Last 7 days
1
Features: 1
Changes: 0
Fixes: 0
Deprecations: 0
Identity platform for authentication, authorization, and application security.
Latest Auth0 changelog updates, official release notes, breaking changes, security patches, pricing changes, and developer reactions in one product feed.
Follow this Auth0 release-notes page to spot useful features, risky migrations, noisy announcements, and source links before they hit your backlog.
Changes.Watch links back to official changelog and release-note sources so summaries stay easy to verify.
Use channels to follow groups of tools around a stack, workflow, or topic.
Rolling windows show how many product updates landed in the last 7, 30, 90, and 365 days, grouped by existing changelog semantics.
1
16
41
147
Introduces early‑access Custom Rate Limits allowing per‑client or group throttling of Authentication API requests via API‑based self‑service configuration.
Introduces GA Flexible Password Policy replacing legacy settings with a unified `options.password_options` object for granular controls (composition, history, dictionary, profile data).
Custom signup/login fields and consent checkboxes now also apply to Social and Enterprise connections.
Added Session Delegation via Custom Token Exchange, letting authorized actors establish web sessions on behalf of other users
Adds GA support for syncing Google Workspace groups and memberships
Adds advanced filtering to Organizations Search, allowing lookup by name, display name, ID, metadata, third‑party client access, and app entitlement status
Global Search via Cmd+K now in Beta, enabling real‑time search across Applications, APIs, Organizations, and Users.
Introduce Agents as Principal in Early Access, giving each AI agent a unique identity, credentials, and audit trail separate from human users and clients.
Introduces GA‑level curated blocklists for Tenant Access Control Lists, enabling automated threat‑intel based IP blocking.
Launches Enterprise Connect in Beta, a modular B2B identity layer that lets Auth0 federate with SAML or OIDC providers and add enterprise SSO, user provisioning, and self‑service onboarding.
Adds Token Vault Privileged Worker in Early Access, enabling background agents to exchange user third‑party tokens without an active user session.
Introduce organization-scoped roles that can be created, updated, and deleted per organization via the Management API or Dashboard.
Introduces real-time dashboard search for organization members (public beta).
Added an Actions Reference Catalog to Auth0 Docs
Introduces Organization-to-Application Entitlement, enabling per‑org control of app access without custom code
Cross App Access (XAA) for Resource Applications is now in Open Early Access, available to Enterprise, B2B Pro, B2B Essential customers and free‑trial tenants
Added delegation of third‑party application access decisions to customer admins during self‑service enterprise configuration tickets.
Introduces Anonymous Sessions in beta, allowing stateless guest sessions with a new POST /anonymous/token endpoint.
Dashboard role search is now in public beta, enabling real‑time search by ID and name.
Organizations can now allow or block third‑party app access on a per‑organization basis, with access blocked by default for existing orgs.
Adds Google One Tap support to Universal Login for early access
Adds support for the session_expiry claim on Okta and OIDC Enterprise connections, following the IPSIE SL1 profile.
Introduces an interactive Tenant Log Catalog in Auth0 Docs for exploring log codes and schemas.
Introduces an outbound SCIM Action template for Event Streams to push user.created/updated/deleted events to any SCIM 2.0‑compliant service without building custom infrastructure.
Refresh Token Metadata is now GA for Enterprise customers, allowing up to 25 custom key‑value pairs on each refresh token.
Google Workspace Directory Sync for Groups is now generally available in Early Access without enrollment, including automated sync, “Sync all”, and partial group selection.
Dashboard API search is now available in public beta
Added GET /api/v2/refresh-tokens to retrieve refresh tokens by user_id or user_id+client_id
Updated ML model for bot detection in the signup flow, lowering false‑negative rates while keeping false‑positive rates low for legitimate users
Inbound SCIM Groups for Enterprise Connections is now GA, letting you sync groups and map them to Auth0 roles globally or per organization.
Introduces a flattened, label‑only navigation with reorganized task groups and moves external actions to the top bar
Dashboard Search for Applications is now in public beta, allowing real‑time search and filtering of applications in the dashboard.
Added client_credentials grant type support for strict third‑party applications to enable machine‑to‑machine access.
Enable shared Passkey enrollment across subdomains by customizing the RP ID.
Introduce a Tenant Manager role for delegating tenant‑level user management
GA release adds organization support to Token Vault, enabling per‑org token storage and exchange.
Introduces new Credentials Exchange Actions interfaces to add, remove, set, clear, and read target scopes during token issuance.
Added Delegated Authorization to Custom Token Exchange, preserving both user (sub) and actor (act) identities per RFC 8693.
Federated logout for OIDC and Okta enterprise connections is now generally available; adding `?federated` to the logout URL triggers Auth0 to call the IdP's `end_session_endpoint` and terminate the upstream session.
Added canonical hostname routing to Tenant ACLs, enabling rule enforcement on backend default domains while keeping custom domains open
DPoP sender constraining for Enterprise Connections is now generally available
Added a dashboard UI to configure Suspicious IP Throttling for Custom Token Exchange
GA release of Non-Unique Emails enabling multiple accounts to share the same email in new database connections.
Introduce ACR EA to enforce step‑up authentication for sensitive scopes when issuing Account API tokens
Introduces Online Refresh Tokens in beta, binding refresh tokens to the originating session for SPAs
Resend email provider is now Generally Available as a built‑in option in Auth0
Auth for MCP is now generally available, providing built‑in authentication, authorization, and client registration via CIMD metadata
Fixes inclusion of an empty `login_hint` query parameter in redirects to external identity providers.
Added GA support for Private Key JWT client assertions on Okta and OIDC enterprise connections.
Introduces a global CMD+K command palette in the Auth0 dashboard for instant navigation and actions
Introduces Enhanced Security Controls for third‑party applications, now generally available.
Introduces the FGA Permissions Index in developer preview, pre‑calculating permission paths to eliminate real‑time graph traversal.
Event Streams is now generally available for all customers
Renamed Self-Service SSO to Self-Service Enterprise Configuration to reflect the broader suite of enterprise features.
Enables IT admins to verify, add, re‑verify, and delete email domains via DNS TXT records directly in the SSO setup assistant.
Organization Discovery by Domain is now generally available.
General Availability of Self‑Service Provisioning, enabling customers’ admins to manage SCIM setup themselves
Auth0 Private Cloud now available on Azure Japan East (Tokyo) region
Adds GA dry‑run mode to Auth0 Deploy CLI for previewing tenant changes without applying them
Added official Auth0 Actions TypeScript definitions on GitHub and npm
End of free trial for Mobile Driver’s License Verification Service Early Access after May 11, 2026 and removal of access for enrolled tenants.
Added Partial Group Sync for Google Workspace Directory, letting you import only selected Enterprise Groups into Auth0.
Added support for a Custom Domain Hook in the Delegated Administration Extension, enabling custom behavior with multiple custom domains.
MRRT is now generally available with full production support and can be configured directly in the Auth0 Dashboard via a visual policy editor and application settings integration.
Early Access release of DPoP sender constraining for Enterprise Connections, enabling Auth0 to generate DPoP proofs during token exchange and userinfo calls.
Adds GA-level Akamai Supplemental Signals integration across the full Auth0 authentication lifecycle.
Updated Universal Login forgot password CTA text from "Forgot Password" to "Reset Password".
Introduces My Organization API for secure, scalable delegated administration of organization details and identity providers
Multiple Custom Domains (MCD) is now Generally Available, letting enterprises configure multiple branded login experiences within a single Auth0 tenant.
Added a new Auth0-specific section in the Okta Integration Network (OIN) wizard.
Introduce Developer Preview as a new release stage for early access to upcoming Auth0 capabilities
Introduced a visual editor in the Auth0 dashboard for managing custom authentication screen partials, with syntax highlighting, code snippets, variable reference, and interactive preview
Session IDs are now rotated after successful SAML‑P or WS‑Fed login, issuing a new session cookie.
New auth0-springboot-api SDK for Spring Boot 3.2+ (Java 17+) simplifies authentication via Auth0AuthenticationFilter integration
Introduces early‑access Google Workspace Directory Sync for Groups, automatically mirroring Workspace groups into Auth0 Enterprise Groups.
