Zum Inhalt springen

Auth0 Release Notes

613 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Auth0, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Node 22 für Actions und weitere Neuerungen

Node.js 22 ist als Runtime für Extensibility-Integrationen allgemein verfügbar und neue Actions nutzen es standardmäßig, außerdem lässt sich die Runtime für Legacy Extensibility und allgemeine Extensibility nun getrennt einstellen.

Node.js 22 is now generally available (GA) as a runtime for your extensibility integrations (such as Actions, Rules, Hooks, Custom Database Connections etc). New Actions created will now default to Node 22 as the runtime. As part of this release, we have also split runtime selection for Legacy Extensibility (for Rules & Hooks) separate from the general Extensibility (for Custom Database Scripts & Custom Social Connections). These setting are available within [Tenant > Settings > Advanced](https://manage.auth0.com/#/tenant/advanced) and allows you to individually manage desired runtime configuration as required. ![Extensibility Runtime](//images.ctfassets.net/kbkgmx9upatd/64aCyAYo4gSPYJmQ9pM3o0/c6952971e36570f1552b91283bb976c0/Screenshot_2025-01-10_at_12.32.07_PM.png) Please [refer to our docs](https://auth0.com/docs/troubleshoot/product-lifecycle/deprecations-and-migrations/migrate-nodejs-22) for more details on how to migrate to Node 22.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

CIBA-Flow im Early Access verfügbar

Der Client-Initiated Backchannel Authentication (CIBA) Flow ist im Early Access verfügbar und ermöglicht entkoppelte Authentifizierung über zwei Geräte, etwa für Callcenter oder Geräte mit eingeschränkter Interaktion.

We are delighted to announce that support for the Client-Initiated Backchannel Authentication (CIBA) flow is now available in Early Access. The CIBA flow works as a *decoupled authentication flow* across two different devices: - Consumption device: initiates the authentication request. - Authentication device: handles end-user authentication, implemented as a custom mobile app which embeds the Guardian mobile SDK. The CIBA flow supports a number of powerful use cases driven by backend client applications, such as: - Customer authentication by headless devices or devices with limited interaction capabilities. - Customer authentication in call centre scenarios. - Authorising sensitive operations on behalf of yourself or a third-party e.g. a customer service agent. To evaluate CIBA for securing your sensitive customer interactions, contact your Technical Account Manager. For more details, check out our [product documentation](https://auth0.com/docs/get-started/authentication-and-authorization-flow/client-initiated-backchannel-authentication-flow).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Organization ID in „srrt“-Logs

Die Auth0 Tenant Logs enthalten beim Event „Successfully revoked a refresh token (srrt)“ jetzt die Organization ID.

We’ve added the **Organization ID** to the [Auth0 Tenant Logs](https://auth0.com/docs/deploy-monitor/logs/log-event-type-codes) for the **Successfully revoked a refresh token (srrt)** event. This enhancement allows you to correlate the organization associated with the revoked refresh token for improved tracking and auditing.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Maximale Länge von Actions-Secrets erhöht

Die maximale Länge von Secret-Werten in Actions wurde von 2048 auf 4096 Zeichen erhöht.

We have increased the max secret value length from 2048 to 4096 to allow for larger secrets to be stored within Actions. ![Actions Secrets](//images.ctfassets.net/kbkgmx9upatd/52TGNtKI3IvOndGaRrRZeE/8798f00f8f923d287cfcadd854e6f632/Screenshot_2024-12-20_at_12.09.07_PM.png) You can [refer to our docs](https://auth0.com/docs/customize/actions/limitations) for further details on Actions limitations.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Neue Hochleistungsstufe für Private Cloud auf AWS

Für das Auth0 Private Cloud Performance Angebot auf AWS gibt es eine neue 10.000-RPS-Stufe (100x) zusätzlich zu den bestehenden 30x- und 60x-Stufen.

We're excited to introduce the new 10,000 RPS (100x) tier for Auth0 Private Cloud Performance offering on AWS. This enhanced tier supports a higher volume of authentication requests, complementing the existing 30x and 60x tiers for customers who need high performance thresholds. Please see [Private Cloud documentation](https://auth0.com/docs/deploy-monitor/deploy-private-cloud/private-cloud-on-aws) to learn more.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Bot-Detection-ML-Modell für Classic und Custom Login

Das ML-Modell zur Erkennung von Signup-Angriffen steht jetzt auch für Classic Login und Custom Login zur Verfügung, ist für Enterprise-Kunden mit Attack-Protection-Add-on gedacht und wird in den kommenden Wochen ausgerollt.

