Logto
Requests
Discover our plans and suggest new improvements.
New request
In Progress
ποΈ
Session management
Managing user sessions with multi-device session tracking, session controls, etc.
49
π
Passkey as a first authentication factor
Support passwordless authentication with passkey sign-in
47
π‘οΈ
Adaptive MFA
Trigger MFA according to the current risk level, e.g. a new device, IP, etc.
26
π€
Out-of-the-box account settings
Instantly integrate account setting flows (e.g., update email, password, MFA) with a prebuilt UI into your app.
23
Include IP address in HTTP SMS connector
Add the client IP address to the payload to enable IP-based rate limiting and reduce abuse.
0
π°οΈ
Third-party app for SPA & Native
Currently in progress
0
Planned
π¨οΈ
OAuth 2.0 device flow
Support RFC 8628: OAuth 2.0 Device Authorization Grant.
21
π€
Username policies
Adjust username case-sensitivity, length restrictions, allowed charset, etc.
14
π
SCIM API
System for cross-domain identity management APIs.
12
πΆ
Connectors: Sync unverified email
Choose whether to sync unverified emails from social or enterprise identity providers via OIDC.
2
π
Set up MFA for Logto Cloud
Manage MFA (passkeys, authenticator apps, backup codes) in your Logto Cloud console profile.
2
π
Custom ID token
Add custom user data to the ID token so clients can access identity details instantly
0
Backlog
π¨
Account center elements
A set of framework-agnostic web components that can interact with Account API.
36
π
API authentication
Authenticate users via API. No redirect needed.
32
π
Redirect URI wildcards
Support for wildcard patterns in redirect URIs to improve authentication for dynamic environments like preview deployments.
27
π
RBAC as code
Allow to use code-based configuration to provision role-based access control, for example, a YAML file.
18
π’
Authentication policy
Customize policies to control authentication, such as username rules, IP blacklist / whitelist, verification code expiration, etc.
17
π°οΈ
Sign-in experience elements
A set of framework-agnostic web components that can interact with Experience API.
16
π₯οΈ
Single sign-on dashboard
Making it easier for users to see all the apps theyβre connected to in one simple, centralized place.
13
πΊ
Organization portal
An out-of-the-box solution that allows org admins to manage identities, organization profiles, and set up enterprise SSO themselves.
13
Custom content blocks in sign-in experience
Insert custom text, links, and images into the default sign-in and sign-up pages.
10
π
Logto Management API key
Generate a secure key for programmatic access to the Logto Management API
8
β΅
Attribute-based access control (ABAC)
Define dynamic access policies using user or resource attributes for context-aware security.
7
β‘οΈ
Just-in-time user migration
Migrate users from your legacy system to Logto only when they sign in.
6
β‘
Google One Tap for websites
Add Google One Tap to your website and authenticate users through Logto.
6
π§ββοΈ
Restrict user sign-ins to a specific app within a multi-app product
Block users at the login stage if they come from a specific app. This will essentially enable app-level authentication (beyond just branding).
5
π
Custom claims for ID tokens
Add custom claims to ID tokens using JavaScript code snippet.
5
π
Support Dynamic Client Registration
RFC 7591: OAuth 2.0 Dynamic Client Registration Protocol
4
β
Prevent search engine indexing
Provide an option to emit a noindex meta tag or X-Robots-Tag response header for sign-in pages.
4
β²οΈ
Customize OIDC access token TTL & session TTL
Provide an option to override the default OIDC access token time-to-live (TTL) and session TTL.
4
π²οΈ
Support CIBA flow
Support Client Initiated Backchannel Authentication (CIBA) Flow.
3
Account API audit logs
Track all end-user activities performed through the Account API, including identifier, password, MFA, and profile updates.
3
βοΈ
Registration from forgot password
Directly register via forgot password instead of prompting for another round of verification.
3
π‘οΈ
Support machine-to-machine access policy
Limit access by IP address, user agent, and other policies.
2
π
Support localization parameter in content URLs
Allow specifying a localization parameter in privacy policy and terms of use URLs.
2
πͺ
User role change webhook event
Invokes your API whenever a userβs role or organization role changes.
1
β
Unverified email/phone number
Skip verifying email/phone number during sign-up.
1
βοΈ
Allow concurrent Google Workspace and social login
Option to allow both Google Workspace and Google social logins for the same account.
1
π
Unverified SSO email verification
Allow verification code flow for SSO-provided unverified emails.
1
M2M authentication IP allowlist
Restrict access to machine-to-machine applications only from allowed IP addresses or CIDR ranges.
1
Email allowlist
Allow admins to define a list of email domains or addresses that can register.
1
π
Support Central Authentication Service protocol
Currently under consideration.
0
Support OIDC "select_account" prompt
Currently under consideration.
0
Minimum age limit for sign-up
Configure a mandatory minimum age for the birthdate sign-up field to ensure compliance
0
Country code restrictions for phone input
Limit selectable country codes in the phone number field to support region-specific apps
0
Completed
βοΈ
Profile fulfillment
Collect mandatory and optional profile fields during user registration.
41
β¨
Multiple custom domains
Support multiple custom domains and render different sign-in experience brandings according to the domain.
27
π
SAML IdP
Use Logto as a SAML identity provider.
20
π«
Block disposable email registration
Reject any sign-up attempts using a disposable email address to prevent spam and improve user quality.
20
π§βπ
Account API
A set of APIs and rules that allow end-users to update their identifiers and profile.
19
π°
Captcha support
Add reCAPTCHA / Cloudflare Turnstile / hCaptcha for bot protection.
18
π©
Dev to Pro plan production tenant
Directly convert Dev tenant to a Pro tenant.
12
π§
Friendly "continue" prompt
Simplify wording when no matching account is found during sign-in experience.
3
π§°
Typed library for Management API
Provide typed libraries for services (e.g., Node.js) to use Logto Management API.
3
π
Account API for MFA
Allow end users to update, delete, and verify TOTP via Account API.
3
π
Hide Logto branding
Remove "Powered by Logto" to spotlight your brand exclusively on the sign-in experience.
3
π
Email & SMS verification for MFA
Enable email or SMS passwordless verification for multi-factor authentication.
3
πͺ
Magic link
One-time token for organization member invitation, user invitation, password recovering, etc.
2
πΎ
Sign-up capability improvement
Multiple sign-up identifiers (e.g., email & username) and other improvements
2
ποΈ
Secret vault
Securely let users authorize third-party services, then store, manage, and use the tokens with Logto.
2
π
Account API for Passkey
Register, name, and manage multiple passkeys via Account API.
2
π
Console UI for Account API
Directly manage access permissions for Account API in the console.
1
π€
Call third-party APIs with secret vault
Store and retrieve 'access and refresh tokens' from social providers (e.g., Google) for API access.
0
β»οΈ
Customize identifier lockout policy
Customize the policy to provisionally lock accounts after multiple failed sign-ins to prevent brute force access.
0
IdP-initiated SAML SSO
Currently under consideration.
0
π
Add `ui_locales` authentication parameter
Use ui_locales to adjust the sign-in locale dynamically and expose it to email templates.
0
π¨
Custom CSS per organization
Customize organization's sign-in experience with exclusive logo, favicon, colors, and custom CSS.
0
π§΅
WordPress plugin integration
Currently under consideration.
0
Powered by Productlane