Zum Inhalt springen

Auth0 Release Notes

613 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Auth0: M2M-Unterstützung für Third-Party-Anwendungen allgemein verfügbar

Strict Third-Party-Anwendungen unterstützen nun M2M-Zugriff über den client_credentials-Grant, auch organisationsbezogen, jedoch nur für manuell per Management API oder Dashboard angelegte Anwendungen und nicht für solche aus Dynamic Client Registration.

We're happy to announce that `strict` third-party applications now support machine-to-machine (M2M) access using the `client_credentials` grant type. As you expose your APIs to AI agents and partner backend services that operate without a user in the loop, you need those integrations to work within the same secure-by-default posture as the rest of your third-party application setup. This release makes that possible. ![M2M-third-party-app](https://cdn.auth0.com/blog/M2M-third-party-app.png) __What's included__: - `client_credentials` grant type support for `strict` third-party applications, available via the Management API and Dashboard. - Organization-scoped M2M access: `strict` third-party applications can request access tokens within the scope of a specific organization, with the same explicit grant requirements that apply to all M2M applications. Learn more about [M2M access for organizations](https://auth0.com/docs/manage-users/organizations/organizations-for-m2m-applications). - M2M access is intentionally restricted to applications created manually via the Management API or Dashboard. Applications registered via Dynamic Client Registration are excluded to prevent uncontrolled token issuance by unvetted third parties. To learn more, visit the [Third-Party Applications documentation](https://auth0.com/docs/get-started/applications/third-party-applications).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Auth0: Dashboard-Navigation und IA-Refresh in der Beta

Die neu gestaltete Dashboard-Navigation mit flacherer Struktur, zusammengeführten und umbenannten Seiten, externen Aktionen in der oberen Leiste und überarbeiteter Optik ist als Beta auf Anfrage verfügbar, während Funktionen und APIs unverändert bleiben.

We are excited to announce that the redesigned __Dashboard navigation and information architecture (IA)__ is now available in Beta. This update is the first step toward a more unified platform experience across Auth0, making it faster to find what you need and easier to act on everything across the platform. Alongside the IA changes, this beta also includes a significant visual refresh. ## What's in the Beta ### Flattened navigation - __Label-only group headers__ so every item is visible at a glance, reducing clicks and making pages faster to reach. - __Reorganized around common tasks__ to surface the pages you use most and match the way you actually work. - __External actions__ have moved out of the sidebar and into the top bar, keeping the sidebar focused on tenant configuration. ### Consolidated & renamed pages - __Related functionality grouped together__ to bring common tasks closer together. - __Clearer naming__ to better align functionality across the platform. ### Availability - Existing bookmarks and deep links will continue to work and you'll be automatically redirected to the new page. - This is a navigation, IA, and visual update only. All underlying functionality and APIs remain the same. ## Join the beta! If you're interested in joining the Dashboard Navigation & IA Refresh beta program, please send a request through the [Auth0 Support Center](https://support.auth0.com) or contact your Technical Account Manager (TAM) or Auth0 Sales Execu…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Auth0: Dashboard-Suche für Anwendungen in der Beta

Im Dashboard lassen sich Anwendungen in der Public Beta in Echtzeit nach Name, Client-ID, Metadaten, Typ und weiteren Kriterien mit bis zu 5 kombinierbaren Filtern suchen, wobei Filter in der URL erhalten bleiben.

We're excited to announce that __Dashboard Search for Applications__ is now available in Public Beta! Find your applications faster without scrolling through paginated lists. __What's New:__ Dashboard users can now __search and filter applications__ in real time by application name, client ID, external client ID, metadata, application type, and first-party status. - __Multiple filter options__ — Combine up to 5 filters - __Guided filter menu__ with Boolean search logic - __Filters persist in URLs__ for sharing and bookmarking Rolling out progressively to Public Cloud tenants starting this week, with broader availability in the coming weeks. For detailed documentation on search capabilities, visit our [Product documentation](https://www.auth0.com/docs/get-started/auth0-overview/dashboard/search-and-filter-auth0-dashboard).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Auth0: Anpassbare RP-ID für Passkeys allgemein verfügbar

Die RP ID für Passkeys lässt sich nun anpassen, sodass ein einzelner Passkey Nutzer über mehrere Anwendungen unter derselben Root-Domain authentifizieren kann.

