Beta

Create a tenant

A new tenant starts with its own users, OAuth settings, audit history and logs. You are its first Tenant Admin.

BTL Admin

Changelog

What changed, and when.

2026

October

A hands-on lab for every lesson
  • Every lesson now has a lab: a step-by-step walkthrough in your tenant with real requests, real settings and the real events your tenant records. Labs that depend on features not built yet show exactly how they will run and what you can already try, and labs that also need a second tenant say so. These labs replace the earlier ones, and earlier lab progress was not carried over.
  • Start a lab in a tenant you manage and check your progress at any time. The lab compares your tenant's own Audit records with each step, in order, after you press Start.
  • Lab pages can send their example requests to your tenant from the page, and a new lab callback page shows what an authorization server sent back without keeping or sending it anywhere.
  • The lab toolkit, a small command-line helper for PKCE values, callbacks, token validation, introspection and a local practice API, is available to download with its checksum.
  • Tenant Admins signed in with their Beyond the Login account can reset a tenant to a clean start. Audit and Logs history is kept by default, clearing it needs its own permission, and the reset can set the tenant up for the labs.
  • Fixes and refinements: SCIM userName filters now find every user, revoking a token issued to another client is now refused instead of silently doing nothing, token managers can allow a short grace period for a client retrying a lost refresh response, and tenant pages refuse framing in older browsers too.
  • Claim names reserved for protocol features can no longer be set by claim mappings or token policy scripts. Existing mappings that used them were removed and recorded in Audit, and a token policy script that sets one stops issuing tokens until the claim is removed from it.
Your account now lives in your own tenant
  • Every account now lives in its owner's personal tenant, the same way a tenant's own users do. You sign in on the site as before, and you can also sign in on your tenant's own address with the same password.
  • Your Profile page lets you change your name, and your email address after you confirm a code sent to the new address.
  • In a tenant's Users list, Beyond the Login users now appear alongside tenant users, marked by type. Their name, email and sign-in methods stay under their own control, and tenant administrators manage only their roles.
  • BTL support can now lock an account, give Beta Access, reset sign-in methods and help inside a member's tenant. Each support action is recorded in that tenant's Audit.
  • Accounts created before this change were cleared as part of the move, along with their support tickets, ideas and lab progress, so you will need to sign up again.
Easier to move through Learn on any screen
  • Previous and Next now follow the menu through every lesson, so the last lesson of each section leads straight into the first lesson of the next.
  • On phones, wide lesson tables now scroll inside their own area instead of stretching the page, and long addresses in quizzes wrap to fit.
  • Planned labs stay out of search engines until they open, and two lab descriptions were corrected to match their steps.
A new Learn section on identity security
  • 24 lessons follow one fictional incident at Cedar Inc. through identity threats, account takeover, sessions, tokens and trust, privilege and persistence, detection and response, and building identity systems that hold up under attack.
  • Lessons include clearly labeled simulated exercises and diagrams of the key attacks and responses, and each ends with a short quiz.
  • The Lab has a new Identity security track with planned exercises and a guided review of your own test tenant.
The rest of the OAuth 2.0 lessons
  • 84 new lessons complete the OAuth 2.0 section: tokens and resource servers, application architectures, security and failure cases, fifteen groups of advanced topics, implementation and operations, and the history of OAuth with guidance on moving away from older approaches.
  • The lessons continue the photo printing story with annotated requests, responses and tokens. They link back to the lessons they build on, sixteen include sequence diagrams, and each ends with a short quiz.
  • The Lab's OAuth track lists twenty more planned exercises for these lessons.
New lessons on authorization and policy
  • Fourteen new lessons explain how applications decide what each person can do, following a fictional newsroom's photo library: designing permissions, checking access to each object, roles and their scope, safe role administration, rules based on attributes and context, access through relationships and sharing, and how policies are evaluated, enforced, tested and changed.
  • Each lesson ends with a short quiz, and four new diagrams show role assignments, where attributes come from, a relationship graph and one access decision from request to answer.
