- Added AM/AIC transactional backchannel authentication support to the Journey module via
Journey.start(backchannelUri)[SDKS-5157] - Added conditional UI (autofill with passkeys) support to FIDO authentication on Android 15+ [SDKS-4574]
- Added AM/AIC transactional backchannel authentication support to the Journey module [SDKS-5157]
- Added new
pingonemfamodule for PingOne MFA integration [P14C-86660] - Added DaVinci
MOBILE_PAIRINGcollector support for pairing PingOne MFA accounts directly within a DaVinci flow [P14C-82522] - Added new
recognizemodule for biometric face recognition (enrollment/authentication), with Journey and DaVinci integration [P1RECMOB-3476] - Added
MetadataCollectorfor DaVinci flows to support exchanging custom SDK metadata [SDKS-5168] - Added
ImageCollectorfor DaVinci forms to display images [SDKS-5169] - Added an optional HTTP status code to
ErrorNode[SDKS-5202]
- Fixed the browser redirect URI scheme manifest placeholder to apply only to debug builds, allowing release consumers to provide their own value [SDKS-5296]
- Fixed Journey
submitButtonText/pageFooterto resolve against the device's ordered preferred-locale list [SDKS-5310] - Fixed OIDC
refresh()to no longer delete the cached token from storage or revoke a non-expired access token before refreshing [SDKS-5414] - Fixed OAuth 2.0 Device Authorization Grant polling to retry on transient network/transport failures instead of terminating the flow [SDKS-5124]
- Fixed
AbstractValidatedCallbackthrowing when AM returns an emptypoliciesarray instead of an object [SDKS-5260] - Fixed
QRCodeCollector.id()to return a stable key from the collector configuration instead of a random value [SDKS-5293] - Fixed FIDO2 collectors to report WebAuthn/credential errors as actionable events instead of generic submit failures [SDKS-4477]
- Fixed FIDO2 authentication to support per-request API selection via
useFido2ApiClient[SDKS-5411] - Fixed Jackson dependency versions to address security vulnerabilities (CVE-2026-54512, CVE-2026-54513, CVE-2026-54514, CVE-2026-54515) [SDKS-5199]
- Fixed missing blank-secret validation on
OathCredentialandOathTypeserialized as lowercase [SDKS-5075]
- Added OAuth 2.0 Device Authorization Grant (RFC 8628) support [SDKS-4784]
- Added Pushed Authorization Request (PAR) support for OIDC [SDKS-4231]
- Added standardized JSON configuration support [SDKS-5065]
- Added
PollingCollectorfor DaVinci flows [SDKS-4681] - Added
QrCodeCollectorfor DaVinci flows [SDKS-4679] - Added
BooleanCollectorto support Checkbox and Switch input types in DaVinci forms [SDKS-4919] - Added
ReadOnlyTextCollectorfor DaVinci forms to support Terms of Service and agreement displays [SDKS-4927] - Added support for links in Translatable Rich Text (Forms) [SDKS-4246]
- Added support for phone number extensions in
PhoneNumberCollector[SDKS-4669] - Support for Android 17 (the SDK has been verified to build and run correctly on Android 17) [SDKS-5191]
- Fixed OATH and Push URI parsers to propagate typed
InvalidUriExceptionfor structural URI parse errors [SDKS-5074] - Fixed Ktor CIO engine dropping repeated
Set-Cookieheaders with mixed casing (KTOR-8614 workaround) [SDKS-4742] - Fixed Push Number Challenge not surfacing a distinct failure for wrong-number responses [SDKS-5116]
- Fixed
PasswordCollectornot handling nested Password policies [SDKS-4694]
- Upgraded
bcpkix-jdk18onfrom1.81to1.84to address a security vulnerability (CVE-2026-5588). [SDKS-5037]
- Added new
networkmodule [SDKS-4505] - Added new
journeymodule [SDKS-3917] - Added new
mfa-commonsmodule [SDKS-4106] - Added new
mfa-oathmodule [SDKS-4021] - Added new
mfa-pushmodule [SDKS-4023] - Added new
auth-migrationmodule [SDKS-4716] - Added new
fidomodule [SDKS-4134] - Added new
device-binding,device-binding-uianddevice-binding-migrationmodules [SDKS-4115] - Added new
device-idmodule [SDKS-4120] - Added new
device-clientmodule [SDKS-4190] - Added new
device-profilemodule [SDKS-4300] - Added new
device-rootmodule [SDKS-4365] - Added new
recaptcha-enterprisemodule [SDKS-4422]
- Added new
protectmodule [SDKS-4069] - Added new
oidclogin module with integrated browser support [SDKS-4150] - Added support for Android 16 and updated
compileSdkto version 36 andminSdkto 29 [SDKS-4278] - Added Auth Tab support to the
BrowserLaunchercomponent [SDKS-3932]
- Enhanced form handling in the DaVinci SDK to automatically reset form values after submission [SDKS-4511]
- Improved SDK storage configuration to simplify overrides [SDKS-4109]
- Enhanced Storage module with cache strategy support [SDKS-4112]
- Refactored logger initialization for session and cookie configurations [SDKS-4358]
- Updated
PhoneNumberCollectorto support new JSON format [SDKS-4198] - Upgraded datastore library to version 1.1.7 [SDKS-4207]
- Support for native social login with Google and Facebook [SDKS-3449]
- Support for PingOne Forms MFA OTP components
DEVICE_REGISTRATION,DEVICE_AUTHENTICATION, andPHONE_NUMBER[SDKS-3562] - Support for accessing the previous
ContinueNodenode fromErrorNode[SDKS-3890] - Support for accessing the
keyattribute ofLabelCollector[SDKS-3957] - Support for using StrongBox during key generation [SDKS-4098]
- Support for PingOne Forms field types
LABEL,CHECKBOX,DROPDOWN,COMBOBOX,RADIO,PASSWORD,PASSWORD_VERIFY,FLOWLINK[SDKS-3649] - Support for validation of PingOne Forms fields [SDKS-3649]
- Handling default values for PingOne Forms fields [SDKS-3649]
- Interface for access of ErrorNode with validation error [SDKS-3649]
- Support for Social Login with Browser Redirect [SDKS-3662]
- Support for
Accept-Languageheader [SDKS-3622] - New
browsermodule [SDKS-3662] - New
external-idpmodule [SDKS-3662] - Dynamic Environment Switching in Test Sample App [SDKS-3642]
- A side effect on the Global Logger when configuring the DaVinci Logger [SDKS-3616]
- General Availability release of the Ping SDK for Android
- Initial release of the DaVinci module [SDKS-3186]