The new Bot Detection ML model designed to detect signup attacks is now available for Classic Login and Custom Login implementations. For customers using Classic or Custom login experiences, this enhancement leverages advanced machine learning to identify and block automated signup attacks effectively. For those using New Universal Login, no configuration changes are required. This feature was rolled out for New Universal Login in September, as highlighted in the changelog [here](https://auth0.com/changelog#7o1YXe52Gl7jEYENzFikEn). Below is the demo showcasing how to enable this feature in Auth0 for Classic and Custom Login experiences. ![](https://cdn.auth0.com/blog/bot\_detection\_signup\_classic.gif) This enhanced security capability is now available to all Enterprise customers with the Attack Protection add-on. The rollout is underway and will be completed in the coming weeks, aligned with individual customer release schedules. For details on activation or to learn more, visit our [documentation](https://auth0.com/docs/secure/attack-protection/bot-detection) or reach out to your account team. We’re here to support you in protecting your systems against evolving threats.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Private-Cloud-Wiederherstellung im Early Access

Ausgewählte Private-Cloud-Kunden können im Early Access die Wiederherstellung ihres Produktions-Space aus einem Backup der letzten 14 Tage anfordern, was bei Datenverlust oder -korruption und bei regulatorischen Anforderungen wie DORA helfen soll.

Auth0 is pleased to announce the Early Access (EA) of enhanced support for customer data recovery. This resilience feature is available to a set of Private cloud customers during EA. It would come handy in the event of customer data loss or data corruption, and would assist customers in meeting regulatory requirements such as European Union’s Digital Operational Resilience Act (DORA). Customer will be able to request restoration of their production Private Cloud space from a backup within the past 14 days. Please refer to [Operational policies](https://auth0.com/docs/troubleshoot/customer-support/operational-policies) documentation for details.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Security Center Alerts for Thresholds (Early Access)

Enterprise-Kunden können im Security Center per Webhook benachrichtigt werden, wenn eine Bedrohungsmetrik ihren festgelegten Schwellenwert überschreitet.

Introducing a new capability within the Security Center Dashboard offering - __Security Center Alerts for Thresholds__ Early Access. This new feature expands on the Security Center metrics and Thresholds to allow Enterprise customers to not only monitor their tenant security but also receive notifications when a threat metric exceeds their predefined thresholds. Customers can now configure __webhook alert notifications__ on security threat metrics and monitor when threats exceed the acceptable value. To learn more Alerts for Thresholds, click [here](https://auth0.com/docs/secure/security-center/security-alerts)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Neu gestaltete anpassbare E-Mail-Vorlagen

Alle Customizable Email Templates wurden optisch modernisiert und sind live, ohne dass Text oder Inhalt geändert wurden und ohne Auswirkung auf bereits angepasste Vorlagen.

We’re excited to announce that all __Customizable Email Templates__ have been styled with a modern look and feel and are now __live__! No verbiage or content has been changed on any of the emails and customers that have customized the email templates are unaffected. ![email-changelog (1)](//images.ctfassets.net/kbkgmx9upatd/yf5zzwtlmroz8fJnwLjJ8/86ee375e78af87f9f8396c3a761ce23e/email-changelog__1_.png)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Auth0 Teams: SSO-Verbindungen hinzufügen (Beta)

Team-Owner können in der Beta ihren IdP selbst anbinden, um SSO für Dashboard-Administratoren einzurichten, vorerst nur für Public-Cloud-Enterprise-Kunden.

Single Sign On (SSO) allows one set of credentials to access multiple resources through a centralized identity provider (IdP). Auth0 Teams security policies allows team owners to configure and implement authentication rules that adhere to their organization's IT security policies for access to infrastructure systems or applications. Announcing in beta the ability for team owners to self-configure and connect their IdP to provide SSO for dashboard administrators. ![Teams SSO Add connection](//images.ctfassets.net/kbkgmx9upatd/3PuPyW9iDKrkP3SLUwLtoD/abba1c539a82e21f6c816181a7f5b7b5/Teams_SSO_Connection.png) Auth0 Teams Self-Service SSO beta is currently limited to Public Cloud Enterprise customers. Interested in the BETA? Reach out to your Technical Account Manager to enrol in our beta program.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Auth0 Dashboard Session Management allgemein verfügbar

Dashboard-Admins können aktive Dashboard-Sitzungen einsehen und widerrufen, für Public- und Private-Cloud-Kunden.

