What's new

Find the latest updates, new features, and release-specific details for IBM® Verify here.

Note: The new features might not be available in your location yet.

July 2026

  • The Accounts tab is introduced on the user details page, enabling you to view all application accounts associated with a user, including their provisioning and compliance status. See Managing user accounts for more details.
  • The Add new users and Add new groups screens, accessed from App role management and Administrator roles, now support field-level search to locate specific users and groups more precisely. Users can be searched by username, first name, last name, email address, or mobile phone number (all using starts-with matching), while groups can be searched by display name or description (starts with), or located exactly by group ID or external ID (equals matching). The sorting is disabled on both screens from this release.
  • Updates were made to customizing your email domain. See Customizing email and SMS providers.
  • A Back button is now available for customizing specific forms. See, Customizing a user form, Customizing an identity proofing flow, and Customizing a user flow.
  • The OpenID Connect implementation in IBM Verify is certified conformant to FAPI 2.0 OP Security Profile. For a full list of certifications, see Conformance status.
  • New RSA and ECDSA leaf certificates are now available for *.verify.ibm.com tenants. The current certificates are expiring on 19 August 2026. See New RSA and ECDSA certificates.
  • IBM Verify now supports Integrated Windows Authentication (IWA) by using a requestable feature - Kerberos (VDEV-196042). This enhancement enables seamless, password-less authentication for users in Windows domain environments, providing a more secure and user-friendly Single Sign-On (SSO) experience. See Configuring kerberos authentication for more details.
  • A new requestable feature is available for branding trial tenants. See Template branding for trial tenants (Beta: Template Branding for Trial Tenants).
  • Updated list of supported application templates. Added support for the following applications:
    • None
    See Supported connectors for applications.
Notifications
  • The following filter operators and options are being deprecated for the Get/v2.0/Users and GET /v2.0/Groups APIs. Support for the operators ends 31 August 2027.
    Filter operators:
    • pr - present
    • npr - not present
    • co - contains
    • lt - less than
    • ne - not equal
    • gt - greater than
    Query options:
    • not
  • You can generate a user list report to obtain the same data. See the generate user list report API or Generating a users list report .
  • As part of the transition from Dynamic roles to Dynamic groups, the v1.0 APIs for administrator and application dynamic roles are deprecated. The end of life is 01 July 2026. See Administrator dynamic role APIs and Application dynamic role APIs for more details.
  • The Device trust feature, CI-114829 Separating device and user authentication, is now generally available and included in device manager authentication.
  • Importing .bpmn file in Flow designer is now deprecated. Use a .json file for all future imports. To ease the transition, the system supports converting BPMN format to JSON format before import. The end of life is 30 June 2026. See Managing flow designer for more details.
  • IBM is implementing backend changes to the following OpenID Connect (OIDC) endpoints.
    • /v1.0/endpoint/default/*
    • /oidc/endpoint/default/*
    The following is the status of the deployment for different data centers:
    • Australia data centers - completed
    • US data centers - completed (14 October 2025)
    • Canada data centers - completed (16 December 2025)
    • Japan data centers - completed (14 January 2026)
    • Europe data centers - scheduled (26 January 2026)
    • US SL2 data centers - pending
    No disruption is expected for existing /oauth2/* endpoint users. For more information about the changes, see OpenID Connect implementation notes. If you have any concerns, open a support ticket.
  • Some password policy APIs are being deprecated. The end of life is 31 July 2027. See Deprecated APIs for more details.
  • The adaptive access feature is not supported in a FedRAMP environment.
  • The design system for the IBM Verify Admin UI is being upgraded in an upcoming release. The latest version of the Carbon design component library improves accessibility and loading times. These behind-the-scenes changes provide developers with access to the latest tools. You might notice changes in colors, spacing, or size as the design is standardized.
  • The Subscription Usage Dashboard is currently still in preview mode. Some inaccuracies were discovered in the usage statistics. The levels of consumption for your subscriptions might be incorrectly displayed in the dashboard. The issue is being worked on.
    Note: The inaccuracies in the data that is displayed do not affect your billing in any way.

