Skip to main content
Version: 11.3.0

11.3.1 Release Notes

HYPR 11.3.1 is a patch to the 11.3.0 Enterprise Channel Release.

The Enterprise Release Channel follows a quarterly upgrade cycle, ensuring a stable and predictable update process. This schedule provides organizations with ample time to test, adapt, and implement changes while minimizing disruptions to business operations. With each release, customers receive the latest security, performance, and feature enhancements, allowing them to stay up to date with improvements while maintaining operational stability.

Looking for the full history?

Bug fixes for this patch are listed in Bug Fixes below. The per-item record for this release and every prior release is maintained in the Changelog.

Minimum Supported Versions

Release DateHYPR ProductMinimum RequirementNotes
July 24HYPR Passwordless for Windows 11.3.1Windows (10 "2004", 11)Reboot required if upgrading from 7.6 or below; Security Key Support for YubiKey 5 Series with firmware 5.X, YubiKey Bio Multi-Protocol Edition, IDEMIA ID-One on Cosmo 8.2, Feitian K9 Plus and K40 Plus and its offshoots
June 24HYPR Passwordless for Mac 11.3.0macOS (High Sierra, Mojave, Catalina, Big Sur, Monterey, Ventura, Sonoma 14.1 [not 14.0], Sequoia, Tahoe)Security Key Support for YubiKey 5 Series with firmware 5.X and Feitian ePass K9 Plus, K40 Plus and their respective offshoots
July 24HYPR Mobile App for Android 11.3.1Android 9.0+
August 5HYPR Mobile App for iOS 11.3.1iOS 12.4+
July 24HYPR Server 11.3.1Java Development Kit (JDK) 17Upgrade to 7.10 required before upgrading to 8.0.0 or higher
July 24HYPR SDK for Android 11.3.1Android 9.0+
August 5HYPR SDK for iOS 11.3.1iOS 12.4+
July 24HYPR SDK for Java 11.3.1Java Development Kit (JDK) 17+
Backward Compatibility

All HYPR components are fully compatible across the three previous/subsequent minor (X.X) HYPR releases.


Breaking Changes

  • [API] The JWT application configuration replaces the single issuer field with one field per direction of the flow. On GET/PUT /cc/api/appconfig/jwt, validationIssuer holds the issuer expected when HYPR validates an incoming ID token, and creationIssuer holds the issuer written to the JWTs HYPR creates. The schema also declares hyprClaims and jwtTokenCreationEnabled as required, and accepts kcKid for the signing key's Key ID. Update any automation that reads or writes this configuration to use the new field names. Administrators who configure JWT settings in the Control Center have nothing to change. See JWT Token Configuration.

Integrations

Enhancements

▸ New CrowdStrike webhook handler template

HYPR Adapt adds a new CrowdStrike webhook handler template, updated for CrowdStrike's current webhook payload format. The new template receives events on an authenticated Control Center endpoint using a Bearer token, rather than the HMAC-signed endpoint used by the previous template. Existing CrowdStrike integrations that use the HMAC signature configuration continue to work; adopt the new template when you configure CrowdStrike's updated payload format. See CrowdStrike IdP Policy Configuration and CrowdStrike ZTA Policy Configuration.


HYPR Control Center

Notable UI/UX Changes

▸ Redesigned JWT Token Configuration

The Application-level JWT Token Configuration is reorganized around two independent controls — Enable ID Token Validation and Enable JWT Token Creation — each surfacing only the flows and settings it applies to. Registration and authentication flows now use clear Passkey and UAF (FIDO) labels, ID-token validation and JWT creation each have their own Issuer field, and the signing-key options adapt to your Host JWKS Endpoint selection. See JWT Token Configuration.


Bug Fixes

  • [HYPR Mobile App for iOS] Fixed workstation unlock failing for a saved workstation after registering again.
  • [HYPR Mobile App for iOS] Fixed workstation and passkey deregistration failing after unlocking a saved workstation.
  • [HYPR Mobile App for iOS] Fixed repeated settings requests after a token refresh failure.
  • [HYPR Mobile App for iOS] Fixed the Save Pairing prompt appearing when unlocking a certificate-based (x509) workstation that was already paired.
  • [SDK] Fixed a database migration failure on a fresh install of the iOS SDK.
  • [Affirm] Fixed a "medium" spoofing-detection result being shown as a failure on the requester and approver scorecards.
  • [Affirm] Fixed identity verification returning an "Unverified" result after a successful document verification for certain document types.
  • [Affirm] Fixed an identity verification flow that could stall on the verification step under certain content-customization configurations.
  • [HYPR Mobile App for Android] Fixed Enterprise Passkey workstation unlock on Entra-joined workstations failing with "Authenticator not registered."
  • [HYPR Mobile App for Android] Fixed the associated passkey being disabled after deleting a web pairing from the mobile app.
  • [Enterprise Passkey] Fixed deregistering a HYPR Passkey not fully removing the associated workstation and web registrations from Control Center.
  • [HYPR Mobile App for Android] Fixed the Save Computer prompt appearing on an already-saved workstation during lock or tap-to-unlock.
  • [HYPR Mobile App for Android] Fixed the Save Computer prompt not appearing when unlocking a workstation as a second user registered on the same device.
  • [HYPR Mobile App for Android] Fixed scan-to-unlock authentication failing in multi-registration scenarios when the user is selected from the web sign-in interface.
  • [HYPR Passwordless for Windows on ARM] Fixed the first scan-to-unlock after pairing failing with "No certificate record found" on Entra-joined Windows on ARM.
  • [HYPR Passwordless for Windows] Fixed a Windows desktop SSO sign-in failure reported as an unsupported logon method on hybrid-joined workstations.
  • [HYPR Server] Resolved intermittent authentication failures affecting some high-volume deployments.
  • [Control Center] Fixed deleting an Application's JWT configuration not removing the hosted JWKS endpoint when Host JWKS Endpoint was enabled.
  • [HYPR Passwordless for Windows] Fixed a failure enrolling a security key certificate on a hybrid-joined workstation.
  • [Enterprise Passkey] Fixed deregistering one of two workstations registered to the same user on the same mobile device also removing the other workstation.
  • [HYPR Mobile App for iOS] Fixed the app closing unexpectedly when registering a direct passkey through Device Manager or Microsoft Entra ID.
  • [HYPR Mobile App for iOS] Fixed a passkey created from a workstation sign-in being removed when upgrading the app from an earlier release.
In the Changelog

The Changelog holds the per-item record of bug fixes and known issues for this release and every prior release.