releases.shpreview
Auth0/Auth0 Changelog

Auth0 Changelog

$npx @buildinternet/releases show auth0-changelog
Mon
Wed
Fri
MayJunJulAugSepOctNovDecJanFebMarApr
Less
More
Releases510Avg156/moVersionsv202547 → v202614
Feb 10, 2025

Email OTP Verification is now Generally Available (GA), minor improvements will continue to roll out over the next 1-4 weeks to enhance performance and usability.

With Email OTP Verification, users are required to enter a One-Time Password (OTP) sent to their email during the signup or password reset process. This ensures email verification happens before account creation or password reset is completed, offering enhanced security and reducing the chances of mistyped or fake email accounts.

Key Highlights:

  • Synchronous Email Verification: Prevents account creation or password reset until users verify their email via OTP.
  • Improved Security: Helps prevent fake accounts, ensures accurate email addresses, and discourages phishing through email links.
  • Applicability: Available for both email verification during signup and password reset challenges.

Prerequisites:

  • Must be using Universal Login.
  • Connection must have Flexible Identifiers enabled.
  • Email OTP is only compatible when using the Identifier First Authentication Profile.

To enable this feature, navigate to the Attributes tab on any connection and change the Verification Method under the Email attribute settings from Verification Link to OTP.

Email OTP Verification is now Generally Available (GA), minor improvements will continue to roll out over the next 1-4 weeks to enhance performance and usability.

With Email OTP Verification, users are required to enter a One-Time Password (OTP) sent to their email during the signup or password reset process. This ensures email verification happens before account creation or password reset is completed, offering enhanced security and reducing the chances of mistyped or fake email accounts.

Key Highlights:

  • Synchronous Email Verification: Prevents account creation or password reset until users verify their email via OTP.
  • Improved Security: Helps prevent fake accounts, ensures accurate email addresses, and discourages phishing through email links.
  • Applicability: Available for both email verification during signup and password reset challenges.

Prerequisites:

  • Must be using Universal Login.
  • Connection must have Flexible Identifiers enabled.
  • Email OTP is only compatible when using the Identifier First Authentication Profile.

To enable this feature, navigate to the Attributes tab on any connection and change the Verification Method under the Email attribute settings from Verification Link to OTP.

Email OTP Verification is now Generally Available (GA), minor improvements will continue to roll out over the next 1-4 weeks to enhance performance and usability.

With Email OTP Verification, users are required to enter a One-Time Password (OTP) sent to their email during the signup or password reset process. This ensures email verification happens before account creation or password reset is completed, offering enhanced security and reducing the chances of mistyped or fake email accounts.

Key Highlights:

  • Synchronous Email Verification: Prevents account creation or password reset until users verify their email via OTP.
  • Improved Security: Helps prevent fake accounts, ensures accurate email addresses, and discourages phishing through email links.
  • Applicability: Available for both email verification during signup and password reset challenges.

Prerequisites:

  • Must be using Universal Login.
  • Connection must have Flexible Identifiers enabled.
  • Email OTP is only compatible when using the Identifier First Authentication Profile.

To enable this feature, navigate to the Attributes tab on any connection and change the Verification Method under the Email attribute settings from Verification Link to OTP.

Email OTP Verification is now Generally Available (GA), minor improvements will continue to roll out over the next 1-4 weeks to enhance performance and usability.

With Email OTP Verification, users are required to enter a One-Time Password (OTP) sent to their email during the signup or password reset process. This ensures email verification happens before account creation or password reset is completed, offering enhanced security and reducing the chances of mistyped or fake email accounts.

Key Highlights:

  • Synchronous Email Verification: Prevents account creation or password reset until users verify their email via OTP.
  • Improved Security: Helps prevent fake accounts, ensures accurate email addresses, and discourages phishing through email links.
  • Applicability: Available for both email verification during signup and password reset challenges.

Prerequisites:

  • Must be using Universal Login.
  • Connection must have Flexible Identifiers enabled.
  • Email OTP is only compatible when using the Identifier First Authentication Profile.