Boost Passkey adoption by enabling shared enrollment across subdomains. You can now customize the RP ID to allow a single Passkey to authenticate users across multiple applications under the same root domain. Now GA! Learn more: [Enable and Configure Passkey Authentication for Database Connections](https://auth0.com/docs/authenticate/database-connections/passkeys/configure-passkey-policy) [Native Passkeys for Mobile Applications](https://auth0.com/docs/authenticate/database-connections/passkeys/native-passkeys-for-mobile-applications) [Passkey Authentication for Database Connections](https://auth0.com/docs/authenticate/database-connections/passkeys) -

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Auth0 Teams: Neue Rolle Tenant Manager zur Delegation der Tenant-Verwaltung

Die neue Rolle Tenant Manager erlaubt es, Tenant-Mitglieder ohne Team Owner einzuladen, zu aktualisieren und zu entfernen, wobei sensible Einstellungen wie Connections und Security-Logs Team Ownern vorbehalten bleiben und alle Aktionen in den Team-Activity-Logs erfasst werden.

You can now delegate tenant-level user management with the **Tenant Manager** role. This allows you to offload day-to-day administrative tasks from Team Owners to dedicated managers, providing the autonomy they need without exposing sensitive configuration settings. **Key capabilities:** * **Independent administration:** Directly invite, update, and revoke tenant members without escalating to Team Owners. * **Scoped permissions:** Access is limited strictly to assigned tenants; sensitive configurations—such as connections and security logs—remain restricted to Team Owners. * **Audit trails:** All management actions are captured in Team Activity logs for full compliance and visibility. **Use cases:** * **Regional autonomy:** Empower regional leads to manage their own tenant members without granting visibility into other regional or global tenants. * **Separation of duties:** Delegate administrative tasks to specific departments while centralizing control of critical security settings at the account level. [Learn more about Teams Roles and Responsibilities](https://auth0.com/docs/get-started/auth0-teams/team-member-management#team-membership-role-comparison).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Auth0: Token Vault mit Organization-Unterstützung allgemein verfügbar

Token Vault und der Connected-Accounts-Flow berücksichtigen nun durchgängig org_id, sodass Drittanbieter-Tokens pro Benutzer und Organisation getrennt gespeichert werden, während Exchanges ohne org_id-Claim unverändert funktionieren.

We're excited to announce the GA release of __Token Vault with Organization Support__! ISVs building multi-tenant B2B SaaS applications and agents on Auth0 Organizations can now use Token Vault to store and exchange third-party tokens within the context of each organization their users belong to. With this release, Token Vault exchanges and the Connected Accounts flow respect `org_id` end-to-end. Tokens are scoped to `(user, org_id)`, so each organization maintains its own token records for a given user and data isolation between organizations is preserved by default. Token Vault exchanges that do not carry an `org_id` claim continue to behave as before. For complete setup instructions and more, refer to our [documentation](https://auth0.com/docs/secure/call-apis-on-users-behalf/token-vault#use-with-organizations)..

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Auth0: Custom Token Exchange unterstützt Delegated Authorization im Open Early Access

Custom Token Exchange unterstützt nun Delegated Authorization, bei der sub den Benutzer und ein act-Claim nach RFC 8693 den Handelnden ausweist, mit actor_token-Parametern, der setActor()-Action-Methode, Validierung von Auth0-ID-Tokens als Actor Tokens und Erfassung der Actor-Identität in Tenant-Logs.

