Zum Inhalt springen

Auth0 Release Notes

613 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Auth0, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Signup- und Login-Prompts: Dashboard-Editor, Passkeys, Custom Database

Custom-Prompt-Partials lassen sich nun in einem visuellen Editor im Dashboard verwalten, und sie unterstützen zusätzlich Passkey-Screens sowie die Übergabe erfasster Daten an Custom-Database-Skripte.

You can now manage custom authentication screen partials directly in the Auth0 dashboard with a purpose-built visual editor. Instead of encoding HTML as strings and sending them through the API, you get a proper code editor with syntax highlighting and live feedback. ![Custom Prompts Dashboard UI](//images.ctfassets.net/kbkgmx9upatd/5IuiTcddCX8fTQb9FOQ1oz/e6ab41985aff4f48ec34a18ffec60cc6/Screenshot_2026-04-02_at_1.13.12â__PM.png) The editor includes supporting tools: - **Code snippet library:** pre-built snippets for common use cases like first and last name, phone number, terms of service checkboxes, and more, ready to insert with a click - **Template variable reference:** a clickable list of all context variables available in the partial, for quick insertion without leaving the editor - **Actions shortcut:** open Actions in a new window directly from the editor - **Interactive preview:** click into entry points to edit HTML inline, see visually which entry point each element belongs to, and toggle entry point wrappers off to preview what the prompt looks like in the login flow This update also expands what's possible with partials: - **Passkey screens:** customize passkey authentication screens anywhere they appear in your flow; data capture is supported in the signup flow - **Custom database connections:** data captured from partials is now surfaced in custom database connection scripts Head over to the [Auth0 Docs](https://auth0.com/docs/c…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Session-ID-Rotation bei SAML- und WS-Fed-Authentifizierung

Nach erfolgreichem Login über SAML-P oder WS-Fed wird die Session-ID rotiert und ein neues Session-Cookie ausgestellt, was Implementierungen betrifft, die Session-IDs auslesen oder speichern.

## What's new:                                                                                                   We've updated session handling in SAML-P and WS-Fed authentication flows to align with industry best practices and our existing OAuth2/OIDC behavior. Following a successful login via SAML-P or WS-Fed, the session ID will now be rotated and a new session cookie will be issued. ## What this means for you:                                                                        If your implementation includes client-side logic, downstream services, or integrations that read or store session IDs across SAML-P or WS-Fed login flows, you will now receive a new session ID after authentication completes. Please review and update any such implementations accordingly. This change brings SAML-P and WS-Fed session handling in line with the existing behavior of OAuth2 and OIDC flows, ensuring consistent and secure session management across all authentication protocols.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Neues Spring Boot API SDK: auth0-springboot-api

Das neue offizielle SDK auth0-springboot-api vereinfacht die Absicherung von Spring-Boot-APIs (ab 3.2, Java 17+) mit JWT-Validierung, Scope-Mapping und DPoP-Unterstützung.

We are excited to announce the release of auth0-springboot-api, a new official SDK designed to streamline authentication and security for Spring Boot backend applications. __Key Benefits:__ - __Supports Spring Boot 3.2+ (Java 17+)__ and built for the modern filter-chain pattern.Developers can secure an API by injecting Auth0AuthenticationFilter into their SecurityFilterChain — just configure auth0.domain and auth0.audience in application.yml and go. - __Abstracts the complexity of JWT validation__. Developers no longer need to write fragile boilerplate code to check Audiences or Issuers. The SDK handles JWKS fetching, token validation, and scope-to-authority mapping (SCOPE_ prefix) out of the box. - __Supports DPoP with flexible enforcement modes__ (Allowed, Required, Disabled). Enterprise customers can enforce proof-of-possession token security per RFC 9449 with a single config property — no controller changes needed. __Getting Started:__ - [Quickstart](https://auth0.com/docs/quickstart/backend/java-spring-security5) - [Official Repo](https://github.com/auth0/auth0-auth-java) - [Examples](https://github.com/auth0/auth0-auth-java/blob/main/auth0-springboot-api/EXAMPLES.md)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Google Workspace Directory Sync for Groups im Early Access

Gruppenstrukturen und Mitgliedschaften aus Google Workspace werden im Early Access automatisch in Auth0 Enterprise Groups synchronisiert und können per Dashboard oder Management API verwaltet und in Post-Login-Actions genutzt werden.