To enable this feature, navigate to the Attributes tab on any connection and change the Verification Method under the Email attribute settings from Verification Link to OTP.

Email OTP Verification is now Generally Available (GA), minor improvements will continue to roll out over the next 1-4 weeks to enhance performance and usability.

With Email OTP Verification, users are required to enter a One-Time Password (OTP) sent to their email during the signup or password reset process. This ensures email verification happens before account creation or password reset is completed, offering enhanced security and reducing the chances of mistyped or fake email accounts.

Key Highlights:

  • Synchronous Email Verification: Prevents account creation or password reset until users verify their email via OTP.
  • Improved Security: Helps prevent fake accounts, ensures accurate email addresses, and discourages phishing through email links.
  • Applicability: Available for both email verification during signup and password reset challenges.

Prerequisites:

  • Must be using Universal Login.
  • Connection must have Flexible Identifiers enabled.
  • Email OTP is only compatible when using the Identifier First Authentication Profile.

To enable this feature, navigate to the Attributes tab on any connection and change the Verification Method under the Email attribute settings from Verification Link to OTP.

Email OTP Verification is now Generally Available (GA), minor improvements will continue to roll out over the next 1-4 weeks to enhance performance and usability.

With Email OTP Verification, users are required to enter a One-Time Password (OTP) sent to their email during the signup or password reset process. This ensures email verification happens before account creation or password reset is completed, offering enhanced security and reducing the chances of mistyped or fake email accounts.

Key Highlights:

  • Synchronous Email Verification: Prevents account creation or password reset until users verify their email via OTP.
  • Improved Security: Helps prevent fake accounts, ensures accurate email addresses, and discourages phishing through email links.
  • Applicability: Available for both email verification during signup and password reset challenges.

Prerequisites:

  • Must be using Universal Login.
  • Connection must have Flexible Identifiers enabled.
  • Email OTP is only compatible when using the Identifier First Authentication Profile.

To enable this feature, navigate to the Attributes tab on any connection and change the Verification Method under the Email attribute settings from Verification Link to OTP.

Email OTP Verification is now Generally Available (GA), minor improvements will continue to roll out over the next 1-4 weeks to enhance performance and usability.

With Email OTP Verification, users are required to enter a One-Time Password (OTP) sent to their email during the signup or password reset process. This ensures email verification happens before account creation or password reset is completed, offering enhanced security and reducing the chances of mistyped or fake email accounts.

Key Highlights:

  • Synchronous Email Verification: Prevents account creation or password reset until users verify their email via OTP.
  • Improved Security: Helps prevent fake accounts, ensures accurate email addresses, and discourages phishing through email links.
  • Applicability: Available for both email verification during signup and password reset challenges.

Prerequisites:

  • Must be using Universal Login.
  • Connection must have Flexible Identifiers enabled.
  • Email OTP is only compatible when using the Identifier First Authentication Profile.

To enable this feature, navigate to the Attributes tab on any connection and change the Verification Method under the Email attribute settings from Verification Link to OTP.

Feb 6, 2025

At Auth0, we understand that no two customer identity stories are the same. Every company has a brand identity, a secret sauce, and a unique aesthetic vision. Today, we are very excited to introduce the next evolution in customization for Universal Login, Advanced Customizations for Universal Login (ACUL). ACUL enables your team to build custom, client-rendered versions of each Universal Login screen, allowing you to control every pixel of the Universal Login experience.

This Early Access release of ACUL is available to all paid customers. Public cloud customers can start using it today! Those on private cloud will be enabled as part of their regular release cycle. This initial EA release provides a new configuration API, CDT and SDK support, and allows you to build custom versions of the following screens:

  • Login
  • Login Id
  • Login Password
  • Login Passwordless Email Code
  • Login Passwordless SMS OTP
  • Signup
  • Signup Id
  • Signup Password
  • Passkey Enrollment
  • Passkey Enrollment Local
  • Phone Identifier Enrollment (used for identity verification during Signup)
  • Phone Identifier Challenge (used for identity verification during Signup)
  • Email Identifier Challenge (used for identity verification during Signup)
  • Interstitial Captcha
  • Reset Password
  • Reset Password Email
  • Reset Password Request
  • Reset Password Error
  • Reset Password Success

