releases.shpreview

Autonomous agents pull user tokens without a session

1 featureThis release1 featureNew capabilitiesAI-tallied from the release notes
From the original release noteView original ↗

We're thrilled to announce Privileged Worker is now in Early Access, letting your autonomous agents pull a user's third-party tokens - Gmail, Drive, Slack, and more - from Token Vault with no user session required. Token Vault today assumes a human is actively logged in to hand over their token; if your agent runs on a schedule, in CI, or wakes up at 2am with no one signed in, there may not always be a user signed in. Privileged Worker gives your background agents their own strong credential to authorize that exchange directly.

With privileged worker, you can register a trusted worker identity, authenticate it with Private Key JWT or mTLS, and it can request a specific user's third-party token directly from Token Vault. We give you the ability to pin each worker credential to specific connections and scopes, so a compromised credential can only reach what it was actually authorized for.

To enable the Privileged Worker Early Access release in your Auth0 tenant once available in your environment, please contact your Auth0 Account Team.

Learn more in the documentation.

Fetched July 30, 2026