  • The Lab has a new Authorization and policy track with four planned labs, and two existing labs now link to the lessons they practice.
A new Learn section on identity governance and administration
  • 21 lessons follow a clinic's staff through joining, changing jobs, and leaving, and through directories, provisioning with SCIM, access rules and requests, roles, separation of duties, access reviews, and audit evidence.
  • Every lesson ends with a short quiz, and diagrams illustrate the key flows.
  • The Lab lists planned hands-on exercises for this section.
Feature flags and Beta Access
  • BTL administrators can now turn platform features on or off from a new Feature Flags page. Each change is confirmed first and recorded in BTL Audit.
  • The first flag, Beta Access, gives new accounts a Beta Access role when they sign up while the flag is on. It starts off, and we'll use it to offer member features free of charge as they arrive.
OpenID Connect lessons
  • Added the OpenID Connect series to Learn: 55 lessons that continue the photo printing story from the OAuth lessons and show how an application signs people in through another service.
  • The lessons cover the sign-in exchange, checking ID tokens, provider discovery, claims and the UserInfo endpoint, accounts and sessions, controlling how people sign in, and signing out across applications, followed by advanced extensions and guidance for building and testing.
  • Every lesson ends with a short quiz, and a new OpenID Connect track in the Lab lists seventeen planned exercises.
Safer sign-in for accounts and tenant users
  • A second sign-in step now always uses a different kind of method from the first, so an email code no longer counts as a second step after signing in by email.
  • Wrong second-step codes are now limited for the whole account, not just one sign-in attempt, and failed password attempts from one network no longer lock you out when you sign in from another.
  • Changing or resetting a password now also signs out the apps connected to that account, and new passwords are checked against known breached passwords wherever they can be set.
  • BTL administrators can reset a BTL account's sign-in methods for someone who has lost access. Sensitive administrative actions now ask you to confirm it is you if you have not signed in recently, and accounts with administrative roles are signed out sooner when idle.
OAuth and OpenID Connect follow the standards more closely
  • A user's subject identifier now belongs to that user for good, the sign-in details in ID tokens always reflect how the user actually signed in, and UserInfo returns the same subject as the ID token.
  • ID tokens are now signed with RS256 by default, and requests that use max_age, prompt=select_account or id_token_hint behave as OpenID Connect describes.
  • Browser applications can now finish the authorization code flow from their own site, native apps can use any loopback port, and a confidential client can be allowed to check other clients' access tokens as a resource server.
  • offline_access is now a built-in scope, refresh tokens can have an overall lifetime, and renaming a client or editing a scope's description no longer signs its users out.
SCIM follows the standard more closely
  • Bulk requests, PATCH filters, primary email changes, version tags and sorting now behave as the SCIM standard describes, and the bulk example in the SCIM guide completes cleanly.
  • When a user's email address is changed in the portal or over SCIM, the new address must be confirmed before it can be used to sign in. Changing an existing user's email, in the portal or over SCIM, now needs the same permission as setting their password.
Tenant Recovery keeps revoked access revoked
  • Restoring a tenant to an earlier time now signs everyone out and applies again the security changes made after that time, such as locked users, disabled keys and rotated secrets, so a restore cannot bring back access that had been removed.
  • The tenant's Audit now shows the time it was restored to, and tenant administrators who sign in on the tenant's own address can read its Audit and Logs.
Lessons reviewed for accuracy and flow
  • Lessons across the curriculum were checked against the current standards and guidance, with corrections to certificate revocation, password guidance, passkeys, identity proofing and several OAuth details.
  • History of SSO now ends with a quiz, the refresh token grant now opens the Other grants lessons, Why use the authorization code flow? was rewritten, and repeated forward references were combined so each lesson reads more smoothly.
Docs, Labs and the Token Decoder
  • The Token Decoder now offers only the response types your tenant allows, explains why a refresh token was or was not issued, and checks more of each response and ID token.
  • Planned labs now list what they still need, and the Docs overview and Architecture pages describe the site as it is today.
  • Correction: the 2026-10-01 entry about the OAuth client lessons said they link two existing labs. Those labs are planned, not yet available.

