Admin Console Release 28.0.0
This LoginRadius Admin Console release adds token and key management, stronger security controls, and usability improvements.
Changelog
Added
-
Signing Key Rotation: Added Manage Signing Keys under Tenant Settings. Administrators can view and rotate RSA key pairs used to sign JSON Web Tokens (JWTs) for OAuth applications.
-
Refresh Token Rotation: Added a Refresh Token Rotation card with a configurable Reuse Interval in the OAuth Application Token tab. The previous token remains valid during the grace period to reduce failures from concurrent refresh requests.
-
Enforce PKCE: Added an Enforce PKCE toggle for the Authorization Code flow in OAuth application settings. When enabled, OAuth and OpenID Connect authorization requests must include the code_challenge parameter. This control also appears in the Hosted Pages test preview.
-
Password Policy Presets and Additional Settings: Added predefined password complexity tiers under Password Policy. These presets replace the manual regex-only approach with simpler configuration.
-
User Audit Logs Lifecycle View: Added a lifecycle view for User Audit Logs. It includes a new service object type and now appears in the Event Summary tab.
-
Spam Email Domain Protection: Added a Spam Email Domain control under Domain Access Management in Attack Protection. Administrators can block signups from known spam, abuse, and throwaway email domains.
-
Passkey Preview Experience: Added a visual preview in the Passkey section. The preview updates by passkey type, making the end-user experience easier to review before saving changes.
Removed
-
Platform Security Section: Removed the legacy Platform Security section after moving its remaining functionality to more relevant locations.
-
Send Test Email: Removed Send Test Email from SMTP and email template configuration screens.
Please reach out to LoginRadius Support for any further queries.