Click Studios

Click Studios (SA) Pty Ltd is an Agile software development company specialising in the development of a secure Enterprise Password Management solution called Passwordstate.

Get in Touch

Level 2, 70 Hindmarsh Square, Adelaide, SA 5000, Australia
sales@clickstudios.com.au

Follow Us

Changelog V10

Find out what is newly added, changed, fixed, improved or updated in the latest Passwordstate V10 versions.

v10.1 Build 10142 - 28th September 2026

Database Schema Updates Security Updates
  • Breaking Added a SAML Reply URL (Assertion Consumer Service URL) setting to both System Settings and Entra ID Domains, for sites behind a reverse proxy or Entra ID Application Proxy which rewrites the Host header. If affected, Emergency Access login will be required after upgrade to set this Reply URL setting.
  • Updated Multiple security updates (CVEs Pending)
  • Updated Added new option to prevent passwords that require a reason to access from being used with the browser extension
  • Updated When updating passwords via the API, and if the password record is linked to other Password Lists, the "API Settings" for all lists must have the "API is authorised to update passwords" setting enabled
  • Updated Added new System Setting to control which users are allowed to see the OTP Secret value for password records, based on their permission level
  • Updated Simplified the initial One-Time Password login screen where you specify settings for your OTP login
  • Updated SHA1 certificates for SAML Authentication have been deprecated
  • Updated Added a new Regex Pattern Match setting for the Provide A Reason setting on Password Lists, to ensure user input conforms to certain criteria
  • Updated Entra ID users without a First Name are now synchronised and imported using their Display Name instead of being skipped
  • Updated Deprecated support for SQL Server sessions via the Client Based Launcher, as Microsoft has not supported automated authentication since SSMS 2017
  • Fixed Fixed a UI positioning bug for Scramble Pad authentication on the screen where you initial set you PIN during authentication
  • Fixed Scheduled Security Group Debugging Action menu was not visible if only Entra domains where being used
  • Fixed Fixed an issue when requesting access to data with specific times set. It will not honor the expiry dates
  • Fixed Fixed a potential error of "Public member 'Split' on type 'DBNull' not found" when searching for passwords from Passwords Home
  • Fixed Fixed a potential bug of "Object reference not set to an instance of an object" when searching for Hosts within the Hosts navigation tree
  • Fixed Fixed an issue with Entra ID sync process, if the user account did not contain a first name, or last name
  • Fixed Fixed a potential issue in the APIs where updating permissions on a folder configured for propagation, was not considering the disable inheritance setting on nested nodes
  • Fixed Fixed an issue with adding an additional authentication option for Entra ID SAML provider, where the option was not being saved
  • Fixed Fixed a javascript error when clicking on the Heartbeat icon for active directory accounts on the add Privileged Account Credential screen
  • Fixed Fixed an issue with Date Formats when requesting access to passwords, where the displayed format could change upon swapping between permission levels
  • Fixed Fixed an issue when editing account discovery jobs and PowerShell jobs, where the scheduled hour may not have displayed correctly in the UI

v10.1 Build 10122 - 25th August 2026

  • Updated Increased the default SQL execution timeout for Search Passwords methods in the API from 30 seconds to 5 minutes
  • Fixed Fixed a general error for the Self Destruct feature referring to Ganss.Xss.HtmlSanitizer
  • Fixed Fixed a potential error accessing the System Settings screen referring to AngleSharp assembly