Tenant Recovery shows times in your time zone
  • Tenant Recovery now takes the restore time in your own time zone and shows the UTC equivalent as you pick it. The confirmation and the list of restores show both.
  • After you enter a tenant ID, the page shows the range of times that tenant can be restored to, and only lets you pick from it.
BTL support can restore a tenant to an earlier time
  • BTL support can now restore a tenant's data to how it was at any point in the last 30 days, for example to recover from an accidental change. The tenant's Audit and Logs history is kept through the restore.
  • While a restore runs, usually for a few minutes, the tenant shows that it is briefly unavailable for maintenance. Its Audit then records that BTL support restored it.
  • Storage for the live site's HR Simulator and support ticket attachments is now set up ahead of its release.
Unnamed tenants show a shorter label
  • A tenant you haven't named yet, such as your first one, now shows as the start of its ID, for example "4213cb58", instead of repeating "Tenant" next to the Tenant label.
Sign-in pages show only the form
  • On wider screens, sign-in pages now show just the sign-in form, without the floating account and help card. Help links, your profile and the theme switch remain in the menu on small screens.
New lessons on OAuth clients and registration
  • Five new OAuth lessons cover how applications are registered and how they prove who they are: client IDs and registration, redirect URIs and client metadata, client authentication methods, secrets and signed assertions, and rotating client credentials.
  • Each lesson walks through annotated examples, such as requests, responses and client metadata, and ends with a short quiz.
  • The Lab catalogue links two existing labs to these lessons and lists three planned labs that will practice them.
Development now runs separately from the live site
  • The development version of Beyond the Login moved to beyondthelogin.dev and now runs in its own hosting account, fully separate from the live site at beyondthelogin.com.
  • Development tenants now use addresses on beyondthelogin.dev. Accounts, tenants and data from the old development address don't carry over, so sign up again there to keep testing.
  • With the two environments separated, the live site can host tenant addresses of its own when tenant features are released there.
Clearer OAuth errors from tenant services
  • A tenant's token, revocation and introspection services now return the specific standard error for each problem, such as a scope the client can't request or a grant it isn't allowed to use, each with a consistent description.
  • When a request fails on the server, the response includes a reference ID that the tenant's administrators can look up in the tenant's Logs.
  • A sign-in request that stops on a tenant's address now shows a page naming the problem and its error code.
  • Refresh requests can ask for fewer scopes than originally granted, and public clients can revoke their own tokens.
  • The HR Simulator shows the reference ID and a link to the tenant's Logs when a token request fails on the server.
The Lab catalogue pairs each lesson with its labs
  • Each Lab track now lists its lessons one per row, with the labs that practice each lesson beside it and their status.
  • The card that pointed to your next lab is gone. Instead, the track holding your next lab opens automatically, and signed-out visitors see a short note to sign in to track their progress.
  • When you're signed in, your progress replaces only the Available badge, so you can still see which labs are simulations.
The Lab page puts your next lab first
  • The Lab page now opens with your next lab. Signed-in learners see a card for the first available lab they haven't finished, with a link to the lesson it practices.
  • Each track is a section you can open and close, with a progress bar. Inside it, each lab sits directly under the lesson it practices, and planned labs take up a single line.
  • Tracks where you've completed every available lab move to a Completed group at the bottom, so what you're working on stays at the top.
  • On a return visit the page appears already arranged from your last progress instead of rearranging as it loads. Signing out clears that saved progress from your browser.
  • The Beyond the Login name in the top-left corner no longer flickers or jumps in size each time you open a new page. Its font now loads before the page appears.

