What's New

IBM Verify Identity Access OIDC Provider is a new cloud native OIDC provider. The topic introduces new features and other information that is specific to the current release for IBM Verify Identity Access OIDC Provider.

Version 26.03

  • Support for encrypted JWT based access token.
  • FAPI 2.0 conformance fixes.
  • Activation by activation code for the IVIAOP container.
  • Protecting /userinfo resource endpoint using DPoP.
  • Base image updates.
    Note: Without the correct activation code the container will not start. Further details

Version 25.10

  • Refresh token enhancements.
    • Ability to set maximum grant lifetime in the mapping rule.
    • Ability to configure allowed list of scopes which will result in a refresh token generation during a runtime flow.
  • Support for OIDC Single logout.
  • Base image updates.
  • Janitor performance improvements for Postgres database.
  • Defect fixes
    • Ability to throw custom exception in a JWT Bearer grant flow mapping rule.
    • Issue with Retrieving user attributes when LDAP client is used in an Access policy.

Version 25.06

  • Support for disabling refresh token rotation.
  • Support for DPoP Nonce.
  • Audit correlation between web reverse proxy and OP runtime.
  • Base image updates.

Version 25.03

  • Support for Microsoft SQL Server 2022.
  • Support for Prometheus monitoring.