Upgrade Path

authentik 2026.5.0 → 2026.8.3

10 versions, 1 with breaking changes, 1 required stop

Required stops

Version by version, oldest first

2026.5.2 – 2026.5.6: no action items (5 versions)

2026.5.7 2026-09-09

Full release notes for 2026.5.7

2026.8.0 2026-08-18

Breaking

hash_password management command security improvements

The hash_password management command no longer accepts a password as a positional command-line argument (password was visible in the process list). Run the command without arguments to enter the password in a hidden interactive prompt:

docker compose run --rm server hash_password

For automation, pipe the password through standard input:

printf '%s' "$PASSWORD" | docker compose run --rm server hash_password

"Prevent duplicate device" in WebAuthn setup stage removed

The Prevent duplicate devices option of the WebAuthn authenticator setup stage has been removed. It compared attestation certificates, which manufacturers deliberately share across entire production batches, so it rejected legitimate enrollments of a second security key bought at the same time as the first. The option was disabled by default in 2026.5.4 and is now gone; no configuration is required to replace it, and no action is needed when upgrading.

Forwarded headers are now restricted to trusted proxies

Starting with authentik 2026.8, the authentik server only uses forwarded request headers such as X-Forwarded-Proto, X-Forwarded-Host, and X-Forwarded-For when the connection comes from a trusted proxy network. Previous versions did not apply this restriction consistently to all forwarded headers.

This change prevents clients from supplying forged proxy headers and more strictly enforces the existing trusted proxy configuration.

Before upgrading, verify that your reverse proxy sends the required proxy headers and that every address or network from which it connects directly to authentik is included in AUTHENTIK_LISTEN__TRUSTED_PROXY_CIDRS.

An incorrect configuration can cause authentik to interpret HTTPS requests as HTTP, resulting in blocked mixed content, an endless loading indicator, or authentication errors.

From docs.goauthentik.io/releases/2026.8#breaking-changes

Note

PostgreSQL custom connection options are deprecated

The AUTHENTIK_POSTGRESQL__CONN_OPTIONS and its replica equivalent are deprecated and will be removed in an upcoming version. It was never properly used and may cause future breakages. If you're looking for a specific usage, open an issue to discuss alternative solutions.

From docs.goauthentik.io/releases/2026.8#deprecations

Note

This release does not introduce new configuration options, but it more strictly enforces trusted proxy configuration. Review the breaking change before upgrading. You can follow the upgrade instructions below; for more detailed information about upgrading authentik, refer to our Upgrade documentation.

From docs.goauthentik.io/releases/2026.8#upgrading

Full release notes for 2026.8.0

2026.8.1 – 2026.8.3: no action items (3 versions)

Release notes from github.com/goauthentik/authentik/releases, and the release notes on docs.goauthentik.io, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. authentik publishes one release-notes page per YYYY.M release on docs.goauthentik.io. Its “Breaking changes” section is quoted whole as “Breaking” on the first release of that line (YYYY.M.0; 2022.1 to 2022.8 started at YYYY.M.1), its “Deprecations” section as “Note”, and the opening paragraph of its “Upgrading” section as “Note” unless it only says “This release does not introduce any new requirements”. Fixes in patch releases (“Fixed in …”) are not quoted, and neither are GitHub release notes (lists of merged pull requests). Versions are covered from 2022.1.0. Required stops: the latest patch release of every YYYY.M line on the way, per the upgrade documentation.