Zum Inhalt springen

Auth0 Release Notes

613 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Auth0, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Einstellung der Real-time Webtask Logs Extension

Die Real-time Webtask Logs Extension wird nach dem 16. September 2025 eingestellt und ist für Neuinstallationen nicht mehr verfügbar, als Ersatz dienen die Actions Real-time Logs im Auth0 Dashboard unter Monitoring > Actions Logs.

#### What is changing? We are deprecating the Real-time Webtask Logs extension with a planned end-of-life after (EOL) **September 16, 2025**. As a replacement, we have published the [Actions Real-time Logs](https://auth0.com/docs/customize/actions/actions-real-time-logs) feature integrated within the Auth0 Dashboard. The extension will cease to be available for new installations, but tenants with the extension already installed will maintain access until the planned EOL. #### Why are we making this change? The transition to the dashboard will improve the security posture and maintainability of the functionality, while simplifying future enhancements. #### How are you affected? For active users of the Real-time Webtask Logs extension, its scheduled removal will affect you, as the transition from extension to a direct dashboard capability inherently implies some user experience differences. #### What action do you need to take? You can start using the [Actions Real-time Logs](https://auth0.com/docs/customize/actions/actions-real-time-logs#how-to-use) feature by navigating to **Auth0 Dashboard** > **Monitoring** > **Actions Logs**. We recommend that extension users familiarize themselves with the new user interface to avoid disruption once the extension becomes unavailable.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Zugriff auf bestimmte Request-Properties in Actions wird entfernt

In Actions der Trigger post-login und credentials-exchange sind die Properties auth_session, authn_response, client_secret, client_assertion und refresh_token in event.request.query und event.request.body künftig undefined, wobei potenziell betroffene Tenants bis zum 16. September 2025 das bisherige Verhalten behalten.

#### What is changing? The service will restrict access to additional property names within the `event.request.query` and `event.request.body` objects when executing actions for the `post-login` and `credentials-exchange` triggers. Tenants identified as using actions that may reference request properties planned for restriction will maintain access until **September 16, 2025**. The service will restrict the following property names in the request-related objects: - `auth_session` - `authn_response` - `client_secret` - `client_assertion` - `refresh_token` Previously, the implementation of an action could access the properties listed above in `event.request.query` and `event.request.body` to retrieve the value included in the corresponding network request. Once the planned restrictions become effective for a given tenant, all properties above will be undefined independently of the network request content. The rollout of these additional restrictions is in progress for tenants where historical data did not show any actions using these property names. Tenants identified as potentially impacted by these restrictions will maintain existing behavior until the previously mentioned date. #### Why are we making this change? By restricting access to these properties, we aim to prevent potential mishandling of sensitive data within the custom code implemented for `post-login` and `credentials-exchange` actions. For example, we reduce the risk of uninte…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Kanadisches Französisch in Auth0 Dashboard und Docs

Dashboard und Dokumentation werden bei entsprechender Browser-Spracheinstellung automatisch auf Kanadisch-Französisch angezeigt, was sich über den Sprachwechsler oben rechts ändern lässt.

We’ve added a new language option-Canadian French-to help our users in Canada and beyond build secure identity solutions more easily. If your language preference is set to Canadian French in your browser settings, Auth0 will detect this and automatically serve the Dashboard and Documentation in Canadian French. You can manually override this setting in the Auth0 Dashboard and Docs via the language switcher in the top-right corner.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Private Cloud Restoration allgemein verfügbar

Kunden können bei Datenverlust oder -korruption die vollständige Wiederherstellung ihrer produktiven Private-Cloud-Umgebung aus einem Backup der letzten 14 Tage anfordern, zudem ist ein Restoration-Test pro Jahr in einer Nicht-Produktivumgebung möglich.

Auth0 is excited to announce the General Availability of Private Cloud Restoration resilience enhancement. This capability would come handy in the event of customer data loss or data corruption, and would assist customers in meeting regulatory requirements such as European Union’s Digital Operational Resilience Act (DORA). This capability allows customers to request full restoration of their production Private Cloud environment from an Auth0 backup in the last 14 days. It also includes the option for one restoration test per year on a non-production Private Cloud environment. Please refer to [Operational policies documentation](https://auth0.com/docs/troubleshoot/customer-support/operational-policies#private-cloud-restoration "Private Cloud Restoration") for more.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Brute-Force-Protection-Unblock-Seite über Universal Login anpassbar

Die Unblock-Seite der Brute-Force Protection lässt sich nun über Universal Login im eigenen Branding gestalten und entsperrt das Konto beim Laden der Seite statt beim Klick auf den Link, was Probleme mit E-Mail-Security-Scannern vermeidet.