DPoP sender‑constrained tokens are now generally available on Enterprise plans, providing token binding via asymmetric keys per RFC9449.
Added ability to customize RP ID for Passkeys, enabling shared enrollment across subdomains.
Stream real-time Auth0 Management API usage and rate‑limit metrics to your observability platform
Added OAuth Client Credentials support for Forms HTTP Vault connections, keeping access tokens fresh.
Adds proactive blocking of passwordless email and SMS codes for users already blocked
Adds GA support for transaction metadata in post‑login Actions, exposing `event.transaction.metadata` and `api.transaction.setMetadata` to set and retrieve custom key/value pairs.
Introduces Actions Modules in Early Access, enabling reusable code across Actions.
GA adds dashboard configuration, refresh‑token metadata in Actions, step‑up MFA, React Native SDK support, Organizations integration, and web SDK examples for Native‑to‑Web SSO
Added self‑service SSO templates for Okta SAML and Auth0 SAML with guided step‑by‑step configuration
Added Send SMS and Make Call actions to Flows using Auth0 phone providers
GA release of Session Metadata for Enterprise tenants, enabling custom key‑value data on user sessions via Actions and the Management API
Added detection of breached phone credentials in Credential Guard
Introduces Auth0 Agent Skills beta, AI-native instructions for implementing Auth0 authentication across multiple frameworks.
Adds Refresh Token Metadata in early access, letting Enterprise customers attach up to 25 custom key‑value pairs to each refresh token.
Numeric keyboard auto‑shown for OTP entry on mobile devices
Integrated JA4 signals into the Bot Detection ML engine to improve detection of sophisticated automated threats
API Access Policies for Applications are now GA and can be configured directly in the Auth0 Dashboard.
Introduced per‑connection SCIM groups endpoint with dedicated /users and /groups URLs and credentials.
Introduces per‑member authorization with new roles (Group Manager, Store Editor, Store Viewer) alongside renamed Account Owner role.
Added GA inbound Google Workspace directory sync to keep Auth0 user profiles up‑to‑date without login events
Introduces a web UI for viewing and managing FGA logs directly in the dashboard
Integrated Organization Discovery by Domain into Self-Service SSO, automatically syncing verified domains to organization records for email‑based login.
Introduces Universal Custom Password Hash in limited early access, allowing bulk import of users with custom or legacy password formats.
Deprecates the `enabled_clients` field in GET (multiple and single) and PATCH connection endpoints.
Added ability to configure non‑persistent (ephemeral) sessions via post‑login Actions
Added Auth0 Private Cloud on Azure with new 30x and 30x Burst performance tiers (up to 3,000 RPS).
Custom Token Exchange now in Open Early Access, enabling Auth0 Actions during OAuth token exchanges
Added granular filtering by application and connection on Overview and Threat Monitoring pages
Added Flows Auth0 Send Email Action to send emails from Flows using Auth0 tenant email providers
Modernized the look and feel of the MyAccount API Explorer
Retiring a set of weak TLS 1.2 cipher suites for all Auth0 service endpoints, dashboards, CDN, and custom domains.
General availability of Advanced Customizations for Universal Login, allowing full-screen UI customization of all login flows (login, signup, MFA, password reset, etc.).
Introduces Requesting App for Cross App Access (XAA) in Beta, letting client apps obtain third‑party API tokens via the Identity Assertion Authorization Grant.
Added Google Workspace User Directory Sync in early access, configurable via Auth0 Management Dashboard.
Introduces Auth0.Aspnetcore.Authentication.Api SDK for ASP.NET Core, supporting .NET 8+ and a single-line middleware registration.
Admins can configure custom device remembrance TTL (1‑365 days) for the New Device assessor, default remains 30 days.
Express Configuration with Okta is now generally available for Auth0 SaaS apps in the Okta Integration Network.
General Availability of Auth0 for AI Agents, introducing a new connected accounts flow with purpose and support for Microsoft Entra and Google Workspace.
Refined Security Center metric calculation to count IPs with >10 relevant events per hour
Introduces Auth for MCP in Early Access, adding OAuth 2.1/OpenID Connect support to MCP servers, clients, and agents
Added search and filter for custom domains via Management API and Dashboard
Added Management API endpoints to configure Bot Detection settings, including level and trusted IP allowlist
Added a Dynamic Client Registration (DCR) scope to the Tenant Access Control List.
Release of the @auth0/actions NPM package providing TypeScript definitions for Auth0 Actions
Add ability to attach custom key‑value metadata to Auth0 sessions via Post‑Login Actions or the Management API
Introduces beta Google Workspace User Directory Sync to automatically sync user profiles from Google Workspace into Auth0.
Login flows with organization_require_behavior=pre_login_prompt now respect existing authenticated sessions and allow SSO.
Added Auth0 Private Cloud region in AWS Asia Pacific Thailand
Introduces Organization Discovery by Domain in early access, automatically detecting a user's organization via email or organization name
Added optional `on_duplicate: "ignore"` and `on_missing: "ignore"` parameters to the Write API.
Introduces Sign in with Shop, a new social login integration for Shopify merchants
Introduces a login confirmation prompt for authentication requests using custom URI schemes or loopback URIs, replacing silent redirects
Updated ML model for signup adds user‑agent signals and smarter labeling to improve bot detection.
Introduces an Events Catalog Explorer in Auth0 Docs with detailed event information and examples.
GA release of Auth0 FGA Logging API providing full audit logs for all FGA operations
Introduces Auth0 Nuxt SDK beta with composable useAuth0 functions for a native Nuxt 3 experience
Auth0 now requires the "aud" claim in private‑key‑JWT client authentication to be a single JSON string containing the tenant’s issuer identifier.
Introduced a machine‑readable JSON IP allow list for Auth0 public cloud regions
Introduces Akamai Supplemental Signals in early access for Enterprise customers using Akamai as a reverse proxy
Added support for RS512, PS256, and ES256 signing algorithms for Private Key JWT client authentication and ID token verification.
Introduces Native Passkey Management APIs for MyAccount, enabling deletion and listing of passkeys for a user.
Added ability to configure non‑persistent (ephemeral) sessions via post‑login Actions using `api.session.setCookieMode("non-persistent")`.
Add native passkey flow support for Organizations, enabling sign‑in and registration within an organization context.
Complete SDK rewrite with a simpler API, modern Kotlin Android layer, and unified cross‑platform error handling for better developer experience.
Introduces Cross App Access (XAA) for Resource Applications in beta, allowing centralized control of AI agent and third‑party app connections.
Introduced Self‑Service User Provisioning (SCIM) in Early Access, enabling customers to automate onboarding/offboarding via the Self‑Service SSO wizard.
Introduced a redesigned Auth0 Support Center with AI‑powered search for instant, tailored answers
Added optional pre‑selection of tenants and roles in the team invitation modal, merging invitation and access assignment into a single step
General Availability of Tenant Access Control List (ACL) for security policy enforcement
Bulk User Import/Export is now available directly in the Auth0 Management Dashboard UI, eliminating the need for the extension.
API Access Policies for Applications launched in Early Access, letting you control which applications can obtain tokens for your APIs.
Add a --dry-run flag to the Auth0 Deploy CLI to preview resources that will be created, updated, or deleted before import
Non-Unique Emails feature now in open early access, allowing multiple accounts to share the same email in new database connections.
Introduce Beta Tenant Member Management for Private Cloud, enabling centralized tenant access control, bulk operations, and activity‑log auditing
Added early‑access support for sender‑constrained tokens using DPoP (RFC9449) to bind tokens to the client application.
Added JA3 and JA4 TLS fingerprint data to tenant logs for authentication and anomaly events.
The undocumented /api/v2/api-docs/ Swagger endpoint will be removed on September 11 2025, returning a 404 error.
Adds early‑access support for transaction metadata in post‑login Actions via a new event.transaction.metadata object and api.transaction.setMetadata function
Adds early‑access Native‑to‑Web SSO for enterprise customers, enabling iOS/Android apps to SSO into browser‑based web apps via Session Transfer Tokens
Multi-Resource Refresh Tokens (MRRT) are now in Early Access, letting a single refresh token request access tokens for multiple APIs with different audiences and scopes.
