Ordnary

Changelog

New features, improvements and fixes across Ordnary's products, as they ship.

13 changes RSS feed

October 2026

Tuesday
  1. Improved Ordnary ID

    Resetting your password signs you out everywhere #

    After a password reset via Forgot password:

    • Every session on every device is signed out, along with apps' refresh tokens and recent accounts sign-in. The Log out of other devices option is gone, since this now always happens
    • We email you that your password was changed, so a reset you didn't ask for doesn't go unnoticed
  2. Improved Ordnary ID

    Stricter sign-out from apps #

    Apps that sign you out through Ordnary ID (OpenID Connect RP-initiated logout, GET /api/auth/logout) now need to prove they're acting for you:

    • Signing out requires an id_token_hint: an ID token we issued for the account that's signed in. Expired tokens are accepted for up to 30 days. Without one, nothing changes
    • post_logout_redirect_uri is only followed when it exactly matches a redirect URI registered for the app the ID token belongs to, and state is passed back. Any other value returns you to the sign-in page
  3. Improved Ordnary ID

    Closing an account also ends app and device access #

    Deactivating or deleting your account, or a suspension of it, now ends every way back in, not just your browser sessions:

    • OAuth refresh tokens held by apps you signed in to with Ordnary ID, together with their rotation families
    • Device grants behind the recent accounts list, which let a browser sign back in without a password

    Access tokens that were already issued expire on their own, within 15 minutes for other apps and an hour for Ordnary's own.

  4. New Ordnary ID

    Confirm it's you before sensitive changes #

    If you signed in more than an hour ago, these changes now ask you to confirm it's you with a code sent to your email first:

    • Turning off two-step verification
    • Removing a passkey
    • Adding or removing an email address
    • Deactivating or deleting your account

    After entering the code you're taken back to where you were, and the next hour counts as recently signed in. Within an hour of signing in, nothing changes. The confirmation page only returns you to Ordnary's own sites.

  5. Improved Ordnary ID

    Limits on verification codes #

    Six-digit codes now have attempt and sending limits, so they can't be guessed and can't be used to flood an inbox.

    • Guesses: at most 5 per account per 15 minutes, and 20 per IP address per minute. This covers authenticator codes, sign-in and password reset codes, and registration codes
    • Emails: a code is sent at most 5 times per address per 15 minutes, with a cap per IP address, for signing in, Resend code and Forgot password
    • Requesting a new sign-in code invalidates the previous one, so only the latest code works
    • Hitting a limit shows Too many attempts. Try again later.
  6. Improved Ordnary ID

    Account-level API endpoints are reserved for Ordnary's own apps #

    Endpoints in the Account API (v3) that change or export your whole account now only accept access tokens issued to Ordnary's own apps. Other apps get 403 first_party_only, even with the profile scope.

    • POST /me/deletion and POST /me/reactivate
    • GET /me/data-export
    • POST and DELETE on /me/dsar-requests and /me/privacy-requests
    • PATCH /me/cookie-consent

    The app a token belongs to is read from its aud claim. Reading these resources still works with profile.

  7. Fixed Ordnary ID

    Signing out a device only affects your own sessions #

    Signing out a single device under Security now checks that the session belongs to your account before it's ended.

    • A session ID that isn't yours gets the same 404 as one that doesn't exist
    • Signing out a session that already ended is a no-op instead of an error
  8. Improved Ordnary ID

    Stronger confirmation codes for sensitive changes #

    Before a sensitive change, such as making a new recovery file, we email you a 6-digit confirmation code. These codes are hardened:

    • Each code is bound to its challenge with HMAC-SHA256 under a server-side key, so the challenge held by your browser reveals nothing about the code
    • On top of the limit per IP address, each account can try at most 5 codes per 10 minutes
    • The email with the code is now sent in a way that keeps running after the page has responded, so it no longer occasionally fails to arrive
  9. Improved Ordnary ID

    Two-step verification on every sign-in path #

    If your account has an authenticator app (TOTP), it's now required on every way you sign in:

    • Signing in with an email code continues to the authenticator step instead of signing you in directly
    • After a password reset, the new password is saved and signing in still asks for your authenticator code
    • POST /api/v1/auth/login returns 403 mfa_required for accounts with two-step verification instead of issuing a session
    • The authenticator step offers your recovery file as the fallback when you don't have your authenticator at hand
    • Signing in with an email code or after a password reset now also checks the account's status, so suspended accounts can't sign in that way
    • Sign-in and registration codes are generated with a cryptographically secure random number generator
  10. Improved Ordnary ID

    A confirmation step before you deactivate or delete your account #

    Choosing Deactivate or Delete under Personal details and settings › Account ownership and control now opens a confirmation step before anything happens.

    • Deactivate: you're signed out on all your devices and your profile is hidden from others. Sign in again at any time to reactivate
    • Delete: you're signed out everywhere and lose access to Ordnary and every app you sign in to with your Ordnary ID. The Delete account button stays disabled until you confirm that your account and data are permanently deleted after a 30-day grace period
    • The descriptions of both options now match exactly what happens, in all 30 supported languages
Saturday
  1. Improved Ordnary ID

    Faster account pages #

    Pages in the Account Center load noticeably faster.

    Each request used to set up a new database client several times over, each with its own engine start and connection. A request now creates one client and reuses it until the response is sent.

  2. Fixed Ordnary ID

    Granting access to an app works again in Chrome and Safari #

    After choosing Give access on the consent screen, the page could stay put instead of returning to the app.

    Chrome and Safari apply the page's Content Security Policy (form-action) to the redirect that follows a form submission, which blocked the last step back to the app's redirect_uri. The consent page now allows HTTPS form targets. Every other page keeps form-action 'self'.

    The buttons on the consent screen also show a busy state now and ignore a second click.

  3. New Ordnary ID

    Profile photos #

    Upload your own photo under Personal details and settings in the Account Center.

    • JPG, PNG and WebP are accepted. Your browser crops the photo to a square and scales it to 512 × 512 px before uploading
    • The server checks the real image type of the file, not just its extension
    • Photos are served with long-lived, immutable caching, so they load instantly in every app
    • Accounts without a photo get an avatar generated from their account ID, so the picture claim in OpenID Connect userinfo is never empty
    • The ordnary.com header and the Community show your photo as well

Choose which cookies Ordnary may use. You can change this at any time via Cookie settings at the bottom of every page.