Skip to content
Changelog

Changelog Update: February 2026

Dashboard redesign with dark mode and mobile support, new Authorizer API endpoints for credential retrieval and cross-device flows, and expanded verification policy capabilities for holder binding and transaction data.

Authorizer

  • Credential Claims Retrieval API: A new endpoint (GET /credentials) returns extracted credential claims from completed authorizations. Supports SD-JWT, mDL/mDoc (ISO 18013-5), W3C VC JSON-LD/JWT, and W3C VP formats, with binary data such as mDL portraits encoded as base64. Claims are stored regardless of authorization status, supporting both successful verification workflows and debugging of rejected submissions.
  • Response Code Resolution for Cross-Device Flows: A new endpoint resolves single-use response codes returned in redirect_uri after wallet submission during OpenID4VP cross-device flows. Response codes have a 5-minute TTL with atomic consumption, ensuring only one resolution succeeds per code.
  • Transaction Data Verification Policy: Verification of transaction data as defined in OpenID4VP Appendix B.3.3.1, supporting Strong Customer Authentication (SCA) use cases. Tested with the iGrant wallet.
  • Holder Binding Policy: Holder binding checks are now configurable as a dedicated policy, with support for holder binding requirements via the HAIP profile or DCQL. This separates holder binding from the proof policy for more granular control.
  • Trust Anchor Certificate Display: Authorizer instance details now show the configured trust anchor certificate type, anchor, and certificate content, with copy and download actions. A new management API endpoint provides programmatic access to trust anchor certificates.
  • Authorizer Demo Navigation: The previous authorizer tester has been replaced with navigation to the Authorizer Demo, which includes automatic gateway configuration for faster testing.

Dashboard

  • Complete UI Redesign: The dashboard has been fully migrated to the shadcn component library, replacing the previous Flowbite-based interface. The redesign includes a new overview landing page, simplified instance and configuration page layouts, and an updated icon set throughout.
  • Dark Mode: The dashboard now supports dark mode, reducing eye strain for users working in low-light environments.
  • Mobile-Responsive Layout: The dashboard is now fully usable on mobile devices, with responsive layouts across all pages.
  • Bug Fixes: Corrected wildcard CORS header handling, fixed an instance row alignment issue, removed a false warning displayed when accounts had no instances, and corrected instance links on the welcome page.

Platform

  • Improved Error Handling: DELETE operations and other API error paths now return appropriate HTTP status codes (400 for validation errors, 404 for not-found, 409 for conflicts) instead of exposing internal error messages, improving both security and developer experience.