September

BTL Admin gets the tenant workspace, an Overview and custom roles
  • BTL Admin now uses the same sidebar as tenant management: Overview, a User Management group with Users and Roles, Authentication, OAuth Management, Audit and Logs. Tickets and ideas have their own Platform section. Admin links hold their place while your access loads instead of appearing late.
  • The new BTL Overview shows the organization at a glance: your roles, how many verified accounts there are and how many hold a platform role.
  • BTL accounts can now be given custom platform roles. The Roles page works like a tenant's: create a role from the platform permissions you hold yourself, then use Edit access on the Users page to assign it. BTL Admin stays a protected role that always keeps at least one holder, and every role change appears in BTL Audit and Logs.
  • Client secret fields in the HR Simulator and the SCIM console now ask password managers not to fill or save them.
  • Nested topics in the Learn sidebar step in from their parent again, and every sidebar is a little wider so long titles wrap less.
Custom SCIM schemas, a SCIM console in Docs, and client presets
  • Tenants can now describe their own user attributes. The new Schemas page under User Management creates SCIM extension schemas with typed attributes, such as a badge number or a list of skills. Each attribute can be required, unique, set once, or returned only when a client asks for it. SCIM clients send and read these values, filter and sort by them, and find the schemas in the SCIM API's discovery endpoints.
  • User details in User Management now show each user's custom attribute values. Deleting an attribute or a schema removes its stored values, and Audit records how many were removed.
  • The SCIM provisioning page in Docs is now a console. Choose your tenant, create a provisioning client in one step, and send every SCIM method to your own tenant, with each request and response shown. One-step clients follow your flow policy like any other client, so allow the client credentials grant first.
  • New OAuth clients can start from web, single-page, native or machine-to-machine presets. Flow policy now saves each grant, response type and response mode on its own, and the client editor offers only the choices your policy allows.
  • Reading a schema from the SCIM API now works when the schema's URN is percent-encoded in the address.
OAuth grant lessons and a full-width workspace
  • Five new OAuth lessons cover other ways an application can get access: client credentials, device authorization, the refresh token grant, JWT and SAML assertion grants, and a guide to choosing a flow. Each has worked examples, an illustration or diagram, and a quiz.
  • The Lab lists three new planned labs for client credentials, refresh tokens and device authorization. They open once the pieces they need are built.
  • Learn, Lab, Docs, the changelog and legal pages now use the full window like the management pages, with the sidebar on the left and the page outline on the right.
  • Header and sidebar links now appear immediately, based on your last confirmed sign-in, instead of popping in after the page loads. The server still checks every request.
  • Tenant User Management now shows "(you)" beside your own BTL account's email.
SCIM provisioning, groups and the HR Simulator
  • Each tenant now has a SCIM 2.0 API, so an HR system or other system of record can create, update, lock and remove users and groups as people join, move and leave.
  • Five built-in SCIM scopes, named after your tenant, control what a provisioning client may do, from read-only access to managing users, groups and passwords. They cannot be deleted, and a client can use one only after you assign it.
  • A new Provisioning page lets administrators turn the API on, choose whether it accepts passwords, how it treats people who already have an account, which roles provisioned users receive, and lower request limits. Usage and limits on the Overview page shows the SCIM budgets.
  • A new Groups page lets administrators organize tenant users into groups. Groups carry no management permissions, and SCIM clients change the same groups.
  • The HR Simulator acts as an HR system for your tenant. Connect a client, start an onboarding, lifecycle, reorganization or edge case run with fictional people, and follow each request into your tenant's Audit.
  • User details now show provisioning attributes. The User directory history can be searched by request or correlation ID and says which attributes changed. A new Docs page explains SCIM setup.
Sign-in methods, a Usage tab, Support and Ideas, and Labs
  • Tenants and the BTL organization can now choose which sign-in methods their users can use, including passkeys, authenticator apps, and email links and codes. They can also require a second step or phase in a new method with a deadline.
  • A new Security page lets each account manage its sign-in methods, recovery codes and trusted browsers. Tenant users get their own profile, security, registration and password reset pages on their tenant's address.
  • Your profile has a new Usage tab. It shows the limits your account and the tenants you created are using, and when each one resets. Tenant Overview shows the same for its tenant to administrators with permission.
  • Tenants now record who created each user, application, scope, signing key, token setting and role, and every tenant records the account that created it.
  • Support tickets let you ask BTL for help and follow the conversation. Ideas let you suggest improvements and vote on others' ideas. BTL Admins answer and review both from BTL Admin.
  • The Lab lets you practice what the lessons teach. The server checks each step against what actually happened on your account.
  • The sidebar's help links are now Learn and Docs, and the dark mode switch shows a sun or a moon.

