releases.shpreview
Auth0/Auth0 Changelog/Session ID Rotation for SAML and WS-Fed Authentication

Session ID Rotation for SAML and WS-Fed Authentication

March 26, 2026Auth0 Changelog
$npx -y @buildinternet/releases show rel_NCxw9aU_9Eqxr36ektPR_

What's new:                                                                                                  

We've updated session handling in SAML-P and WS-Fed authentication flows to align with industry best practices and our existing OAuth2/OIDC behavior. Following a successful login via SAML-P or WS-Fed, the session ID will now be rotated and a new session cookie will be issued.

What this means for you:                                                                       

If your implementation includes client-side logic, downstream services, or integrations that read or store session IDs across SAML-P or WS-Fed login flows, you will now receive a new session ID after authentication completes. Please review and update any such implementations accordingly.

This change brings SAML-P and WS-Fed session handling in line with the existing behavior of OAuth2 and OIDC flows, ensuring consistent and secure session management across all authentication protocols.

Fetched April 18, 2026