The following flows and capabilities are supported in ACUL EA:

  • Single step Signup & Login with password and social & enterprise connections
  • ID First Signup/Login using password, passwordless email/SMS OTP, passkeys, and social & enterprise connections
  • Basic Reset Password flow with and without Bot Detection
  • Flexible Identifiers with and without identity verification enabled during Signup
  • Bot detection with any of our 7 supported Captcha providers during the Signup, Login, and Reset Password flows
  • Capturing additional data during Signup and Login using custom prompts

This is just the beginning! In the coming months, we will be adding support for every screen and capability that Universal Login currently supports out of the box, a shiny new Dashboard UI for configuring ACUL, and lots more DX goodness!

Checkout our online documentation to learn more about ACUL and stay tuned to the Auth0 Changelog for updates and announcements!

We are thrilled to announce the Early Access release of Custom Token Exchange. Enterprise customers can now request access to use this feature.

Token Exchange is an OAuth grant-type that enables the exchange of security tokens for other security tokens, typically access_tokens. Custom Token Exchange provides a flexible solution using Actions that allows customers to provide their custom logic to control the exchange - i.e. effectively providing the means to implement custom authentication semantics using Actions.

This added flexibility can be used by customers to tackle advanced integration use cases, such as:

  • Seamlessly migrating users to Auth0
  • Integrating external IDPs
  • Exchanging Auth0 tokens for a different audience
  • ... and other use cases where regular federation and/or OIDC flows are not an option

To learn more, read our documentation.

Reach out to you Auth0 contact to request access!

We are thrilled to announce the Early Access release of Custom Token Exchange. Enterprise customers can now request access to use this feature.

Token Exchange is an OAuth grant-type that enables the exchange of security tokens for other security tokens, typically access_tokens. Custom Token Exchange provides a flexible solution using Actions that allows customers to provide their custom logic to control the exchange - i.e. effectively providing the means to implement custom authentication semantics using Actions.

This added flexibility can be used by customers to tackle advanced integration use cases, such as:

  • Seamlessly migrating users to Auth0
  • Integrating external IDPs
  • Exchanging Auth0 tokens for a different audience
  • ... and other use cases where regular federation and/or OIDC flows are not an option

To learn more, read our documentation.

Reach out to you Auth0 contact to request access!

At Auth0, we understand that no two customer identity stories are the same. Every company has a brand identity, a secret sauce, and a unique aesthetic vision. Today, we are very excited to introduce the next evolution in customization for Universal Login, Advanced Customizations for Universal Login (ACUL). ACUL enables your team to build custom, client-rendered versions of each Universal Login screen, allowing you to control every pixel of the Universal Login experience.

This Early Access release of ACUL is available to all paid customers. Public cloud customers can start using it today! Those on private cloud will be enabled as part of their regular release cycle. This initial EA release provides a new configuration API, CDT and SDK support, and allows you to build custom versions of the following screens:

  • Login
  • Login Id
  • Login Password
  • Login Passwordless Email Code
  • Login Passwordless SMS OTP
  • Signup
  • Signup Id
  • Signup Password
  • Passkey Enrollment
  • Passkey Enrollment Local
  • Phone Identifier Enrollment (used for identity verification during Signup)
  • Phone Identifier Challenge (used for identity verification during Signup)
  • Email Identifier Challenge (used for identity verification during Signup)
  • Interstitial Captcha
  • Reset Password
  • Reset Password Email
  • Reset Password Request
  • Reset Password Error
  • Reset Password Success

The following flows and capabilities are supported in ACUL EA:

  • Single step Signup & Login with password and social & enterprise connections
  • ID First Signup/Login using password, passwordless email/SMS OTP, passkeys, and social & enterprise connections
  • Basic Reset Password flow with and without Bot Detection
  • Flexible Identifiers with and without identity verification enabled during Signup
  • Bot detection with any of our 7 supported Captcha providers during the Signup, Login, and Reset Password flows
  • Capturing additional data during Signup and Login using custom prompts

This is just the beginning! In the coming months, we will be adding support for every screen and capability that Universal Login currently supports out of the box, a shiny new Dashboard UI for configuring ACUL, and lots more DX goodness!