June 2026

Notifications
  • As part of the transition from Dynamic roles to Dynamic groups, the v1.0 APIs for administrator and application dynamic roles are deprecated. The end of life is 01 July 2026. See Administrator dynamic role APIs and Application dynamic role APIs for more details.
  • The Device trust feature, CI-114829 Separating device and user authentication, is now generally available and included in device manager authentication.
  • Importing .bpmn file in Flow designer is now deprecated. Use a .json file for all future imports. To ease the transition, the system supports converting BPMN format to JSON format before import. The end of life is 30 June 2026. See Managing flow designer for more details.
  • IBM is implementing backend changes to the following OpenID Connect (OIDC) endpoints.
    • /v1.0/endpoint/default/*
    • /oidc/endpoint/default/*
    The following is the status of the deployment for different data centers:
    • Australia data centers - completed
    • US data centers - completed (14 October 2025)
    • Canada data centers - completed (16 December 2025)
    • Japan data centers - completed (14 January 2026)
    • Europe data centers - scheduled (26 January 2026)
    • US SL2 data centers - pending
    No disruption is expected for existing /oauth2/* endpoint users. For more information about the changes, see OpenID Connect implementation notes. If you have any concerns, open a support ticket.
  • Some password policy APIs are being deprecated. The end of life is 31 July 2027. See Deprecated APIs for more details.
  • The adaptive access feature is not supported in a FedRAMP environment.
  • The design system for the IBM Verify Admin UI is being upgraded in an upcoming release. The latest version of the Carbon design component library improves accessibility and loading times. These behind-the-scenes changes provide developers with access to the latest tools. You might notice changes in colors, spacing, or size as the design is standardized.
  • The Subscription Usage Dashboard is currently still in preview mode. Some inaccuracies were discovered in the usage statistics. The levels of consumption for your subscriptions might be incorrectly displayed in the dashboard. The issue is being worked on.
    Note: The inaccuracies in the data that is displayed do not affect your billing in any way.

May 2026

  • The Access certification reviewers can now view all user attributes in User entitlement campaigns and the user’s existing entitlements for the selected application in Account campaigns. See User entitlement and Account campaigns for more details.
  • 12 built-in attributes were added Creation time, Last modified time, Deactivation reason, Home address, User category, Password reset, Password account locked time, Password failure time, Password changed time, Last login, Last login type, and Last login realm. See Built-in attribute sources.
Notifications
  • For performance reasons, the following filter operators are being deprecated for the Get/v2.0/Users and GET /v2.0/Groups APIs. Support for the operators ends 30 September 2026.
    • pr - present
    • npr - not present
    • co - contains
    • lt - less than
    • ne - not equal
    You can generate a user list report to obtain the same data. See the generate user list report API or Generating a users list report .
  • The Device trust feature, CI-114829 Separating device and user authentication, is now generally available and included in device manager authentication.
  • Importing .bpmn file in Flow designer is now deprecated. Use a .json file for all future imports. To ease the transition, the system supports converting BPMN format to JSON format before import. The end of life is 30 June 2026. See Managing flow designer for more details.
  • IBM is implementing backend changes to the following OpenID Connect (OIDC) endpoints.
    • /v1.0/endpoint/default/*
    • /oidc/endpoint/default/*
    The following is the status of the deployment for different data centers:
    • Australia data centers - completed
    • US data centers - completed (14 October 2025)
    • Canada data centers - completed (16 December 2025)
    • Japan data centers - completed (14 January 2026)
    • Europe data centers - scheduled (26 January 2026)
    • US SL2 data centers - pending
    No disruption is expected for existing /oauth2/* endpoint users. For more information about the changes, see OpenID Connect implementation notes. If you have any concerns, open a support ticket.
  • Some password policy APIs are being deprecated. The end of life is 31 July 2027. See Deprecated APIs for more details.
  • The adaptive access feature is not supported in a FedRAMP environment.
  • The design system for the IBM Verify Admin UI is being upgraded in an upcoming release. The latest version of the Carbon design component library improves accessibility and loading times. These behind-the-scenes changes provide developers with access to the latest tools. You might notice changes in colors, spacing, or size as the design is standardized.
  • The Subscription Usage Dashboard is currently still in preview mode. Some inaccuracies were discovered in the usage statistics. The levels of consumption for your subscriptions might be incorrectly displayed in the dashboard. The issue is being worked on.
    Note: The inaccuracies in the data that is displayed do not affect your billing in any way.