OpenID Connect, a tenant switcher and a tidier workspace
  • Tenants and the BTL organization can now issue ID tokens and answer UserInfo requests with OpenID Connect. They can also allow the implicit and hybrid flows when their flow policy permits them.
  • The new ID Token Management page controls how ID tokens are signed, how long they last, and which claims they and UserInfo return, including claims that depend on the scopes a client was granted.
  • Access token and ID token settings each have a default that new clients receive unless you choose another, and each can adjust standard claims within fixed protocol limits.
  • The header now shows which tenant you are working in. Its menu switches between your tenants, creates another named tenant when your account allows it, and replaces the tenant pickers some pages had. Tenant Admins can rename a tenant from Overview.
  • User Management lists tenant users and the tenant's BTL administrators in one table, with each row's actions in a menu. Applications, scopes and token settings use the same menus.
  • Help links, your profile and the dark mode switch now sit at the bottom of the sidebar, and short pages keep the footer at the bottom of the window.
  • Your profile and account activity pages now match the tenant and BTL Admin screens, and lessons no longer show sidebar notes.
  • The design system documentation now describes the two styles in use: reading pages for lessons and docs, and workspace pages once you sign in.
Tenants are ready right away on new storage
  • We moved every tenant to new storage built to support many more tenants.
  • Each tenant's data now lives in its own dedicated store, created the first time the tenant is used. New tenants are ready as soon as they are created, with no separate setup step that could stall or need a retry.
  • New tenant addresses work immediately, without waiting for a deployment.
  • Tenant management, sign-in and token requests for a tenant are handled in the same place as its data, so each change and its audit record are always saved together.
  • Tenants created before this change start again with an empty user directory and default OAuth settings. Their addresses and owners are unchanged, and owners keep Tenant Admin access. Other administrator assignments and custom roles start over.
  • The profile page no longer offers a tenant setup retry, because setup can no longer stop partway.
  • The interface is more compact, with smaller text, controls and corners so management pages show more at once. Touch devices and sign-in pages keep larger targets.
  • The documentation now describes the new storage design and the release steps.
Token Decoder, identity and trust lessons, and cleaner branding
  • Every tenant, and the BTL organization, now includes a Token Decoder. Sign in as one of your tenant's users to see the token response and a decoded access token with its signature checked. You can also paste a JWT or SAML message to decode it in your browser without sending it anywhere. Administrators can rename or disable it, change its scopes and consent, and choose whether the tenant's home address opens it.
  • New tenants can use the authorization code flow right away. Tenants that already changed their flow settings keep them.
  • Access tokens can include custom claims, set as fixed text or calculated with expressions. New token settings default to signed JWTs, with a signing key created for each tenant.
  • Nine new Identity and trust lessons cover identity proofing, credentials and keys, and certificates and PKI, each with a short quiz.
  • Role editing groups permissions by area and shows how many are selected, and several tenant management screens are easier to read.
  • The Beyond the Login logo is sharp and consistent in both themes, and the browser tab icon has been redrawn. Sign-in pages now show the logo once, with a simpler side panel.
  • We documented the plan to move each tenant's data to storage that scales better.
Consistent tenant sign-in pages
  • Tenant sign-in, consent, and error pages now use the same Beyond the Login sign-in design as the main site and follow your device's light or dark setting.
More reliable and secure authorization code sign-in
  • Tenant sign-in and consent now work in standard browsers and return users to the application that asked for access.
  • After the application and its return address are verified, authorization errors go back to that application with its original state and a short explanation. Every authorization response now names the tenant that issued it, which protects applications that trust more than one tenant, and discovery advertises this.
  • Reusing an authorization code now revokes every token issued from it, including refreshed tokens. Tokens issued to an application and tokens issued for a user can no longer share an identifier.
  • Flow settings now offer only the grants, responses, and response modes that work today and list the rest as not yet available. Discovery settings can no longer advertise endpoints or features the service does not provide.
  • Tenant Audit now records the requesting application separately from the signed-in user, and Logs keep the reason an OAuth request was rejected.
  • Sign-up and password recovery emails now have separate delivery allowances, and repeated requests from one network are limited, so account recovery stays available during heavy sign-up traffic.
  • The BTL site now keeps its OAuth sign-in state between steps. BTL organization sign-in still needs organization-local user enrollment before it can be used.

OAuth configuration and authorization code sign-in
  • Added organization-specific OAuth settings for tenants and BTL, including selectable grants and responses, client settings, consent choices, token rules, signing keys, and endpoint paths.
  • Tenant directory users can now sign in, review consent when required, and receive a single-use authorization code that can be redeemed for an access token. Tenant administrators can set user passwords and choose browser session and code lifetimes.
  • Client credentials can now issue access tokens. Tenant-managed token inspection and revocation use saved settings. Tenant Audit shows individual authenticated OAuth requests with client and subject IDs when known, while Logs shows request summaries.
  • Grant and response selections can include implicit, password, and hybrid training flows, but those runtime flows are not active yet. BTL organization interactive sign-in still needs organization-local user enrollment.
Clearer authentication lessons and DEV tenant access
  • Rewrote the authentication methods and multi-factor authentication lessons with clearer examples and explanations, including password salts, and updated the guidance for writing Learn articles.
  • Opened DEV tenant management to verified accounts for their own tenants, subject to the existing tenant permission checks. Production access remains unchanged.
Improved account page sizing
  • Adjusted sign-in and registration layouts to fit below the site header, with more compact spacing and responsive branding while keeping form controls usable on smaller screens.
Completed DEV organization discovery setup
  • Connected DEV's BTL organization discovery endpoints to its authorization service so configured common scopes appear in discovery. Sign-in and token issuance through these endpoints remain in development.