Add custom buttons via Universal Login Custom Prompts to enable connection switching
Auth0 now sends email notifications for brute‑force blocks even when the login identifier is phone or username, provided the user's email is available.
Improved bot detection reduces false positives for VPN and shared IP users
Added customizable PII masking for log streams, allowing customers to hash or mask sensitive data such as email, phone, and username.
Added Mexico as a new AWS Private Cloud region, the first Private Cloud presence in the country.
Added cascade revocation for Native‑to‑Web SSO: revoking the original refresh token now automatically revokes all dependent web sessions and their refresh tokens.
Enables passkey‑based authentication for custom database connections without requiring import mode.
My Account API Explorer launched and accessible via the documentation link
Added support for multiple custom domains per Auth0 tenant, enabling branded login URLs, emails, and domain‑specific templates.
Early Access adds Right-to-Left language support (Arabic, Persian, Hebrew, Urdu) to Universal Login, configurable via the Admin Dashboard and API.
Add Filters screen configuration to control when custom UI is applied
Updated bot detection model improves user‑agent interpretation, handling new browser and OS versions more accurately
Added Security Center Metric Data as a new data source for the Auth0 Guide AI chatbot, enabling security‑related queries.
Actions for post‑login and credentials‑exchange will no longer expose auth_session, authn_response, client_secret, client_assertion, and refresh_token in event.request.query and event.request.body (restricted by Sep 16 2025 or earlier fo...
Enables full restoration of production Private Cloud environments from backups up to 14 days old
Branded Brute-Force Protection unblock page is now part of Universal Login, allowing full customization of appearance and content.
Introduces Native-to-Web SSO early access, enabling session sharing between native mobile apps and web apps.
Improved bot detection model for signups reduces unwanted registrations and boosts onboarding security
Introduces Fine-Grained M2M Token Quotas in early access for Enterprise, allowing hourly and daily limits per application and organization.
Add ability to rename existing Actions via the Auth0 Dashboard
Added ACUL SDK support for custom WebAuthn + Biometrics authentication, MFA, reset‑password, and logout screens in Universal Login.
CIBA (Client‑Initiated Backchannel Authentication) flow is now generally available for Enterprise plan customers
Team owners can now perform full CRUD on tenant members, including editing roles, directly from the Auth0 Teams Dashboard.
Introduces Event Streams for real‑time notifications of Auth0 user and organization changes
Password field is now optional when updating SMTP Email Provider host settings
Streamlined Universal Login customization flow and tenant settings management commands
Added ability to fully customize push notification text in the iOS Guardian SDK
Adds UI for end users to manually select a language on Universal Login
Adds native Google sign‑in for Android apps via the Android Credential Manager
Introduces federated logout for Okta and generic OIDC enterprise connections via the Auth0 logout endpoint.
Added ACUL SDK support for custom Device Authorization screens and multiple MFA factor screens (voice, phone, recovery code) including reset password challenges.
Add direct mobile enrollment for Guardian Push, eliminating the need for QR code scanning.
Provides real-time logs for Actions, Custom Database Scripts, and Custom Social Connections via console.log and similar commands.
Introduces Token Vault in Early Access, letting apps securely call third‑party APIs on users’ behalf without handling refresh tokens.
Introduces Auth0 MCP Server beta, enabling natural‑language management of Auth0 tenants via AI agents.
Search now provides AI‑generated answers to queries in the Auth0 Support Center (beta)
Introduced Auth for GenAI Developer Preview, offering user authentication, token vault, and asynchronous authorization for AI agents
Introduces Tenant Access Control List (ACL) enabling custom allow, block, or redirect rules based on signals such as IP, geolocation, and user agents.
Introduces Mobile Driver’s License Verification Service in limited early access, enabling mDL verification during signup, login, and ad‑hoc checks.
Add UI for creating Self‑Service SSO tickets directly in the dashboard, removing the need for API calls
Added domain verification step to the Self‑Service SSO wizard, enabling customers to verify domains during setup
Added ACUL SDK support for custom Universal Login screens: Organizations, MFA TOTP enrollment/challenge, and Reset Password challenge variations.
Improved bot detection accuracy
Introduces Event Streams for user lifecycle events (create, update, delete) in public beta
Captures unhandled Actions execution errors as tenant logs
Standardized the Reset Custom Provider button behavior across Email and Phone providers.
Added Japanese language option for Auth0 Dashboard and Documentation
Added Swift Package Manager support for the Guardian SDK
Credential Guard added for Private Cloud on Azure customers
GA of Custom Phone Providers: configure custom phone providers and messages for Phone ID, MFA, and Passwordless, with full support in Auth0 CLI, Deploy CLI, and Terraform Provider.
Added Breached Password Detection to the password reset flow, blocking compromised passwords during resets.
Enables bulk testing of custom database scripts for compatibility with supported Node.js runtime versions.
Introduces MFA support in Advanced Customizations for Universal Login (ACUL) early access.
Deprecated Node.js 12 and 16 extensibility runtimes in all environments
Deprecated automatic session invalidation when updating a user's email or email_verified to unchanged or true values via the Management API.
Added a Usage Metrics Dashboard to Okta FGA for monitoring MAUs, total tuple count, and average requests per second.
Native mobile TOTP enrollment now defaults to manual code entry, skipping the QR code
Email OTP verification is now generally available, requiring an OTP during signup or password reset.
Introduces Advanced Customizations for Universal Login (ACUL) enabling client‑rendered, pixel‑perfect custom login screens via a new configuration API, CDT, and SDK support.
Early Access release of Custom Token Exchange for enterprise customers, enabling custom token exchange logic via Actions.
Add Hyderabad as a new AWS region for Auth0 Private Cloud deployments in India
Auth0 adds Universal Logout integration with Okta Workforce Identity using the Global Token Revocation spec
Adds Per-Module Authorization so application credentials can write only to designated modules of an Okta FGA model.
Added per‑minute api_limit log when a rate limit is exhausted
Adds middleware‑based authentication and edge‑compatible architecture, supporting Next.js 15, Turbopack and React 19.
Default From address field is now required in the Dashboard when creating or updating email provider configurations.
Custom Email Providers are now Generally Available, letting customers configure and fully control email delivery
Introduces a beta real-time logging feature for custom Actions, capturing console.log output and exceptions
Node.js 22 is now GA and set as the default runtime for new Actions and other extensibility integrations.
Introduced early‑access support for the Client‑Initiated Backchannel Authentication (CIBA) flow.
Added Organization ID to the "Successfully revoked a refresh token" (srrt) log event.
Increased the maximum Actions secret value length from 2048 to 4096 characters.
Introduce a new 10,000 RPS (100×) tier for Auth0 Private Cloud on AWS.
Adds early‑access alerts for security metrics when thresholds are exceeded
Introduces early‑access private‑cloud space restoration from backups up to 14 days old
Introduces a Bot Detection ML model for signup attack protection in Classic and Custom Login flows.
New modern styling applied to all customizable email templates.
Added beta self‑service SSO connections for Auth0 Teams dashboards.
General Availability of Auth0 Dashboard Login Session Management.
Increased organization metadata slots from 10 to 25
Customer Managed Keys (CMK) is now generally available, adding key management options to the Highly Regulated Identity suite.
Added Batch Check endpoint to Okta FGA API for batching multiple authorization checks in a single request.
Introduced api.transaction.setResultUrl to specify a post‑reset redirect URL
Added aggregated tenant‑level signals to fourth‑generation Bot Detection, improving accuracy across public and private cloud environments.
Self-Service SSO is now generally available for B2B Professional, Enterprise, and Enterprise Premium plans.
Beta v4 introduces middleware‑based authentication, encrypted cookies, and compatibility with Next.js 15, Turbopack, and React 19, enhancing security and maintenance.
Rules and Hooks are now read‑only in public cloud; script modifications are disabled
Add customizable welcome text for the SSO wizard landing screen
Added user‑agent signal analysis to fourth‑gen Bot Detection, integrated into the ML model.
Added SAML response manipulation methods in post‑login actions: setRelayState and setIssuer.