You can now customize the __Brute-Force Protection unblock page__ using Universal Login. This update allows for a fully branded experience when users are locked out due to repeated failed login attempts. __What’s New?__ - __Branded unblock experience via Universal Login -__ The brute-force protection unblock page is now part of Universal Login, giving you full control over its appearance and content. This ensures a seamless, branded experience throughout the recovery flow. - __Improved compatibility with email security scanners -__ Account unblock now occurs when the unblock page loads rather than on clicking the unblock link. This helps prevent issues caused by email security scanners that pre-process links. __To enable these new features__ Navigate to __Settings__ > __Advanced__ tab In the __Migrations__ section, near the bottom of the page, disable the existing functionality with the toggle shown below ![Brute Force Deprecation Toggle](//images.ctfassets.net/kbkgmx9upatd/aq1x1nHXvy3b9nEcvNyGE/8b4e39918582a1f4250f42c2efe43618/DeprecationScreenShot.png) The existing __Brute-Force Protection unblock page and behavior__ will remain available for now. However, it is __planned for deprecation within the next 6 months__, giving you __ample time to transition__ to the __new and improved experience__ at your convenience. For more information about our __Brute-Force Protection__ feature, see our online documentation [here](http…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Offset-Pagination bei Connections Management API wird begrenzt

Ab dem 27. Oktober 2025 liefert die Offset-Pagination des Management-API-Endpoints zum Abrufen aller Connections keine Ergebnisse jenseits der ersten 1000 Connections mehr, darüber hinaus ist Checkpoint-basierte Pagination zu verwenden.

Starting October 27, 2025, the offset-based pagination available for the Management API [get all connections](https://auth0.com/docs/api/management/v2/connections/get-connections) endpoint will no longer support retrieving a paginated result beyond the first 1000 connections. Use checkpoint-based pagination to iterate beyond 1000 connections. Additional information about this upcoming change is available in a [dashboard and support center notification](https://support.auth0.com/notifications/68115c979be58b755a85b543).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Native Passkey Enrollment mit My Account

Mit der neuen Self-Service-API My Account können Anwendungen in Limited Early Availability das Hinzufügen von Passkeys zu Nutzerkonten per API vollständig selbst abwickeln.

We’re very excited to announce the Limited Early Availability of Native Passkey Enrollment, the first capability on our new self-service API, My Account. Using My Account, customers can build self-service management experiences at scale, powered directly from their applications. Native Passkey Enrollment enables users to add a passkey to their account using APIs; applications can fully manage user onboarding of passkeys. This feature is the first of many capabilities being added to My Account. To learn more and request access to the feature, contact your Auth0 account manager.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Verbesserte Bot-Erkennung bei Signups

Ein neues Modell zur Bot-Erkennung bei Signups unterscheidet legitime Nutzer genauer von automatisierter Schadaktivität und steht Enterprise-Kunden mit dem Attack-Protection-Add-on in den kommenden Wochen schrittweise zur Verfügung.

We're excited to announce a significant upgrade to our bot **detection capabilities for signups**, delivering superior accuracy and staying ahead of evolving traffic patterns. This latest model further improves our ability to distinguish legitimate new users from automated malicious activity. The result is a substantial reduction in unwanted signups, enhancing your user onboarding experience and overall platform security. By enhancing our model training and deployment system, we can now accelerate model improvements, increase deployment frequency, and reduce detection latency, ensuring you always have the most advanced protection. This enhanced security feature is available now to all **Enterprise customers with the Attack Protection add-on**. The rollout is currently underway and will be completed in the coming weeks, aligned with individual customer release schedules. For activation details or to learn more about safeguarding your systems, please refer to our [documentation](https://auth0.com/docs/secure/attack-protection/bot-detection) or reach out to your account team. We are committed to supporting you in protecting your digital presence against evolving threats.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Native to Web SSO im Early Access

Native to Web SSO ermöglicht im Early Access das Teilen von Sessions zwischen nativen iOS-/Android-Apps und Web-Apps über Session Transfer Tokens, inklusive Device Binding per IP oder ASN und Unterstützung in Actions, CLI, Terraform und SDKs.