Checkout our online documentation to learn more about ACUL and stay tuned to the Auth0 Changelog for updates and announcements!

At Auth0, we understand that no two customer identity stories are the same. Every company has a brand identity, a secret sauce, and a unique aesthetic vision. Today, we are very excited to introduce the next evolution in customization for Universal Login, Advanced Customizations for Universal Login (ACUL). ACUL enables your team to build custom, client-rendered versions of each Universal Login screen, allowing you to control every pixel of the Universal Login experience.

This Early Access release of ACUL is available to all paid customers. Public cloud customers can start using it today! Those on private cloud will be enabled as part of their regular release cycle. This initial EA release provides a new configuration API, CDT and SDK support, and allows you to build custom versions of the following screens:

  • Login
  • Login Id
  • Login Password
  • Login Passwordless Email Code
  • Login Passwordless SMS OTP
  • Signup
  • Signup Id
  • Signup Password
  • Passkey Enrollment
  • Passkey Enrollment Local
  • Phone Identifier Enrollment (used for identity verification during Signup)
  • Phone Identifier Challenge (used for identity verification during Signup)
  • Email Identifier Challenge (used for identity verification during Signup)
  • Interstitial Captcha
  • Reset Password
  • Reset Password Email
  • Reset Password Request
  • Reset Password Error
  • Reset Password Success

The following flows and capabilities are supported in ACUL EA:

  • Single step Signup & Login with password and social & enterprise connections
  • ID First Signup/Login using password, passwordless email/SMS OTP, passkeys, and social & enterprise connections
  • Basic Reset Password flow with and without Bot Detection
  • Flexible Identifiers with and without identity verification enabled during Signup
  • Bot detection with any of our 7 supported Captcha providers during the Signup, Login, and Reset Password flows
  • Capturing additional data during Signup and Login using custom prompts

This is just the beginning! In the coming months, we will be adding support for every screen and capability that Universal Login currently supports out of the box, a shiny new Dashboard UI for configuring ACUL, and lots more DX goodness!

Checkout our online documentation to learn more about ACUL and stay tuned to the Auth0 Changelog for updates and announcements!

We are thrilled to announce the Early Access release of Custom Token Exchange. Enterprise customers can now request access to use this feature.

Token Exchange is an OAuth grant-type that enables the exchange of security tokens for other security tokens, typically access_tokens. Custom Token Exchange provides a flexible solution using Actions that allows customers to provide their custom logic to control the exchange - i.e. effectively providing the means to implement custom authentication semantics using Actions.

This added flexibility can be used by customers to tackle advanced integration use cases, such as:

  • Seamlessly migrating users to Auth0
  • Integrating external IDPs
  • Exchanging Auth0 tokens for a different audience
  • ... and other use cases where regular federation and/or OIDC flows are not an option

To learn more, read our documentation.

Reach out to you Auth0 contact to request access!

At Auth0, we understand that no two customer identity stories are the same. Every company has a brand identity, a secret sauce, and a unique aesthetic vision. Today, we are very excited to introduce the next evolution in customization for Universal Login, Advanced Customizations for Universal Login (ACUL). ACUL enables your team to build custom, client-rendered versions of each Universal Login screen, allowing you to control every pixel of the Universal Login experience.

