Feature availability and versions
A Caddy integration release and a go-authcrunch library release are different artifacts. Installing a newer standalone library does not update the dependency inside a previously built Caddy executable.
As checked on October 5, 2026, the latest published Caddy integration is caddy-security v1.3.0, whose go.mod pins go-authcrunch v1.3.8. The standalone library has separately released v1.3.11. These guides use the published Caddy bundle unless they state another boundary.
Check the executable you run
authcrunch version
authcrunch security version
authcrunch list-modules
The first reports Caddy, the second the AuthCrunch library, and the third the
compiled modules. For a custom build named caddy, use that executable instead.
Keep its integration revision too: the library version alone does not prove
that an adapter exposes a new directive.
Features in the released bundle
| Capability | Documentation |
|---|---|
| Local, LDAP, OAuth/OIDC and SAML login | Authentication overview |
| Local MFA and ordered challenge policies | MFA and challenges |
| Rotating local refresh sessions | Refresh sessions |
| Completed-session and generated-key persistence | Runtime state |
| Provider login directly in an app policy | Direct OAuth |
| AuthCrunch serving relying parties as an OIDC provider | OIDC provider |
| Bundled local management CLI and reusable Go login client | CLI and Go client |
| Argon2id and bcrypt local passwords | Password management |
| Numeric GitHub IDs and organization transforms | GitHub |
| Diagnostic message filtering | Logging |
| Explicit administrative API permissions and private-key export | Server API |
| RSA, EC, and Ed25519 public signing-key JWKS | Token verification |
| Header/query/Basic/API-key credential stripping | Identity headers |
Newer library and integration work
The current Caddy source checkout contains changes after v1.3.0:
| Feature | Library availability | Released Caddy bundle |
|---|---|---|
| Typed policy-local custom ACL fields | go-authcrunch v1.3.9 and later | Not in v1.3.0; Caddy integration is unreleased |
| Correct unconditional/default ACL evaluation | go-authcrunch v1.3.11 | Not in v1.3.0; see the released limitation |
| Optional cross-device browser login | go-authcrunch v1.3.11 | Not in v1.3.0; Caddy integration is unreleased |
Treat configuration for those features as a preview for a matching custom integration build. Do not paste it into v1.3.0 and expect parser support. Verify the next release's dependency and adapter before adopting it.
Upgrade deliberately
Read the relevant release notes, validate the configuration with the replacement binary, and test login, allowed access, denied access, logout and session behavior. Persistent-state deployments require a stop/start handover. Regenerate adapted JSON from the Caddyfile when adopting direct OAuth, rather than carrying forward an old authorization-handler representation.