We’re excited to announce that __Google Workspace Directory Sync for Groups__ is now available in Early Access (EA)! This enhancement enables the automatic and reliable sync of group structures and memberships from Google Workspace directly into Auth0 Enterprise Groups. __Key Highlights:__ - __Automated group synchronization:__ Continuously mirror your Google Workspace groups into Auth0 to ensure your roles and access permissions remain accurate and up to date without manual intervention or relying on login events. - __Streamlined "Sync All" functionality:__ Enable groups synchronization for your entire Google Workspace Enterprise Connection through either the Management Dashboard or Management API in one step. - __View groups in Auth0:__ Groups provisioned using Google Workspace Directory Sync for Groups can be viewed in the Management Dashboard under Enterprise Groups, or retrieved through the Management API. - __Sync groups from Auth0 to external systems:__ Users and groups provisioned inbound to Auth0 can be synchronized outbound to external systems using Auth0’s Event streams feature. - __Use groups in the Post-Login Action:__ Use group information pushed from Enterprise identity providers in your Auth0 post-login actions to make access control and authorization decisions in Auth0. To join the EA program, please complete the EA Terms & Conditions [form](https://forms.gle/AtySc6Y9fxs15yXj9) and contact your Auth0 Account Team to request activ…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

DPoP-gebundene Tokens auf Enterprise-Plänen allgemein verfügbar

Sender Constraining von Tokens per DPoP (RFC 9449) ist auf Enterprise-Plänen GA und bietet nun zusätzlich Replay-Schutz sowie die Option, DPoP nur für Public Clients oder für alle Clients zu verlangen.

Support for sender constraining tokens using Demonstrating Proof of Possession (DPoP) is now generally available on Enterprise plans. Demonstrating Proof of Possession (DPoP) as defined in RFC9449, is an application level mechanism for binding tokens issued by Auth0 to the client application that requested that token. This is implemented using asymmetric key cryptography and with keys that are generated and managed by the client application - no public key infrastructure (PKI) is required. Sender constraining tokens in this way using DPoP helps to: - enhance security by mitigating against token theft and misuse by unauthorised parties - improve user experience by being able to use longer-lived access tokens without significantly increasing security risk i.e. not requiring frequent user authentication Additional features since the EA release includes replay protection against client applications sending repeated DPoP proofs, and the ability to require DPoP for public clients only, or all clients. A number of Auth0 SDKs have shipped with support for DPoP: - Authentication SDKs supporting DPoP for client applications: auth0-spa-js, auth0-react, auth0-angular, nextjs-auth0, auth0-flutter, Auth0.Swift and Auth0.Android - Authentication SDKs supporting DPoP for APIs/Resource Servers:express-oauth2-jwt-bearer, auth0-api-js, auth0-api-python, aspnetcore-api - Management SDKs supporting DPoP configuration: terraform-provider, go-auth0,deploy-cli, node-auth0, auth0.net For more details…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Anpassbare RP-ID für Passkeys im Early Access

Die RP ID lässt sich nun anpassen, sodass ein einzelner Passkey Nutzer über mehrere Anwendungen unter derselben Root-Domain authentifizieren kann.

Boost Passkey adoption by enabling shared enrollment across subdomains. You can now customize the RP ID to allow a single Passkey to authenticate users across multiple applications under the same root domain.Currently in EA Learn more about customizing RP ID for Passkeys: [Configure Passkey Policy ](https://auth0.com/docs/authenticate/database-connections/passkeys/configure-passkey-policy) Native Passkeys for Mobile Applications - Auth0 Docs - [Native Passkeys for Mobile Applications ](https://auth0.com/docs/authenticate/database-connections/passkeys/native-passkeys-for-mobile-applications) Passkeys - Auth0 Docs - [Passkeys Docs](https://auth0.com/docs/authenticate/database-connections/passkeys)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Echtzeit-Metriken zu API und Rate Limits (Beta)

Metriken zur Management-API-Nutzung und zu Rate-Limit-Ereignissen lassen sich in der Beta in Echtzeit an Observability-Plattformen streamen, mit Datadog-Support sowie New Relic, Prometheus und Splunk via OpenTelemetry.

