- Disabled the embedded session helper by default (re‑enable via TELEPORT_UNSTABLE_DISABLE_EMBEDDED_REEXEC env var) due to endpoint‑protection incompatibility.
- Added secret lookup support for OIDC Google service accounts and a web‑terminal clipboard mode role option to restrict copying text.
- Improved auth service performance and reduced memory usage for clusters with large numbers of registered Kubernetes clusters and databases when per‑session MFA is enabled.