Trending:

Ktor 3.6.0 lands with typed authentication, OpenID Connect support, and experimental HTTP/3 for Netty

Ktor 3.6.0 branding with Netty and OpenID Connect icons
TechStaged-owned

Summary

  • Ktor 3.6.0 adds new experimental features including typed authentication capabilities with specialized support for OpenID Connect and HTTP/3 support for the Netty engine.
  • The release includes quality-of-life improvements for routing and request handling and more convenient defaults for Kotlin Multiplatform clients.
  • A new OIDC plugin provides typed authentication providers, sessions, and a browser login interface with auto-refreshing tokens.

Ktor 3.6.0 is now available, signaling a shift toward stronger type safety in authentication and broader network protocol experimentation on the Netty engine. The release prioritizes new experimental features, including typed authentication with targeted OpenID Connect support, alongside HTTP/3 experimentation and several quality‑of‑life improvements for routing and request handling.

  • Typed authentication with specialized OpenID Connect support
  • Experimental HTTP/3 support for the Netty engine
  • Improved routing and request handling, with easier defaults for Kotlin Multiplatform clients

TYPED AUTHENTICATION AND THE OPENID CONNECT PLUGIN

Ktor 3.6.0 introduces new types to guarantee full type safety when working with complex authentication. The release also adds an OpenID Connect (Oidc) plugin designed to simplify securing services through OpenID Connect Providers. Features include sessions and a browser login interface with auto‑refreshing tokens, as documented in the release notes. TechStaged has also covered GPT-5.6 debuts in Kiro, boosting price-performance for developers.

  • New typed authentication flows
  • Oidc plugin with typed providers
  • Sessions and browser login with token auto‑refresh

NETTY ENGINE GAINS EXPERIMENTAL HTTP/3 SUPPORT

The Netty server engine now supports experimental HTTP/3 over QUIC. To enable this, users configure an SSL connector and opt in with an enableHttp3 block, which also allows tuning QUIC settings such as flow control and UDP socket configuration.

  • HTTP/3 over QUIC is experimental
  • SSL connector required to enable HTTP/3
  • QUIC tuning parameters available

MULTIPLE SSL/TLS CONNECTORS AND HTTP/2 OPTIONS

A Netty server can serve both h2c on one connector and HTTP/2 over TLS on another by enabling enableH2c and enableHttp2. This provides flexibility for mixed traffic scenarios within the same application.

  • Support for h2c on one connector and HTTP/2 over TLS on another

CLIENT EXPERIENCE AND CACHING IMPROVEMENTS

The release introduces ktor-client-engine-defaults, a curated set of client engines for Kotlin Multiplatform projects, enabling HttpClient() creation without choosing an engine in shared code. The HTTP cache storage has also moved toward a path based on kotlinx-io, broadening cross‑platform compatibility for persistent caching.

  • Client engines chosen automatically per target
  • Cross‑platform HTTP cache storage using kotlinx-io paths

OTHER NOTABLE API AND TOOLING IMPROVEMENTS

Additional enhancements include request parameter conversion support for Kotlin types such as UUID and Byte, nullable types for ApplicationCall.receive(), and a new respondHtmlPartial API replacing the deprecated respondHtmlFragment with TagConsumer usage. The ContentNegotiation plugin also gains a SkipIfPresent strategy to respect explicit Accept headers when provided.

  • Nullable receive support and new type conversions
  • respondHtmlPartial for partial HTML responses
  • ContentNegotiation SkipIfPresent behavior

WHAT’S NEW BEYOND THESE HIGHLIGHTS

The What’s New section notes broader changes, including WebRTC support for JVM, asynchronous DNS resolution for CIO, OpenAPI tag descriptions, duplicate-cookie parsing, and JavaScript fetch() overrides. This reflects the breadth of the 3.6.0 release as a whole.

  • WebRTC support for JVM
  • Asynchronous DNS resolution for CIO
  • OpenAPI tag descriptions
  • Duplicate-cookie parsing
  • JavaScript fetch() overrides

Reporting by Owen Blackridge; editing by TechStaged editors

Editorial disclosure: This article was prepared with AI assistance from a source-limited research package and passed TechStaged's automated factual, originality, licensing, and publication checks.

Our Standards: The TechStaged Editorial Principles.

Suggested Topics: Software Business Software
f in

Owen Blackridge

Owen Blackridge

Technology Editor

Owen covers platform shifts, AI launches, and the practical impact of emerging technology on small teams.