April 2026

No new features were added in April.
Notifications
  • Importing .bpmn file in Flow designer is now deprecated. Use a .json file for all future imports. To ease the transition, the system supports converting BPMN format to JSON format before import. The end of life is 30 June 2026. See Managing flow designer for more details.
  • IBM is implementing backend changes to the following OpenID Connect (OIDC) endpoints.
    • /v1.0/endpoint/default/*
    • /oidc/endpoint/default/*
    The following is the status of the deployment for different data centers:
    • Australia data centers - completed
    • US data centers - completed (14 October 2025)
    • Canada data centers - completed (16 December 2025)
    • Japan data centers - completed (14 January 2026)
    • Europe data centers - scheduled (26 January 2026)
    • US SL2 data centers - pending
    No disruption is expected for existing /oauth2/* endpoint users. For more information about the changes, see OpenID Connect implementation notes. If you have any concerns, open a support ticket.
  • Some password policy APIs are being deprecated. The end of life is 31 July 2027. See Deprecated APIs for more details.
  • The adaptive access feature is not supported in a FedRAMP environment.
  • The design system for the IBM Verify Admin UI is being upgraded in an upcoming release. The latest version of the Carbon design component library improves accessibility and loading times. These behind-the-scenes changes provide developers with access to the latest tools. You might notice changes in colors, spacing, or size as the design is standardized.
  • The Subscription Usage Dashboard is currently still in preview mode. Some inaccuracies were discovered in the usage statistics. The levels of consumption for your subscriptions might be incorrectly displayed in the dashboard. The issue is being worked on.
    Note: The inaccuracies in the data that is displayed do not affect your billing in any way.

March 2026

Notifications
  • Importing .bpmn file in Flow designer is now deprecated. Use a .json file for all future imports. To ease the transition, the system supports converting BPMN format to JSON format before import. The end of life is 30 June 2026. See Managing flow designer for more details.
  • IBM is implementing backend changes to the following OpenID Connect (OIDC) endpoints.
    • /v1.0/endpoint/default/*
    • /oidc/endpoint/default/*
    The following is the status of the deployment for different data centers:
    • Australia data centers - completed
    • US data centers - completed (14 October 2025)
    • Canada data centers - completed (16 December 2025)
    • Japan data centers - completed (14 January 2026)
    • Europe data centers - scheduled (26 January 2026)
    • US SL2 data centers - pending
    No disruption is expected for existing /oauth2/* endpoint users. For more information about the changes, see OpenID Connect implementation notes. If you have any concerns, open a support ticket.
  • Some password policy APIs are being deprecated. The end of life is 31 July 2027. See Deprecated APIs for more details.
  • The adaptive access feature is not supported in a FedRAMP environment.
  • The design system for the IBM Verify Admin UI is being upgraded in an upcoming release. The latest version of the Carbon design component library improves accessibility and loading times. These behind-the-scenes changes provide developers with access to the latest tools. You might notice changes in colors, spacing, or size as the design is standardized.
  1. The Subscription Usage Dashboard is currently still in preview mode. Some inaccuracies were discovered in the usage statistics. The levels of consumption for your subscriptions might be incorrectly displayed in the dashboard. The issue is being worked on.
    Note: The inaccuracies in the data that is displayed do not affect your billing in any way.

February 2026

Notifications
  • Importing .bpmn file in Flow designer is now deprecated. Use a .json file for all future imports. To ease the transition, the system supports converting BPMN format to JSON format before import. The end of life is 30 June 2026. See Managing flow designer for more details.
  • IBM is implementing backend changes to the following OpenID Connect (OIDC) endpoints.
    • /v1.0/endpoint/default/*
    • /oidc/endpoint/default/*
    The following is the status of the deployment for different data centers:
    • Australia data centers - completed
    • US data centers - completed (14 October 2025)
    • Canada data centers - completed (16 December 2025)
    • Japan data centers - completed (14 January 2026)
    • Europe data centers - scheduled (26 January 2026)
    • US SL2 data centers - pending
    No disruption is expected for existing >/oauth2/* endpoint users. For more information about the changes, see OpenID Connect implementation notes. If you have any concerns, open a support ticket.
  • Some password policy APIs are being deprecated. The end of life is 31 July 2027. See Deprecated APIs for more details.
  • The adaptive access feature is not supported in a FedRAMP environment.
  • The design system for the IBM Verify Admin UI is being upgraded in an upcoming release. The latest version of the Carbon design component library improves accessibility and loading times. These behind-the-scenes changes provide developers with access to the latest tools. You might notice changes in colors, spacing, or size as the design is standardized.
  1. The Subscription Usage Dashboard is currently still in preview mode. Some inaccuracies were discovered in the usage statistics. The levels of consumption for your subscriptions might be incorrectly displayed in the dashboard. The issue is being worked on.
    Note: The inaccuracies in the data that is displayed do not affect your billing in any way.