Ahead

What is not done yet

This page lists what Obelisk does not do yet: what is built but not switched on, and what has not been started. Nothing here has a promised date.

Last updated 2026-10-08

Why this page exists

Forward-looking statements used to live inside body copy — a sentence on one page saying we were "moving" something, a note on another saying a capability was "on the roadmap". Future tense in body copy rots silently: nothing dates it, nothing tracks it, and nobody notices when it has been true for two months or false for one. Collecting it here makes each statement checkable, and makes its absence from a product page meaningful.

Nothing on this page is a commitment to a date. Where a thing is genuinely blocked on a decision rather than on work, it says so.

The list

ItemState
Self-serve app registration
Apps are registered on request today (contact us). Registering an app yourself from your account, and letting software register itself (OAuth Dynamic Client Registration, RFC 7591), are built and switched off.
Built, not switched on
Built and tested. What's left is switching it on, not writing it.
SDK 1.1
Version 1.0.0 is public: npm install @obeliskgate/obelisk-auth and pip install obelisk-auth. The next release of each adds a receipt-inclusion check and an MCP server kit, and the JavaScript release also adds an Express helper and a setup command (obelisk-auth init). Publishing them is the remaining step.
Built, not switched on
Built and tested. What's left is switching it on, not writing it.
Post-quantum signatures
An ML-DSA-65 signer is deployed but not yet signing; our host runtime doesn't support it yet. Once the server runs a runtime that does, the signer adds a post-quantum signature to the transparency tree head alongside the existing ES256 signature.
Built, not switched on
Built and tested. What's left is switching it on, not writing it.
Per-user sealed storage for authenticator seeds
Not started; no code for it exists yet. Today an authenticator app's seed is encrypted at rest under a key the service holds, so an operator with server access could read it in principle. This row tracks sealing each seed to its own user instead.
Not started
Listed here so that no other page implies it.
Security certifications
Obelisk has no SOC 2 or ISO 27001 report. If your security review needs one, tell us what your questionnaire asks.
Not started
Listed here so that no other page implies it.
Machine sign-in for agents
Today an agent's access token always starts with a person signing in: the token endpoint grants only authorization_code and refresh_token. A device authorization grant (RFC 8628) for bootstrapping an agent is designed but not started; accepting ID-JAG assertions from other identity providers has not been sized.
Designed
Design recorded, implementation not started.
Connecting SAML apps to the hosted Gate
The SAML 2.0 identity provider is built and its metadata is published, but the hosted Gate has no way to register a service provider, so no SAML app (GitHub, Slack, AWS and the rest) can connect yet. OpenID Connect sign-in works today.
Not started
Listed here so that no other page implies it.

Recently shipped

Anything that lands moves off this page and onto the changelog, which is written in plain language and also served as JSON bound to the exact revision serving it.

Give your users a login that keeps receipts.

Passkey sign-in, OAuth for agents, and a record anyone can check.

Create your account →Verify it yourself →

Already have an account? Sign in.