync, Microsoft Teams workflow integration, Hashicorp Vault sync, and automatic GitHub SS...
Added ability to sync imported secrets in the agent
UI fix for users with edit permissions but lacking read secret value permission.
Fixed a KMS memory leak.
Add an alias field to SSH host configurations
Introduce an optional alias field for SSH host configurations
Added several new features including secret caching v2, AWS IAM user secret rotation, LDAP connection, TeamCity secret sync, user token CLI, admin SSO bypass with email/audit, and non‑interactive mode enhancements.
Adjusted CLI flags to dash-case syntax.
Added service token expiration notifications, project delete protection (default off), and Windmill integration;
Increased Certificate SAN character limit to 4096 and added metadata‑based permissions for dynamic secrets
Add warning when deleting secrets that are imported elsewhere
Added caching layer for secret DAL to improve performance
Added SSH host management features such as writeHostCaToFile, configure sshd flag, ssh host command, and host endpoint for issuing certificates
Added new features: project identity lookup, Vercel and Terraform Cloud secret sync integrations, Camunda app connection, and Infisical SSH V2.
Added automatic Kubernetes service‑account token creation for k8s auth and winget support in the build process.
Renamed the installation file.
Updated artifact distribution for Debian/Ubuntu releases
Added banner handling that respects the silent flag
Added numerous features including audit‑log filtering by secret key, folder content replication, PKI telemetry, Secret Rotations v2, UI enhancements, and a self‑hosted license fetch without redeploy.
Fix missing token error when executing the `secrets set` command in the CLI
Added nodeSelector/tolerations support in Helm charts, Go templating for InfisicalPushSecret CRD and preserved Helm charts to streamline releases
Added support for custom HTTP headers in CLI and SDK Config, with enhanced documentation
Added validation for dynamic secrets and optimized client secret comparison in machine identity login.
Ensures domain settings are retained when writing the initial config during CLI login.
Added recursive flag to folder GET endpoint and indexed/optimized folder queries for faster nested retrieval.
Fixed minor gateway issues.
Added automated instance bootstrapping command to the CLI
Reverts the added environment existence check for the run command
Upgrade passport/saml dependency to version 5.0
Added Kubernetes ConfigMap support for managing secret configurations
Added support for verifying project environments and introduced related utilities and models.
Added project slug editing, admin console role access tree, machine identity view, and enhanced secret permission features.
Add proper support for systemd with a new `install` subcommand that decouples installation from running the gateway