Connect2id server 20.0
Connect2id server 20.0 moves to Java 21, introduces per-authorisation signing algorithms for JWT access tokens, updates Native SSO session handling and adds TLS support for Redis connections. The release also upgrades the underlying Infinispan and AWS SDK dependencies.
Java 21 and 25
Version 20.0 targets Java 21 and supports running on Java 21 and 25. Deployments running an earlier Java version must update their runtime before upgrading the server.
The c2id/c2id-server-min:20.0 Docker
image uses Java
25, which offers reduced heap memory usage through compact object
headers.
Enable this feature with the following JVM option:
-XX:+UseCompactObjectHeaders
Per-authorisation signing algorithms for access tokens
Deployments issuing self-contained (JWT-encoded) access tokens can now select the JWS signing algorithm for each authorisation. This enables deployments to accommodate APIs with different signing requirements and introduce a new algorithm selectively.
Algorithm selection can address compatibility, security policy, token size and performance requirements. For a comparison of signing and verification speeds, see our 2018 Nimbus JOSE+JWT benchmarks. Results vary with the runtime, cryptographic provider and hardware.
The consent,
direct authorisation
and CIBA web APIs accept
an optional access_token.jws_alg parameter. The integration can
use the requested scope, client ID or other criteria to decide which algorithm
to apply.
Example consent that sets a specific JWS algorithm for the access token:
{
"scope" : [ "urn:c2id:scope:accounts:read",
"urn:c2id:scope:accounts:transfer" ],
"access_token" : { "jws_alg" : "ES256" }
}
Custom OAuth 2.0 grant handlers can make the same choice through the updated AccessTokenSpec in Connect2id server SDK 6.0.
The authzStore.accessToken.jwsAlg configuration property specifies the default algorithm. It continues to apply whenever an authorisation does not specify an override.
The built-in client credentials, self-issued JWT bearer and device SSO grant handlers also receive optional configuration properties for choosing their access token signing algorithm.
Native SSO session claims and data
OpenID Connect Native SSO enables
applications from the same vendor to share a device session linked to a
device_secret.
When the server creates a native client group (NCG) session, it now copies the
claims and data from the web session used to authenticate the end-user.
These fields are updated again whenever an application in the group completes a
new successful OAuth 2.0 authorisation
request, using the web session
associated with that authentication.
This makes the web session’s claims and application-specific data available in the shared native session, and refreshes them as users complete subsequent authorisations.
TLS connections to Redis
Redis-backed deployments
can now enable
TLS
by setting the redis.tls Java system property to true.
By default, the server uses the JVM’s trust store to verify the Redis server
certificate. Deployments using a private certificate authority can configure a
custom trust store with redis.tls.trustStore and its accompanying password
property.
For Redis installations that require mutual TLS, the optional
redis.tls.keyStore and password properties provide the client private key and
certificate chain.
Infinispan and AWS SDK updates
The release upgrades Infinispan from 14.0 to 16.2 and migrates from AWS SDK for Java 1.x to 2.x. The supplied Infinispan XML configurations use the 16.2 schema.
Upgrading to 20.0
Alongside the Java runtime requirement, deployments should account for the following changes:
-
SQL schema update. The
long_lived_authorizationstable gains anata(access token JWS algorithm) column. The server adds it automatically on startup, with an appropriate default value. If automatic schema changes are disabled throughdataSource.createTableIfMissing=false, arrange for the column to be added before starting the upgraded server. -
Infinispan XML customisations. If you have modified an Infinispan XML file directly, review your changes against the supplied 16.2 configurations. This review is not required if you use the supplied XML files and configure them through Java system properties.
-
Asynchronous session purges. The session store /purge endpoint now returns HTTP 202 Accepted for asynchronous requests.
-
Legacy session identifiers. Support for sessionStore.acceptLegacySIDs and the Legacy-SID request header is removed. These deprecated options, originally added in March 2017, enabled import of sessions from Connect2id server 5.x and older, whose identifiers lacked HMAC protection.
The release also includes fixes to client authentication error reporting, access token certificate-chain handling and session store maintenance. See the release notes for the complete list of changes.
New login pages designed for secure AI-assisted customisation
We have started a new project to develop sample login and logout pages for the Connect2id server. Planned scenarios include common two-factor authentication methods, third-party identity providers (social logins) and SAML logins.
The pages are rendered entirely on the server, with no client-side JavaScript required. Avoiding a client-side framework keeps the implementation simpler and reduces exposure to third-party script risks and the dependency risks documented in npm ecosystem research.
