releases.sh
Auth0

Auth0

auth0.comSecurity
$npx @buildinternet/releases get auth0

Advanced MFA Configurations now GA

This release3 featuresNew capabilitiesAI-tallied from the release notes

Advanced MFA Configurations are now generally available, letting you tailor enrollments to security needs. This expands remember-device lifetimes (1 hour to 90 days absolute vs. fixed 30 days), broadens OTP lengths for SMS and email factors (4 to 10 digits vs. fixed 6), and makes OTP lifetimes configurable.

Read more →

Cross-App Access requesting app now in Early Access

This release1 featureNew capabilitiesAI-tallied from the release notes

Auth0 can now act as the requesting application in Cross-App Access flows, letting apps fetch third-party API tokens for enterprise users without requiring manual account connections. Built on Auth0 Token Vault with the ID-JAG protocol, it supports OIDC and Okta Workforce connections with org-aware connection resolution.

Read more →

Custom token exchange reaches GA

This release1 featureNew capabilities2 enhancementsImprovements to existing featuresAI-tallied from the release notes

Custom Token Exchange is now generally available to all Enterprise, B2B Professional, and B2C Professional customers, plus Trial tenants. It lets apps exchange existing tokens for Auth0 tokens using fully controlled custom Action logic, and underpins delegated authorization for services acting on behalf of users.

Read more →

Early access: Auth0 customers can now self-configure custom rate limit policies — capping the rate of Authentication API OAuth requests per client or per app group (all third-party or CIMD apps). Enforcement can be set to block requests or to send non-blocking notifications, letting teams roll out limits gradually.

Read more →

Flexible Password Policy GA; new connections default to it

BreakingThis release1 featureNew capabilities1 enhancementImprovements to existing featuresAI-tallied from the release notes

Auth0's Flexible Password Policy is now generally available, replacing legacy password configuration with a single options.password_options object covering composition, history, dictionary, and profile-data rules. As of July 2026, new database connections created without an explicit password configuration use the policy by default; existing connections are unchanged. On update, PATCH /api/v2/connections/{id} returns 400 invalid_body if a request contains both password_options and legacy password fields.

Read more →

Custom Prompt fields now apply to Social and Enterprise logins

This release1 featureNew capabilities1 enhancementImprovements to existing featuresAI-tallied from the release notes

Custom signup and login fields and consent checkboxes in Universal Login now capture data on Social and Enterprise connections, matching database and passwordless behavior. No configuration changes are needed; existing Custom Prompts setups apply across all connection types.

Read more →

Session delegation: authorized actors act as end users

This release1 featureNew capabilitiesAI-tallied from the release notes

Auth0 now supports session delegation via custom token exchange, letting an authorized actor establish a web session as another user. Both identities are preserved via sub and act claims, with short-lived sessions, no refresh tokens, skipped MFA/consent, and a dedicated audit trail. Available to Enterprise, B2B Professional, and B2C Professional plans.

Read more →

Google Workspace group sync now GA with self-service setup

This release2 featuresNew capabilitiesAI-tallied from the release notes

Group and Group Membership support in Google Workspace Inbound Directory Sync is now generally available for all Auth0 customers, adding a paginated, searchable group browser in the Management Dashboard and self-service selective group sync through the assistant flow.

Read more →

Organizations Search gains advanced filtering

This release6 featuresNew capabilitiesAI-tallied from the release notes

Organizations Search now supports filtering by name, display name, ID, metadata, third-party client access, and app entitlement status, with up to 5 simultaneous filters and shareable URLs.

Read more →

Global Search ships in Cmd+K Beta

This release1 featureNew capabilitiesAI-tallied from the release notes

Global Search is now in Beta, enabling entity search for Applications, APIs, Organizations, and Users directly from the Command Palette (Cmd+K). Available to all public cloud customers, with private cloud rollout in the coming months.

Read more →

Curated blocklists integrate threat intel into Tenant ACLs

This release1 featureNew capabilitiesAI-tallied from the release notes

Curated Blocklists now integrate dynamically updated threat intelligence categories into Tenant ACL rules, covering low-reputation IPs, TOR exit nodes, proxies, VPNs, and iCloud Private Relay. Configured via the auth0_managed array in the Network ACLs Management API.

Read more →

Enterprise Connect Beta: federate SAML/OIDC servers into Auth0

This release3 featuresNew capabilitiesAI-tallied from the release notes

Enterprise Connect is now in Beta, allowing Auth0 to serve as a modular B2B identity layer by federating existing SAML or OIDC authorization servers. Includes guided setup, user provisioning, self-service onboarding, and connection lifecycle events.

Read more →

Autonomous agents pull user tokens without a session

This release1 featureNew capabilitiesAI-tallied from the release notes

Privileged Worker lets background agents authenticate with Private Key JWT or mTLS to pull a user's third-party tokens from Token Vault without requiring a signed-in user session. Worker credentials can be pinned to specific connections and scopes.

Read more →

Control which apps org members can access natively

This release1 featureNew capabilitiesAI-tallied from the release notes

Organization-to-Application Entitlement lets you control which applications org members can access natively, without custom code. Enforcement is opt-in per org and disabled by default.

Read more →

Organization-level roles now in Early Access

This release1 featureNew capabilitiesAI-tallied from the release notes

Roles can now be created, updated, and deleted scoped to individual organizations via the Management API or Dashboard, with independent permissions and user assignments per organization. Existing tenant-level RBAC is unchanged.

Read more →

Cross App Access for Resource Applications enters Open Early Access

This release1 featureNew capabilitiesAI-tallied from the release notes

Cross App Access (XAA) for Resource Applications is now in Open Early Access, letting Auth0 customers expose MCP servers and APIs to AI agents and enterprise apps with no code changes. The feature is available to Enterprise, B2B Pro, and B2B Essential customers, with trial access on Free tenants.

Read more →

Customer admins can now choose third-party app access during SSO setup

This release1 featureNew capabilitiesAI-tallied from the release notes

When generating a Self-Service Enterprise Configuration ticket, you can now delegate the third-party application access decision to the customer admin, who will see a new step in the setup wizard to allow or skip third-party app access. This option is mutually exclusive with setting domain connection access directly on the ticket.

Read more →