Why this page exists
Forward-looking statements used to live inside body copy — a sentence on one page saying we were "moving" something, a note on another saying a capability was "on the roadmap". Future tense in body copy rots silently: nothing dates it, nothing tracks it, and nobody notices when it has been true for two months or false for one. Collecting it here makes each statement checkable, and makes its absence from a product page meaningful.
Nothing on this page is a commitment to a date. Where a thing is genuinely blocked on a decision rather than on work, it says so.
The list
| Item | State |
|---|---|
| Self-serve app registration Apps are registered on request today (contact us). Registering an app yourself from your account, and letting software register itself (OAuth Dynamic Client Registration, RFC 7591), are built and switched off. | Built, not switched on Built and tested. What's left is switching it on, not writing it. |
| SDK 1.1 Version 1.0.0 is public: npm install @obeliskgate/obelisk-auth and pip install obelisk-auth. The next release of each adds a receipt-inclusion check and an MCP server kit, and the JavaScript release also adds an Express helper and a setup command (obelisk-auth init). Publishing them is the remaining step. | Built, not switched on Built and tested. What's left is switching it on, not writing it. |
| Post-quantum signatures An ML-DSA-65 signer is deployed but not yet signing; our host runtime doesn't support it yet. Once the server runs a runtime that does, the signer adds a post-quantum signature to the transparency tree head alongside the existing ES256 signature. | Built, not switched on Built and tested. What's left is switching it on, not writing it. |
| Per-user sealed storage for authenticator seeds Not started; no code for it exists yet. Today an authenticator app's seed is encrypted at rest under a key the service holds, so an operator with server access could read it in principle. This row tracks sealing each seed to its own user instead. | Not started Listed here so that no other page implies it. |
| Security certifications Obelisk has no SOC 2 or ISO 27001 report. If your security review needs one, tell us what your questionnaire asks. | Not started Listed here so that no other page implies it. |
| Machine sign-in for agents Today an agent's access token always starts with a person signing in: the token endpoint grants only authorization_code and refresh_token. A device authorization grant (RFC 8628) for bootstrapping an agent is designed but not started; accepting ID-JAG assertions from other identity providers has not been sized. | Designed Design recorded, implementation not started. |
| Connecting SAML apps to the hosted Gate The SAML 2.0 identity provider is built and its metadata is published, but the hosted Gate has no way to register a service provider, so no SAML app (GitHub, Slack, AWS and the rest) can connect yet. OpenID Connect sign-in works today. | Not started Listed here so that no other page implies it. |
Recently shipped
Anything that lands moves off this page and onto the changelog, which is written in plain language and also served as JSON bound to the exact revision serving it.