Changelog
New features, improvements and fixes across Ordnary's products, as they ship.
October 2026
-
Improved Ordnary ID
Resetting your password signs you out everywhere #
After a password reset via Forgot password:
- Every session on every device is signed out, along with apps' refresh tokens and recent accounts sign-in. The Log out of other devices option is gone, since this now always happens
- We email you that your password was changed, so a reset you didn't ask for doesn't go unnoticed
-
Improved Ordnary ID
Stricter sign-out from apps #
Apps that sign you out through Ordnary ID (OpenID Connect RP-initiated logout,
GET /api/auth/logout) now need to prove they're acting for you:- Signing out requires an
id_token_hint: an ID token we issued for the account that's signed in. Expired tokens are accepted for up to 30 days. Without one, nothing changes post_logout_redirect_uriis only followed when it exactly matches a redirect URI registered for the app the ID token belongs to, andstateis passed back. Any other value returns you to the sign-in page
- Signing out requires an
-
Improved Ordnary ID
Closing an account also ends app and device access #
Deactivating or deleting your account, or a suspension of it, now ends every way back in, not just your browser sessions:
- OAuth refresh tokens held by apps you signed in to with Ordnary ID, together with their rotation families
- Device grants behind the recent accounts list, which let a browser sign back in without a password
Access tokens that were already issued expire on their own, within 15 minutes for other apps and an hour for Ordnary's own.
-
New Ordnary ID
Confirm it's you before sensitive changes #
If you signed in more than an hour ago, these changes now ask you to confirm it's you with a code sent to your email first:
- Turning off two-step verification
- Removing a passkey
- Adding or removing an email address
- Deactivating or deleting your account
After entering the code you're taken back to where you were, and the next hour counts as recently signed in. Within an hour of signing in, nothing changes. The confirmation page only returns you to Ordnary's own sites.
-
Improved Ordnary ID
Limits on verification codes #
Six-digit codes now have attempt and sending limits, so they can't be guessed and can't be used to flood an inbox.
- Guesses: at most 5 per account per 15 minutes, and 20 per IP address per minute. This covers authenticator codes, sign-in and password reset codes, and registration codes
- Emails: a code is sent at most 5 times per address per 15 minutes, with a cap per IP address, for signing in, Resend code and Forgot password
- Requesting a new sign-in code invalidates the previous one, so only the latest code works
- Hitting a limit shows Too many attempts. Try again later.
-
Improved Ordnary ID
Account-level API endpoints are reserved for Ordnary's own apps #
Endpoints in the Account API (v3) that change or export your whole account now only accept access tokens issued to Ordnary's own apps. Other apps get
403 first_party_only, even with theprofilescope.POST /me/deletionandPOST /me/reactivateGET /me/data-exportPOSTandDELETEon/me/dsar-requestsand/me/privacy-requestsPATCH /me/cookie-consent
The app a token belongs to is read from its
audclaim. Reading these resources still works withprofile. -
Fixed Ordnary ID
Signing out a device only affects your own sessions #
Signing out a single device under Security now checks that the session belongs to your account before it's ended.
- A session ID that isn't yours gets the same
404as one that doesn't exist - Signing out a session that already ended is a no-op instead of an error
- A session ID that isn't yours gets the same
-
Improved Ordnary ID
Stronger confirmation codes for sensitive changes #
Before a sensitive change, such as making a new recovery file, we email you a 6-digit confirmation code. These codes are hardened:
- Each code is bound to its challenge with HMAC-SHA256 under a server-side key, so the challenge held by your browser reveals nothing about the code
- On top of the limit per IP address, each account can try at most 5 codes per 10 minutes
- The email with the code is now sent in a way that keeps running after the page has responded, so it no longer occasionally fails to arrive
-
Improved Ordnary ID
Two-step verification on every sign-in path #
If your account has an authenticator app (TOTP), it's now required on every way you sign in:
- Signing in with an email code continues to the authenticator step instead of signing you in directly
- After a password reset, the new password is saved and signing in still asks for your authenticator code
POST /api/v1/auth/loginreturns403 mfa_requiredfor accounts with two-step verification instead of issuing a session- The authenticator step offers your recovery file as the fallback when you don't have your authenticator at hand
- Signing in with an email code or after a password reset now also checks the account's status, so suspended accounts can't sign in that way
- Sign-in and registration codes are generated with a cryptographically secure random number generator
-
Improved Ordnary ID
A confirmation step before you deactivate or delete your account #
Choosing Deactivate or Delete under Personal details and settings › Account ownership and control now opens a confirmation step before anything happens.
