Changelog
New features, improvements and fixes across Ordnary's products, as they ship.
October 2026
-
Improved Ordnary ID
Resetting your password signs you out everywhere #
After a password reset via Forgot password:
- Every session on every device is signed out, along with apps' refresh tokens and recent accounts sign-in. The Log out of other devices option is gone, since this now always happens
- We email you that your password was changed, so a reset you didn't ask for doesn't go unnoticed
-
Improved Ordnary ID
Stricter sign-out from apps #
Apps that sign you out through Ordnary ID (OpenID Connect RP-initiated logout,
GET /api/auth/logout) now need to prove they're acting for you:- Signing out requires an
id_token_hint: an ID token we issued for the account that's signed in. Expired tokens are accepted for up to 30 days. Without one, nothing changes post_logout_redirect_uriis only followed when it exactly matches a redirect URI registered for the app the ID token belongs to, andstateis passed back. Any other value returns you to the sign-in page
- Signing out requires an
-
Improved Ordnary ID
Closing an account also ends app and device access #
Deactivating or deleting your account, or a suspension of it, now ends every way back in, not just your browser sessions:
- OAuth refresh tokens held by apps you signed in to with Ordnary ID, together with their rotation families
- Device grants behind the recent accounts list, which let a browser sign back in without a password
Access tokens that were already issued expire on their own, within 15 minutes for other apps and an hour for Ordnary's own.
-
Improved Ordnary ID
Limits on verification codes #
Six-digit codes now have attempt and sending limits, so they can't be guessed and can't be used to flood an inbox.
- Guesses: at most 5 per account per 15 minutes, and 20 per IP address per minute. This covers authenticator codes, sign-in and password reset codes, and registration codes
- Emails: a code is sent at most 5 times per address per 15 minutes, with a cap per IP address, for signing in, Resend code and Forgot password
- Requesting a new sign-in code invalidates the previous one, so only the latest code works
- Hitting a limit shows Too many attempts. Try again later.
-
Improved Ordnary ID
Account-level API endpoints are reserved for Ordnary's own apps #
Endpoints in the Account API (v3) that change or export your whole account now only accept access tokens issued to Ordnary's own apps. Other apps get
403 first_party_only, even with theprofilescope.POST /me/deletionandPOST /me/reactivateGET /me/data-exportPOSTandDELETEon/me/dsar-requestsand/me/privacy-requestsPATCH /me/cookie-consent
The app a token belongs to is read from its
audclaim. Reading these resources still works withprofile. -
Improved Ordnary ID
Stronger confirmation codes for sensitive changes #
Before a sensitive change, such as making a new recovery file, we email you a 6-digit confirmation code. These codes are hardened:
- Each code is bound to its challenge with HMAC-SHA256 under a server-side key, so the challenge held by your browser reveals nothing about the code
- On top of the limit per IP address, each account can try at most 5 codes per 10 minutes
- The email with the code is now sent in a way that keeps running after the page has responded, so it no longer occasionally fails to arrive
-
Improved Ordnary ID
Two-step verification on every sign-in path #
If your account has an authenticator app (TOTP), it's now required on every way you sign in:
- Signing in with an email code continues to the authenticator step instead of signing you in directly
- After a password reset, the new password is saved and signing in still asks for your authenticator code
POST /api/v1/auth/loginreturns403 mfa_requiredfor accounts with two-step verification instead of issuing a session- The authenticator step offers your recovery file as the fallback when you don't have your authenticator at hand
- Signing in with an email code or after a password reset now also checks the account's status, so suspended accounts can't sign in that way
- Sign-in and registration codes are generated with a cryptographically secure random number generator
-
Improved Ordnary ID
A confirmation step before you deactivate or delete your account #
Choosing Deactivate or Delete under Personal details and settings › Account ownership and control now opens a confirmation step before anything happens.
- Deactivate: you're signed out on all your devices and your profile is hidden from others. Sign in again at any time to reactivate
- Delete: you're signed out everywhere and lose access to Ordnary and every app you sign in to with your Ordnary ID. The Delete account button stays disabled until you confirm that your account and data are permanently deleted after a 30-day grace period
- The descriptions of both options now match exactly what happens, in all 30 supported languages
-
Improved Ordnary ID
Faster account pages #
Pages in the Account Center load noticeably faster.
Each request used to set up a new database client several times over, each with its own engine start and connection. A request now creates one client and reuses it until the response is sent.
-
Improved Network Centre
Automatic checks on the status page #
Monitors in the Network Centre are now checked automatically every minute, so an outage shows up without anyone having to flag it.
- Two failed checks in a row mark a service as an outage. The next successful check marks it operational again
- A status set by our team stays until we change it: automatic checks only close the incidents they opened themselves
- Service Health now shows five monitors: Ordnary ID, Ordnary Web Services, Developer Documentation, Support Center and Billing, each labelled with the kind of service (for example API)