v10.1 Build 10119 - 20th August 2026

Database Schema Updates Third-Party Security Updates
  • New Added new methods to the APIs to allow searching for documents in Password Folders, Password Lists and Password records
  • New Added new methods to the APIs to allow deletion of Password Lists and Folders
  • Updated The One-Time Password authentication option can now have its label changed on login screens, and user preferences screen
  • Updated Google OTP Authentication has been deprecated and all relevant users have been automatically migrated to use the One-Time Password option. Existing Google Apps on phones can still be used.
  • Updated Disabled autocomplete suggestions on ScramblePad authentication input fields
  • Updated Cleared authorization process requirement if a Primary Server was changed to a Test instance
  • Updated Improved swipe gestures for Edit and Delete actions in the Mobile App
  • Updated Updated Telerik ASP.NET AJAX controls to version 2026.3.812 (Security Update)
  • Updated Adding additional error checking into the Fortigate Password Reset script
  • Updated Added back the feature where you could specify the Page Title within the browser tab
  • Fixed Hid an incorrect message on Administration -> Browser Extension Settings screen, when Master Password is disabled
  • Fixed Restored all Job Scheduling Engine code snippet scripts for the Standard API due to the possibility of some being restored incorrectly previously
  • Fixed Fixed an issue with Expiry Dates on User accounts where it could have failed a conversion of Null to Datetime
  • Fixed Fixed initial theme selection and custom logo on first page load when logging in via Windows Auth SSO
  • Fixed Fixed an issue where the navigation tree would never load, after trying to action a health check notification
  • Fixed Fixed an issue when requesting access to data with specific times set. It will not honor the expiry dates
  • Fixed Fixed an issue when setting multiple generic password fields on a Password List the Password Generator Options would disappear
  • Fixed Fixed an issue with the Browser Extension where Generic Field 2 wasn't masking data by default, if it was configured as a Password field
  • Fixed Fixed an issue with formatting of the Notes field, in the History of password records
  • Fixed Fixed an issue where deselecting multiple approvers on a password list did not save the change
  • Fixed Fixed some UI issues for the Password Reset Portal Verification Policies
  • Fixed Fixed an issue with Password Reset Portal and SAML where an error of "The reply URL does not match..."
  • Fixed Fixed an issue with Scramble pad Authentication, where it wouldn't accept PINs longer than 4 digits
  • Fixed Fixed an issue with Passkeys in the browser extensions, if the user only had view access to the record
  • Fixed Fixed Actions menu not displaying correctly for Active Directory OUs grid with Host Discovery jobs
  • Fixed Fixed an issue where Password Reset Portal Privileged Account Tooltip for showing hiding password value would not disappear
  • Fixed Fixed a start and end date data issue with Email notifications when requesting access to a Password Record
  • Fixed Fixed passkey registration error in the browser extension for certain websites
  • Fixed Fixed an issue in the Mobile App where instance settings could be lost when the App Server URL contained a trailing /
  • Fixed Fixed a potential SAML error referring to the AssertionConsumerServiceURL attribute
  • Fixed Fixed a general error issue when deleting a blacklisted password
  • Fixed Fixed an issue with Expiry Date picker on multiple features
  • Fixed Fixed a potential error of "Conversion from type 'DBNull' to type 'Date' is not valid" when accessing the screen Administration -> User Accounts
  • Fixed Fixed an issue deleting multiple users out of the Password Reset Portal, using the bulk delete feature
  • Fixed Fixed an issue with Remote Site Locations Discovery jobs, where the execution status was not being updated

v10.0 Build 10084 - 23rd July 2026

  • Fixed Fixed an issue after upgrading to version 10 where it was possible SAML authentication may not work if no audience restriction value was set
  • Fixed Fixed another condition where the Entra ID sync schedule may not have executed on the times specified
  • Fixed Fixed a general error screen when trying to edit a user's account on the screen Administration -> User Accounts, due to a Null value in the database for the mail server field
  • Fixed Fix an issue where a loading animation icon would not clear after certain postback events
  • Fixed Fixed a general error on the Jobs home page, when sorting on the Status column
  • Fixed Fixed bug on Add Password screen for OTP field where progress bar was not showing after uploading QR Code
  • Fixed Fixed an issue where the Self Destruct Default Passphrase on System Settings screen was not displaying

v10.0 Build 10077 - 20th July 2026

Database Schema Updates Third-Party Security Updates
  • New Added a new SAML Override feature which can be restricted to a specified number of users
  • Updated Updated Telerik ASP.NET AJAX controls to version 2026.2.708 (Security Update)
  • Fixed Fixed UI issue on Add Password Lists screens where icons could have wrapped to next line
  • Fixed Fixed a potential issue where Mobile App may fail to authenticate, due to a hash check failure
  • Fixed Fixed an issue where it was not possible to add a 'dependency' for a password record if the user only had permissions configured at the individual password record level
  • Fixed Fixed a bug for the Mobile App where it could not pair to Passwordstate if using FIPS encryption
  • Fixed Fixed a DBNull exception when clearing up old App Tokens for mobile app if the user had cleared their Mobile App Password
  • Fixed Fixed a general error screen when exporting Auditing Data from the Administration area
  • Fixed Fixed an issue affecting view permissions on Email Notification Groups when an Entra ID Security Group was granted access
  • Fixed Fixed an issue where the Entra ID sync schedule may not have executed on the times specified

v10.0 Build 10067 - 8th July 2026

  • Updated Minor UI updates and improvements
  • Fixed Fixed an “Insufficient Permissions” error on Administration → Folders when Security Administrators applied permissions to Job Folders they did not already have access to
  • Fixed Fixed a potential issue where an approver could have been sent duplicate Access Requests from a user, if they were also configured as an 'Additional Approver'
  • Fixed Fixed phonetics on Spell Out Password screen where all text was being displayed in uppercase
  • Fixed Fix an issue where a loading animation icon would not clear after certain postback events
  • Fixed Fixed a Windows Service crash during Entra sync due to poor performance of Entra, or Entra not being available
  • Fixed Fixed a potential data integrity issue when synchronizing Entra accounts, if the UserPrincipalName field for the account had any uppercase letters in it