Machine‑to‑Machine access scoped to specific organizations is now generally available via the Client Credentials flow
Launch of Private Performance Burst AWS 30x and 60x options, delivering up to 3000 RPS and 6000 RPS for 80 hours per month (with reduced caps for the remaining time)
Add support for creating conditional relationship tuples in the Okta FGA Dashboard.
Adds an Extended Group Attribute Format option for Google Workspace Enterprise connections
Tenant admins can now select which IdPs appear in the SSO setup wizard
Closed support tickets older than 24 months will be automatically deleted on Oct 16, improving security posture.
Introduces Custom Phone Providers in early access, letting customers configure their own phone messaging providers.
Adds United Arab Emirates (UAE) as a new AWS region for Auth0 Private Cloud deployments.
Added EN 301 549 accessibility compliance for Universal Login, with out‑of‑the‑box or configurable options
Adding a new identifier (email, phone, username) no longer terminates the user session, enabling smoother progressive profiling.
Adds Email OTP Verification for signup and password reset, requiring a one‑time password sent to the user's email before account creation or reset completes.
Dashboard UI and documentation now use a unified “Triggers” concept instead of separate Flows and Triggers
Added POST /api/v2/users/{id}/revoke-access to revoke a user’s sessions and optionally their refresh tokens
Introduces Continuous Session Protection GA for enterprise, adding dynamic session and refresh token expiration via new setExpiresAt and setIdleExpiresAt methods.
Add customizable passwordless signup and login flows in Universal Login for email/SMS OTP.
Introduce SaaStart, a B2B SaaS reference application built with Next.js, Radix UI, and Auth0
Test custom DB scripts against a specific Node runtime version
Forms is now generally available, enabling custom login and signup flows with server‑side data injection and new UI components
Added limited early access support for Okta Universal Logout using Global Token Revocation
Add support for multiple Self-Service SSO profiles
Customers can set metric thresholds in the Security Center Dashboard
Added ML-powered bot detection for signup attacks in the New Universal Login experience.
Okta FGA is now generally available in a Private Cloud deployment option with dedicated resources alongside the public SaaS offering.
Prioritized Log Streams are now Generally Available for Enterprise customers.
Introduces Security Center Thresholds in early access, allowing Enterprise customers to set custom thresholds on security threat metrics.
Added optional consistency parameter to all query APIs (Check, Read, ListObjects, ListUsers, Expand) with values MINIMIZE_LATENCY (default) and HIGHER_CONSISTENCY.
Introduced `setExpiresAt(Date)` and `setIdleExpireAt(Date)` methods on post‑login Action objects (`api.session` and `api.refresh_token`) to control absolute and inactivity timeouts.
Self-Service SSO for Customer Identity Cloud is now available in Early Access.
Legacy non‑compliant Universal Login UI will be removed on February 23 2025
Introduces Guide, an AI‑powered chatbot for quick answers about Auth0
Reduced minimum character requirement for Organization Name and Display Name from 3 to 1 character
Added advanced biometric authentication (FaceID/Fingerprint) before obtaining credentials
Universal Login now provides out‑of‑the‑box WCAG 2.2 AA compliance with optional configurability.
Introduces Prioritized Log Streams in Early Access for Enterprise customers.
Added release version numbers to the Auth0 Changelog where applicable.
Adds a Dashboard Login Session Management view for admins to see all active Auth0 dashboard sessions across devices.
Deprecated the "Support Access" role; access to Subscription Tickets now requires the new "Elevated Support Access" role.
Introduces a new Log Stream filter category that streams only SCIM tenant logs when SCIM is enabled.
Deleting a Team Member now also removes them from all tenant memberships they belong to.
Integrates ASN reputation and untrusted IP data into Bot Detection ML model to better catch scripted attacks with frequent IP changes
Flexible Identifiers is now GA, adding a smoother signup flow that collects passwords after phone verification
Add RSS/ATOM feed subscription for Auth0 Private Cloud status page
Added 27 new languages, increasing Universal Login support to 78 languages.
Inbound SCIM for Enterprise Connections is now generally available in Okta Customer Identity Cloud.
Added a User ID Attribute Type menu to Azure AD connections for selecting sub or oid claims
Early Access release of Bring Your Own Key (BYOK) and Control Your Own Key (CYOK) for Highly Regulated Identity.
Added event.session and event.refresh_token objects in Actions for detailed session and refresh token information.
Improved quota utilization reports for Machine to Machine authentication to exclude Auth0 Management API tokens
Introduces the ListUsers API endpoint to retrieve all users with a specific relationship to a resource
JWT Profile for OAuth 2.0 Access Tokens (RFC9068) is now generally available
General Availability of a new Public Cloud region in Canada
Added Private Cloud AWS regions in Hong Kong and Calgary, Canada
Refresh Tokens Management API is now generally available for Enterprise customers
Added a per‑organization toggle to enable or disable self‑service signup for Database connections, overriding the application‑level setting
Introduced Actions migration tooling to convert Rules code to Actions syntax using QuickFix
Added dynamic UI switching in the user creation modal: tenants with >20,000 connections now see a text input instead of a dropdown
From August 5 2024, only members with the new Elevated Support Access role can use the Subscription Tickets feature to view and manage all tickets across a tenant.
Added JetBrains plugin providing syntax highlighting and validation for Okta FGA models and tests
Added early‑access embedded Action to configure a custom email provider in Branding → Email Provider section
Bot Detection added to the password reset flow
Highly Regulated Identity (HRI) is now generally available.
Added mandatory Autonomous System Network (ASN) binding for Auth0 Dashboard admin sessions in Private Cloud environments (v202422.31.0).
Adds support for multiple unique identifiers (email, phone number, username) for authentication, including phone‑only login.
Auth Challenge is now generally available as the default bot detection method, offering an invisible, frictionless alternative to CAPTCHAs.
Introduces Forms for Actions visual editor for building custom login and signup forms with built‑in validation and business logic
Launch of fourth‑generation Bot Detection that combines our CIC ML model with third‑party bot scoring
Added a Team Activity report to the Teams Dashboard for owners to audit member actions
Team owners with username/password accounts must verify their email before inviting members via the Teams Dashboard.
Introduces JWT Profile for OAuth 2.0 Access Tokens (RFC9068) in early access.
Add support for creating multiple credentials per Okta FGA store with scoped permission sets
Added client‑side email validation and ARIA enhancements (accessible labels, inline error announcements, and password‑complexity announcements) to improve screen‑reader support.
Added privacy manifest files to the iOS Guardian app and SDK to describe collected data and required reason APIs.
Adds Java Spring Security integration for Okta FGA via the OpenFGA Spring Boot Starter
Introduce modular authorization models composed from multiple files.
Opt-in early‑access release adds WCAG 2.2 AA accessibility improvements to Universal Login
Updated IP allow list for Auth0 Public Cloud regions with new address ranges for US, Europe, Australia, Japan, and UK
Added post-login actions enrollWith and enrollWithAny to let apps enroll users in specific MFA factors.
Enable OTP MFA enrollment directly in the Guardian app or SDK on the same mobile device, removing the need for QR code scanning.
Okta Fine Grained Authorization is now generally available in US, Europe, and Australia regions.
Introduced management API endpoints to list, explore, and terminate user sessions and refresh tokens.
Introduced V1 log event schemas for Okta Customer Identity Cloud (CIC)
Pro-code customization for signup and login flows is now generally available.
Add support for Cisco Duo Web SDK V4 for MFA
Tenant admins created with username/password must verify their email before inviting members via the Auth0 Dashboard.
General Availability of Auth0 Teams, providing a central place to manage tenants, members, and subscriptions.
Session cookies for Auth0 and Teams dashboard users are now bound to the originating Autonomous System Network (ASN) at creation.
General Availability of OIDC Back-Channel Logout initiators, enabling apps to receive server‑initiated logout events on session termination.
Introduces Auth Challenge, an invisible captcha alternative using browser and device challenges
Enforce MFA enrollment for all Auth0 Dashboard users logging in with username/password or social connections.
Added option to display an Enterprise Connection as a button on organization login screens
Enabled Private Cloud customers to request custom Session Timeout values for Auth0 Dashboard users.
Introduces Public Performance add‑on allowing up to 200 RPS for 48 hours/month on Public Cloud tenants.
Inbound SCIM for Okta Customer Identity Cloud is now available in limited early access.
