- Introduced passwordless Passkeys, full DPoP support (including refresh‑only binding) and FAPI 2 final compliance, strengthening security.
- Added federated client authentication (preview), automatic SAML certificate provisioning, MCP OAuth metadata endpoint, and a new conditional authenticator to skip 2FA when a Passkey is used.
- Enhanced administration with an update‑email workflow, optional organization email domain, options to hide identity providers in the account console, enforcement of recovery codes after OTP setup, and new documentation guides.