You can now stream real-time metrics for Auth0 Management API usage and rate limit events directly to your observability platform. These new metric streams give you detailed telemetry on every API request, including success/failure status, specific failure reasons like rate limits, and diagnostic data such as Client ID and request path. This allows you to proactively monitor for rate limit issues, troubleshoot API errors faster, and correlate Auth0 performance with your own application's health, all from within your existing monitoring tools. We've included out-of-the-box support for Datadog, and you can connect to New Relic, Prometheus, and Splunk using OpenTelemetry. This feature is now available in Beta. To get started, check out our Metric Streams documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Forms: Neue Optionen für HTTP Vault Connections

Forms HTTP Vault Connections unterstützen jetzt Client Credentials, API Key und Basic Auth als Autorisierungsmethoden für HTTP Request Flow Actions, wobei Basic Auth die ältere integrierte Option ersetzen soll.

We’re excited to announce that we added new options for __Forms HTTP Vault Connections__! This new set of options allows you to configure different authorization methods for your HTTP Request Flow Actions. ![http-vault-connection-options](//images.ctfassets.net/kbkgmx9upatd/3q09gMqKtLyOuVngPdJlV1/bb95459cac6209d240d42c02002cb922/Changelog.svg) What's new: - __Client Credentials Support:__ Configure [OAuth Client Credentials](https://auth0.com/docs/customize/forms/vaults/http#configure-your-http-vault-connection-for-oauth-client-credentials) and keep the access token fresh for your HTTP Request Flow Actions authorization. - __API Key Support:__ Authorize your HTTP Request Flow Actions using an [API Key](https://auth0.com/docs/customize/forms/vaults/http#configure-your-http-vault-connection-for-api-key), defining the header or query param key and secret value. - __Basic Auth Support:__ Configure and reuse [Basic Auth](https://auth0.com/docs/customize/forms/vaults/http#configure-your-http-vault-connection-for-basic-authentication) authorization for your HTTP Request Flow Actions, helping you replace the legacy built-in option.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Brute Force Protection für Passwordless-Benachrichtigungen

Brute Force Protection verhindert jetzt, dass Passwordless-E-Mail- und SMS-Codes an bereits gesperrte Nutzer gesendet werden.

To improve the end-user experience and mitigate message spam, Brute Force Protection now proactively prevents the sending of passwordless email and SMS codes to users who are already blocked. This update ensures that restricted users cannot continue to trigger unsolicited notifications, closing a gap in our abuse prevention coverage and reducing unnecessary messages For more information on _Brute Force Protection_, check out our [online documentation](https://auth0.com/docs/secure/attack-protection/brute-force-protection).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Actions Transaction Metadata ist jetzt GA

Actions Transaction Metadata ist allgemein verfügbar und ermöglicht es, über event.transaction.metadata und api.transaction.setMetadata eigene Key/Value-Daten zwischen Actions derselben post-login-Ausführung zu teilen.

We are excited to announce that __Actions Transaction Metadata__ is now GA. This feature allows you to set, share, and access, custom data between Actions run in the same `post-login` execution. Functionality includes: - __Accessing Transaction Metadata:__ A new `event.transaction.metadata` object within `post-login` Actions that contains the custom `key/value` pairs, which can be accessed through `key`. - __Setting Transaction Metadata:__ A new `api.transaction.setMetadata` function within `post-login` Actions that serves as interface to set the custom `key/value` pairs. - __Immediate Access:__ Values are available immediately after being set in the calling Action and subsequent Actions. - __Values Types:__ Values can be `boolean`, `number`, `string`, or `string` serialization of `object` and `array`. - __Docs:__ [Actions Transaction Metadata](https://auth0.com/docs/customize/actions/transaction-metadata "Actions Transaction Metadata Docs")

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Actions Modules jetzt im Early Access

Actions Modules sind im Early Access verfügbar und erlauben wiederverwendbaren Code über mehrere Actions und alle Trigger-Typen hinweg, mit eigenen Secrets und Dependencies.