v10.0 Build 10060 - 1st July 2026

  • Updated In the global search bar, the width is now dynamically adjusted when generating random passwords
  • Updated Updated Copy To Clipboard icon based on customer feedback
  • Updated Search fields on Passwords Home, Folders and Password Lists, will now be given focus when you first enter the page
  • Fixed Fixed an issue on some fields which use RadEditor control where pasting line breaks into the field was not working
  • Fixed Updated ScramblePad screens to mask input of temporary data
  • Fixed Fixed an issue with the add shared Password List wizard, where it was not adding permissions for Azure security groups
  • Fixed Fixed an issue where nested Entra ID Security Groups were not being considered during a synchronization
  • Fixed Fixed an issue where on a small number of screens when trying to apply/version permissions, security group names may not have been visible
  • Fixed Fixed a logic issue where one setting to deny creating Password Lists was conflicting with another which was allowing creating Password Lists
  • Fixed Fixed a potential error of 'HostTypes has a SelectedValue which is invalid' when Filtering on Hosts in the grid on the Add Hosts to Folder screen
  • Fixed Fixed an issue where changing the theme color could have resulted in a redirect to a different port number if using Load Balancers or Reverse Proxies
  • Fixed Fixed an issue with Save and Add Another button when adding passwords, where it would not clear the fields if you used the button more than once
  • Fixed Fixed a General Error after re-encrypting all data, due to lack of NTFS permissions on the root Passwordstate folder itself
  • Fixed Fix a general error when editing a user's account and the Google Authenticator option was set to be hidden for them
  • Fixed Fix an error when hiding certain authentication options on the User Preferences screen
  • Fixed Corrected a label on Preferences Tab Visibility & Options tab on the System Settings screen
  • Fixed Provided a work around for Firefox bug where screen background could flash white briefly when using dark mode and navigating around certain screens
  • Fixed Fixed a potential General Error screen showing when generating random passwords in the global search bar
  • Fixed Fixed a potential Invalid Column name error for 'BadPassword' in the API's or UI, under certain conditions
  • Fixed Fixed an error of 'Unable to cast object of type' when trying to view the value of a Generic Field which has been configured as type Password
  • Fixed Fixed an error of 'Object reference not set to an instance of an object' when selecting an Entra ID account type for a password record
  • Fixed Fixed an issue where the radiobutton for the new auto push option for Duo could not be selected on the System Settings screen
  • Fixed Fixed a potential Web Server Authorization popup when an old web server was set to 'Decommissioning'
  • Fixed Fixed an issues on the screen Administration -> User Accounts, where the Bulk Actions option for Toggle Enabled Status was not working
  • Fixed Fixed an issue where you could not open a auditing scheduled report, if a Password List selected in the report was deleted from the screen Administration -> Password Lists
  • Fixed Fixed a potential error of 'A malformed RADIUS message was received' when using RADIUS authentication

v10.0 Build 10034 - 17th June 2026

Database Schema Updates Security Updates
  • Updated Option to specify which html folder to use with the Remote Session Gateway has been deprecated
  • Updated Minor updates and security improvements
  • Fixed Fixed an error of "Save Failed Unexpected error occurred" when trying to add new records via the Mobile App
  • Fixed Fixed a potential NTFS permission issue which was preventing uploading a custom logo
  • Fixed Fixed a Javascript error when generating initials for the user preferences dropdown if the user had a quote in their name
  • Fixed Fixed a bug editing the record for a primary web server where it could have reported a primary server already existed

