releases.shpreview
Auth0/Auth0 Changelog/Token Vault now organization-scoped; multi-tenant isolation built-in

Token Vault now organization-scoped; multi-tenant isolation built-in

1 featureThis release1 featureNew capabilitiesAI-tallied from the release notes

We're excited to announce the GA release of __Token Vault with Organization Support__! ISVs building multi-tenant B2B SaaS applications and agents on Auth0 Organizations can now use Token Vault to store and exchange third-party tokens within the context of each organization their users belong to. With this release, Token Vault exchanges and the Connected Accounts flow respect `org_id` end-to-end. Tokens are scoped to `(user, org_id)`, so each organization maintains its own token records for a given user and data isolation between organizations is preserved by default. Token Vault exchanges that do not carry an `org_id` claim continue to behave as before. For complete setup instructions and more, refer to our [documentation](https://auth0.com/docs/secure/call-apis-on-users-behalf/token-vault#use-with-organizations)..

Fetched May 29, 2026