Roadmap
What's built.
What isn't. No dates.
Described by capability and current state, not by internal sequencing. A capability we describe honestly lets you evaluate what's actually true today.
How to read this roadmap
Available
Available today
Hosted login
OpenID Connect authorization-code flow with PKCE, plus a first-party API for a product that builds its own login screen.
Multi-tenant isolation
Tenant scoping enforced at the data layer, so one tenant's request cannot reach another tenant's data.
Session management and revocation
Idle and absolute session expiry, a visible device and session inventory, and revocation by the user, a tenant administrator, or the product via API.
Per-tenant security policy
Password rules, session lifetimes, and notification behavior configured per tenant.
Machine and agent identity
Sender-constrained tokens (DPoP, RFC 9449) and Token Exchange (RFC 8693) for services and agents.
Tenant branding
A tenant's own logo, color, and copy on the hosted login screen, checked for accessible contrast before publishing.
In progress
Actively being built and hardened, on top of the capabilities already available above.
Custom login domains
Serve the hosted login experience on a tenant-owned hostname without changing the tenant's OpenID Connect integration.
Finer-grained session policy controls
Additional per-tenant control over session behavior beyond today's idle and absolute expiry and revocation.
Expanded tenant branding surface
Broader customization of the hosted login and account-security experience, still reviewed against WCAG AA before it can ship.
Planned
Planned
What this page deliberately leaves out
No dates, no version numbers, no internal phase names. A roadmap that reveals exactly what's unfinished and when it's due is useful to a competitor and not especially useful to you. What you actually need to know is whether a capability exists today, is being hardened, or hasn't started. That's what the three states above tell you, and we keep them current.
For the standards each capability is built on, see the platform page. For what's stored and how credentials are handled today, see Security.
Curious where something specific stands?
Ask directly, and we'll give you the honest current state, not a projected one.