v10.0 Build 10028 (Release Candidate) - 1st June 2026

Database Schema Updates
  • UpdatedThe option 'Prevent Saving Logins' for browser extensions will now update with every synchronization of the browser extensions.
  • UpdatedAdded a new 'Exact Match' option for Browser Extensions, where form-filling will only occur if the URL in the browser, and in Passwordstate, match exactly.
  • UpdatedMade some improvements for alerts and handling of the new authorised web servers feature.
  • UpdatedUpdated to latest version of Chilkat library, used for SSH sessions and zip functionality for backups.
  • UpdatedWhen adding a 'Dependency' record to a password credential, if the dependency type is set to Ignore, it will no longer clear the Dependency Name on save.
  • UpdatedReintroduced a feature for adding custom logos for login screens, and main UI.
  • UpdatedMobile App no longer needs to be re-paired when the certificate for the App Server is updated.
  • FixedFixed a bug on the View Dependencies page for a password record, where a user with View permissions could add/delete dependency records.
  • FixedFixed an "Ambiguous column name" error in the APIs when trying to add a Host record.
  • FixedFixed a potential error when saving screen options on Passwords Home.
  • FixedFixed a general error on the OTP screen for a password record, when manually typing in the secret, and then trying to view the secret on the screen.
  • FixedFixed an issue where the MAC Address field on Authorised Web Servers screen was disabled, when it should not have been.
  • FixedFixed an issue where the logged in user's name was not displaying at the top of Email Notifications screens.
  • FixedFixed an error on the Add Password screen when a Password List does not have the 'Password' field selected.
  • FixedFixed a potential general error when accessing the screen Administration -> Browser Extension Settings.
  • FixedFixed an error when adding an Azure Entra Domain where it said the column 'SAMLNameID' did not exist.
  • FixedFixed a bug where you could make changes to 'dependency' records on passwords when you had view permissions on a Password List.
  • FixedFixed a potential database schema issue for new installs of V10 Beta 1 where the MostRecent column was missing from the JobsHistory table.
  • FixedFixed a post-upgrade notification within Passwordstate incorrectly saying an out-of-band AD Sync had completed when no AD domain records existed in Passwordstate.
  • FixedFixed an inaccurate Password List name in the Auditing description for 'Copy/Move' password functionality, under certain conditions when selecting a Password List but then using global search.
  • FixedFixed a bug for Privileged Account Credentials where you could not "link" a privileged account to a password record.
  • FixedFixed an issue where you could not select any Manual Login options under System Settings when logged in as the Emergency account.
  • FixedFixed an issue where a change in Entra ID UserID was not synchronizing into Passwordstate.
  • FixedMade improvements under the Jobs screens to inform users if the Remote Site Locations license key had expired.
  • FixedFixed an issue where tooltips on 'Actions' menu items in grids were not displaying.
  • FixedFixed an issue when pairing the Mobile App on the Preferences screen where it reported the App Server did not have the correct functional role.

v10.0 Build 10000 (Beta) - 4th May 2026

Database Schema Updates
  • NewIntroduced a brand-new modern UI with light and dark themes.
  • NewAdded support for synchronizing Entra Security Groups and User Accounts.
  • NewAdded a new Job Scheduling Engine to centralize the management, execution, and auditing of operational scripts, including Passwordstate API scripts.
  • NewAdded a new User-Based API, which gives users the same access they have when logged in to the UI.
  • NewAdded new API methods for managing Host Folders and Remote Session Credentials.
  • NewAdded a new webhook integration for delivering audit events to external systems.
  • NewIntroduced a new licensing requirement requiring customers to register their Authorised Web Servers with Click Studios.
  • UpdatedUpdated system requirements.
  • UpdatedRewrote the Syslog integration to support TCP + TLS, event selection, and event severity classification.
  • UpdatedRewrote RADIUS authentication, which now supports MSCHAPv2.
  • UpdatedRenamed Bad Passwords to Blacklisted Passwords.
  • UpdatedOne-Time Password codes can now be shown on Passwords Home and in Password Folders.
  • UpdatedMobile App can now connect to multiple Passwordstate instances.
  • UpdatedAdded a new Test option to the re-encryption feature, allowing you to report on possible corrupted records before re-encrypting.
  • UpdatedAdded a configurable Time To Live (TTL) option for temporary Remote Session Tokens.
  • UpdatedLocal Windows accounts can now be configured to use a Privileged Account Credential to perform password validations.
  • UpdatedLocal Windows accounts can now be configured to reset themselves, no longer requiring a Privileged Account Credential.
  • UpdatedSecurity Administrators can now hide tabs and options in User Preferences.
  • UpdatedDuo Push can now be sent automatically upon login.
  • UpdatedDuo authentication buttons can now also be selectively hidden on login screens.
  • UpdatedSecurity Administrators can now create Scheduled Reports that are not owned by any specific user account.
  • UpdatedAdded five new auditing record types for managing folders and their permissions under the Hosts tab.
  • UpdatedWhen the sAMAccountName for an Active Directory account is updated, it will now automatically update on the User Accounts screen in Passwordstate, as well as in all related database records.
  • UpdatedThe Manual Synchronization option in the UI for AD Security Groups has been changed to trigger synchronization via the Passwordstate Windows Service.
  • UpdatedDeprecated the feature that allowed Security Administrators to impersonate other users from the Administration -> User Accounts screen.
  • UpdatedDeprecated the feature that allowed custom CSS to be specified for the core Passwordstate product.
  • UpdatedDeprecated the combined login screens for AD/Local accounts and MFA; separate screens are now used.
  • BreakingNative RSA SecurID has been deprecated. SAML Authentication can be used instead if your environment is configured to support it.
  • BreakingFor the Standard API, API keys used within the URL query string are no longer supported.
  • BreakingSpecific API controllers for Devolutions Remote Desktop Manager have been deprecated. Please use the regular API controller methods instead.