Logto
In progress
βοΈ
Profile fulfillment
Collect mandatory and optional profile fields during user registration.
37
ποΈ
(Feature name pending) Third-party services and tokens
Securely let users authorize third-party services, then store, manage, and use the tokens with Logto.
0
π
Account API for Passkey
Register, name, and manage multiple passkeys via Account API.
0
β‘
Google One Tap for websites
Add Google One Tap to your website and authenticate users through Logto.
0
Planned
π
Passkey as a first authentication factor
Then no password is required for sign-in.
25
π¨
Account center elements
A set of framework-agnostic web components that can interact with Account API.
24
β¨
Multiple custom domains
Support multiple custom domains and render different sign-in experience brandings according to the domain.
22
π‘οΈ
Adaptive MFA
Trigger MFA according to the current risk level, e.g. a new device, IP, etc.
18
π’
Authentication policy
Customize policies to control authentication, such as username rules, IP blacklist / whitelist, verification code expiration, etc.
14
π¨οΈ
Support device flow
Support RFC 8628: OAuth 2.0 Device Authorization Grant.
14
π©
Dev to Pro plan production tenant
Duplicate dev tenant configurations (connectors, roles, resources, etc.) to a new production tenant.
13
π€
Username policies for Logto Cloud
Adjust username case-sensitivity, length restrictions, allowed charset, etc.
10
π
Redirect URI wildcards
Support for wildcard patterns in redirect URIs to improve authentication for dynamic environments like preview deployments.
8
π§°
Typed library for Management API
Provide typed libraries for services (e.g., Node.js) to use Logto Management API.
3
β‘οΈ
Just-in-time user migration
Migrate users from your legacy system to Logto only when they sign in.
2
π
Account API for TOTP
Allow end users to update, delete, and verify TOTP via Account API.
2
ποΈ
Session management
Managing user sessions with multi-device session tracking, session controls, etc.
2
π§
Friendly "continue" prompt
Simplify wording when no matching account is found during sign-in experience.
2
π
Support Dynamic Client Registration
RFC 7591: OAuth 2.0 Dynamic Client Registration Protocol
1
βοΈ
Allow concurrent Google Workspace and social login
Option to allow both Google Workspace and Google social logins for the same account.
1
π
Unverified SSO email verification
Allow verification code flow for SSO-provided unverified emails.
1
ποΈ
Customize account existence visibility
Show whether the account exists before code verification during sign-in or sign-up.
0
β
Unverified email/phone number
Skip verifying email/phone number during sign-up.
0
π‘οΈ
Support machine-to-machine access policy
Limit access by IP address, user agent, and other policies.
0
πΊοΈ
SAML social connector
Support SAML social connector for government-backed regional IdPs (e.g., SPID, eIDAS, Singpass).
0
Backlog
π
API authentication
Authenticate users via API. No redirect needed.
25
π°οΈ
Sign-in experience elements
A set of framework-agnostic web components that can interact with Experience API.
11
π
RBAC as code
Allow to use code-based configuration to provision role-based access control, for example, a YAML file.
11
πΊ
Organization portal
An out-of-the-box solution that allows org admins to manage identities, organization profiles, and set up enterprise SSO themselves.
7
π
Logto Management API key
6
β΅
Attribute-based access control (ABAC)
5
π₯οΈ
Single sign-on dashboard
Making it easier for users to see all the apps theyβre connected to in one simple, centralized place.
4
π€
Out-of-the-box account center
Instantly integrate a fully featured Account Settings page into your app.
4
π
SCIM API
System for cross-domain identity management APIs.
3
βοΈ
Registration from forgot password
Directly register via forgot password instead of prompting for another round of verification.
2
π²οΈ
Support CIBA flow
Support Client Initiated Backchannel Authentication (CIBA) Flow.
1
π
Email & SMS verification for MFA
Enable email or SMS passwordless verification for multi-factor authentication.
0
π«§
RFC 9396: OAuth 2.0 Rich Authorization Requests
Implement RFC 9396 and provide some useful feature around it.
0
π§ββοΈ
Restrict user sign-ins to a specific app within a multi-app product
Block users at the login stage if they come from a specific app. This will essentially enable app-level authentication (beyond just branding).
0
Completed
π«
Block disposable email registration
Reject any sign-up attempts using a disposable email address to prevent spam and improve user quality.
20
π
SAML IdP
Use Logto as a SAML identity provider.
20
π§βπ
Account API
A set of APIs and rules that allow end-users to update their identifiers and profile.
19
π°
Captcha support
Add reCAPTCHA / Cloudflare Turnstile / hCaptcha for bot protection.
18
π«
Email template i18n
15
π
SOC 2 compliance
Achieve SOC 2 compliance and obtain certification.
4
πͺ
Magic link
One-time token for organization member invitation, user invitation, password recovering, etc.
2
πΎ
Sign-up capability improvement
Multiple sign-up identifiers (e.g., email & username) and other improvements
1
π§΅
WordPress plugin integration
0
β»οΈ
Customize identifier lockout policy
Customize the policy to provisionally lock accounts after multiple failed sign-ins to prevent brute force access.
0
Powered by Productlane
Powered by Productlane