Passkeys are now Generally Available, providing passwordless authentication via FIDO credentials
Introduce Limited Early Access of Financial Grade Identity (FAPI v1 Advanced) for highly regulated industries
Added mapping of Google "hd" claim to Auth0 idp_tenant_domain
Improved screen reader navigation for the MFA country code selector to meet WCAG 2.2 AA compliance
Reduced administrator session timeout on Teams dashboard to 12 hours of inactivity.
Reduced Auth0 Dashboard admin session timeout to 12 hours, prompting re‑authentication after inactivity.
Introduces Action Templates for rapid creation of pro‑code Actions
Introduce a GA Actions trigger for password reset flows, enabling custom extensibility
Add tenant search functionality to the Teams dashboard
Adds client‑side sanitization of .HAR files before they are uploaded via the Support Center
Add `email_locale` parameter to MFA enrollment API to specify language for enrollment tickets and prompts.
Launches Private Cloud in Indonesia via the Jakarta AWS region
Okta Access Gateway (OAG) integration is now Generally Available, enabling Auth0 as the identity provider for OAG.
Adds OIDC Back-Channel Logout Initiators (early access) to trigger logout from any session‑termination event
Add Private Cloud support in Melbourne, Australia and Osaka, Japan.
Added three new phone attributes (line type, region, provider) to Adaptive MFA risk assessment object.
Adds early‑access Tenant Member Management to Teams, allowing owners to grant dashboard users access to multiple tenants
Added challengeWith and challengeWithAny commands to the post‑login API for custom MFA factor selection
Added dismissable checks with a restore option and a progress gauge for overall readiness
Added quick search for team members by name or email in the Teams Dashboard.
Added support for 40+ languages in the Guardian app, matching the full Universal Login set
Introduces Account Linking in Actions, enabling users to authenticate via multiple identity providers while maintaining a single profile.
Introduces LinkedIn Social Connection V3 for new Sign‑in with LinkedIn OpenID Connect apps
Adds dark mode support to Teams Dashboard (beta)
Adds native integration with Arkose Labs for bot detection
Rules and Hooks will be unavailable for any new tenant created on or after Oct 16.
Introduces an Actions integration allowing Auth0 (Customer Identity Cloud) to trigger Okta Workflows.
Introduces OpenID Connect Back-Channel Logout, enabling backend-driven single logout via OIDC tokens.
Updated the Private Instances page in the Auth0 Support Center.
Integrated the Auth0 Community Response Series YouTube playlist as a searchable knowledge source in the Auth0 Support Center.
Add optional RBAC role data to the GET Organization Members endpoint
Quota Utilization Reports now display the actual Private Cloud environment name in the 'Environment' column.
Introduces data sources and resource relationship modeling for Auth0 entities.
Automatic redirect to Teams dashboard after successful Auth0 Teams login
Node-auth0 v4 is now GA, completely rewritten in TypeScript with full type definitions for methods, parameters, bodies, errors, and responses.
Integrates Auth0 Recommended Articles into the Support Center ticket creation flow
Added passcode, Touch ID, and Face ID support for the iOS Guardian App
Introduces passkeys for passwordless, FIDO‑based authentication as an early‑access feature.
Added a dark theme option for Auth0 documentation
Added required and recommended production readiness checks to the Readiness Check tool in the Auth0 Management Dashboard
Introduces Dark Mode alongside Light Mode for the Guardian App.
Added SAML mapping support in Actions for mapping user attributes and claims to profiles.
Migrated SDK to TypeScript and introduced full Hook support for authentication and user data.
Adds support for using Organization Names instead of IDs in the /authorize and /samlp endpoints.
Added integration with Friendly Captcha, a proof‑of‑work captcha, to Bot Detection
Introduced Bot Detection Slider to set friction level (Low, Medium, High) for the “When Risky” bot detection mode.
Added custom domain support for iOS and Android Guardian SDKs.
Introduced Security Policies for Teams, letting owners define access rules aligned with organizational IT policies.
Added new Auth0 Management Dashboard role "Editor - Organizations" for granular organization admin access
Added support for Microsoft 365 Modern Authentication as an external SMTP email provider.
Added PKCE support for OIDC and Okta Workforce connections, enhancing security between Auth0 and IdPs.
Node.js 18 is now GA for Actions, Rules, and Hooks in public cloud tenants.
Added ability to edit team names via the Teams dashboard settings.
Updated the Production Readiness Checks tool UI in the Management Dashboard
Added Home Realm Discovery tying identifier-first flow to connections with IdP domains linked to Organizations.
OIDC Back-Channel Logout is now in early access for Auth0 Enterprise tenants
Added six new language translations for Universal Login (Basque, Catalan, Galician, Norwegian, Norwegian Nynorsk, Welsh).
Added multilingual support for Guardian App (English US, French Canada, French, Portuguese Brazil, Spanish Argentina)
Rules & Hooks unavailable to new tenants from Oct 16 2023
Private Key JWT is now General Availability, enabling asymmetric public/private key authentication for Auth0 apps.
Introduces Security Center on the Converged Platform for Enterprise customers, providing real‑time monitoring of attack trends and metrics.
Auth0 is deprecating three SDK repositories: express‑oauth2‑bearer (EOL June 30 2023), angular‑auth0 and auth0‑cordova (EOL October 31 2023).
Unified search now spans Auth0 Docs, Community, and Blog within the Support Center.
Introduced Adaptive MFA Risk Ratings Score in Actions, exposing `event.authentication.riskAssessment` for login flow risk analysis.
Auth0 CLI v1 reaches General Availability, transitioning from experimental to officially supported.
Added an `organization_id` filter to User Search in the dashboard and Management API
Dashboard Activity page is now generally available to all customers
General Availability of the UK Public Cloud region for Auth0 tenants
General Availability of SMS and Email passwordless authentication on New Universal Login, previously limited to Classic login.
Introduces a new configuration option to prompt end‑users to select their MFA factor during enrollment in New Universal Login
Introduces a pluggable HTTP component with configurable defaults for flexible request handling.
Added two new Private Cloud tiers supporting up to 180,000 and 360,000 requests per minute.
Subscription quota reports now include Active Enterprise Connections usage, GA for both Private and Public Cloud customers.
Added environment name, version, deployment type, and cloud provider information to the Private Cloud Instances page
Introduces Security Center, a real‑time monitoring dashboard for attack‑related events.
Adds early‑access SMS and email passwordless flows to New Universal Login
auth0-angular, auth0-react, and auth0-vue v2 are now generally available.
Added Bot Detection support for passwordless authentication flows
Introduced the reimagined Dashboard Activity page for all public cloud tenants
Adds a no‑code text customization editor for Universal Login, letting users change all login box text without coding.
Manage Dashboard now retains the current view when switching tenants
Introduces dark mode as a beta feature in the Manage dashboard
Added support for SAML IdP‑initiated login within Organizations, appending the organization ID to the callback URL.
Add Status Page support for Private Cloud environments on the Converged Platform
General Availability release of nextjs-auth0 v2 for Next.js authentication.
Introduce public caching API (api.cache) for Actions to persist data across executions
SMS MFA for Auth0 Dashboard is now limited to paid subscriptions.
Offset pagination on Get Role Users endpoint capped at 1,000 items; use checkpoint pagination for larger result sets.
Adds a UK public cloud environment (beta) for Auth0 tenants
Added a `context` parameter to custom database scripts that includes organization information
Introduced Okta Workforce Enterprise Connection for seamless integration with Okta Workforce Identity Cloud.
Reduced inactivity timeout for administrator sessions on manage.auth0.com to 12 hours
Expanded log event types visible to Viewer-Users and Editor-Users dashboard roles
Introduces a Bot Detection Allowlist in the dashboard for trusted IPs/CIDRs.
Support Access role now can view and comment on Subscription Tickets in Support Center
Auth0 Teams now displays all tenant members, not just administrators.
- Added a toggle in the Breach Password Detection dashboard to block breached credentials during sign‑up.
Custom Guardian SDK apps can now send push notifications directly through FCM (Android) and APNs (iOS).