Authentication lessons and DEV signup testing
  • Added seven lessons covering authentication methods, multi-factor authentication, credential recovery, and SSO, with diagrams, quizzes, and a simulated authentication-policy exercise.
  • Simplified signup verification for designated test accounts in DEV while preserving normal production verification.
  • Preserved branding concepts and illustration review materials for future site improvements.
Expanded OAuth management and learning resources
  • Added tenant OAuth client and scope management, including configurable redirect addresses, scope access, and tenant discovery. Tenant sign-in and token issuance remain in development.
  • Added matching OAuth Clients, Scopes, Audit, and Logs views for BTL administrators managing BTL's own organization.
  • Added custom tenant management roles and controls for existing administrators' access, with current permissions enforced throughout tenant management.
  • Added website documentation and contextual links to relevant Learn and Docs pages.
  • Added illustrations throughout the authorization code lessons and an introductory page explaining when to use the flow, with a short quiz.
  • Refined authentication-page alignment and dark-theme separation, and simplified the learning overview.
Refreshed the Beyond the Login branding
  • Introduced a new logo, browser icon, and graphite-and-lime colors throughout the site.
  • Redesigned login, registration, email verification, and password reset with a shared clean split layout that adapts to phones, tablets, and both themes.
  • Added Show and Hide password controls to login and registration while preserving the existing account flows.
Added a session-expiry prompt
  • Open account and administration pages now ask you to sign in again when your BTL session expires or you sign out in another tab.
Prepared production services and clarified tenant history
  • Prepared separate production account, tenant management, and logging services with isolated databases and deployment checks.
  • Made tenant Audit and Logs identify the requested action and history source, including rejected and failed requests, and clarify older records with missing detail.
  • Clarified the OAuth authorization request quiz and PKCE pronunciation.
  • Recorded the existing paid hosting plan and production release procedure.
Compact history viewers and tenant runtime logs
  • Made Audit and Logs more compact, with searchable tables, filters, paging, and expandable details in one viewer.
  • Added tenant-scoped runtime logs alongside management, directory, and protocol history sources, with access limited by tenant permissions.
  • Improved service log messages and tenant attribution while keeping BTL account security history separate.
  • Clarified BTL administrator access-denied messages.
Fixed the development build runtime
  • Pinned the development site's build runtime so the TypeScript build runs with the required Node.js version.
Added BTL Admin history views and improved site maintenance
  • Added separate BTL Admin Audit and Logs views with search, filters, paging, event details, and request correlation for retained BTL account and administration history.
  • Protected each history view with its own permission and recorded access to those records.
  • Made curriculum article links easier to distinguish from category headings and improved navigation and footer alignment.
  • Converted the site, backend, and development tools to TypeScript, with strict type checks to catch errors before deployment.
  • Documented tenant customization requirements for future development and reviews.
Added a BTL Admin account directory and refreshed the interface
  • Added a separate BTL Admin panel for searching registered BTL accounts, filtering by platform role, viewing account details, and opening account security activity. The directory is read-only and excludes tenant-created users.
  • Protected account-directory access with administrator permissions and recorded access history.
  • Unified buttons, forms, tables, dialogs, typography, and diagrams across the site, with improved light and dark themes and layouts for different screen sizes.
  • Added shared design guidance and checks to keep future interface changes consistent.
Improved tenant management, history, and isolation
  • Added user creation, editing, role assignment, locking, and deletion to the BTL Admin tenant preview. Tenant sign-in and custom role management remain in development.
  • Made tenant Audit and Logs searchable, with filters, paging, clearer event details, and request summaries.
  • Strengthened tenant capacity controls, setup recovery, database ownership checks, and separation from BTL account sessions.
  • Improved abuse controls for future tenant protocol endpoints, which remain inactive.
  • Added theme-aware expandable diagrams to OAuth lessons.
Published authorization code lessons and completed the dev rollout
  • Added seven OAuth authorization code lessons with worked HTTP examples, curriculum navigation, and fourteen quiz questions.
  • Completed the dev backend rollout required for the BTL Admin tenant management preview.
  • Made complete deployment and live verification mandatory for every push.
Added a tenant management preview and OAuth learning materials
  • Added a BTL Admin-only tenant management preview with Overview, User Management, Roles, Audit, and Logs navigation. Overview shows tenant details and Audit shows recent tenant activity; user administration, custom roles, and service logs remain in development.
  • Restricted BTL account security history to authorized BTL Admins.
  • Added illustrations to four OAuth Foundations lessons.
  • Added authorization code flow lesson drafts and updated illustration authoring guidance.
Added OAuth Foundations lessons
  • Added five OAuth Foundations lessons with short quizzes to check understanding.
  • Prepared diagram options for review and updated lesson authoring guidance.
  • Documented plans for tenant management, permissions, and activity history.

