What goauthentik/authentik shipped
Written by FoxPlug from public releases; not affiliated with Goauthentik. An automatic summary of the public release, pull request and commit data of github.com/goauthentik/authentik. Goauthentik did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Blueprints now export with references, fixing the long-standing issue that exported blueprints couldn't be re-imported in different authentik instances due to hardcoded primary keys. Pull request #26069
- RAC provider now correctly parses IPv6 literal endpoint hosts like [2001:1234::1]:5900 instead of splitting incorrectly on the first colon. Pull request #24465
- OAuth2 provider now returns authorization errors to custom scheme redirect URIs used by native apps, instead of bare HTTP 400 responses. Pull request #26386
- CAPTCHA widgets in flows now render without iframe wrappers, resolving providers directly via challenge
js_urlinstead of window global sniffing. Pull request #26143 - Removed legacy user and group attribute filters that inefficiently loaded all matching objects before pagination, causing performance issues. Pull request #25802
- Core now filters application entitlements for bound users, improving efficiency when querying user-specific application access. Pull request #26384
- Added new Paginator component and revised Table and DualSelect to use standardized pagination across the web interface. Pull request #26327
- Email stage now handles errors correctly when recovering with admin-generated tokens. Pull request #24409
- Blueprints admin interface now available to read-only role, allowing broader access to blueprint management. Pull request #26363
- LDAP now supports X25519MLKEM768 hybrid cryptographic key when using TLS. Pull request #26368
Why it matters
This week brings significant infrastructure improvements: blueprints are now portable across instances, IPv6 and OAuth2 native apps work correctly, and performance issues with user filtering are resolved. The UI also gets better consistency with standardized pagination and improved CAPTCHA rendering.
Changelog entry
- Blueprints: Export with references instead of hardcoded primary keys for cross-instance portability Pull request #26069
- Providers/RAC: Fix IPv6 literal endpoint host parsing Pull request #24465
- Providers/OAuth2: Return authorization errors to custom scheme redirect URIs Pull request #26386
- Web/Flows: Render CAPTCHA widgets without iframe wrapper Pull request #26143
- Core: Remove legacy user and group attribute filters to improve query performance Pull request #25802
- Core: Add filter for application entitlements for bound users Pull request #26384
- Web/Elements: Add Paginator component and revise Table and DualSelect Pull request #26327
- Core: Remove unnecessary DISTINCT from users list when filtering by type Pull request #26413
- Blueprints: Add admin interface to read-only role Pull request #26363
- Internal/Utils: Add X25519MLKEM768 support for LDAP hybrid cryptography Pull request #26368
- Stages/Email: Fix error when recovering with admin-generated token Pull request #24409
- Core: Fix client certificate header forwarded to mTLS stage Pull request #26438
- Web/Elements: Fix scroll sticking when too many tables are visible Pull request #26423
- Web/Admin: Fix device view page and outpost view page Pull request #26383
- Web/Admin: Add user deletion to detail view Pull request #26397
- Packages/Django-Dramatiq-Postgres: Reconcile pending tasks during continuous notifications Pull request #26152
This week: blueprints export with references for portability, IPv6 RAC endpoints work, OAuth2 native app errors route correctly, and user filtering performance improves.
This week in authentik: exported blueprints are now re-importable across instances thanks to reference-based exports [5]. IPv6 RAC endpoints parse correctly [2], OAuth2 native apps receive proper error responses [3], CAPTCHA widgets render without iframe wrappers [14], and legacy user attribute filters that caused performance issues are removed [4]. Also added: standardized pagination components [28], read-only blueprint access [27], and X25519MLKEM768 hybrid crypto support for LDAP [29].
Week of September 14, 2026
What shipped
- Released version 2026.8.3 with fixes for file search, API autocomplete, blueprints, and Docker Compose configuration. Release
- Fixed migration failures occurring when upgrading from 2026.5.7 to 2026.8.2 due to inconsistent migration history. Pull request #26208
- Replaced ESLint and Prettier with Oxlint and Oxfmt for faster web linting and formatting. Pull request #26061
- Converted all JSDoc types to TypeScript using Node's built-in type stripping, bringing type safety to build scripts and web modules. Pull request #25525
- Fixed RAC browser WebSocket disconnects by implementing Guacamole instruction parsing and ping echo handling. Pull request #26207
- Added GitLab compatibility option to the web SCIM form that was missing from the 2026.8 release. Pull request #26154
- Fixed admin sidebar expansion regression and added persistence of expansion state to session storage. Pull request #26218
- Static authenticator tokens now display in hyphenated groups and accept separators during verification. Pull request #26251
- RADIUS property mappings now support returning additional properties as dictionaries and continue processing after mapping failures. Pull request #26029
- Documented percent-encoding of proxy headers to prevent failures in upstream applications with non-ASCII header values. Pull request #26093
Why it matters
This week includes a critical maintenance release fixing upgrade failures, substantial web tooling improvements for developer experience, and bug fixes for WebSocket stability and UI regressions. TypeScript adoption across the web build pipeline strengthens type safety going forward.
Changelog entry
- 2026.8.3 released with file search, API autocomplete, and blueprint fixes Release
- core: fix migrations for 2026.5.7 to 2026.8.2 upgrade path Pull request #26208
- web: replace ESLint/Prettier with Oxlint/Oxfmt Pull request #26061
- web: convert JSDoc types to TypeScript Pull request #25525
- providers/rac: fix WebSocket disconnects by parsing Guacamole instructions Pull request #26207
- web/scim: add GitLab compatibility option Pull request #26154
- web/router: fix sidebar expansion and add persistence Pull request #26218
- stages/authenticator_static: display tokens in hyphenated groups with separator support Pull request #26251
- providers/radius: allow returning properties as dictionaries and continue on mapping failure Pull request #26029
- website/docs: document percent-encoding for proxy headers Pull request #26093
2026.8.3 released: upgrade path fixed, RAC WebSocket stability improved, web tooling upgraded to Oxlint/Oxfmt, and sidebar persistence restored.
authentik 2026.8.3 is out. This release fixes migration failures from earlier versions, restores the admin sidebar expansion behavior, improves WebSocket stability for RAC sessions, and replaces ESLint/Prettier with faster Oxlint/Oxfmt tooling. The web build pipeline is now fully TypeScript for better type safety.