Updated Post‑login Trigger to v3 with security enhancements and new APIs
Added in‑dashboard notifications mirroring those from the Auth0 Support Center
auth0-flutter SDK reaches General Availability, adding native Auth0 support for Flutter apps
Introduced native Log Streaming integrations for Mixpanel and Twilio Segment.
Actions Integrations are now available in the Auth0 Marketplace for Private Cloud customers
Introduces Auth0 Teams for Enterprise tenants, offering centralized visibility and control
Non‑namespaced custom claims are now generally available for Access and ID tokens in OIDC flows.
Adds a new Support Access role to the Auth0 Dashboard.
Direct invites to Auth0 Support Center are discontinued; use Dashboard roles to grant access.
Introduces auth0-flutter SDK in First Availability, providing native Auth0 support for Flutter apps
SimpleKeychain v1 and JWTDecode.swift v3 are now generally available
Node 16 becomes the default runtime for Auth0 Rules and Hooks, with a tenant setting to select it; Node 12 is no longer supported and will be phased out.
Added automatic storage and revocation of Apple tokens for users created via Sign in With Apple to meet Apple’s account‑deletion requirement.
Added search capability for Organizations in the Manage Dashboard.
Introduce a no-code editor for customizing Universal Login UI, enabling branding, colors, fonts, borders, and backgrounds.
Added a machine‑learning engine to Auth0 Bot Detection, boosting coverage to ~90% of attacks
Search in the `details` object of `/api/v2/logs` is now limited to a whitelist of common fields.
Removed the undocumented `last_used` field from the Device Credentials Management API response.
Support for installing several Log Extensions ends on November 2 2022, with deprecation starting May 4 2022.
Org names can now be renamed after creation (must remain unique).
CSV export now escapes string fields to mitigate CSV injection (double quotes escaped, strings prefixed with a single quote and wrapped in double quotes).
Introduced a limit of 200 active refresh tokens per user per application to improve security and performance
Adds Laravel 9 support and new plug‑and‑play authentication controllers
Viewer and Editor user roles now have read access to the Organizations list and members in the Dashboard.
auth0-vue v1 reaches General Availability, delivering a native Vue 3 authentication SDK
Added async/await and Combine support plus custom headers and credential storage
Auth0 Terraform provider is now Verified by HashiCorp in the Terraform Registry.
Expose attack protection settings (breached password detection, brute‑force protection, suspicious IP throttling) via the Auth0 Management API
Added RSS feed support to the Auth0 Status Page
Introduces Credential Guard, an enterprise add‑on that detects breached passwords earlier by leveraging a security team’s access to private breach data.
Improved article navigation by grouping docs into job-focused topics
General Availability release of go-jwt-middleware V2 with a revamped API and JWKS support
Added caching for low‑change, high‑frequency Authentication API endpoints (tenant configuration and branding)
General availability of Auth0 Identity Platform as a private‑cloud deployment on Microsoft Azure.
General Availability release of the express‑oauth2‑jwt‑bearer SDK for Express APIs
Updated Auth0 Docs UI to match the new Auth0 brand
Added caching for low‑change, high‑traffic Authentication API endpoints (connections and applications).
General availability of the Auth0.AspNetCore.Authentication SDK for ASP.NET Core
Auth0 Identity Platform is now available as a private cloud deployment on Microsoft Azure (First Availability).
General Availability of Log Stream Flexibility
Introduces Threshold Manager for Suspicious IP throttling, now generally available.
Tokyo private space users now receive an Auth0 tenant in the Japan region when adding the Auth0 add-on
Added new audit event (mgmt_api_read) to track when client secrets appear in management API read responses
Bulk Users Export API now uses AWS S3 pre‑signed URLs for one‑time downloads
Add support for SAML IdP flows to specify an Organization ID, prompting users for org selection when required.
Added support for Bosnian, Bulgarian, Croatian, Serbian, Slovenian, Icelandic, Ukrainian, Estonian, Lithuanian, and Latvian languages in the New Universal Login flow.
Adds interactive authoring for Universal Login page templates via Auth0 CLI
Discontinue Private Cloud Custom Domain support as of Dec 20 2021
Introduces Threshold Manager GA, enabling users to set custom brute‑force protection thresholds
Adaptive MFA Risk Assessors are now Generally Available, enabling risk signal assessment without forcing an MFA flow
Linked individual error messages to their corresponding form fields for better screen‑reader support.
Viewer‑Config role now has read access to the Organizations list in the Dashboard
Added support for Google reCAPTCHA Enterprise in Auth0 Bot Detection.
Added MFA recovery codes, Organizations support, and scope‑insufficient prompt linking to Auth0 docs.
Add WebAuthn with security keys and device biometrics as new MFA options for Dashboard login
Recovery Codes are now configurable like other MFA methods and can be enabled or disabled per tenant.
Introduces a refreshed Dashboard Activity page that displays high-level metrics such as Active Users, Sign‑ups, Retention, and Failed logins.
General Availability of WebAuthn device biometrics as a passwordless first factor via a new Authentication Profile in the dashboard.
Sharelock service will shut down on August 1 2021, with creation of new secrets disabled after June 9 2021
Updated the Auth0 Dashboard UI to reflect the new Auth0 brand.
Three community GitHub repos (ember-simple-auth-auth0, auth0-socketio-jwt, auth0-joomla) will be removed after September 30, 2021.
Actions graduates to GA, unifying and replacing legacy Rules and Hooks with a single developer‑focused experience
Added option to assign Tenant Environment tags from the Manage Dashboard
Updated the Actions programming model for consistent behavior across triggers; existing actions run unchanged while new actions use the updated model
Auth0 now stores Google Workspace refresh_token in the user profile when returned by Google during offline authentication
Adds ability to start a log stream from a specific point in time
Added Thai, Turkish, Indonesian, Greek, and Vietnamese language options to the New Universal Login flow.
Introduce Organizations to represent teams, business customers, and partners, enabling B2B and SaaS use cases
Adds Account Lockout mode to Brute-force Protection, blocking accounts after multiple consecutive failed login attempts
WebAuthn with device biometrics for MFA is now generally available
Auth0 introduces non‑persistent sessions that automatically delete session cookies when the browser is closed.
Removed the Application Admin dashboard role in favor of newer dashboard roles
Introduces the GA "Always CAPTCHA" option for Bot Detection, giving developers control over when CAPTCHAs appear in login and sign‑up flows.
Introduces a new flexible layout with a collapsible sidebar for the Management Dashboard.
Public cloud edge will stop accepting TLS 1.0 and 1.1 traffic as of 10 May 2021.
Updated the availability SLA to 99.99% for all enterprise production Auth0 tenants (max ~4 minutes downtime per month)
Removed Auth0 Deploy extensions (Auth0 Deploy CLI, GitLab, Bitbucket, GitHub, Azure/VSTS) from the extension gallery.
General availability of WebAuthn MFA using FIDO security keys
Updated login page to the new Universal Login experience.
Adds an AllowList to Brute‑Force Protection, letting specified IPv4/IPv6 addresses bypass block rules.
Fixed user.multifactor property to always reflect the current MFA enrollment status.
Add configurable option to decouple refresh‑token revocation from grant revocation
Added built‑in dashboard roles (Admin, multiple Editor and Viewer variants) for enterprise plans, providing granular access control.
Hide connection and MFA secrets in the Auth0 Dashboard after they are saved
Add identifier-first flow to the New Universal Login Experience, enabling Home Realm Discovery for enterprise connections
Adds optional `client_id` parameter to POST /api/v2/tickets/password-change endpoint
Added CSS support to hide or replace the New Universal Login page logo via Page Templates.
Moved the Sign Up link below the Continue button on the New Universal Login page.
General availability of a new public cloud environment in Japan, adding to existing US, EU, and Australia regions.
Introduces configurable refresh token expiration with absolute and inactivity methods.
Introduces Adaptive MFA, enabling context‑driven MFA triggers based on risk scores (unknown devices, impossible travel, risky IPs).
Renamed Anomaly Detection to Attack Protection and moved it under a new Security section
Correlation-ID support for the Management API is now generally available
IPv6 addresses are now exposed on public endpoints (e.g., acme.us.auth0.com).
Introduces native Log Streaming integration with Sumo Logic for Auth0 events.
