releases.shpreview
Auth0/Auth0 Changelog/Tenant ACLs now match canonical hostnames; IP verification added

Tenant ACLs now match canonical hostnames; IP verification added

3 featuresThis release3 featuresNew capabilitiesAI-tallied from the release notes

We have enhanced Tenant Access Control Lists (ACLs) to provide granular control over upstream proxy infrastructure and canonical domain routing. With this update, you can now isolate traffic by enforcing distinct rules on your canonical hostnames while keeping your user-facing custom domains open. ##### What's New? * **Canonical Hostname Routing** * Match access rules directly against your canonical hostnames. This allows you to lock down backend default domains while keeping customer-facing custom domains open and accessible to your users. * **Connecting IP Verification** * Define precise allowed IPv4 and IPv6 CIDR blocks for the infrastructure (such as reverse proxies or content delivery networks) connecting directly to the Auth0 edge. * **Expanded Attribute Quotas** * The limit for Tenant ACL attributes has been increased from 10 to 20 per signal, giving you the additional flexibility needed to scale complex, multi-domain configurations seamlessly. ##### Resources To learn more about Tenant ACLs, click [here](https://auth0.com/docs/secure/tenant-access-control-list)

Fetched May 26, 2026