We are excited to announce that __Actions Modules__ is now available in [__Early Access__](https://auth0.com/docs/troubleshoot/product-lifecycle/product-release-stages#early-access "Early Access"). This feature allows you to create, manage, and share reusable code across different Actions within your Auth0 Tenant. __Early Access__ functionality includes: - __Simplified Code Management:__ Reduce code duplication and improve organization by writing common logic once and importing it into any Action where it is needed. This makes your Actions easier to maintain and update. - __Improved Performance:__ Move expensive initialization work into a module that can be reused across multiple Actions. This avoids re-running the same setup code in every execution. - __Cross-trigger Access:__ Actions Modules become available for every Action Trigger type. - __Independent Secrets and Dependencies:__ Actions Modules have independent secrets and dependencies from Actions. - __Docs:__ [Actions Modules](https://auth0.com/docs/customize/actions/modules/actions-modules-overview)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Native to Web SSO ist jetzt allgemein verfügbar

Native to Web SSO ist GA und bringt unter anderem Dashboard-Konfiguration, Refresh-Token-Metadaten in Actions, Step-up-Authentifizierung, React-Native-SDK- und Organizations-Unterstützung.

### Description Native to Web SSO enables seamless single sign-on from native mobile applications to web applications. Users authenticated in a native mobile app can now transition to web content without re-authenticating, providing a frictionless cross-platform experience. ### What's New in GA Building on the Early Access release, GA includes the following enhancements: - **Auth0 Dashboard Support**: Configure Native to Web SSO directly from the Auth0 Dashboard, no longer limited to Management API configuration - **Refresh Token Metadata in Actions**: Access parent refresh token metadata within Session Transfer Actions, enabling richer context for customization and security decisions during the session transfer flow - **Step-up Authentication Support**: Trigger MFA challenges during the Native to Web SSO flow for enhanced security when accessing sensitive web content - **React Native SDK Support**: Native to Web SSO is now available in the Auth0 React Native SDK, supporting both Hooks (`useAuth0`) and class-based approaches - **Organizations Support**: Use Native to Web SSO with Auth0 Organizations to maintain organization context when transferring sessions from native to web - **Web SDK Integration Examples**: New code examples for Auth0 SPA SDK (`@auth0/auth0-spa-js`) and Auth0 React SDK (`@auth0/auth0-react`) for receiving session transfer tokens in web applications - **Enhanced Monitoring & Troubleshooting**: Comprehensive warning log e…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Neue Self-Service-SSO-Templates für Okta SAML und Auth0 SAML

Für Self-Service SSO gibt es zwei neue IdP-Templates für Okta SAML und Auth0 SAML mit schrittweiser, IdP-spezifischer Anleitung statt des generischen Templates.

We’ve expanded our Self-Service SSO capabilities with two new, highly-requested IdP templates for Okta SAML and Auth0 SAML. This update streamlines the configuration process for your enterprise customers, enabling faster, more reliable SSO integration. __Guided, Step-by-Step Configuration__ Previously, setting up connections for providers like Okta SAML required using a generic template. Now, your customers will get a purpose-built, guided experience. Our new templates provide detailed, step-by-step instructions with screenshots specific to each IdP, reducing complexity and eliminating guesswork for your customers' IT teams. __Key Enhancements:__ - New Templates: A dedicated guide for customers who use Okta or Auth0 as their identity provider, making one of the most common connection types easier than ever. - Reduced Support Load: By making the process more intuitive for your customers, we help reduce your team's support burden and speed up your enterprise onboarding flow. Learn more about Self-Service SSO in the [product documentation](https://auth0.com/docs/authenticate/enterprise-connections/self-service-SSO "product documentation").

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Forms: Auth0 Send SMS und Make Call Actions in Flows

In Flows können jetzt über den im Auth0 Tenant konfigurierten Phone Provider per Send SMS und Make Call Action Telefonnachrichten versendet werden, auch mit Custom Phone Provider und Liquid-Syntax.