We’re excited to announce the Early Access release of Native to Web SSO — a new capability that enables session sharing between native mobile apps and web apps using a secure, standards-based approach. This helps create a seamless user experience where authentication in one platform (native or web) carries over to the other, without requiring a separate login. With this release, developers can: - Implement SSO from native iOS or Android apps to browser-based web apps. - Securely issue and consume Session Transfer Tokens. - Leverage device binding enforcement (IP or ASN) for additional security. - Access Session Transfer Token support in Auth0 Actions. - Use the feature across the Auth0 CLI SDK, Terraform Provider, Deploy CLI, and native mobile SDKs (iOS and Android). - Integrate with WS-FED and SAML clients, and invoke Post Login Actions during token consumption. 📘 To get started: [Read our documentation](https://auth0.com/docs/authenticate/single-sign-on/native-to-web) [Read the Quickstart](https://auth0.com/docs/authenticate/single-sign-on/native-to-web/configure-mobile-to-web-payment-flows)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Actions lassen sich im Dashboard umbenennen

Im Auth0 Dashboard können bestehende Actions nun auf der Detailseite umbenannt werden, wobei eindeutige Namen sichergestellt bleiben.

Action name editing is now available within the Auth0 Dashboard, providing developers the ability to rename existing Actions while ensuring unique names are maintained. To rename an Action: 1. Navigate to the specific Action Details page in the Auth0 Dashboard. 2. At the Action Details page, click the edit button located next to the Action's name to make your changes. 3. Enter the new name. 4. Apply or cancel the changes.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Fine-Grained M2M Token Quotas im Early Access

Enterprise-Kunden können im Early Access stündliche und tägliche Limits für M2M-Access-Tokens pro Application und Organization festlegen, wobei bei erreichtem Limit 429-Antworten erfolgen und die Nutzung über Tenant-Logs und HTTP-Header überwacht werden kann.

We’ve excited to announce that Fine-Grained M2M Token Quotas is now in __Early Access for Enterprise customers__. This feature allows __setting hourly and daily limits on M2M access tokens at the Application and Organization level__. __When a quota is reached, affected Applications receive 429 responses until the quota resets__. Customers can also enable or disable quotas in real time and monitor usage via tenant logs and HTTP headers. ![M2M token quota error](//images.ctfassets.net/kbkgmx9upatd/4WFjgTHnAXtwxaw6FvVtUk/d79cad77dc6eed76196a5ff4c20c81e4/Screenshot_2025-05-29_at_11.11.41.png) This gives customers granular control over token issuance, helping __prevent excessive consumption — especially important when APIs are exposed to Third-Party Apps__ or internal teams outside their direct control. It addresses common issues like missing token caching, which can lead to uncontrolled token usage, unexpected costs and imbalanced usage across Organizations. To learn more, check out the [documentation](https://auth0.com/docs/fine-grained-m2m-token-quotas-early-access). __Reach out to you Auth0 contact to request access!__

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

ACUL Early Access: WebAuthn, Biometrie und Logout

Advanced Customizations for Universal Login unterstützt im Early Access nun eigene Versionen der Screens für WebAuthn und Biometrie, Logout, MFA Recovery Code, Email Verification und Reset-Password-Challenges über das ACUL SDK und aktualisierte Tools.

We are excited to announce the next Early Access release of Advanced Customizations for Universal Login! This release adds support for building custom versions of Universal Login’s WebAuthn + Biometrics authentication and the matching MFA and Reset Password Challenge screens, as well as Logout and a few other odds and ends, all using the new ACUL SDK. Advanced Customizations for Universal Login enables you to build custom, client-rendered interfaces for Universal Login screens, allowing you to control every pixel of your Universal Login experience. This release allows you to building custom versions of the following screens: - MFA WebAuthn Change Key Nickname - MFA WebAuthn Enrollment Success - MFA WebAuthn Error - MFA WebAuthn Platform Challenge - MFA WebAuthn Platform Enrollment - MFA WebAuthn Roaming Challenge - MFA WebAuthn Roaming Enrollment - Reset Password MFA WebAuthn Platform Challenge - Reset Password MFA WebAuthn Roaming Challenge - Logout - Logout Aborted - Logout Complete - MFA Recovery Code Challenge New Code - Email Verification Result - Login Email Verification #### DX Updates The latest versions of the ACUL SDK and our CDT tooling all include support for these new screens. - [Typescript SDK](https://github.com/auth0/universal-login/releases/tag/auth0-acul-js%400.1.0-beta.5) - [Auth0 CLI](https://github.com/auth0/auth0-cli/releases/tag/v1.14.1) - [Deploy CLI](https://github.com/auth0/auth0-deploy-cli/releases/tag/v8.8.3) - [Terraform Provider Auth0](ht…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