- Deactivate: you're signed out on all your devices and your profile is hidden from others. Sign in again at any time to reactivate
- Delete: you're signed out everywhere and lose access to Ordnary and every app you sign in to with your Ordnary ID. The Delete account button stays disabled until you confirm that your account and data are permanently deleted after a 30-day grace period
- The descriptions of both options now match exactly what happens, in all 30 supported languages
-
New ordnary.com
A public changelog #
Every change across Ordnary's products now lands on this page.
- Filter by product and by type of change (New, Improved, Fixed). Filters live in the URL, so a filtered view can be bookmarked or shared
- Every entry has its own permalink
- Follow along in any feed reader with the RSS feed
-
Improved Ordnary ID
Faster account pages #
Pages in the Account Center load noticeably faster.
Each request used to set up a new database client several times over, each with its own engine start and connection. A request now creates one client and reuses it until the response is sent.
-
Fixed Ordnary ID
Granting access to an app works again in Chrome and Safari #
After choosing Give access on the consent screen, the page could stay put instead of returning to the app.
Chrome and Safari apply the page's Content Security Policy (
form-action) to the redirect that follows a form submission, which blocked the last step back to the app'sredirect_uri. The consent page now allows HTTPS form targets. Every other page keepsform-action 'self'.The buttons on the consent screen also show a busy state now and ignore a second click.
-
New Community
Voting, notifications and member profiles #
- Voting: one up- or downvote per member per post. Click your vote again to take it back. Authors can't vote on their own posts
- Notifications: you automatically follow topics you start or reply to, and can follow any other topic by hand. You're notified of new replies and when your reply is accepted as the solution, with an unread count in the bar
- Member profiles at
/community/u/<id>show a member's topics, recent replies and totals, plus nine badges that stay greyed out with progress until they're earned - Search with
?q=matches every word against topic titles and posts - Markdown in posts: bold, italic, inline code, lists, quotes and links
-
New Ordnary ID
Profile photos #
Upload your own photo under Personal details and settings in the Account Center.
- JPG, PNG and WebP are accepted. Your browser crops the photo to a square and scales it to 512 × 512 px before uploading
- The server checks the real image type of the file, not just its extension
- Photos are served with long-lived, immutable caching, so they load instantly in every app
- Accounts without a photo get an avatar generated from their account ID, so the
pictureclaim in OpenID Connectuserinfois never empty - The ordnary.com header and the Community show your photo as well
-
New Community
The Ordnary Community is open #
Ask questions, share what you've built and help each other at ordnary.com/community.
- Anyone can read. Sign in with your Ordnary ID to start a topic or reply
- Topics have a category and up to five tags. Filter by category, tag, unanswered or solved
- The topic's author or Ordnary staff can mark a reply as the solution
- Reply to a specific post: answers are threaded under it, up to three levels deep
- Ordnary staff carry the Ordnary mark next to their name, and are the only ones who can post in Announcements
-
Improved Network Centre
Automatic checks on the status page #
Monitors in the Network Centre are now checked automatically every minute, so an outage shows up without anyone having to flag it.
- Two failed checks in a row mark a service as an outage. The next successful check marks it operational again
- A status set by our team stays until we change it: automatic checks only close the incidents they opened themselves
- Service Health now shows five monitors: Ordnary ID, Ordnary Web Services, Developer Documentation, Support Center and Billing, each labelled with the kind of service (for example API)