We’re excited to announce that we added __Flows Auth0 Send SMS and Auth0 Make Call Actions__! This new feature allows you to send phone messages from Flows using the customized Phone Provider at your Auth0 Tenant. ![auth0-notifications-send-sms-make-call-preview](//images.ctfassets.net/kbkgmx9upatd/2npX0Xj85LdlsdStjFLTuN/160af1b5cf5890673df0bb912faac5e9/Changelog.svg) What's new: - __Phone Providers:__ take advantage of the [supported phone providers](https://auth0.com/docs/customize/phone-messages/configure-phone-messaging-providers) that can be configured at your Auth0 Tenant. - __Custom Phone Provider:__ write custom code to send your phone messages to unsupported phone providers using the [Custom Phone Provider Action](https://auth0.com/docs/customize/phone-messages/configure-phone-messaging-providers/configure-a-custom-phone-provider). - __Custom Properties:__ customize [Send SMS Action](https://auth0.com/docs/customize/forms/flows/integrations/auth0#send-sms) and [Make Call Action](https://auth0.com/docs/customize/forms/flows/integrations/auth0#make-call) for the outgoing phone messages including from, to, message, and variables. - __Liquid Syntax:__ use [Liquid syntax](https://auth0.com/docs/customize/email/email-templates/use-liquid-syntax-in-email-templates) at your phone message.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Session Metadata ist für Enterprise-Kunden allgemein verfügbar

Session Metadata ist GA für Enterprise-Kunden und erlaubt, per Actions oder Management API bis zu 25 String-Key-Value-Paare an Sessions zu hängen, auch für OIDC Back-Channel Logout Tokens.

## What's New Session Metadata allows you to attach custom key–value data to a user's session using Actions or the Auth0 Management API. This enables you to persist contextual data throughout the session lifecycle, powering richer integrations, stronger audit trails, and personalized session behavior. ### Key capabilities: - **Set and retrieve metadata in Actions** using `api.session.setMetadata(key, value)` and `event.session.metadata` - **Manage metadata via Management API** with `GET` and `PATCH` on `/api/v2/sessions/{id}` - **Delete individual keys** using `api.session.deleteMetadata(key)` or evict all metadata with `api.session.evictMetadata()` - **Include session metadata in OIDC Back-Channel Logout tokens** for downstream systems to receive context during logout events ### Example usage in Actions: exports.onExecutePostLogin = async (event, api) => { api.session.setMetadata("deviceName", event.request.user_agent); api.session.setMetadata("loginRegion", event.request.geoip?.countryCode); api.session.setMetadata("orgContext", event.organization?.id); }; ### Limits: - Maximum of **25 key-value pairs** per session - Each key and value must be a **string** with max **255 characters** - Metadata is stored as a flat JSON object (no nesting) --- ## Use Cases - **Self-service device management**: Store device names or login locations for user-facing session management UIs - **Keep Me Signed In**: Persist user preferences to cu…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Refresh Token Metadata im Early Access

Enterprise-Kunden können im Early Access bis zu 25 eigene Key-Value-Paare an Refresh Tokens anhängen und diese über Actions und die Management API verwalten.

We're excited to announce that **Refresh Token Metadata** is now available in **Early Access** for Enterprise customers. Refresh Token Metadata allows you to attach custom key-value pairs to refresh tokens, enabling richer context storage and more personalized authentication experiences. ### What's New **Store Custom Data on Refresh Tokens** You can now attach up to 25 custom key-value pairs to each refresh token. This metadata persists throughout the token's lifecycle and can be accessed or modified via the Management API. ```javascript // In Post-Login Action exports.onExecutePostLogin = async (event, api) => { api.refreshToken.setMetadata('deviceName', event.request.user_agent); api.refreshToken.setMetadata('loginRegion', event.request.geoip?.countryCode); api.refreshToken.setMetadata('orgContext', event.organization?.id); }; ``` **Management API Support** Access and manage refresh token metadata programmatically: - `GET /api/v2/refresh-tokens/{id}` - Retrieve token with metadata - `PATCH /api/v2/refresh-tokens/{id}` - Update token metadata - `DELETE /api/v2/refresh-tokens/{id}` - Revoke token Learn more about Refresh Token Metadata in our [documentation](https://auth0.com/docs/secure/tokens/refresh-tokens/refresh-token-metadata)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Auth0 Agent Skills (Beta)

Die Beta von Auth0 Agent Skills liefert strukturierte Anleitungen, mit denen KI-Coding-Assistenten wie Claude Code Auth0-Authentifizierung für viele Frameworks umsetzen und per npx skills add auth0/agent-skills installiert werden können.

