releases.shpreview
Home/Auth0
Auth0

Auth0

APIs searchable by ID, identifier, or name

This release1 featureNew capabilitiesAI-tallied from the release notes

Dashboard Search for APIs is now in Public Beta, letting users search APIs in real time by ID, identifier, or name without scrolling through paginated lists.

Read more →

Refresh token management endpoints in Early Access

This release2 featuresNew capabilities1 enhancementImprovements to existing featuresAI-tallied from the release notes

New API endpoints allow granular search and bulk revocation of refresh tokens. The GET endpoint retrieves refresh tokens by user ID or user ID and client ID. The POST endpoint supports revocation by IDs (up to 100), user ID, user ID + client ID, or user ID + client ID + audience. Contact your TAM or open a support ticket to enable this feature.

Read more →

Bot Detection model catches more automated traffic; false positives reduced

This release1 enhancementImprovements to existing featuresAI-tallied from the release notes

The machine learning model driving Bot Detection during signup has been updated to lower false-negative rates and intercept more automated traffic while keeping false-positive rates low for valid users. The model now delivers uniform detection accuracy across tenants of all sizes and rolls out automatically to Enterprise tenants with Attack Protection enabled.

Read more →

SCIM groups map to Auth0 roles; self-service provisioning added

This release3 featuresNew capabilitiesAI-tallied from the release notes

Inbound SCIM for Enterprise Connections now supports mapping synced groups to Auth0 roles at tenant level or scoped to organizations, and enterprise customers can self-configure SCIM provisioning for groups directly. Users in synced groups automatically inherit assigned roles globally or workspace-scoped permissions at login when combined with Auto-Membership.

Read more →

Dashboard navigation redesigned; flattened sidebar and reorganized pages

This release1 featureNew capabilities1 enhancementImprovements to existing featuresAI-tallied from the release notes

The redesigned dashboard navigation and information architecture is now available in beta, featuring flattened navigation with label-only group headers, pages reorganized around common tasks, and external actions moved to the top bar. Related functionality is grouped together with clearer naming. Existing bookmarks and deep links continue to work with automatic redirects, and all underlying functionality and APIs remain unchanged.

Read more →

Dashboard application search launches in beta

This release1 featureNew capabilitiesAI-tallied from the release notes

Dashboard Search for Applications is now available in public beta, allowing users to search and filter applications in real time by name, client ID, external client ID, metadata, application type, and first-party status. Filters can be combined (up to 5), persist in URLs for sharing, and follow Boolean search logic.

Read more →

Strict third-party apps now support M2M with client_credentials

This release2 featuresNew capabilitiesAI-tallied from the release notes

Strict third-party applications now support machine-to-machine access using the client_credentials grant type, including organization-scoped M2M access with explicit grant requirements. M2M access is restricted to applications created manually via the Management API or Dashboard; applications registered via Dynamic Client Registration are excluded.

Read more →

Credentials Exchange Actions: customize access token scopes

This release1 featureNew capabilities1 enhancementImprovements to existing featuresAI-tallied from the release notes

New Credentials Exchange Actions interfaces let you customize scopes considered when the access token is issued, with add/remove and set/clear operations on target scopes. Scope limits increased to 1000 for Credentials Exchange Actions and Post Login Actions.

Read more →

Custom Token Exchange adds Delegated Authorization support

This release1 featureNew capabilitiesAI-tallied from the release notes

Custom Token Exchange now supports Delegated Authorization, allowing a principal (support agent, backend service, or AI agent) to perform actions in a user's context while preserving both identities via the standards-based act claim per RFC 8693. Features include actor token parameters, setActor() Action command for explicit delegation control, automatic validation of Auth0 ID tokens as actor tokens, audit trail capture, and support for up to 5 levels of delegation chains.

Read more →

Tenant ACLs now match canonical hostnames; IP verification added

This release3 featuresNew capabilitiesAI-tallied from the release notes

Tenant Access Control Lists now support matching access rules directly against canonical hostnames, allowing you to lock down backend default domains while keeping custom domains accessible. New connecting IP verification lets you define allowed IPv4 and IPv6 CIDR blocks for infrastructure connecting to the Auth0 edge, and the Tenant ACL attribute limit has increased from 10 to 20 per signal.

Read more →

Federated logout terminates IdP sessions on logout

This release1 featureNew capabilitiesAI-tallied from the release notes

Federated Logout is now generally available for OIDC and Okta enterprise connections. When a user logs out with ?federated appended to the logout URL, Auth0 calls the upstream identity provider's end_session_endpoint to terminate the IdP session, closing the gap where a lingering IdP session could silently re-authenticate the user on their next login attempt.

Read more →

DPoP now available on Okta and OIDC Enterprise Connections

This release1 featureNew capabilitiesAI-tallied from the release notes

DPoP sender constraining for Enterprise Connections is now generally available on all plans. Customers can establish Okta and OIDC Enterprise Connections with DPoP enabled, allowing Auth0 to generate DPoP proofs when performing token exchange and calling userinfo endpoints on upstream connections.

Read more →

Tenant Manager role delegates member management

This release1 featureNew capabilitiesAI-tallied from the release notes

A new Tenant Manager role allows delegation of tenant-level user management tasks—inviting, updating, and revoking members—without exposing sensitive configuration settings like connections and security logs, which remain restricted to Team Owners. All management actions are captured in Team Activity logs for audit compliance.

Read more →

Non-Unique Emails is now generally available, allowing multiple user accounts to share the same email address within a database connection on new connections only. Users must be distinguished by a different primary identifier such as username or phone number, while all email communications remain sent to the shared address.

Read more →
Last Checked
2h ago
Domain
auth0.com
Featured in
Accounts
Tracking since Sep 25, 2024