Expanded learning resources and prepared authorization services
  • Added illustrations to identity lessons and expanded the planned OAuth and OpenID Connect curriculum.
  • Added backend foundations for tenant OAuth and OpenID Connect services. These endpoints are not active yet; application authorization and token issuance remain in development.
  • Updated tenant activity and logging plans to distinguish existing capabilities from future work.
Prepared support for multiple tenants
  • Added backend groundwork for paid subscribers and BTL Admins to own multiple tenants. Billing and additional tenant creation are not yet available through the site.
Improved tenant setup and privacy controls
  • Improved tenant setup recovery, including administrator retries and clearer status messages.
  • Improved activity logs when tenant setup results are uncertain.
  • Improved handling of privacy choices when browser storage is unavailable.

Added account activity and tenant setup
  • Added account activity history and support tools.
  • Added administrator roles and personal tenant setup. Tenant database activation still requires configuration.
  • Improved account navigation while sign-in status is checked.
  • Updated privacy information and development review requirements.
Improved account navigation
  • Prevented signed-out account links from flashing while signed-in users move between pages.
Added password reset
  • Added password reset from the sign-in page.
  • Updated verification emails to better accommodate delayed delivery.
  • Added Git commit references to changelog dates.
  • Cleaned up earlier changelog wording.
Improved email diagnostics
  • Added diagnostics to help investigate account email delivery issues.
Updated email rate limits
  • Updated email rate limits.
Registration password rules and service setup
  • Changed new-account passwords to require at least 8 characters and three of four groups: uppercase letters, lowercase letters, numbers, and symbols.
  • Removed the explanatory text below the password field.
  • Added the missing development account service, database setup, and site connection. Live email delivery still needs verification.
Account groundwork and expanded curriculum navigation
  • Implemented initial registration, email/password sign-in, and a profile page showing name, email, and country. Public account access awaits deployment and live email verification.
  • Added email integration with a verification code and magic link that expire after ten minutes. Using either invalidates both, and the waiting registration page completes sign-in automatically.
  • Added compromised-password screening and verification recovery after a page refresh or interrupted connection.
  • Updated privacy and cookie information to explain account data and verification.
  • Expanded curriculum navigation with planned topics, including detailed OAuth and OpenID Connect sections.
  • Added focused account tests and required independent review before every push.
  • Made registration limits and failed-code handling consistent for new and existing accounts. Existing accounts receive a sign-in notice, and registration attempts leave their details and access unchanged.
Privacy controls and navigation updates
  • Added Privacy, Cookie, and Terms pages explaining how the educational service works and handles information.
  • Added Allow All and Only Necessary choices, with cookie settings available in the footer. Optional analytics loads only with permission on the public website.
  • Moved About and Changelog to the footer alongside the policy pages.
  • Updated the site tagline, removed the Early days label, and added a Beta badge.

Building the foundation
  • Created Beyond the Login's learning website, with an overview, an introduction to the founders, and support for mobile screens and light and dark themes.
  • Added nine Identity Fundamentals lessons and a History of SSO article.
  • Added short quizzes with unlimited retries and progress saved in the learner's browser.
  • Added search metadata, a sitemap, and a security reporting contact.
  • Simplified navigation to show available lessons, removed the Reference page, and added this dated changelog.
  • Added a version number and Git commit identifier to page footers to make reported issues easier to trace.
  • Established separate development and production release workflows, and connected the initial development databases. Accounts and live identity labs are still being built.

We value your privacy

We use cookies and similar technologies to enhance your browsing experience, and analytics to understand our traffic. By clicking "Allow All", you consent to optional analytics. Cookie Policy

Changelog