- Added numerous new features: orphan membership cleanup queries, PKI approval workflows, project template groups and machine identities, user account recovery, organization role API, and Azure SAML sign‑assertion‑only support;
- Updated documentation (rate limits section, CA:true policy, PKI docs) and introduced improvements such as increased secret name size, safe JWT schema for gateway, sanitized schema generation, and role‑based analytics grants;
- Fixed multiple bugs and edge cases including migration errors, disposable‑email validation, secret field JSON diff visibility, URL sharing for approvals, soft‑deleted secret handling, and MFA unlock email handling.