We're excited to announce that __Custom Token Exchange now supports Delegated Authorization__. This release is available to all __Enterprise, B2B Professional, and B2C Professional customers__. Delegated Authorization covers scenarios where a principal (e.g. a human support agent, a backend service, an AI agent) performs actions in the context of a user. Unlike traditional impersonation where the actor's identity is lost, delegated authorization preserves both identities: the `sub` claim identifies the user being acted for, while a standards-based `act` claim (per [RFC 8693](https://www.rfc-editor.org/rfc/rfc8693.html)) identifies who is actually performing the action. Every token carries a verifiable record of the delegation. With the flexibility to define custom actor semantics and authorization logic via Actions, __customers now have the tools to address emerging access patterns, including agentic AI flows, alongside traditional delegation scenarios__ like support tooling and service-to-service chains. Key __highlights__ of this release: - Actor token parameters: Pass `actor_token` and `actor_token_type` to convey the acting party's credential - `setActor()` Action command: Developers explicitly control when and how delegation `act` claim is included in tokens via the new `setActor()` method - Auth0 ID tokens as actor tokens: Automatic validation when the actor is an Auth0-managed user - Audit trail: Actor identity captured in tenant logs…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Auth0: Anpassung von Access-Token-Scopes in Actions im Early Access

Neue Schnittstellen in Credentials Exchange Actions erlauben im Early Access das Hinzufügen, Entfernen, Setzen, Leeren und Lesen von Ziel-Scopes bei der Access-Token-Ausstellung, mit auf bis zu 1000 Scopes erhöhten Limits, auch für Post Login Actions.

We are excited to announce that we are adding __new Credentials Exchange Actions Access Token Scope Interfaces__ and they are now available in [__Early Access__](https://auth0.com/docs/troubleshoot/product-lifecycle/product-release-stages#early-access "Early Access"). These new interfaces allow you to customize the scopes to be considered when the access token is issued by writing __Credentials Exchange Actions__, considering the restrictions based on API and Client Grants definitions. __Early Access__ functionality includes: - __Add/Remove:__ New interfaces to add or remove target scopes from Credentials Exchange Actions. - __Set/Clear:__ Additional interfaces to clear or set target scopes from Credentials Exchange Actions without having to loop through the list of scopes. - __Read:__ The list of target scopes becomes available immediately after being transformed. - __Limits:__ Increased limits to handle up-to 1000 scopes for both __Credentials Exchange Actions__. - __Bonus:__ The limits were also increased for __Post Login Actions__. - __Docs:__ - __Event Object__: [https://auth0.com/docs/customize/actions/explore-triggers/machine-to-machine-trigger/credentials-exchange-event-object#param-target-scopes\](https://auth0.com/docs/customize/actions/explore-triggers/machine-to-machine-trigger/credentials-exchange-event-object#param-target-scopes "Event Object") - __API Object__: [https://auth0.com/docs/customize/actions…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

DPoP Sender Constraining für Enterprise Connections allgemein verfügbar

DPoP Sender Constraining ist für Okta- und OIDC-Enterprise-Connections in allen Plänen mit Enterprise Connections allgemein verfügbar, sodass Auth0 beim Token Exchange und bei Userinfo-Aufrufen DPoP-Proofs erzeugen kann.

Demonstrating Proof of Possession (DPoP) sender constraining for Enterprise Connections is now generally available. Customers can now establish Okta and OIDC Enterprise Connections with DPoP enabled on those connections. This is available on all plans with Enterprise Connections. DPoP for Enterprise Connections enables Auth0 to generate DPoP proofs when performing token exchange and calling userinfo endpoints on upstream OIDC and/or Okta connections. DPoP is a core building block of FAPI2 and IPSIE (Identity Proofing and Secure Identity Exchange) ecosystems. It provides a lightweight, standards-based way to enforce proof-of-possession (of a private key) without the operational overhead of mTLS token binding. Please see [product documentation](https://auth0.com/docs/authenticate/enterprise-connections/enable-dpop-enterprise-connections) for further details.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Federated Logout für OIDC- und Okta-Enterprise-Connections allgemein verfügbar

Mit angehängtem ?federated an die Logout-URL ruft Auth0 nun den end_session_endpoint des vorgelagerten Identity Providers auf, um dessen Session zu beenden; fehlt dieser Endpoint, wird ein federated_logout_failed-Tenant-Log erzeugt, der Nutzer aber dennoch bei Auth0 abgemeldet.