CIBA-Flow jetzt allgemein verfügbar

Der Client-Initiated Backchannel Authentication (CIBA) Flow für asynchrone Authentifizierung und Autorisierung über zwei Geräte ist für Enterprise-Kunden nun Generally Available und unterstützt Rich Authorization Requests (RFC9396).

Asynchronous authentication and authorisation using the Client-Initiated Backchannel Authentication (CIBA) flow is now Generally Available for our Enterprise plan customers. The CIBA flow works as an asynchronous, decoupled flow across two different devices: - Consumption device: initiates the authentication request. - Authentication device: handles end-user authentication, implemented as a custom mobile app which embeds the Guardian mobile SDK. The flow supports the use of Rich Authorization Requests [RFC9396](https://www.rfc-editor.org/rfc/rfc9396.html) to provide contextual information to authenticating and/or authorizing users. This enables the CIBA flow to support a number of powerful use cases driven by backend client applications, such as: - Customer authentication by headless devices or devices/applications with limited interaction capabilities. - Customer authentication in call-centre scenarios. - Authorising sensitive operations on behalf of yourself or a third-party e.g. a customer service Agent, an autonomous AI Agent. For more details, see the [product documentation](https://auth0.com/docs/get-started/authentication-and-authorization-flow/client-initiated-backchannel-authentication-flow).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Tenant-Member-Rollen in Auth0 Teams bearbeiten

Team-Owner können im Auth0 Teams Dashboard nun alle CRUD-Aufgaben für Tenant-Mitglieder zentral erledigen, sofern das Feature Tenant Member Management aktiv ist.

We're excited to announce a significant enhancement to the Tenant Member Management feature within Auth0 Teams. All tenant member management tasks can now be completed centrally within the Auth0 Teams Dashboard. Previously, we introduced tenant member management with support for inviting and assigning dashboard users to team tenants, followed by the ability to remove access from tenants directly within the Teams dashboard. With this release, a team owner gains the comprehensive ability to perform all Create, Read, Update, and Delete (CRUD) tasks on tenant members directly from the Teams Dashboard. This streamlines administrative workflows and provides unparalleled control over user access across your tenants. Note: The Tenant Member Management feature is required for this functionality. This feature is on by default for all Self-Service customers and most Public Cloud Enterprise customers. It is configurable for some existing Public Cloud Enterprise customers and is coming soon to Private Cloud customers. Please refer to the following documentation for more information. 1. [How do you edit a Tenant Member role from Auth0 Teams Dashboard?](https://auth0.com/docs/get-started/auth0-teams/tenant-member-management#edit-tenants-membership-with-tenant-member-management "Edit Tenant Member access.") 2. [I am a Public Cloud Customer; how do I verify that I have the suitable feature turned on to support tenant member management?](https://auth0.com/docs/get-started/auth0-teams/tenan…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Event Streams für Auth0 im Early Access

Event Streams sind im Early Access verfügbar und melden abgeschlossene Änderungen an Users und Organizations über Webhook oder Amazon EventBridge, einrichtbar im Dashboard oder per Management API.

Event Streams is now available for all customers who desire to discover completed changes to Auth0 Users and Organizations as they happen. They can do this by: - Creating an Event Stream in the Manage Dashboard or the Management API - Configuring the Event Streams with the desired destination ([Webhook](https://auth0.com/docs/customize/events/create-an-event-stream#create-an-event-stream-webhooks- "Create a Webhook") or [Amazon EventBridge](https://auth0.com/docs/customize/events/create-an-event-stream#aws-eventbridge "Create an Event Stream via Eventbridge")) and selecting the events to receive See the [Auth0 Docs](https://auth0.com/docs/customize/events) for further instructions.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Passwort bei SMTP-Provider-Änderungen erforderlich

Beim Ändern bestimmter Konfigurationsfelder des SMTP Email Providers eines Tenants muss künftig gleichzeitig das SMTP-Passwort angegeben werden, Details und Zeitplan stehen in einer Benachrichtigung im Support Center.