We're introducing Auth0 Agent Skills Beta- structured guidance that teaches AI coding assistants how to implement Auth0 authentication correctly across any framework. Agent Skills are AI-native instructions that work with popular coding assistants like Claude Code, Codex, Gemini CLI, etc... They provide production-ready code patterns, security best practices, and step-by-step implementation flows directly within your development workflow. __Key Features__ - Framework Coverage: Support for React, Next.js, Vue, Angular, Express, Nuxt, React Native, and more - Security First: Built-in best practices for MFA, protected routes, and secure token handling - Migration Support: Guided migration from Firebase Auth, AWS Cognito, Supabase, and other providers - Easy Installation: Install via CLI (npx skills add auth0/agent-skills) or directly in Claude Code plugins - Production Ready: Generate complete authentication implementations in minutes __Getting Started__ - Install Auth0 Agent Skills: `npx skills add auth0/agent-skills` - Then ask your AI assistant: "Add auth0 to my app" and you're ready to go. __Learn More__ - [auth0/agent-skills repo](https://github.com/auth0/agent-skills) - [Documentation](https://auth0.com/docs/quickstart/agent-skills)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Credential Guard erkennt jetzt kompromittierte Telefon-Credentials

Credential Guard enthält nun Millionen kompromittierter Telefon-Credentials, sodass Organisationen mit Phone als Identifier betroffene Zugangsdaten erkennen und automatische Reaktionen wie Login-Sperren oder Passwort-Resets auslösen können.

To strengthen defenses across the identity surface, we have added millions of breached phone credentials to our detection capabilities within __Credential Guard__ This enhancement allows organizations using Phone as an Identifier to proactively identify compromised credentials and trigger automated security responses, such as login blocks or password resets. This expansion ensures that phone-based authentication is as secure as traditional email-based methods without impacting system performance. For more information on __Credential Guard__, check out our [online documentation](https://auth0.com/docs/secure/attack-protection/breached-password-detection#detect-breaches-faster-with-credential-guard).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Numerische Tastatur jetzt Standard bei OTP-Eingabe auf Mobilgeräten

Bei SMS- und E-Mail-OTP-Abfragen zeigen Mobilgeräte in Universal Login automatisch die numerische Tastatur an, ohne dass Kunden etwas tun müssen.

We’re excited to roll out a highly requested update to the mobile login experience! We know that every tap matters when it comes to user conversion, so we’ve eliminated a common friction point in the authentication journey. ![otp_numeric_pad.png](//images.ctfassets.net/kbkgmx9upatd/695PTlpJ9e7m5fcfOonCZy/79286d8ef2a1db5c63bf38543ab14c30/otp_numeric_pad.png) Previously, users might have been met with a standard alphabetical keyboard when prompted for a code. Now, for all SMS and Email OTP challenges, mobile devices will automatically surface the numeric keyboard. This change spans 16+ touchpoints—including MFA enrollment, Passwordless login, and password resets—ensuring your authentication flow feels native, intuitive, and fast. ### What do you need to do? Nothing at all. This optimization is automatically enabled for all customers using the Universal Login experience. Your users are already enjoying a smoother, "fat-finger" proof login today! ### Experience it yourself Trigger an MFA challenge or Passwordless login from your mobile device to see the new flow in action. * Visit your [Dashboard](https://manage.auth0.com)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Bessere Bot Detection durch JA4-Signale

Die Bot Detection von Auth0 nutzt jetzt JA4-Signale im Machine-Learning-Modell, was für Enterprise-Kunden mit Attack-Protection-Add-on schrittweise in den kommenden Wochen ausgerollt wird.

To provide a more robust defense against sophisticated automated threats, Auth0 has integrated JA4 signals into the core of our Bot Detection machine learning engine. The addition of JA4 signals allows our models to surface and mitigate sophisticated automated threats that traditional signals often miss. This enhanced security feature is available now to all Enterprise customers with the Attack Protection add-on. The rollout is currently underway and will be completed in the coming weeks, aligned with individual customer release schedules. To learn more about Auth0's Bot Detection Product, click [here](https://auth0.com/docs/secure/attack-protection/bot-detection)

Originalquelle(öffnet in neuem Tab)Problem melden