Federated Logout is now generally available for OIDC and Okta enterprise connections. When a user logs out with `?federated` appended to the logout URL, Auth0 calls the upstream identity provider's `end_session_endpoint` to terminate the IdP session, closing the gap where a lingering IdP session could silently re-authenticate the user on their next login attempt. Note: if federated logout is attempted without providing an `end_session_endpoint`, federated logout will not be able to be completed, and a `federated_logout_failed` tenant log will be generated. The user will be successfully logged out of Auth0 and redirected back to the application, just as with a standard (non-federated) logout. With federated logout: - Auth0 takes the burden off customers by handling IdP session termination - Customers simply indicate if the IdP session should be ended when the Auth0 logout endpoint is reached — no extra setup needed for compliant IdPs - Employers and employees have peace of mind that their data is not accessible when they logout from their applications This feature is available on all plans that include enterprise connections. Read the [documentation](https://auth0.com/docs/authenticate/login/logout/log-users-out-of-idps ) to learn more.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Tenant ACLs mit neuen Signalen für kanonische Domains

Tenant Access Control Lists können nun Regeln gezielt auf kanonische Hostnamen und verbindende IP-Bereiche (IPv4/IPv6 CIDR) anwenden, und das Limit für Attribute pro Signal wurde von 10 auf 20 erhöht.

We have enhanced Tenant Access Control Lists (ACLs) to provide granular control over upstream proxy infrastructure and canonical domain routing. With this update, you can now isolate traffic by enforcing distinct rules on your canonical hostnames while keeping your user-facing custom domains open. ##### What's New? * **Canonical Hostname Routing** * Match access rules directly against your canonical hostnames. This allows you to lock down backend default domains while keeping customer-facing custom domains open and accessible to your users. * **Connecting IP Verification** * Define precise allowed IPv4 and IPv6 CIDR blocks for the infrastructure (such as reverse proxies or content delivery networks) connecting directly to the Auth0 edge. * **Expanded Attribute Quotas** * The limit for Tenant ACL attributes has been increased from 10 to 20 per signal, giving you the additional flexibility needed to scale complex, multi-domain configurations seamlessly. ##### Resources To learn more about Tenant ACLs, click [here](https://auth0.com/docs/secure/tenant-access-control-list)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Suspicious IP Throttling für Custom Token Exchange im Dashboard

Im Dashboard gibt es jetzt eine Konfigurationsoberfläche, über die Administratoren Schwellenwerte zur Drosselung von hochfrequentem Traffic verdächtiger IP-Adressen beim Custom Token Exchange festlegen können.

We have introduced a Dashboard configuration interface for Suspicious IP Throttling, specifically for Custom Token Exchange. This update allows administrators to easily set thresholds to throttle high-velocity traffic from suspicious IP addresses during the token exchange process. Learn more about Custom Token Exchange attack protection [here](https://auth0.com/docs/authenticate/custom-token-exchange/cte-attack-protection)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Non-Unique Emails allgemein verfügbar

Non-Unique Emails ist für alle Kunden allgemein verfügbar und erlaubt mehreren Benutzerkonten dieselbe E-Mail-Adresse in einer neuen Database Connection, wobei ein anderer Primärbezeichner wie Benutzername oder Telefonnummer nötig ist und die Einstellung dauerhaft bleibt.

Non-Unique Emails is now Generally Available (GA) for all Auth0 customers. This feature allows multiple user accounts to share the same email address within a database connection, supporting real-world use cases like families, small businesses, and multi-role users who need separate accounts tied to the same email. **Key Details:** - Available on new database connections only (cannot be enabled on existing connections). - Requires a different primary identifier (username or phone number) to uniquely distinguish users. - All email communications (verification, password reset, etc.) are still sent to the shared email address. - Once enabled on a connection, the non-unique email setting is permanent. **Documentation:** [Non-Unique Emails](https://auth0.com/docs/authenticate/database-connections/non-unique-emails)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Account API mit ACR (Early Access) absichern

Mit dem ACR-EA-Release lässt sich die Token-Ausstellung der Account API für sensible Scopes per Step-up-Authentifizierung absichern, entweder über Actions-basierte Richtlinien oder einen Secure-by-default-Schalter.