This Early Access release of ACUL is available to all paid customers. Public cloud customers can start using it today! Those on private cloud will be enabled as part of their regular release cycle. This initial EA release provides a new configuration API, CDT and SDK support, and allows you to build custom versions of the following screens:

  • Login
  • Login Id
  • Login Password
  • Login Passwordless Email Code
  • Login Passwordless SMS OTP
  • Signup
  • Signup Id
  • Signup Password
  • Passkey Enrollment
  • Passkey Enrollment Local
  • Phone Identifier Enrollment (used for identity verification during Signup)
  • Phone Identifier Challenge (used for identity verification during Signup)
  • Email Identifier Challenge (used for identity verification during Signup)
  • Interstitial Captcha
  • Reset Password
  • Reset Password Email
  • Reset Password Request
  • Reset Password Error
  • Reset Password Success

The following flows and capabilities are supported in ACUL EA:

  • Single step Signup & Login with password and social & enterprise connections
  • ID First Signup/Login using password, passwordless email/SMS OTP, passkeys, and social & enterprise connections
  • Basic Reset Password flow with and without Bot Detection
  • Flexible Identifiers with and without identity verification enabled during Signup
  • Bot detection with any of our 7 supported Captcha providers during the Signup, Login, and Reset Password flows
  • Capturing additional data during Signup and Login using custom prompts

This is just the beginning! In the coming months, we will be adding support for every screen and capability that Universal Login currently supports out of the box, a shiny new Dashboard UI for configuring ACUL, and lots more DX goodness!

Checkout our online documentation to learn more about ACUL and stay tuned to the Auth0 Changelog for updates and announcements!

We are thrilled to announce the Early Access release of Custom Token Exchange. Enterprise customers can now request access to use this feature.

Token Exchange is an OAuth grant-type that enables the exchange of security tokens for other security tokens, typically access_tokens. Custom Token Exchange provides a flexible solution using Actions that allows customers to provide their custom logic to control the exchange - i.e. effectively providing the means to implement custom authentication semantics using Actions.

This added flexibility can be used by customers to tackle advanced integration use cases, such as:

  • Seamlessly migrating users to Auth0
  • Integrating external IDPs
  • Exchanging Auth0 tokens for a different audience
  • ... and other use cases where regular federation and/or OIDC flows are not an option

To learn more, read our documentation.

Reach out to you Auth0 contact to request access!

At Auth0, we understand that no two customer identity stories are the same. Every company has a brand identity, a secret sauce, and a unique aesthetic vision. Today, we are very excited to introduce the next evolution in customization for Universal Login, Advanced Customizations for Universal Login (ACUL). ACUL enables your team to build custom, client-rendered versions of each Universal Login screen, allowing you to control every pixel of the Universal Login experience.

This Early Access release of ACUL is available to all paid customers. Public cloud customers can start using it today! Those on private cloud will be enabled as part of their regular release cycle. This initial EA release provides a new configuration API, CDT and SDK support, and allows you to build custom versions of the following screens:

  • Login
  • Login Id
  • Login Password
  • Login Passwordless Email Code
  • Login Passwordless SMS OTP
  • Signup
  • Signup Id
  • Signup Password
  • Passkey Enrollment
  • Passkey Enrollment Local
  • Phone Identifier Enrollment (used for identity verification during Signup)
  • Phone Identifier Challenge (used for identity verification during Signup)
  • Email Identifier Challenge (used for identity verification during Signup)
  • Interstitial Captcha
  • Reset Password
  • Reset Password Email
  • Reset Password Request
  • Reset Password Error
  • Reset Password Success

The following flows and capabilities are supported in ACUL EA:

  • Single step Signup & Login with password and social & enterprise connections
  • ID First Signup/Login using password, passwordless email/SMS OTP, passkeys, and social & enterprise connections
  • Basic Reset Password flow with and without Bot Detection
  • Flexible Identifiers with and without identity verification enabled during Signup
  • Bot detection with any of our 7 supported Captcha providers during the Signup, Login, and Reset Password flows
  • Capturing additional data during Signup and Login using custom prompts

This is just the beginning! In the coming months, we will be adding support for every screen and capability that Universal Login currently supports out of the box, a shiny new Dashboard UI for configuring ACUL, and lots more DX goodness!

Checkout our online documentation to learn more about ACUL and stay tuned to the Auth0 Changelog for updates and announcements!

We are thrilled to announce the Early Access release of Custom Token Exchange. Enterprise customers can now request access to use this feature.

Token Exchange is an OAuth grant-type that enables the exchange of security tokens for other security tokens, typically access_tokens. Custom Token Exchange provides a flexible solution using Actions that allows customers to provide their custom logic to control the exchange - i.e. effectively providing the means to implement custom authentication semantics using Actions.