Our aim is to provide strong software foundations for customisation with coding agents and LLMs: clear code and templates, documented security practices, and tests that help catch unsafe changes. We will develop this guidance and validation alongside the sample pages, helping teams benefit from AI-assisted development while preserving the security of their authentication flows.
Download 20.0
For the signature validation: Public GPG key
Standard Connect2id server edition
Apache Tomcat package with Connect2id server 20.0: Connect2id-server.zip
GPG signature: Connect2id-server.zip.asc
SHA-256: ec3ec71940645398dc53d1b667835b2953c19e12824d0966be2573e9bcd8873c
Connect2id server 20.0 WAR package: c2id.war
GPG signature: c2id.war.asc
SHA-256: 9c2a45f17f96ccb1d663dd51526a64588ecbf21ae4e2b27fc75f91367bfbfc9b
Multi-tenant edition
Apache Tomcat package with Connect2id server 20.0: Connect2id-server-mt.zip
GPG signature: Connect2id-server-mt.zip.asc
SHA-256: 561366e1abe47e444b7b1f5a5962127e0153ab20a4cad501414575a513bf94b7
Connect2id server 20.0 WAR package: c2id-mt.war
GPG signature: c2id-mt.war.asc
SHA-256: 9bc7d6d5b993e55be7b0cf227a934066c5f0f5080fb14d6b609e80b21cadd432
Questions?
For technical questions about this new release contact Connect2id support. To purchase a production license for the Connect2id server, renew or upgrade your support and updates subscription, email our sales.
Release notes
20.0 (2026-10-07)
Summary
-
Targets Java 21 and supports running on Java 21 and 25.
-
Adds support for overriding the JWS algorithm for self-contained (JWT-encoded) access tokens per authorisation, through the consent web APIs or the grant handler SPIs. The
authzStore.accessToken.jwsAlgconfiguration property now specifies the default algorithm, used when no algorithm is specified for an authorisation. -
Updates OpenID Connect Native SSO. When the Connect2id server creates a new native client group (NCG) session linked to a
device_secret, the session inherits theclaimsanddataof the web session where the end-user was authenticated. The NCG sessionclaimsanddataare also updated whenever a native client participating in the group makes a new successful OAuth 2.0 authorisation request, from the web session used to authenticate the end-user. -
Adds support for TLS connections to Redis, with optional custom trust and key stores.
-
Upgrades Infinispan from version 14.0 to 16.2.
-
Migrates from AWS SDK for Java 1.x to 2.x.
Configuration
-
/WEB-INF/autzStore.properties
authzStore.accessToken.jwsAlg– Now specifies the default JWS algorithm for self-contained (JWT-encoded) access tokens, used when no algorithm is specified for an individual authorisation. In previous releases, this property determined the algorithm for all self-contained access tokens.
-
/WEB-INF/sessionStore.properties
sessionStore.acceptLegacySIDs– Removes support for the deprecated configuration property. It enabled import of sessions from Connect2id server versions 5.x and older. Whentrueit allowed acceptance of legacy session identifiers (SID) without HMAC protection.
-
/WEB-INF/clientGrantHandler.properties
op.grantHandler.clientCredentials.simpleHandler.accessToken.jwsAlg– New optional configuration property to specify the JWS algorithm for self-contained (JWT-encoded) access tokens. If blank or omitted the default algorithm configured byauthzStore.accessToken.jwsAlgapplies.
-
/WEB-INF/selfIssuedJWTBearerHandler.properties
op.grantHandler.selfIssuedJWTBearer.accessToken.jwsAlg– New optional configuration property to specify the JWS algorithm for self-contained (JWT-encoded) access tokens. If blank or omitted the default algorithm configured byauthzStore.accessToken.jwsAlgapplies.
-
/WEB-INF/deviceSSOHandler.properties
op.deviceSSOHandler.accessToken.jwsAlg– New optional configuration property to specify the JWS algorithm for self-contained (JWT-encoded) access tokens. If blank or omitted the default algorithm configured byauthzStore.accessToken.jwsAlgapplies.
-
/WEB-INF/infinispan-*.xml
- Upgrades the XML schema to Infinispan 16.2.
-
/WEB-INF/infinispan-*-{mysql|postgres95|sqlserver|oracle|h2}.xml
- Adds a new
atacolumn to thelong_lived_authorizationstable. In existing Connect2id server deployments with an SQL RDBMS the server will automatically add the new column (with an appropriate default value) on startup. For SQL databases the automatic column addition is enabled by default and can be turned off by setting thedataSource.createTableIfMissingJava system property tofalse.