Introduces a public beta for WebAuthn device‑biometrics MFA
Public beta of WebAuthn with FIDO security keys for multi-factor authentication released.
MFA enrollment tickets now display the enrollment page using the configured Universal Login experience (Classic or New).
Launch of Auth0 Marketplace for discovering pre‑validated integrations
Added native Log Streaming integration to export Auth0 tenant event logs to Splunk.
Admins can now enable MFA for Dashboard access and enroll additional factors like SMS, Push, or OTP.
Added optional `identity` field to the email verification job endpoint, enabling verification of any user identity (secondary, federated, or passwordless).
Add support for Liquid templates to customize New Universal Login pages
Added limited wildcard support for Allowed Web Origins URLs to simplify CI/CD testing
Added Czech, French (Canada), Hungarian, Polish, Romanian, and Slovak languages to the New Universal Login flow.
Added support for voice call delivery of MFA one-time codes alongside SMS.
Add native Facebook login support via the Facebook SDK for iOS and Android applications.
Add support for importing user MFA enrollments via automatic migration or bulk import methods
Log streaming reaches GA status with support for streaming to AWS Eventbridge, Datadog, and other webhook targets.
Added Log Streams integration with Datadog
Introduced a new extensibility hook allowing integration of any SMS provider for MFA delivery.
Auth0 subscribers can now rotate and revoke signing keys via the Management Dashboard or API.
Introduces Refresh Token Rotation with reuse detection for SPA refresh token handling
Added bulk user import support for a wide range of password hash algorithms (Argon2, bcrypt with custom rounds, HMAC, MD4, LDAP, MD5, PBKDF2, SHA1/256/512).
Added ability to direct users to the signup page in the New Universal Login Experience
Added beta support for streaming log events via Webhooks.
Added support for creating and managing Auth0 hooks via the Management API
Added embedded passwordless login support for native and regular web applications.
Introduced a new BETA Post-Change Password Hook for Database Connections
Added Text Customization API for the New Universal Login Experience
Added Hindi localization for the New Universal Login Experience.
Adds Auth0 integration with Amazon EventBridge for near real‑time streaming of Auth0 event logs to AWS services.
Added support for SparkPost EU email provider
Add a dedicated rate limit of 10 requests per minute per user for Management API v2 when using SPA access tokens
Require the logged‑in or sign‑up email to match the email the admin invitation was sent to.
Only the most recent unused OTP (or link) is accepted; earlier OTPs expire when a new one is issued.
Added calendar picker UI component to the Logs page in the dashboard.
Adds native Sign in with Apple support for iOS13+ apps via a fully native flow
OIDC Enterprise Connection is now out of beta
Updated subscription plan pricing in the Dashboard
Added a new Social connection for LINE
Added Authorization Code flow support to the beta OIDC Connection.
Added upsert parameter to Bulk User Import, allowing selective updates of existing users for attributes such as app_metadata, email_verified, name, etc.
Added support for special characters "! # $ ' ^ ` ~ @" in usernames for Database Connections, Bulk User Import, Management API v2, and Universal Login.
Added a new security option in Advanced Tenant Settings to hide existence of usernames/emails in signup API responses.
Added a dropdown filter for log types on the Logs page in the dashboard.
Added beta OIDC Connection to simplify federation with OIDC identity providers.
Added support for OAuth 2.0 Device Authorization Grant (Device Flow) to enable authorization on input-constrained devices such as smart TVs, media players, and CLI tools.
The new Universal Login Experience is now generally available.
Added beta support for Sign in with Apple, enabling Apple ID authentication in Auth0 apps.
Added localization (i18n) support for the new Universal Login experience.
Added ability to enable clickjacking protection in Classic Universal Login
Added the ability to enable clickjacking protection in Classic Universal Login.
Added ability to set the default tenant login URI in the Management Dashboard.
User profile attributes can now be updated directly, removing the need to use user_metadata.
Added ECMAScript 9 linting support to the Rules web editor.
Added custom domain name support to the Delegated Administration extension
Added encrypted secrets support to Bitbucket, GitHub, GitLab, and Visual Studio Team Services Deployments extensions.
Added daily view of M2M calls per application for the last 7 days in quota reports
Added Azure AD support for Microsoft social connections.
Added roles and permissions to Auth0 core for fine-grained authorization.
Rules can now access MFA context stored in the user session
Enterprise customers can now set idle session timeout up to 100 days.
Improved error handling for logs search in Dashboard.
Added support for LinkedIn API v2 authentication.
Fixed quota utilization reporting for Private SaaS employees in the Support Center
Introduced a setting to define a default login URL for both applications and tenants.
Updated the Multi-factor Authentication section in the Dashboard UI
Added YAML config support, export capability (replaces the separate auth0‑dump tool) and optional delete operations via `AUTH0_ALLOW_DELETE`.
Updated ticketing backend with 8‑digit ticket IDs and reassigned existing IDs, affecting email notifications but preserving look‑up via original IDs.
Introduced independent minimum password length setting (1‑128 characters) separate from complexity rules
Expanded rule context to include connectionID, connectionMetadata, connectionOptions, tenant_domain, and domain_aliases.
Updated ticket creation form with new categorization fields to improve information capture
Changed active user counting to per unique user per tenant rather than per application, affecting quota and usage reports.
Version 3 of the Delegated Administration Extension is now available.
Enhanced dashboard user experience for Machine-to-Machine applications
Improved the Quickstarts download page UI and user experience
Added Passwordless connection support for Custom Domains
Enabled self‑service customers to purchase Machine‑to‑Machine applications.
Updated terminology: "Clients" renamed to "Applications" across the Management Dashboard
Added support for defining custom domains on Auth0 tenants
Released Auth0 Spring Security API SDK to simplify securing APIs with JWT.
Updated wp-auth0 SDK to support Lock 11 UI framework.
Enhanced Credentials Manager functionality
Auth0.js v9 switches to the latest embedded login API and removes the `usernamepassword/login` and `user/ssodata` endpoints.
Upgraded to auth0.js v9.0.0 and switched to new API endpoints, changing the default scope to `openid profile email`.
Adds support for the new users‑by‑email endpoint in the Auth0 Java SDK.
Added TLS 1.2 support to the Auth0.Android SDK
Upgrade SDK to auth0.js v8.11.
Added parsing of JWKs 'key_ops' parameter according to the RFC 7517 spec.
Fixed missing state check in certain authentication scenarios
Fix incorrect length handling of ECDSA signatures in the Java-JWT SDK
Added SFAuthenticationSession support to Auth0.swift for iOS 11
Fix navigation issues on non‑touchscreen Android devices.
Adds a new encrypted Credential Manager implementation for Android Lollipop+ devices
Fixed bugs in the authentication flow
Fixed implicit mode handling in auto login.
Added Xcode 9 compatibility to JWTDecode.swift.
Added support for OIDC‑conformant clients using cross‑origin authentication in the Lock Web SDK.
Implemented UI fixes and improvements
Added Xcode 9 compatibility to Lock.swift SDK
Introduces support for specifying a custom `user_id` when creating users via the Management API.
Fixed tenant override in popup mode.
Added Xcode 9 support to the Auth0.swift SDK.
Adds support for the Management API Grants entity in the Auth0-Java SDK.
New clients created via the dashboard now default to OIDC Conformant mode.
Fixed username regex validation.
Corrected snake_case handling for `app_metadata` during user sign-up.
Added Cross Origin Authentication support for passwordless connections
Added support for setting the primary user in rules via `context.primaryUser`.
Added support to the DELETE client grants endpoint to delete all grants for a given user using the `user_id` query parameter.
Disables the 'Use Auth0 for SSO' flag in Client Settings for OIDC Conformant clients.
Lock for Android now supports Android Manifest Placeholders to configure Domain and Scheme values.
Added Android Manifest Placeholders for domain and scheme configuration
- Introduces a new `connectionResolver` option to resolve connections dynamically at runtime
Fix HRD input handling when using the back button in the Lock Web SDK
Added a 'show password' toggle button to password fields in Lock for Android.
Auth0 Android SDK now attempts to use Chrome Custom Tabs for authentication flows.
Added OIDC‑conformant UserInfo class and corresponding API method
Added additional analytics events to track user interactions.
Fixed Internet Explorer 11 autocomplete issue.
