Skip to content
Authreads

Roadmap

What's built.
What isn't. No dates.

Described by capability and current state, not by internal sequencing. A capability we describe honestly lets you evaluate what's actually true today.

Blueprints and technical drawings spread across a table, lit from one side

How to read this roadmap

Everything below is described by capability and current state, not by date or internal sequencing. A date we publish and miss helps no one, and a capability we describe honestly lets you evaluate us on what's actually true today.

Available

Available today

Hosted login

Available

OpenID Connect authorization-code flow with PKCE, plus a first-party API for a product that builds its own login screen.

Multi-tenant isolation

Available

Tenant scoping enforced at the data layer, so one tenant's request cannot reach another tenant's data.

Session management and revocation

Available

Idle and absolute session expiry, a visible device and session inventory, and revocation by the user, a tenant administrator, or the product via API.

Per-tenant security policy

Available

Password rules, session lifetimes, and notification behavior configured per tenant.

Machine and agent identity

Available

Sender-constrained tokens (DPoP, RFC 9449) and Token Exchange (RFC 8693) for services and agents.

Tenant branding

Available

A tenant's own logo, color, and copy on the hosted login screen, checked for accessible contrast before publishing.

In progress

Actively being built and hardened, on top of the capabilities already available above.

Custom login domains

In progress

Serve the hosted login experience on a tenant-owned hostname without changing the tenant's OpenID Connect integration.

Finer-grained session policy controls

In progress

Additional per-tenant control over session behavior beyond today's idle and absolute expiry and revocation.

Expanded tenant branding surface

In progress

Broader customization of the hosted login and account-security experience, still reviewed against WCAG AA before it can ship.

Planned

Planned

Planned

Passkeys and MFA

WebAuthn passkeys and additional multi-factor verification methods as first-class sign-in options.

Planned

Fine-grained authorization

Authorization decisions (what an authenticated identity may do) beyond today's authentication boundary.

Planned

SAML and SCIM

Enterprise federation (SAML) and automated user provisioning (SCIM) for tenants that need to plug into an existing identity provider.

Planned

Hardware-bound sessions

Session binding backed by hardware-rooted device attestation, for tenants with a stronger device-trust requirement.

Planned

Continuous session evaluation

Ongoing, signal-based re-evaluation of an active session rather than trust decided once at login.

What this page deliberately leaves out

No dates, no version numbers, no internal phase names. A roadmap that reveals exactly what's unfinished and when it's due is useful to a competitor and not especially useful to you. What you actually need to know is whether a capability exists today, is being hardened, or hasn't started. That's what the three states above tell you, and we keep them current.

For the standards each capability is built on, see the platform page. For what's stored and how credentials are handled today, see Security.

Curious where something specific stands?

Ask directly, and we'll give you the honest current state, not a projected one.