Updating specific configuration fields for a tenant's SMTP Email Provider may require simultaneously specifying the password field used for SMTP client authentication. We have provided additional information and timelines for enforcing this change across tenants through a dashboard and [support center notification](https://support.auth0.com/notifications/68236562d0bbf8eb81861392).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Sprachauswahl für Endnutzer im Universal Login

Endnutzer können im Universal Login eine andere Sprache wählen, wenn die automatisch per ui_locales oder Browser-Header gewählte nicht passt, und die Darstellung lässt sich über Custom Prompts mit eigenem HTML anpassen.

Enable end users to choose a different language if the automatically selected language based on `ui_locales` or the browser language header is not preferred. By leveraging Auth0 Custom Prompts you can use your own HTML to customize the look and feel for how end-users perform the language selection on Universal Login. [Learn more](https://auth0.com/docs/customize/login-pages/universal-login/customize-signup-and-login-prompts/language-selection)!\[Language Selection on Universal Login](//images.ctfassets.net/kbkgmx9upatd/XQRrvqf3JIB247VTSTXF7/65f189e104e8018be47badb0145ab862/LanguageSelection.png)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Verbesserungen an der Auth0 CLI

Die neue Auth0-CLI-Version bringt einen verbesserten Universal-Login-Anpassungsablauf, das Blockieren und Entsperren von Nutzern, bessere Log- und Nutzerverwaltung, einfachere Tenant-Einstellungen und einen test-login-Befehl mit Organizations-Unterstützung.

We're excited to announce the latest release of the Auth0 CLI! This update brings a host of improvements designed to streamline your development workflow, enhance security capabilities, and provide a more intuitive user experience. ### Key Highlights: - __Improved Universal Login Customization Flow__: Customizing your Universal Login pages is now more straightforward and efficient. We've refined the command-line interface to provide a smoother experience when managing templates and branding, allowing for quicker iterations and deployments. - __Support for Blocking User Authentication__: Enhance your security posture with the new ability to directly block (and unblock) user authentication via the CLI. This feature provides a quick and effective way to manage access for suspicious or compromised accounts. - __Enhanced Logs and User Management Experience:__ We've significantly improved the experience for viewing and managing your Auth0 logs and users. Expect more intuitive commands, better filtering options, and clearer outputs, making it easier to find the information you need and perform administrative tasks. - __Better Tenant Settings Management:__ Managing your tenant settings is now more accessible and user-friendly. The CLI offers improved commands for viewing and updating various tenant configurations, simplifying your operational overhead. - __Extended test login Command to Support Organizations:__ Testing your login flow with Organizations is now eas…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Anpassbarer Benachrichtigungstext im iOS Guardian SDK

Apps mit dem Guardian SDK auf iOS können den Text ihrer Push-Benachrichtigungen jetzt vollständig anpassen.

Introducing the customizable notification text for IOS Guardian SDK. With this update, apps using the Guardian SDK on iOS can now fully customize the text of their push notifications—giving you greater control over your user experience and messaging.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Sign in with Google für Android-Apps

Entwickler können Nutzer in nativen Android-Apps über den Android Credential Manager mit Sign in with Google anmelden, ohne Passwortabfrage und unter Wiederverwendung der bestehenden Google-Session.

Auth0 Developers can now easily and securely authenticate users on native applications by using the Android Credential Manager’s Sign in with Google. This enables a secure and streamlined experience for end-users to login without being prompted for a password and by re-using their existing Google session on the device. [Learn more](https://auth0.com/docs/authenticate/identity-providers/social-identity-providers/google-native) ![Native Sign in with Google](//images.ctfassets.net/kbkgmx9upatd/2kRfgCc6743tlYfdNMzqMo/f03da5e2194e2b1a317014bbe4d80458/NativeSigninWithGoogle.gif)

Originalquelle(öffnet in neuem Tab)Problem melden