Supabase Auth shipped two stable releases over the past 90 days, advancing OAuth provider flexibility and password security. Version 2.188.0 enabled custom OIDC providers by default, added OIDC discovery document caching to reduce external calls, and shipped admin endpoints for passkey management. Version 2.187.0 introduced metadata fields to all webhook hooks, added password verification on password changes, and shipped support for fully custom OAuth and OIDC providers beyond the built-in list, letting developers wire in any OpenID Connect-compatible identity service.
Expanded hook capabilities and OAuth flexibility while hardening account security. Added metadata support across all hooks and required current password verification on password changes. Support for custom OAuth and OIDC providers shipped, alongside index worker rollout controls and version-aware metrics for operational visibility.