New Features
Self-Service Account Unlock
Strivacity now supports self-service account unlock workflows for password lockouts. When customers lock their account during login, they can immediately receive a password reset link along with customizable messaging. Admins can also manually unlock accounts affected by password or OTP locks, or trigger a password reset to clear password-reset locks.
Fine-Grained Access Control for the Admin Console
Building on recent improvements to policy tagging and filtering, brand admins can now define permissions—based on policy tags—for viewing or managing individual policies. A new “use” permission has also been added, allowing admins to use a policy (e.g., in flows) without being able to view or modify its configuration. This enables precise control over who can read, write, delete, or apply specific policies.
Centralized Lifecycle Event Hook Logging
All Lifecycle Event Hook (LEH) logs are now accessible through a single, centralized UI. You can filter logs by date/time, Identity Store, Account Event ID, Account ID, and Application Client ID for easier troubleshooting and auditing.
Organization Portal Enhancements
We’ve rebuilt the organization administration portal from the ground up. Improvements include:
- Admin Console-style user filtering
- Easier management of favorite organizations
- Improved session expiry handling and smoother return-to-login flow
Policy Filtering Improvements
We’ve enhanced filtering throughout the Admin Console:
- Filters now persist across sessions—return to any page and your last-used filters are retained
- Admin Console URLs now support query string parameters, enabling deep linking to filtered views
Expanded Session Information for Login Flow UIs
Front-end brand developers now have access to more session context for building custom experiences. Newly available data includes:
- Password and OTP failed attempt counts and limits
- Session timeout configuration for login flows
Other Enhancements
- ECDSA JWT signing support for JWT private keys
- Ability to set multiple audience claims on access tokens
- Support for sending multiple email invitations to recipients with existing accounts or pending invitations
Bug Fixes
- Fixed an issue where account attributes on the MyAccount page always appeared in English despite a selected language
- Fixed a bug preventing hooks with underscores in tag labels from being deployed
- Resolved issue where notifications were sent to disabled email identifiers
- Fixed an error that blocked deletion of identifiers on disabled accounts
- Resolved an issue that prevented admins from changing their password via the admin MyAccount portal
- Fixed a permissions bug preventing full-access admins from resetting translations
- Corrected UI text in the event streaming interface