This added flexibility can be used by customers to tackle advanced integration use cases, such as:

  • Seamlessly migrating users to Auth0
  • Integrating external IDPs
  • Exchanging Auth0 tokens for a different audience
  • ... and other use cases where regular federation and/or OIDC flows are not an option

To learn more, read our documentation.

Reach out to you Auth0 contact to request access!

At Auth0, we understand that no two customer identity stories are the same. Every company has a brand identity, a secret sauce, and a unique aesthetic vision. Today, we are very excited to introduce the next evolution in customization for Universal Login, Advanced Customizations for Universal Login (ACUL). ACUL enables your team to build custom, client-rendered versions of each Universal Login screen, allowing you to control every pixel of the Universal Login experience.

This Early Access release of ACUL is available to all paid customers. Public cloud customers can start using it today! Those on private cloud will be enabled as part of their regular release cycle. This initial EA release provides a new configuration API, CDT and SDK support, and allows you to build custom versions of the following screens:

  • Login
  • Login Id
  • Login Password
  • Login Passwordless Email Code
  • Login Passwordless SMS OTP
  • Signup
  • Signup Id
  • Signup Password
  • Passkey Enrollment
  • Passkey Enrollment Local
  • Phone Identifier Enrollment (used for identity verification during Signup)
  • Phone Identifier Challenge (used for identity verification during Signup)
  • Email Identifier Challenge (used for identity verification during Signup)
  • Interstitial Captcha
  • Reset Password
  • Reset Password Email
  • Reset Password Request
  • Reset Password Error
  • Reset Password Success

The following flows and capabilities are supported in ACUL EA:

  • Single step Signup & Login with password and social & enterprise connections
  • ID First Signup/Login using password, passwordless email/SMS OTP, passkeys, and social & enterprise connections
  • Basic Reset Password flow with and without Bot Detection
  • Flexible Identifiers with and without identity verification enabled during Signup
  • Bot detection with any of our 7 supported Captcha providers during the Signup, Login, and Reset Password flows
  • Capturing additional data during Signup and Login using custom prompts

This is just the beginning! In the coming months, we will be adding support for every screen and capability that Universal Login currently supports out of the box, a shiny new Dashboard UI for configuring ACUL, and lots more DX goodness!

Checkout our online documentation to learn more about ACUL and stay tuned to the Auth0 Changelog for updates and announcements!

We are thrilled to announce the Early Access release of Custom Token Exchange. Enterprise customers can now request access to use this feature.

Token Exchange is an OAuth grant-type that enables the exchange of security tokens for other security tokens, typically access_tokens. Custom Token Exchange provides a flexible solution using Actions that allows customers to provide their custom logic to control the exchange - i.e. effectively providing the means to implement custom authentication semantics using Actions.

This added flexibility can be used by customers to tackle advanced integration use cases, such as:

  • Seamlessly migrating users to Auth0
  • Integrating external IDPs
  • Exchanging Auth0 tokens for a different audience
  • ... and other use cases where regular federation and/or OIDC flows are not an option

To learn more, read our documentation.

Reach out to you Auth0 contact to request access!

We are thrilled to announce the Early Access release of Custom Token Exchange. Enterprise customers can now request access to use this feature.

Token Exchange is an OAuth grant-type that enables the exchange of security tokens for other security tokens, typically access_tokens. Custom Token Exchange provides a flexible solution using Actions that allows customers to provide their custom logic to control the exchange - i.e. effectively providing the means to implement custom authentication semantics using Actions.

This added flexibility can be used by customers to tackle advanced integration use cases, such as:

  • Seamlessly migrating users to Auth0
  • Integrating external IDPs
  • Exchanging Auth0 tokens for a different audience
  • ... and other use cases where regular federation and/or OIDC flows are not an option

To learn more, read our documentation.

Reach out to you Auth0 contact to request access!

Latest
Apr 23, 2026
Tracking Since
Sep 25, 2024
Last checked Apr 26, 2026