Auth0's ACR EA release empowers you to secure Account API token issuance by enforcing step-up authentication for sensitive scopes. Whether your users are managing their authentication factors via Universal Login or Embedded flows, you can now gate access through Actions-driven policies or enable a secure-by-default toggle. This ensures stronger security for self-service account management while maintaining a seamless experience for low-risk actions. Learn more here: [API Settings Auth0 Docs ](https://auth0.com/docs/get-started/apis/api-settings) [My Account API Docs](https://auth0.com/docs/manage-users/my-account-api)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Online Refresh Tokens jetzt in der Beta

Online Refresh Tokens sind für alle Kunden in der Beta verfügbar, werden über den neuen Scope online_access angefordert, sind an die ursprüngliche Session gebunden und werden mit dieser ungültig; die Konfiguration erfolgt pro Audience unter API > Settings.

We are excited to announce that our new feature "Online refresh tokens" is now available to all customers in Beta. This powerful new feature is designed to simplify token management and modernize your application architecture, especially for Single Page Applications (SPAs) allowing you to bind refresh tokens to the sessions they originated from, which provides seamless and consistent continuation of a session when cookies are affected by the browser vendor behaviour across different applications. ### What's in the Beta #### ✨ New configuration options - **Configure specific audiences to provide Online refresh tokens** - online refresh tokens configuration is now available under the API > settings page #### 🔒 Applications Integration - **New scope** — Request the new online_access scope to receive your online refresh tokens, which will be bound to the session - **Refresh tokens normally** — Online refresh tokens will continue your application access while the session exists - **Revoke a session, revoke its refresh tokens** — Once the session is revoked, all its online refresh tokens become invalid, too #### 🚀 Availability - Since online refresh tokens lifecycle is entirely based on their underlying session, online refresh tokens can be issued only in OIDC flows that generate a valid session and can return refresh tokens - Following OIDC standards, implicit sessions that do generate a session but shall not return a refresh token, will not provide online refre…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Fix für leeren login_hint-Parameter bei externen Identity Providern

Auth0 sendet den Parameter login_hint bei Weiterleitungen zu externen Identity Providern künftig nur noch, wenn tatsächlich ein Wert vorhanden ist, wobei der Fix schrittweise über 1–2 Wochen ausgerollt wird und keine Kundenaktion erfordert.

__What's Changing:__ We are fixing an issue where Auth0 was including an empty `login_hint` query parameter when redirecting users to external identity providers. Going forward, `login_hint` will only be included in the authorization request when a value is actually present. __Why This Matters:__ Some external OAuth providers strictly validate request parameters and reject authorization requests that contain empty parameter values. This caused authentication failures for customers whose upstream identity providers do not tolerate empty `login_hint` values — particularly in scenarios where customers do not control the external IdP and cannot modify its validation behavior. __Rollout Timing:__ This fix will be rolled out progressively over the next 1–2 weeks. __Action Required:__ No action is required from customers. If you previously implemented a workaround by [overriding connection parameters](https://auth0.com/docs/authenticate/identity-providers/pass-parameters-to-idps#update-the-connection-static-) to suppress the empty `login_hint`, you may optionally remove that override after confirming the fix is active in your environment.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Resend Email Provider allgemein verfügbar

Resend ist jetzt in allen Auth0-Plänen als vorkonfigurierter E-Mail-Versanddienst allgemein verfügbar und kann direkt in Auth0 eingerichtet werden.

![Resend Email Provider](//images.ctfassets.net/kbkgmx9upatd/38WSnL4J8G0N29XEkycNUh/67a787ba40829ea953a838679b3afcd8/CleanShot_2026-05-07_at_10.07.31_2_2x.png) We're excited to announce that __Resend__ is now __Generally Available__ as an out-of-the-box email delivery provider in Auth0! With this release, you can now configure Resend as your email delivery provider with built-in configuration directly within Auth0. Resend offers a modern, developer-friendly approach to transactional email with excellent deliverability and a clean API. Check out our [documentation](https://auth0.com/docs/customize/email/smtp-email-providers/resend) for detailed setup instructions. Have questions or suggestions? Reach out to us in our community channel and we'd love to hear how Resend is working for you! --- *This feature is available on all Auth0 plans.*

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Auth for MCP allgemein verfügbar

Auth for MCP ist allgemein verfügbar und ermöglicht Authentifizierung und Autorisierung für MCP-Server inklusive CIMD-Registrierung und On-Behalf-Of Token Exchange für KI-Agenten.

