OpenProof 1.1.0-rc2
Pre-release
Pre-release
Fixed
- Fixed duplicate canonical identities when a user first authenticated through a trusted federated provider and later enrolled local email/password with the same verified email. OpenProof now converges onto the single active canonical identity instead of creating a second account.
- Verified-email convergence now fails closed when that email maps ambiguously to multiple active identities, or belongs to a suspended/non-authenticating identity, rather than guessing an owner.
- Completing signup email verification now establishes an IAL1 browser session, removing the unnecessary second sign-in immediately after proving control of the address. The OpenAPI response now includes
session_idandassurance.
Documentation and developer tooling
- Added the end-to-end Deployment & Developer Handbook for installation, production configuration, OAuth/OIDC, Node.js, PHP, C++ and generic HTTP integration.
- Added machine-readable LLM documentation surfaces and the public, read-only OpenProof documentation MCP server with reproducible source.
Full Changelog: v1.1.0-rc1...v1.1.0-rc2