- Adds a new
-
/WEB-INF/infinispan--redis-.xml
-
redis.tls– New optional Java system property to enable TLS for Redis connections. Set totrueto enable TLS. Defaults tofalse. -
redis.tls.trustStore– New optional Java system property to specify
the path to a custom trust store containing trusted X.509 certificates for verifying the Redis server certificate. If TLS is enabled and this property is not set, the JVM’s default trust store, typically${java.home}/lib/security/cacertsis used. No default value. -
redis.tls.trustStore.password– New optional Java system property to specify the password for the custom trust store. No default value. -
redis.tls.keyStore– New optional Java system property to specify the path to a custom key store containing the client private key and certificate chain for TLS client authentication to Redis. If not set, no client certificate is presented. Required when Redis is configured to require TLS client authentication. No default value. -
redis.tls.keyStore.password– New optional Java system property to specify the password for the custom key store. No default value.
-
Web API
-
/authz-sessions/rest/v3/
- The consent prompt receives a new optional
access_token.jws_algparameter, to enable deployments to override the defaultauthzStore.accessToken.jwsAlgconfiguration property for specific OAuth 2.0 authorisation requests, based on thescope,client_idor another criteria.
- The consent prompt receives a new optional
-
/direct-authz/rest/v2
- The direct authorisation request receives a new optional
access_token.jws_algparameter, to enable deployments to override the defaultauthzStore.accessToken.jwsAlgconfiguration property for specific requests, based on thescope,client_idor another criteria.
- The direct authorisation request receives a new optional
-
/ciba-sessions/rest/v1
- The CIBA authorisation receives a new optional
access_token.jws_algparameter, to enable deployments to override the defaultauthzStore.accessToken.jwsAlgconfiguration property for specific requests, based on thescope,client_idor another criteria.
- The CIBA authorisation receives a new optional
-
/session-store/rest/v2
-
The
purgeresource now returns HTTP 202 Accepted for asynchronous purges. -
Removes support for the deprecated
Legacy-SIDHTTP request header,
alongside removal of thesessionStore.acceptLegacySIDsconfiguration property.
-
SPI
-
Upgrades the Connect2id server SDK to com.nimbusds:c2id-server-sdk:6.0
-
AccessTokenSpec– Enables OAuth 2.0 grant handler SPIs to set a specific JWS algorithm for self-contained (JWT) access tokens, overriding the default algorithm configured inauthzStore.accessToken.jwsAlg. -
JWTSigner– Enables SPI implementations that issue signed JSON Web Tokens (JWT) to set a specific JWS algorithm. Previously the Connect2id server signed the JWTs using the algorithm configured inauthzStore.accessToken.jwsAlg, which remains the default setting in the updatedJWTSigner.
-
Resolved issues
-
Token requests with missing required client authentication must log and return
client_auth_id(issue server / 1224). -
Removes obsolete DynamoDB item sanitisation as no longer required for current DynamoDB and AWS SDK 2.x (issue dynamodb / 33).
-
The LDAP claims source must not treat a missing configuration file (
/WEB-INF/ldapClaimsSource.properties) as an error (issue claims-source-ldap / 5). -
Prevents configuration of non-positive DynamoDB
read-capacity,
write-capacityandpurge-max-read-capacityvalues (issue server / 963). -
The
authzStore.accessToken.includeX5Cconfiguration property must be applied to ECDSA (ES256, ES384, ES512) signed access tokens, instead of always including the X.509 certificate chain (issue authz-store / 255). -
Defines the SQL
pending_codes.acltable column asNOT NULLfor new deployments (issue authz-store / 261). -
Adds extra protections to retrieve pending authorisation SQL records with an undefined
aclfield as expired (issue authz-store / 260). -
The authorisation session web API must reject submitted subject sessions with a
ctx(context) value that is notwebor unspecified (implies the defaultweb). This is to prevent login pages from creating subject sessions with inappropriatectx, such asNCG(native client group), in browser-based OAuth 2.0 flows (issue server / 1230). -
Prevents the purge of orphaned subject keys in the session store from running concurrently with itself (issue session-store / 112).
-
Bounds the session store async web API
/purgerequests to a single worker with no queue (issue session-store / 111). -
The session store
/purgeendpoint should return HTTP 202 Accepted for asynchronous purges (issue session-store / 116). -
Improves the
OP7112log info message native client group (native) SSO (issue server / 1228). -
Fixes
/index.jspHTML markup issues (issue server / 1234).