Ordnary

Changelog

New features, improvements and fixes across Ordnary's products, as they ship.

9 changes RSS feed

October 2026

Tuesday
  1. Improved Ordnary ID

    Resetting your password signs you out everywhere #

    After a password reset via Forgot password:

    • Every session on every device is signed out, along with apps' refresh tokens and recent accounts sign-in. The Log out of other devices option is gone, since this now always happens
    • We email you that your password was changed, so a reset you didn't ask for doesn't go unnoticed
  2. Improved Ordnary ID

    Stricter sign-out from apps #

    Apps that sign you out through Ordnary ID (OpenID Connect RP-initiated logout, GET /api/auth/logout) now need to prove they're acting for you:

    • Signing out requires an id_token_hint: an ID token we issued for the account that's signed in. Expired tokens are accepted for up to 30 days. Without one, nothing changes
    • post_logout_redirect_uri is only followed when it exactly matches a redirect URI registered for the app the ID token belongs to, and state is passed back. Any other value returns you to the sign-in page
  3. Improved Ordnary ID

    Closing an account also ends app and device access #

    Deactivating or deleting your account, or a suspension of it, now ends every way back in, not just your browser sessions:

    • OAuth refresh tokens held by apps you signed in to with Ordnary ID, together with their rotation families
    • Device grants behind the recent accounts list, which let a browser sign back in without a password

    Access tokens that were already issued expire on their own, within 15 minutes for other apps and an hour for Ordnary's own.

  4. Improved Ordnary ID

    Limits on verification codes #

    Six-digit codes now have attempt and sending limits, so they can't be guessed and can't be used to flood an inbox.

    • Guesses: at most 5 per account per 15 minutes, and 20 per IP address per minute. This covers authenticator codes, sign-in and password reset codes, and registration codes
    • Emails: a code is sent at most 5 times per address per 15 minutes, with a cap per IP address, for signing in, Resend code and Forgot password
    • Requesting a new sign-in code invalidates the previous one, so only the latest code works
    • Hitting a limit shows Too many attempts. Try again later.
  5. Improved Ordnary ID

    Account-level API endpoints are reserved for Ordnary's own apps #

    Endpoints in the Account API (v3) that change or export your whole account now only accept access tokens issued to Ordnary's own apps. Other apps get 403 first_party_only, even with the profile scope.

    • POST /me/deletion and POST /me/reactivate
    • GET /me/data-export
    • POST and DELETE on /me/dsar-requests and /me/privacy-requests
    • PATCH /me/cookie-consent

    The app a token belongs to is read from its aud claim. Reading these resources still works with profile.

  6. Improved Ordnary ID

    Stronger confirmation codes for sensitive changes #

    Before a sensitive change, such as making a new recovery file, we email you a 6-digit confirmation code. These codes are hardened:

    • Each code is bound to its challenge with HMAC-SHA256 under a server-side key, so the challenge held by your browser reveals nothing about the code
    • On top of the limit per IP address, each account can try at most 5 codes per 10 minutes
    • The email with the code is now sent in a way that keeps running after the page has responded, so it no longer occasionally fails to arrive
  7. Improved Ordnary ID

    Two-step verification on every sign-in path #

    If your account has an authenticator app (TOTP), it's now required on every way you sign in:

    • Signing in with an email code continues to the authenticator step instead of signing you in directly
    • After a password reset, the new password is saved and signing in still asks for your authenticator code
    • POST /api/v1/auth/login returns 403 mfa_required for accounts with two-step verification instead of issuing a session
    • The authenticator step offers your recovery file as the fallback when you don't have your authenticator at hand
    • Signing in with an email code or after a password reset now also checks the account's status, so suspended accounts can't sign in that way
    • Sign-in and registration codes are generated with a cryptographically secure random number generator
  8. Improved Ordnary ID

    A confirmation step before you deactivate or delete your account #

    Choosing Deactivate or Delete under Personal details and settings › Account ownership and control now opens a confirmation step before anything happens.

    • Deactivate: you're signed out on all your devices and your profile is hidden from others. Sign in again at any time to reactivate
    • Delete: you're signed out everywhere and lose access to Ordnary and every app you sign in to with your Ordnary ID. The Delete account button stays disabled until you confirm that your account and data are permanently deleted after a 30-day grace period
    • The descriptions of both options now match exactly what happens, in all 30 supported languages
Saturday
  1. Improved Ordnary ID

    Faster account pages #

    Pages in the Account Center load noticeably faster.

    Each request used to set up a new database client several times over, each with its own engine start and connection. A request now creates one client and reuses it until the response is sent.

Choose which cookies Ordnary may use. You can change this at any time via Cookie settings at the bottom of every page.