We are excited to announce Auth for MCP is now Generally Available. Auth for MCP gives you a straightforward way to add authentication and authorization to any MCP server, so you control exactly who gets access, and what they get access to. Implement authentication, CIMD registration, and OBO token exchange for AI agents. Auth for MCP is a product capability that uses the combination of the following features: ### Client ID Metadata (CIMD) Registration (GA) For MCP clients to connect to MCP servers, they need to identify themselves. But how does a server trust a new client it's never seen? The MCP spec solves this by recommending the use of CIMD: each client hosts a document containing its metadata at a URL that identifies the client. In Auth0, tenant admins provide that URL, and Auth0 fetches the metadata, validates it, and displays it for confirmation before creating the client. You get control over which clients can access your MCP server ensuring no surprise registrations. ### On-Behalf-Of Token Exchange (GA) After a user's agent authenticates with an MCP server and issues a request, it needs to call another API like a Salesforce instance or HR system to finish the job. The question is: how does that second API know the request is legitimate and who it's actually for? On-Behalf-Of Token Exchange lets MCP servers trade the user’s access token for one that works with the downstream API, scoped correctly and still tied to the original user. No shared secrets, no service acco…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Private Key JWT und weitere Signaturalgorithmen für Okta- und OIDC-Connections

Private Key JWT Assertions und die Wahl der Signaturalgorithmen für Client-Assertions sind für Okta- und OIDC-Enterprise-Connections allgemein verfügbar, zudem wird die ID-Token-Prüfung nun um RS384, RS512, PS256, PS384, ES256 und ES384 erweitert.

Private Key JWT assertions and expanded signing algorithm support are now generally available across Enterprise Okta and OIDC Connections. Private Key JWT assertions deliver enterprise-grade security by leveraging asymmetric cryptography to authenticate against your upstream Okta and OIDC identity providers. You now have full control over which signing algorithms Auth0 uses when generating client assertion JWTs - giving you the flexibility to align with your security standards and existing infrastructure. We've also expanded ID token verification on enterprise connections to support additional signing algorithms: RS384, RS512, PS256, PS384, ES256, and ES384. This means fewer integration headaches when connecting to upstream identity providers and greater compatibility across your authentication flows. These capabilities put you in the driver's seat: choose the cryptographic methods that work best for your environment, eliminate integration blockers, and stay ahead of evolving security standards. Please refer to the [product documentation](https://auth0.com/docs/authenticate/enterprise-connections/private-key-jwt-client-auth).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

CMD+K Command Palette im Auth0 Dashboard

Alle Nutzer des Auth0 Dashboards können jetzt per CMD+K eine Command Palette öffnen, mit der sie schnell navigieren, zuletzt besuchte Seiten aufrufen und Aktionen sowie kontextbezogene Aufgaben ausführen.

![CMD+K Command Palette](//images.ctfassets.net/kbkgmx9upatd/60n7SRA7oPIEsPPTco6afZ/be85b9583c66e54af2f311c6093b2b31/CleanShot_2026-05-05_at_12.03.46_2x.png) We're excited to announce the new __CMD+K Command Palette functionality__ is now available to all users in the __Auth0 dashboard__. Get instant access to navigation, quick actions and recently visited pages all from a single keyboard shortcut. __What’s new:__ - __Globally available:__ Always accessible from any page by entering CMD+K. - __Quick navigation:__ Jump to any page, feature, or setting without leaving the keyboard. - __Recently visited:__ Have your last 3 visited pages available at the top. - __Action shortcuts:__ Execute common tasks directly from the palette. - __Contextual actions:__ Get tasks specific to pages right in CMD+K. To keep improving this experience, we’ll be continuously adding more contextual actions and capabilities to the __CMD+K Command Palette__.

Originalquelle(öffnet in neuem Tab)Problem melden