⚑ Major update Headlockr 5 is out now. Passkeys and more are here. Click here to get started with the new setup.

Roadmap

πŸ“± Companion app and magic login

Bring smoother cross-device authentication to Strapi with QR-based sign-in and companion-powered login flows. 

Users will be able to approve login attempts from the dedicated Headlockr mobile app using biometric authentication, or complete secure verification challenges similar to modern mobile approval flows used by platforms like GitHub.

What’s coming:

QR-driven sign-in across devices
Let users start a login on desktop and securely complete it from their mobile device.

Companion-powered passkey experiences 
Enable more flexible passkey flows with the Headlockr mobile app as a trusted companion.

A smoother path to modern authentication in Strapi
Reduce login friction while keeping strong security controls in place.

πŸ“± Companion app and magic login

2026-04-15

Trusted devicesReleased

Trusted devices help reduce unnecessary MFA prompts without weakening security. When a user signs in from a known device, they can choose to skip MFA for a configurable period of time. This keeps the login experience fast and frictionless for trusted environments, while still allowing users & administrators to revoke trusted devices at any moment.

Trusted devices

2026-03-26

Breached password detection with HIBPReleased

Headlockr now integrates with Have I've been Pwned breach corpus. During login accounts will be checked and administrators will be notified when a password in the environment has been compromised. No passwords will leave your environment during this check. It's an offline check against HIBP hashlist.

Breached password detection with HIBP

2026-03-12

Password expiration policiesReleased

You can now force password rotation after a configurable number of days and redirect the user into the reset-password flow when their password has or is about to expire.

Password expiration policies

2026-03-11

πŸ”₯ MFA Enforcement policiesReleased

Require MFA per role, define allowed enrollment methods, and give new users a configurable grace period before enforcement kicks in.

- Set enforcement rules per role
- Allow only approved factors during enrollment
- Use grace periods before hard enforcement begins

πŸ”₯ MFA Enforcement policies

2025-05-30

πŸš€ Major Release: Strapi v5 SupportReleased

Headlockr is now fully compatible with Strapi v5! Our latest version brings full support for the newest Strapi core, so you can upgrade with confidence and stay secure.

πŸš€ Major Release: Strapi v5 Support

2025-05-23

πŸ“§ New: Email-based 2FAReleased

You can now use email as a two-factor authentication method β€” both for verifying identity and completing logins. Fully supported for admin panel and content API.

πŸ“§ New: Email-based 2FA

2025-05-28

Introducing Content API MFAReleased

We're excited to announce that Headlockr now supports multi-factor authentication for the content API β€” not just the admin panel. This brings powerful security to your public endpoints as well. SDKs and a starter project are coming soon to make integration even easier.

Introducing Content API MFA

2025-07-30

MFA Challenge Grace PeriodReleased

The MFA challenge grace period will allow users a predefined window of time during which they will not need to re-authenticate via MFA after a successful login. This feature strikes a balance between user convenience and security by reducing repetitive MFA prompts while maintaining secure session management. Administrators will be able to configure the grace period to suit their security policies.

MFA Challenge Grace Period

2025-07-31

πŸ”‘ Passkeys (Passwordless Login)Released

We're working on native support for Passkeys β€” enabling secure, passwordless authentication using Face ID, Touch ID, device PINs, or hardware keys. Say goodbye to passwords and hello to phishing-resistant logins.

πŸ”‘ Passkeys (Passwordless Login)

2025-09-27

🌍 Geo BlockingReleased

Add another layer of protection: soon you'll be able to restrict logins based on country or region. Useful for limiting backend access to trusted locations only.

🌍 Geo Blocking

2025-10-31

Auto Logout

Auto logout ensures that inactive users are automatically signed out after a set period of inactivity, reducing the risk of unauthorized access to unattended sessions. Administrators will have the flexibility to configure the inactivity timeout duration based on security requirements. This feature enhances overall account and data security by preventing stale sessions from being exploited.

Auto Logout

2025-12-30

User Management

A robust user management system will allow administrators to efficiently manage user accounts and permissions. This feature will include functionalities such as creating, updating, or deactivating users, assigning roles and privileges, and viewing user activity. Bulk user import and export options will also streamline administration in large organizations.

User Management

© 2026 copyright Headlockr, all rights reserved