Roadmap

Roadmap, as written

A summary of the Go roadmap file: recent releases, work in flight, and what is only under consideration. It lists no dates and commits to nothing beyond what it says. The latest Go release is v2.7.0, published 2026-10-05.

Sources and review date

SourceLast reviewed 2026-10-06
Source
theauth-go docs/ROADMAP.md. Record of what shipped: CHANGELOG.md.
Last reviewed
2026-10-06. Summaries on this page are written by hand and checked against the linked documents on that date. The documents themselves are the record.

Shipped

Recent Go releases

The roadmap calls the changelog the authoritative record of what shipped, and itself the forward-looking part.

  • v2.7.0OAuth redirect URI configuration and validation with the OAuthStart and OAuthCallback entry points, default logs without email addresses, admin password reset clearing login backoff entries, a WebAuthn user handle resolver, and the legacy-hash callback now being invoked.
  • v2.6.0The module path became github.com/glincker/theauth-go/v2, since earlier v2.x tags never resolved through the Go toolchain. Also login throttling on by default, JSON error bodies, a path prefix option, storage capability interfaces, the SQLite adapter and an internal/ package split. It has upgrade notes to read first.
  • v2.5.0The full lifecycle hooks surface, a fix for hooks being bypassed by Mount(), and a batch of storage-layer correctness fixes.
  • Selective re-exportsLetting consumers import fewer symbols from the root package (issue #79, open). The v2.6.0 aliases keep existing names working but are not the selective re-exports that issue asks for.
  • Stability hardeningIn progress. The roadmap lists further unit-test coverage for the RBAC and WebAuthn internals and other hardening work. The full list is in the document.

In flight

What is being worked on

Items are checkboxes in the file and are pruned as they land.

Under consideration

Nothing else is committed

The file says feature requests and discussion happen in GitHub Discussions, and that raised items are added once there is a concrete plan.

The roadmap does not give dates, and neither does this page. For the exact wording and the complete in-flight list, read ROADMAP.md. To raise something, use Go Discussions.

What is not here

  • No TypeScript roadmap. The TypeScript repository has no roadmap file; what shipped is in its changelog and GitHub Releases.
  • No dates. Neither roadmap promises delivery dates.

Get started

Give your first agent an identity.

Install the package, create an agent with scoped permissions, and read its first audit record. The core runs on Postgres, SQLite, MySQL or D1, and the Go module needs a single go get.

  • npm install @glinr/theauth
  • go get github.com/glincker/theauth-go
Or skip hosting with theAuth Cloud