Fixed a bug affecting Passwordless connections in the Hosted Login Page.
Added `client_id` query parameter to GET client grants endpoint for filtering by client ID
Emit an `authorization_error` event when username/password validation fails
Added HTML formatting support for the `flashMessage` option in Lock Web SDK.
Add `client.grant_types` property to Auth0 clients, enabling flow restrictions based on grant types.
Added 1Password support for database connections.
Added a Credentials Manager utility for secure token handling in Auth0.swift
Added support to query by identifier on PATCH/GET/DELETE api/v2/resource-servers endpoints
Removed `client.resource_servers` from the Management API sample response in the documentation.
Deprecated the Java Spring Security MVC SDK; it will no longer be maintained.
Deprecated the Java Servlet SDK; it will no longer be maintained.
Added a new Java SDK (auth0-java-mvc-common) for simplifying web authentication in Java MVC apps via Authorization Code or Implicit Grant
Deprecate the Java Spring MVC SDK – it will no longer receive maintenance
Added postMessageType option to filter iframe events and avoid false renewAuth callbacks.
Corrected handling of overridden configuration options
Added support for new OAuth 2.0 Renew and Revoke Token endpoints in the Auth0-Java SDK
Dropped support for Internet Explorer 10.
Added a new PayPal Sandbox social connection.
Resolved UI layout problems with long titles.
postMessage handler now parses object messages
Adds a 'Key Provider' interface for dynamic RSA/ECDSA key handling, enabling JWK file usage for token verification
Adds PayPal connection support to the Android Lock library
Added support for revoking refresh tokens in the Auth0.Android SDK.
Added Passwordless SMS/Email connection support to Lock.swift.
Introduced PayPal sandbox authentication strategy support in the Lock Web SDK.
Fixed nonce verification bug in the renewAuth method
Fixed UI glitches on mobile devices when in landscape orientation
Added support for the 'auth0-forwarded-for' header in server-side resource-owner password flows.
Auth0.Android SDK now parses rule-defined custom error messages on Rule errors during authentication.
Introduce multifactor authentication support for the oauth/token endpoint
Updated the Sharepoint SSO Integration tutorial with a correct link
Fixed error handling callback malfunction.
Introduced a new method to check native authentication availability for an IdP on the device.
Fixed UI inconsistencies in the username input field.
Added scope support to the `renew` method in Auth0.swift SDK.
Updates user.last_password_reset timestamp immediately when a password is changed
Added Evernote authentication strategy to the Lock Web SDK.
Fixed nonce mismatch error when the state option contains special characters.
Added Connection Scopes support to webAuth calls
Fixed URL fragment parsing when the `state` parameter contains special characters.
Added connection scope support for OAuth2 connections in Lock.swift.
Added filter‑as‑you‑type for tenant dropdowns with >10 tenants and a code‑folding editor for app/user metadata in User Details.
Added support for the `read:user` scope in Github social connections.
Lock Android Passwordless flow now retains the last signed-in user’s identity
Added owp parameter to popup mode requests
Introduced a new 'checkbox' custom input type for the `additionalSignUpFields` option.
Adds support for the Management API GET User Profile endpoint in the Auth0.Android SDK.
Fixed several UI issues in the Lock Web SDK.
Introduced `_idTokenVerification` flag to allow disabling ID token verification for legacy clients.
Added UI option to configure token expiration for the Management API in the API Explorer tab
Rules now execute for password and refresh_token grant types when calling oauth/token.
Introduced a new free‑text `description` property for Client objects.
Introduced Lock for iOS SDK written in Swift
Added Native Authentication support to Auth0.swift SDK.
Released a new Java SDK (auth0-java) supporting Authentication API OAuth 2.0 endpoints and most Management API entities.
Added SAML Single Logout enhancements to send LogoutRequest to the configured logout.callback URL for each Service Provider.
Added support for array-type claims in the Java-JWT SDK
Released auth0.js version 8
Adds a configurable flag to choose OpenID Connect‑compliant or legacy API endpoints in the Auth0.Android SDK.
Added support for custom URL schemes in Android Lock's Web Authentication flow.
Consolidated brute-force detection into a unified Shield component.
Added support for `password-realm` and `refresh_token` grant types in Auth0.swift
Added support for sending an audience value during Web Authentication in the Auth0.Android SDK.
Released a new Java SDK (java-jwt) for JWT verification and signing.
Added `sso_disabled` client flag configurable via the Management API.
Added an `expires_in` field to the oauth/token response to convey token lifespan
Updated Auth0 hosted login page to use Lock 10.7
Added OIDC‑compatible /userinfo and /oauth/token endpoints
Adds support for specifying a custom OAuth scope in Lock for Android
nonce parameter is now mandatory for the implicit grant flow
Released a new version of Lock for Web with bugfixes and various improvements
Fixed handling of double quotes in SAML assertions, restoring valid signature verification.
Added new tenant settings: `default_audience` and `default_directory`.
Added Android-focused SDK (JWTDecode.Android) for decoding JWTs on Android platforms.
Fix verification email template to correctly display the given_name attribute for users in a custom database
Switches Android Lock's default authentication UI from WebView to system Browser
Added pagination to the Database Connections page to support large numbers of connections.
Released new iOS SDK (Auth0.swift) for building custom login screens.
Added tenant log entries for delegation endpoint rate‑limit events
Added opt‑in preview for the new OAuth2aaS pipeline in Account Settings → Advanced.
Fixed error occurring when custom DB scripts are set to null
Released a new major version of Lock for Android featuring a redesigned UI.
Added configurable minimum and maximum username length (up to 128 characters) for database connections.
Introduces the `oid` claim in Azure AD user profile data.
Added SAML response logging to tenant logs when debug mode is enabled in a SAML connection.
Introduce password breach detection that cross‑checks Auth0 accounts against leaked credentials from external provider breaches.
Fixed bug where the secondary account was missing from the Users list after an account was unlinked.
Added insert/upsert mode and an `external_id` parameter to the Bulk Import API, returned in job status for correlation
Introduces a Bitbucket Deployments extension to deploy Auth0 rules and database connection scripts directly from a Bitbucket repository.
Added support for response_mode=form_post on the /authorize endpoint when response_type is id_token or code token.
Introduced password policy with optional dictionary blocking common passwords and up to 200 custom entries
Added full Client Credentials flow for API Authorization, enabling server-to-server access;
Introduce email update capability for users in passwordless connections.
Added Twilio Copilot integration for passwordless connections.
Added support for Fitbit OAuth2 applications.
Allow the last five passwordless codes per user to be valid instead of only the most recent one
Adds a GitHub Deployments extension to deploy Auth0 rules and database connection scripts from a GitHub repo
Introduced password history tracking for database connection password policies.
Added support for Firebase SDK v3 integration
Added a new tenant setting `enable_client_connections` to control client creation flow
Extensions gallery now displays documentation for extensions
Added Bitbucket social connection support.
Added ability to customize language in passwordless email templates
Integrate Rules debugging into the Real-time Logs extension
Added seven new logging extensions to export Auth0 logs to external services (Papertrail, Sumologic, Splunk, Logstash, Mixpanel, Logentries)
Add new Real-time Webtask Logs extension for live log access
Added validation for logout `returnTo` URLs against the Allowed Logout URLs list
Introduces the Authorization Dashboard extension for managing groups, users, and application access
Added a new property to the client entity to configure token endpoint authentication method
Added validation to the /tokeninfo endpoint to ensure the URL account matches the token's account
Suppressed error messages in the change‑password flow to stop user enumeration
Deprecated the `current_user_device_credentials` scopes for POST and DELETE on the /api/v2/device-credentials endpoint.
Introduce configurable post‑logout redirect URLs for Auth0 logout flows.
Added ext_nested_groups option to waad connection strategy
Added basic authentication support to the `device-credentials` endpoint.
Updated Extensions Gallery to support creating custom extensions.
Introduced a new password‑reset flow where users submit their username/email and receive a reset link via email.
Updated password reset flow: users now request a reset link via email and choose a new password after.
Added search capability in the Extensions Gallery
Added new logs query endpoints in Management API v2
Deprecated the Auth0.Android SDK's WebView usage for authentication