Announcing General Availability of Auth0 Dashboard Login Session Management. A feature that allows Auth0 Dashboard admins to view and revoke active dashboard sessions for an added layer of security to the session idle timeout for both our Public and Private Cloud customers. ![Login Sessions GA](//images.ctfassets.net/kbkgmx9upatd/4tUA2Mrw5apASWkV0tie9X/decdfc0e939b6bb95b7a4a7d84824379/Login_Sessions.png) Click [here](https://auth0.com/docs/get-started/dashboard-profile/auth0-dashboard-login-session-management) to learn more about Auth0 Dashboard Login Session Management.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Mehr Metadata-Slots für Organizations

Die Zahl der Metadata-Slots für Organizations wurde von 10 auf 25 erhöht.

We’re excited to announce that we’ve __increased the number of metadata slots for Organizations from 10 to 25__! This enhancement provides you with more flexibility to store and manage additional data within your organization, enabling a more customized and efficient approach to your workflows. To learn more about Organizations, click [here](https://auth0.com/docs/manage-users/organizations).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Customer Managed Keys allgemein verfügbar

Customer Managed Keys ist nun allgemein verfügbar und bietet mit Control Your Own Key und Bring Your Own Key zwei Optionen zur Schlüsselverwaltung für die Einhaltung kryptografischer Sicherheitsrichtlinien.

We are delighted to announce that Customer Managed Keys is now generally available. This solution within the Highly Regulated Identity solution suite enables organizations to comply with cryptographic key-related security policies for data protection. Customer Managed Keys provides customers with two options for key management: Control Your Own Key and Bring Your Own Key. With Control Your Own Key, you can manage the lifecycle of the Tenant Master Key according to your security policy. Bring Your Own Key allows you to maintain ownership of the Root Key that protects the encryption key hierarchy. These features enable compliance with cryptographic key-related security policies for data protection. ![](https://cdn.auth0.com/blog/cmk\_byok.gif) You can read more about this in our [product documentation](https://auth0.com/docs/secure/highly-regulated-identity/customer-managed-keys).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Neuer Batch-Check-Endpunkt für Okta FGA

Die Okta FGA API enthält einen neuen Batch-Check-Endpunkt, der mehrere Autorisierungsprüfungen in einer Anfrage bündelt und so die Netzwerklatenz verringert.

We’ve introduced a new Batch Check endpoint to the Okta FGA API, allowing clients to batch multiple authorization checks into a single request. This enhancement reduces the network latency associated with previously needing to performing multiple Check API requests in parallel, resulting in faster and more efficient requests for applications with high authorization demands. For more details, refer to the [Okta FGA Batch Check documentation](https://docs.fga.dev/integration/perform-check#03-calling-batch-check-api).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Neuer API-Befehl im Password Reset / PostChallenge Trigger

Im Password-Reset/PostChallenge-Trigger lässt sich per api.transaction.setResultUrl festlegen, auf welche URL Nutzer nach einem Passwort-Reset in Universal Login weitergeleitet werden.

We added a new API command available in the Password Reset / PostChallenge trigger. This API allows Tenant Developers to specify the url to redirect a user to upon the completion of a password reset on Universal Login. Here is an example of using the command to redirect the user to a sample url after a successful password reset: exports.onExecutePostChallenge = async (event, api) => { api.transaction.setResultUrl('https://yourapp.yourdomain.com/profile'); }; You can learn more in our [reference documentation.](https://auth0.com/docs/customize/actions/explore-triggers/password-reset-triggers/post-challenge-trigger/post-challenge-api-object)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Bot Detection mit zusätzlichen Tenant-Level-Signalen

Die Bot Detection der vierten Generation nutzt zusätzliche aggregierte Tenant-Signale und ist für Enterprise-Kunden mit Attack-Protection-Add-on im Rollout, der in den kommenden Wochen abgeschlossen wird.

We’re thrilled to announce that our fourth-generation Bot Detection has been upgraded to incorporate additional aggregated tenant-level insights. This upgrade strengthens bot detection across both public and private cloud environments, providing a more precise and robust defense against malicious activity while ensuring a seamless and secure experience for all users. This enhanced security capability is now available to all Enterprise customers with the Attack Protection add-on. The rollout is currently underway and will be completed in the coming weeks, aligned with individual customer release schedules. For details on activation or to learn more, please refer to our [documentation](https://auth0.com/docs/secure/attack-protection/bot-detection) or reach out to your account team. We are here to support you in protecting your systems against evolving threats.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Self-Service SSO allgemein verfügbar

Self-Service SSO ist allgemein verfügbar und erlaubt Geschäftskunden, ihr Single Sign-On selbst zu konfigurieren, für B2B Professional, Enterprise und Enterprise Premium.

Auth0 is excited to announce that __Self-Service SSO__ is now in __General Availability__. Our Self-Service SSO feature is designed to simplify and streamline the administrative tasks that are essential for every B2B SaaS product. By equipping your business customers to configure their own Single Sign-On setups, we provide them with a seamless, intuitive experience—eliminating the need for complex IT involvement. This flexibility not only enhances security but also improves the overall user experience, giving businesses more control and agility while reducing overhead. ![Self-Service SSO](//images.ctfassets.net/kbkgmx9upatd/1EJbNDGVayUGTvQ6ZAzmn3/5d703e2229d46a7ae70e5ce440961ee3/Self-Service_SSO_GA.gif) This feature is available for B2B Professional, Enterprise and Enterprise Premium customers. [Click](https://auth0.com/docs/authenticate/enterprise-connections/self-service-SSO) here to learn more.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Beta von nextjs-auth0 SDK v4

Die Beta von nextjs-auth0 SDK v4 bringt unter anderem Middleware-basierte Authentifizierung, verschlüsselte Cookies, Rolling Sessions und Unterstützung für Next.js 15, während v3 nicht für Next.js 15 aktualisiert wird und nach dem GA von v4 noch 6 Monate Sicherheitsupdates erhält.

Hello everyone, We're thrilled to announce the beta release of nextjs-auth0 SDK v4! This new version brings significant improvements, new features, and fixes to enhance your development experience. ### Important Notice About v3 As we move forward, **we will not be updating v3 of the SDK to support Next.js 15**. This allows us to focus on v4, which offers a wealth of new features and improvements. This will also enable us to support future releases of Next.js faster and with more confidence. We understand this may pose challenges, and we're here to help. v3 will continue to receive critical security updates for 6 months after the GA of v4. ### Highlights of v4 Beta - Middleware-Based Authentication: Improved compatibility and reduced maintenance by moving to middleware-based handlers. - Enhanced Security: Switched to encrypted cookies and removed outdated cookie logic. - Resolved State Mismatch Issues: Fixed long-standing issues reported by the community. - Improved Session Management: Implemented rolling sessions and eliminated cookie chunking. - Improved Hooks and Helpers: Introduced useUser(), getAccessToken(), and getSession() for easier data fetching and session handling. - Stateful Sessions with Custom Databases: Support for "Bring Your Own Database" (BYODB). - Compatibility with Next.js 15, Turbopack, and React 19 - Simplified architecture, API, and configuration options ### Try It Out and Provide Feedback We invite you to explore the beta release and share your fee…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Rules und Hooks in Public Cloud jetzt schreibgeschützt

Rules und Hooks sind in allen Public-Cloud-Umgebungen schreibgeschützt, sodass ihre Skripte nicht mehr bearbeitet werden können, während Deaktivieren, Löschen, Reaktivieren und Secrets-Änderungen weiter möglich sind und eine Migration zu Actions empfohlen wird.

We have transitioned the Rules and Hooks features to a read-only mode in all public cloud environments as part of their [announced deprecation](https://auth0.com/docs/troubleshoot/product-lifecycle/deprecations-and-migrations#rules-and-hooks-deprecations) plan. You can still disable, delete or re-enable an existing Rule or Hook. You can also add or remove Rules settings (for updating stored secrets) or Hook secrets but you will no longer be able to modify their script. If this impacts you, our recommendation is to migrate to Actions. Refer to the following docs for more details: - [Migrate Rules to Actions](https://auth0.com/docs/customize/actions/migrate/migrate-from-rules-to-actions) - [Migrate Hooks to Actions](https://auth0.com/docs/customize/actions/migrate/migrate-from-hooks-to-actions)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Bot Detection mit User-Agent-Signalen erweitert

Die Bot Detection der vierten Generation nutzt nun User-Agent-Signale in ihrem Machine-Learning-Modell, verfügbar für Enterprise-Kunden mit Attack-Protection-Add-on, und wird in den nächsten Wochen ausgerollt.

We are excited to announce that our fourth-generation Bot Detection has been upgraded with user-agent signals, and is now integrated into our proprietary machine learning model. This enhancement improves our capability to detect and thwart bot activity, further strengthening protection against malicious traffic without adding any additional friction for legitimate users. This security feature is available to all Enterprise customers with the Attack Protection add-on. We are currently rolling out this enhancement and expect to complete the process within the next few weeks, aligned with your individual release schedules. For activation details or further information, please check our [documentation](https://auth0.com/docs/secure/attack-protection/bot-detection) or reach out to your account team. We’re here to support you in safeguarding your systems against evolving threats. Thank you for trusting us with your security needs.

Originalquelle(öffnet in neuem Tab)Problem melden